logo

Google Confirms 90 Zero-Day Vulnerabilities Actively Exploited in 2025

ID: 7d4729eb-84d4-52d3-a5ca-0957b3ea1d6d

STIX ID: report--7d4729eb-84d4-52d3-a5ca-0957b3ea1d6d

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2026-03-06

Date Updated: 2026-04-21

Author: Abinaya

...
...

Google Threat Intelligence Group's 2025 review reports 90 zero-day vulnerabilities actively exploited in the wild, marking an increase from 2024 and a shift away from browsers toward enterprise infrastructure, mobile operating systems, and edge devices; Commercial Surveillance Vendors and PRC-nexus state actors (e.g., UNC3886, UNC5221) are prominent exploiters, with campaigns like BRICKSTORM targeting source code to accelerate future zero-day discovery. The report highlights enterprise technologies as nearly half of exploited zero-days, the use of chained mobile exploits, the rise of AI-assisted vulnerability discovery, and urges defenses such as strict network segmentation, real-time asset inventories, and tracking Software Bill of Materials (SBoM).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.