The discovery and exploitation of zero-day vulnerabilities in enterprise-specific software and appliances appears to be outpacing the leveraging of zero-day bugs overall, judging by Google's latest research. In a report published today, the web giant's Threat Analysis Group (TAG) and Mandiant division said they tracked 97 total zero-day vulnerabilities found and exploited by miscreants in 2023, which is considerably more than the year prior, which had 62 such holes. That's a 56 percent uplift. The number of found and exploited enterprise-specific technology zero-day vulnerabilities, however, increased by 64 percent in 2023 compared to 2022 with miscreants exploiting 36 of these bugs. This figure has been rapidly growing over the past five years, we're told, with just 11.8 percent of zero-days in 2019 affecting enterprise software. "This percentage increased to 37.1 percent in 2023, signaling a continued shift in the types of products targeted for malicious exploitation," according to the report [PDF]. This year's report combines analysis from both the Mandiant and TAG teams for the first time since Google bought Mandiant in 2022. It also split the zero-day vulnerabilities into two categories: end-user platforms and products – encompassing mobile devices, operating systems, browsers, and other applications – and enterprise-focused software and appliances. While 61 of the 97 zero-days affected end-user products last year, this number isn't increasing as rapidly as its enterpris...
Miscreants are exploiting enterprise tech zero days more and more, Google warns
The Register
·Jessica Lyons
·Published Mar 27, 2024
·Updated
Affected Software
12 affected components
Microsoft Windows
Apple Safari
Apple iOS
Google Android
Google Chrome
Mozilla Firefox
Barracuda Email Security Gateways
Cisco Adaptive Security Appliances
Ivanti Endpoint Manager Mobile
Ivanti Sentry
Trend Micro Apex One
Fortinet FortiOS