• News/
  • https://www.theregister.com/2025/04/29/enterprise_tech_zeroday_google/

75 zero-days exploited in 2024 with focus on enterprise tech

The Register
·
Connor Jones
·
Published Apr 29, 2025
·
Updated

Google says that despite a small dip in the number of exploited zero-day vulnerabilities in 2024, the number of attacks using these novel bugs continues on an upward trend overall. Data released by Google Threat Intelligence Group (GTIG) today, timed with the ongoing RSA Conference 2025, revealed that 75 zero-days were exploited last year. The number is down from 2023's figure of 98, but an increase from 63 the year before, suggesting that zero-days continue to be a hot commodity for the most well-resourced attackers. Disregarding the inherent, obvious advantage that novel, patchless vulnerabilities provide to attackers, it's not just Google saying that zero-days are easier to come by these days ... Over 50 percent of the confirmed zero-days were used for cyberespionage campaigns carried out by state-sponsored groups and customers of spyware companies, or as Google calls them, "commercial surveillance vendors." Google's researchers highlighted China and spyware companies – none of which were named specifically – as the main culprits here, exploiting five and eight zero-days respectively in 2024. However, North Korea also featured with its state-backed attackers accounting for five zero-day exploits – the first time the country has been mentioned in the same breath as the usual leaders in this regard. "GTIG tracked 75 exploited-in-the-wild zero-day vulnerabilities that were disclosed in 2024," said Google's researchers. "This number appears to be consistent with a consolidatin...

Read full article

Affected Software

4 affected components
Ivanti Cloud Services Appliance
Palo Alto Networks PAN-OS
cisco Adaptive Security Appliance
Ivanti Connect Secure VPN
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the trend of zero-day vulnerabilities exploited in 2024, particularly in enterprise technology.

2

What security implications are discussed regarding zero-day vulnerabilities?

The article highlights the increasing attacks leveraging zero-day vulnerabilities, posing significant risks for enterprise security.

3

How many zero-days were exploited in 2024 according to the article?

Seventy-five zero-days were reported as exploited in 2024.

4

Which products or software are affected by these vulnerabilities?

Affected products include Ivanti Cloud Services Appliance, Palo Alto Networks PAN-OS, Cisco Adaptive Security Appliance, and Ivanti Connect Secure VPN.

5

What trend is observed in the exploitation of zero-day vulnerabilities?

Despite a slight decrease in the number of exploited zero-days, the overall trend of attacks is increasing.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203