{"id":26781,"date":"2026-03-06T09:54:09","date_gmt":"2026-03-06T09:54:09","guid":{"rendered":"https:\/\/microvibenews.com\/?p=26781"},"modified":"2026-03-06T09:54:09","modified_gmt":"2026-03-06T09:54:09","slug":"google-says-half-of-all-zero-days-it-tracked-in-2025-targeted-buggy-enterprise-tech","status":"publish","type":"post","link":"https:\/\/microvibenews.com\/?p=26781","title":{"rendered":"Google says half of all zero-days it tracked in 2025 targeted buggy enterprise tech"},"content":{"rendered":"<p><br \/>\n<\/p>\n<div>\n<p id=\"speakable-summary\" class=\"wp-block-paragraph\">A new report by Google found that about half of the zero-day bugs it tracked last year exploited enterprise devices, marking a new high for hackers who are increasingly finding new ways to target large companies and steal their data.<\/p>\n<p class=\"wp-block-paragraph\">According to the search and security giant\u2019s <a href=\"https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/2025-zero-day-review\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">annual report<\/a>, 48% of the tracked zero-days \u2014 vulnerabilities in software that are unknown to its maker at the time they are exploited \u2014 were found in technologies used by corporations and large businesses. About half of those zero-days exploited the very devices that are designed to protect enterprise networks from digital intruders.<\/p>\n<p class=\"wp-block-paragraph\">Google said security and networking devices, such as firewalls made by <a href=\"https:\/\/techcrunch.com\/2026\/02\/26\/cisco-says-hackers-have-been-exploiting-a-critical-bug-to-break-into-big-customer-networks-since-2023\/\" target=\"_blank\" rel=\"noreferrer noopener\">Cisco<\/a> and <a href=\"https:\/\/techcrunch.com\/2025\/03\/17\/hackers-are-exploiting-fortinet-firewall-bugs-to-plant-ransomware\/\" target=\"_blank\" rel=\"noreferrer noopener\">Fortinet<\/a>, and VPN and virtualization platforms like <a href=\"https:\/\/techcrunch.com\/2025\/01\/09\/hackers-are-exploiting-a-new-ivanti-vpn-security-bug-to-hack-into-company-networks\/\" target=\"_blank\" rel=\"noreferrer noopener\">Ivanti<\/a> and <a href=\"https:\/\/techcrunch.com\/2025\/03\/05\/broadcom-urges-vmware-customers-to-patch-emergency-zero-day-bugs-under-active-exploitation\/\" target=\"_blank\" rel=\"noreferrer noopener\">VMware<\/a>, were among the top targeted vendors last year. All four of the companies said hackers have exploited their products on customer networks in recent months.<\/p>\n<p class=\"wp-block-paragraph\">Google\u2019s researchers said that hackers exploited common flaws, like input validation and incomplete authorization processes, to break through firewall and VPN defenses to gain access to customer networks. These classes of bugs are generally easier to exploit, but typically require a software update to fix.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">The company also pointed to other buggy software that makes up the remaining half of enterprise zero-days. Google noted the Clop extortion gang\u2019s campaign against Oracle E-Business Suite customers, which allowed hackers to walk away with reams of <a href=\"https:\/\/techcrunch.com\/2025\/10\/09\/dozens-of-organizations-had-data-stolen-in-oracle-linked-hacks\/\" target=\"_blank\" rel=\"noreferrer noopener\">human resources data from dozens of companies<\/a> about their staff and executives. The hacks affected <a href=\"https:\/\/therecord.media\/harvard-says-limited-number-linked-to-data-theft\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Harvard University<\/a>, the <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/american-airlines-subsidiary-envoy-confirms-oracle-data-theft-attack\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">American Airlines subsidiary Envoy<\/a>, and <a href=\"https:\/\/techcrunch.com\/2025\/11\/07\/washington-post-confirms-data-breach-linked-to-oracle-hacks\/\" target=\"_blank\" rel=\"noreferrer noopener\">The Washington Post<\/a>, among others.<\/p>\n<p class=\"wp-block-paragraph\">The remaining 52% of zero-day bugs were found in consumer and end-user products, such as those made by Microsoft, Google, and Apple, according to the report. Most of the zero-days in consumer software were found in operating systems, with mobile devices also seeing more zero-days than in previous years.<\/p>\n<p class=\"wp-block-paragraph\">Google said it also attributed more zero-days to surveillance vendors than traditional government-backed espionage groups. Surveillance vendors are typically spyware makers and exploit developers, which work on behalf of governments to hack into people\u2019s phones. Google said this shift demonstrated \u201ca slow but sure movement in the landscape\u201d in how governments seek access to hacking tools.<\/p>\n<div class=\"wp-block-techcrunch-inline-cta\">\n<div class=\"inline-cta__wrapper\">\n<p>Techcrunch event<\/p>\n<div class=\"inline-cta__content\">\n<p>\n\t\t\t\t\t\t\t\t\t<span class=\"inline-cta__location\">San Francisco, CA<\/span><br \/>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"inline-cta__separator\">|<\/span><br \/>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"inline-cta__date\">October 13-15, 2026<\/span>\n\t\t\t\t\t\t\t<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<\/div>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/techcrunch.com\/2026\/03\/05\/google-says-half-of-all-zero-days-it-tracked-in-2025-targeted-buggy-enterprise-tech\/\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A new report by Google found t&hellip; <\/p>\n","protected":false},"author":1,"featured_media":26782,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[249],"tags":[10202,1662,15235,12945],"_links":{"self":[{"href":"https:\/\/microvibenews.com\/index.php?rest_route=\/wp\/v2\/posts\/26781"}],"collection":[{"href":"https:\/\/microvibenews.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/microvibenews.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/microvibenews.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/microvibenews.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=26781"}],"version-history":[{"count":0,"href":"https:\/\/microvibenews.com\/index.php?rest_route=\/wp\/v2\/posts\/26781\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/microvibenews.com\/index.php?rest_route=\/wp\/v2\/media\/26782"}],"wp:attachment":[{"href":"https:\/\/microvibenews.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=26781"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/microvibenews.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=26781"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/microvibenews.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=26781"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}