logo

Look What You Made Us Patch: 2025 Zero-Days in Review

ID: 00e8e4b5-8089-5a38-a3df-748492df221f

STIX ID: report--00e8e4b5-8089-5a38-a3df-748492df221f

Feed Name: Threat Intelligence

Threat Score
85/100

Date Published: 2026-03-05

Date Updated: 2026-04-27

Author: Google Threat Intelligence Group

...
...

GTIG's 2025 zero-day landscape report documents a shift toward greater exploitation by commercial surveillance vendors and their customers while PRC-nexus espionage groups remain prolific; financially motivated actors also increased zero-day use, including campaigns tied to CL0P/FIN11 and UNC2165. The report highlights technical spotlights—browser sandbox escapes that exploit OS/hardware components, a multi-stage SonicWall SMA 1000 exploit chain culminating in a reported 0-day local privilege escalation to root, and Samsung DNG image exploits enabling powerful media-store access—and enumerates numerous CVEs observed in the wild, demonstrating active, high-impact exploitation across platforms.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.