ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
SUBSCRIBE
ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
ZeroSecurity - Information Security News
No Result
View All Result
Home Exploits

Large Surge in Zero-Day Vulnerabilities, Google Reports

Kyle by Kyle
March 27, 2024 - Updated on April 2, 2024
in Exploits
Reading Time: 2 mins read
Google reports a 50% increase in zero-day vulnerabilities from 2022 to 2023, with a focus shift to third-party components and libraries.
Share on FacebookShare on Twitter

Google has reported a significant surge in zero-day vulnerabilities, with an increase of over 50% from 2022 to 2023. The rise in bugs found in third-party components is particularly concerning.

Google’s 2023 Review: We’re All in This Together

The tech giant’s 2023 review, titled ‘We’re All in This Together’, brings together the findings of its Threat Analysis Group (TAG) and Mandiant research teams. The teams found a total of 97 zero days in 2023, just short of the record 106 detected in 2021.

You might also like

Hackers Exploit Maximum-Severity Cisco Zero-Day Bug Since 2023 (CVE-2026-20127)

DoubleClickjacking – The Stealthy New Web Exploit Threatening User Security

Critical Vulnerabilities Exposed in Ruijie Networks Cloud Platform

Investments in Security by End-User Platform Vendors

The report highlights the “notable investments” made by end-user platform vendors such as Apple, Google, and Microsoft to curb the number of exploitable zero days. These efforts have rendered certain types of threats “virtually non-existent” today.

Enterprise-Focused Technologies: A Different Story

However, the situation is starkly different for enterprise-focused technologies. Google observed a 64% year-on-year increase in zero days in this sector, along with a general uptick in the number of vendors targeted since at least 2019. The report points out a specific focus on security software and appliances over the past year.

Increasing Threats to Enterprise Technologies

“On the enterprise side, we see a wider variety of vendors and products targeted, and an increase in enterprise-specific technologies being exploited,” the report states.

The report emphasizes the importance of quick discovery and patching of bugs to shorten the lifespan of the exploit and increase the cost for attackers to maintain their capabilities. It calls for the industry to apply these lessons to the wider ecosystem of vendors now finding themselves under attack.

Google’s Key Takeaways

The report also highlights several notable trends:

  • Attackers are shifting their focus to third-party components and libraries, as exploiting these vulnerabilities can scale to affect more than one product.
  • Commercial spyware companies were behind 75% of zero days targeting Google products and Android ecosystem devices in 2023, and 60% of zero days in browsers and mobile devices overall.
  • China was responsible for more government-driven zero days than any other state in 2023, with a total of 12.
  • Financially motivated actors accounted for just 10 zero-days, fewer than the number observed in 2022.
Tags: zero day
Previous Post

Hackers Offered 10% of Funds Recovered After $16M Curio Smart Contract Exploit

Next Post

Emerging Phishing Kit ‘Tycoon 2FA’ Bypasses MFA, Threatens Email Security

Kyle

Kyle

Writer, and editor at ZeroSecurity. Interested in Information Security, the Blockchain, and an overall tech enthusiast. "Formal education will make you a living; self-education will make you a fortune." Contact me here: [email protected]

Recommended For You

Photo of the CISCO logo and text saying "You have been hacked!"

Hackers Exploit Maximum-Severity Cisco Zero-Day Bug Since 2023 (CVE-2026-20127)

March 6, 2026
What is DoubleClickJacking?

DoubleClickjacking – The Stealthy New Web Exploit Threatening User Security

January 1, 2025

Critical Vulnerabilities Exposed in Ruijie Networks Cloud Platform

December 25, 2024

Vulnerability (CVE-2024-54143 ) Discovered in OpenWrt’s Firmware Upgrade System

December 13, 2024

Cybercriminals Unleash Advanced Phishing-as-a-Service Toolkit Targeting Microsoft 365 Users

November 29, 2024

Major Security Vulnerability Uncovered in qBittorrent Client

November 1, 2024

Related News

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

January 30, 2026
KPMG Netherlands Listed as Victim by Nova Ransomware Group

KPMG Netherlands Listed as Victim by Nova Ransomware Group

January 24, 2026
RansomHouse Claims Breach of Key Apple Assembler Luxshare

RansomHouse Claims Breach of Key Apple Assembler Luxshare

January 20, 2026
ZeroSecurity - Information Security News

We cover the latest in technology news, Crypto, Artificial Intelligence, and the threat trends impacting these sectors.

Categories

Piracy

Tutorials

Programming

Malware Analysis

Downloads

  • Contact us
  • Press
  • Writers
  • Privacy Policy
  • Terms of Service

© 2026 ZeroSecurity, All Rights Reserved.

No Result
View All Result
  • Home
  • Security
    • Tools
  • Exploits
  • Data Breaches
  • Malware
  • Privacy
  • Mobile Security
  • Contact Us
    • Press
  • Privacy Policy

© 2026 ZeroSecurity, All Rights Reserved.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.