Site navigation

Enterprise Tech Facing Record Zero‑Day Pressure, Finds Google

Tom Quinn

,

zero days
Major vendors like Microsoft, Cisco, Fortinet, and Ivanti were among the most heavily hit as attackers pursue enterprise‑embedded systems.

Enterprise tech firms are squarely in attackers’ crosshairs, with half of all last year’s zero-day exploits hitting them directly, according to the latest report from Google’s Threat Intelligence Group (GTIG).

While the number of tracked zero-days fell slightly from its 2023 peak, down to 90 from 100, Google’s latest threat intelligence report found that attacks targeting enterprise tech reached an all-time high, accounting for almost 50% of total zero-days exploited in 2025.

Google found that security applications and networking software have become a high-value target, particularly for state-sponsored espionage groups, with almost a quarter (23%) of last year’s zero-days directed toward these enterprise systems.

However, edge devices, including routers, IoT sensors and even printers, have become an even more tempting target, largely due to their position at the outer perimeter of a company’s network and limited compatibility with modern endpoint detection and response (EDR) tools, which Google said makes them an ideal blind spot and attack surface for hackers.

Further evidence of hackers’ fixation on enterprise firms comes from the vendors they are zeroing in on.

Microsoft suffered the most hits by far, accounting for 25 zero-day exploits, with Google (11) and Apple (8) trailing, but all are prime targets thanks to their huge user bases for consumer and business products.

However, other vendors, more deeply embedded in the enterprise stack, such as Cisco (4), Fortinet (4), Ivanti (3), and VMware (3), were also aggressively pursued, underscoring the types of victims attackers now prioritise.

“As certain vendors continue to drive improvements that have made vulnerability exploitation more difficult, particularly in the browser and mobile space, adversaries will continue to adapt with more expansive techniques and diverse targets,” said GTIG.

“Enterprise exploitation will continue to be further enabled by the breadth of applications used across infrastructure. Increased numbers of software, devices, and applications expand attack surfaces, with successful exploitation requiring only a single point of failure to achieve a breach.”


Recommended reading


Even as zero-day attacks aimed at enterprises creep up year by year, GTIG found the threat landscape shifting in other, more notable ways, too.  

For the first time, Google found that commercial spyware vendors were behind more zero-days assaults than state-sponsored hacking groups, traditionally the most prolific attackers.

Of 42 unique zero-day exploits tracked last year, fifteen (34.9%) were confirmed as linked to commercial surveillance vendors (CSVs), while another three were suspected of the same, with Google claiming that vendors like Intellexa have become particularly active in procuring and using zero-days.

That compares to twelve exploits directly attributed to state-sponsored espionage, led by Chinese-linked groups, which have dominated zero-days exploits for nearly a decade, though Google noted that did not attribute any zero-days to North Korean groups, a surprising turn from 2024.

Tom Quinn

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data