Monday, August 3, 2026

Policy & Regulation

Google: Half of 2025 zero-day bugs targeted enterprise tech

Google reports that about half of the zero-day vulnerabilities it tracked in 2025 targeted enterprise devices, highlighting a shift in how hackers attack corporate networks.

Google: Half of 2025 zero-day bugs targeted enterprise tech
Photo: Google Half

In 2025, about half of the zero-day vulnerabilities tracked by Google exploited enterprise devices, highlighting a growing threat to corporate networks. According to a new report by the search and security giant, 48% of these tracked zero-days—which are vulnerabilities in software that are unknown to its maker at the time they are exploited—were found in technologies used by corporations and large businesses. By comparison, the remaining 52% of zero-day bugs were found in consumer and end-user products, such as those developed by Microsoft, Google, and Apple.

Within the enterprise category, about half of those zero-days exploited the very devices designed to protect corporate networks from digital intruders. Google noted that security and networking hardware, alongside virtualization platforms, were primary targets. Specifically, hackers targeted devices from several key vendors:

  • Cisco and Fortinet, which serve as vendors of security and networking devices targeted by hackers.
  • Ivanti and VMware, which act as vendors of VPN and virtualization platforms targeted by hackers.

The report also highlighted how hackers exploited other corporate software. For instance, the Clop extortion gang conducted a campaign against Oracle E-Business Suite customers, allowing attackers to compromise sensitive corporate data. This campaign impacted several high-profile organizations, including:

  • Harvard University
  • Envoy, a subsidiary of American Airlines
  • The Washington Post

Beyond the targets themselves, Google identified a notable shift in the threat actors deploying these exploits. The company attributed more zero-days to surveillance vendors than to traditional government-backed espionage groups. Google described this development as “a slow but sure movement in the landscape” of how governments acquire and deploy hacking capabilities, pointing to an increasing reliance on commercial spyware makers and exploit developers rather than in-house state operations.

Why it matters

The rise in zero-day exploits targeting enterprise infrastructure signals that corporate networks are becoming the primary battleground for both criminal extortion gangs and state-aligned actors. As hackers increasingly target the very security devices meant to protect corporate networks, businesses must adapt to a landscape where commercial surveillance vendors outpace traditional state-backed groups.