• News/
  • https://www.bleepingcomputer.com/news/security/google-97-zero-days-exploited-in-2024-over-50-percent-in-spyware-attacks/

Google: 97 zero-days exploited in 2024, over 50% in spyware attacks

BleepingComputer
·
Sergiu Gatlan
·
Published Apr 29, 2025
·
Updated

Google's Threat Intelligence Group (GTIG) says attackers exploited 75 zero-day vulnerabilities in the wild last year, over 50% of which were linked to spyware attacks. These numbers are down from 97 zero-days in 2023 but up from 63 in 2022, which GTIG analysts attributed to year-to-year swings reflecting expected variation within an upward trajectory for attacks exploiting zero-days, which the company defines as vulnerabilities exploited in the wild before vendors release patches. They noted that cyber-espionage threat actors—including government-backed groups and commercial surveillance vendors' customers—were responsible for more than half of attributable zero-day attacks in 2024. Out of these, China-linked groups exploited five zero-days, commercial surveillance customers eight, while North Korean operators were linked to five zero-day exploits for the first time, used in attacks blending espionage and financial motives. Last year, Google's Threat Analysis Group (TAG) and Google subsidiary Mandiant saw 97 zero-days exploited in attacks, a surge of over 50 percent compared to the previous year's 62 vulnerabilities, many also linked to spyware vendors and their clients. While annual counts have fluctuated massively over the past four years, the average trend line shows a steady increase in zero-day exploitation. In 2024, end-user platforms and products (e.g., web browsers, mobile devices, and desktop operating systems) bore the brunt of this activity, End-user platforms and...

Read full article

Affected Software

6 affected components
Google Chrome
Microsoft Windows
Ivanti Cloud Services Appliance
Cisco Adaptive Security Appliance
Palo Alto Networks PAN-OS
Ivanti Connect Secure VPN
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main focus of the article?

The article reports on the exploitation of 97 zero-day vulnerabilities in 2024, with a significant portion linked to spyware attacks.

2

How many zero-day vulnerabilities were exploited in 2024?

According to Google's report, 97 zero-day vulnerabilities were exploited in 2024.

3

What percentage of zero-day exploits were associated with spyware?

Over 50% of the exploited zero-day vulnerabilities were associated with spyware attacks.

4

Which major products are mentioned as being affected by these vulnerabilities?

The affected products include Google Chrome, Microsoft Windows, Ivanti Cloud Services Appliance, Cisco Adaptive Security Appliance, Palo Alto Networks PAN-OS, and Ivanti Connect Secure VPN.

5

How does the 2024 zero-day exploitation compare to previous years?

The 2024 figures reflect a decline from 97 zero-days exploited in 2023 but an increase from 63 zero-days exploited in prior years.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203