Back Mezha Google Finds Half of 2025 Zero Day Exploits Against Enterprise Devices - Межа
A new Google study shows that approximately half of the zero-day vulnerabilities tracked in 2025 were used against corporate devices. This confirms the growing seriousness of threats to large companies and their data and underscores the need for strengthened enterprise-level cybersecurity.
According to Google’s annual report, 48% of all zero-day vulnerabilities were discovered in technologies used by corporations and large businesses. half of these vulnerabilities affected devices intended to protect corporate networks from cyber threats.
Government-backed sectors are cited among the providers that faced the most massive attacks: Cisco and Fortinet firewalls, VPN solutions and Ivanti and VMware virtualization platforms. Companies say that attackers exploited their products in customers’ networks over the past months.
Analysts explain that hackers exploited common mistakes such as improper input validation and incomplete authorization to bypass firewall and VPN protections and access clients’ internal networks. Although such flaws are usually easier to exploit, fixing them requires updating the corresponding software.
The report also highlights other software with signs of vulnerabilities, which make up the second half of enterprise zero-days. Specifically, the campaign by the Clop group against Oracle E-Business Suite customers allowed attackers to extract significant volumes of HR data employees and executives from dozens of companies. The breaches affected Harvard University, the Envoy unit of a U.S. airline, and The Washington Post, among others.
The remaining 52% of zero-day vulnerabilities were recorded in consumer and end-user products, with Microsoft, Google, and Apple mentioned among them. Most of these vulnerabilities are found in operating systems, and mobile devices also show an increase in the number of suspicious indicators compared with years.
Google also notes that most zero-day vulnerabilities are related to suppliers of security-monitoring solutions, rather than to well-known government espionage groups. Such providers develop surveillance software and exploits that governments use to access users’ devices.
“Slow, but steady movement in the landscape”
Analysts recommend tightening patch management across the system: from firewalls and VPNs to cloud platforms and consumer devices, which can sometimes be the most accessible paths for vulnerabilities. It is important to apply patches promptly, implement multi-layered protection, and regularly conduct penetration tests to reduce the likelihood of a successful attack.
A comprehensive cybersecurity approach, including monitoring, supplier risk management, and staff training, will be a key factor in reducing the risk exposure. Enterprises should focus on updating their system infrastructure and ensuring transparency in the interaction between vendors and internal security teams to improve the speed of threat responses and minimize potential losses.
Against the backdrop of threat distribution among suppliers and consumer products, it is important to understand that attacks are becoming more targeted and sophisticated. It remains critically important to maintain flexibility in security policies and to be ready to quickly adapt responses to new vulnerabilities and exploits.
Related news for you:
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
