/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

FireEye details how zero-days were exploited worldwide from 2012 to 2019, says it was able to link the use of 55 zero-day exploits to state-sponsored operations

The collection of countries using those secret hacking techniques has expanded far beyond the usual suspects.

Wired Andy Greenberg

Context & Ripple Effects

FireEye's report is the product of years of attribution work: by tracing who deployed each of 55 zero-day exploits between 2012 and 2019 back to state-sponsored operators, it turns what was previously scattered incident response into a single dataset on how governments actually stock and spend their offensive arsenals. The headline finding is breadth — the collection of countries using these techniques has expanded well beyond the traditional major powers.

The arc since then validates the report's framing as a baseline rather than a peak. Mandiant's later overview of 55 zero-days exploited in 2022 alone — mostly in Apple, Microsoft, and Google products, with Chinese groups the most active — shows annual exploitation now matching what FireEye attributed across seven years, while Google's researchers counted 97 zero-days observed in the wild in 2023, up 50% year over year and dominated by espionage actors.

First-order effects

  • Defenders and the affected vendors gain a public attribution map: knowing which exploits trace to which states lets network owners prioritize patching and threat hunting against specific national adversaries rather than generic malware.

Second-order effects

  • Commercial tracking becomes a competitive discipline — FireEye's dataset sets the template that Google's Project Zero and Mandiant's annual reviews now follow, pressuring every security vendor to publish zero-day telemetry or cede the attribution narrative.

Third-order effects

  • As the user base of state-grade exploits widens beyond the usual suspects, the case for formal policy over government stockpiles strengthens — a debate already visible when the US was shown to have used zero-days before it had policies governing them — pushing toward disclosure norms and stockpile-reduction rules.

The trend: State-sponsored zero-day exploitation is broadening from a handful of major powers to a wider set of nations, with commercial researchers turning annual exploit counts into the industry's measuring stick.

Discussion

  • @thegrugq Thaddeus E. Grugq on x
    This does not show what they think it shows. Israel. 1 0day?! 8200 be slacking not hacking. Australia. 0 0days? ASD Aussie Slacker Dept. This map shows 0day death where the death has been attributed. Nothing more. It's as content free as a rice cracker https://www.wired.com/...
  • @drbvaler Brandon Valeriano on x
    Interesting, certainly lots of under-reporting for undiscovered zero days but matches quite well to what we know now. Of course China, US and Russia but you also have the contractor players - UAE and Uzbek. https://www.wired.com/...
  • @thegrugq Thaddeus E. Grugq on x
    This map does not show what they think it shows. Israel, 1 0day? 8200 be slacking not hacking Australia, 0 0days? ASD Aussie Slacker Directorate. This is a map of 0day deaths where the death is attributed. Nothing more. https://www.wired.com/...
  • @fireeye @fireeye on x
    Learn about an increase in #zerodays leveraged by groups suspected to be customers of companies that supply offensive cyber capabilities in the 1st blog post in a series that highlights the value of cyber #threatintel in enabling vulnerability management: http://r.socialstudio.ra…