Buying Spying: How the commercial surveillance industry works and what can be done about it
ID: d6a3a02b-1314-507e-bc3f-2719ed2df3c7
STIX ID: report--d6a3a02b-1314-507e-bc3f-2719ed2df3c7
Feed Name: Google's Threat Analysis Group (TAG)
Google TAG’s report *Buying Spying* profiles the Commercial Surveillance Vendor (CSV) ecosystem, tracking around 40 vendors and explaining how researchers, exploit brokers, CSVs/PSOAs, and government customers enable turnkey spyware that leverages 0-day exploit chains against high-risk users. It highlights real-world harms, notes CSVs are behind roughly half of known 0-day exploits targeting Google and Android devices, and outlines both international policy initiatives (e.g., the Pall Mall Process) and Google’s ongoing disruption efforts, including vulnerability patching, information sharing, the VRP, and protections for high-risk users.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
