Skip to content
Information Technology

Google and Mandiant reveal rise in Zero-Day vulnerabilities exploited in 2023

Mandiant 2 mins read

Google's Threat Analysis Group (TAG) and Mandiant, renowned leaders in cybersecurity research, have released their annual report on zero-day vulnerabilities, highlighting a significant surge in exploitation incidents witnessed in 2023. The report, available here, unveils crucial insights into the evolving landscape of cyber threats and underscores the urgent need for enhanced vigilance and collaborative efforts across the industry.

According to the findings, 97 zero-day vulnerabilities were observed exploited in-the-wild throughout 2023, marking a notable escalation from the previous year's figure of 62 vulnerabilities. While this increase is substantial, it falls short of the record high of 106 vulnerabilities recorded in 2021, providing a nuanced perspective on the evolving threat landscape.

Key contributors to the discovery of these vulnerabilities include Google's TAG and Mandiant, who collectively identified 29 of the exploited zero-day vulnerabilities. Their relentless dedication to uncovering emerging threats has been instrumental in fortifying cyber defences worldwide.

The vulnerabilities were categorised into two primary domains: end-user platforms and products, encompassing mobile devices, operating systems, browsers, and other applications, and enterprise-focused technologies, including security software and appliances. Notably, the report emphasises that despite notable strides in addressing vulnerabilities, the pace of zero-day discovery and exploitation remains elevated compared to pre-2021 levels.

Further analysis reveals compelling insights into threat actor motivations, with espionage actors accounting for the majority of exploits. Of the 58 zero-days attributed to threat actors' motivations, 48 were linked to espionage activities, while financially motivated actors accounted for the remaining 10.

The report sheds light on the prominent role of the People's Republic of China (PRC) in government-backed exploitation, with PRC cyber espionage groups exploiting 12 zero-day vulnerabilities in 2023, a significant increase from seven incidents in 2022.

End-user platforms and products bore the brunt of zero-day exploits, with 61 vulnerabilities affecting these systems, underscoring the critical need for fortified defences in consumer-facing technologies. Conversely, enterprise-focused technologies witnessed a surge in targeting, with a 64 percent increase observed in adversary exploitation compared to the previous year.

A notable shift was observed in the nature of vulnerabilities, with a higher prevalence of bugs detected in third-party components and libraries as opposed to first-party code. Additionally, the report highlights disparities between operating systems, with Android and iOS witnessing increased targeting, and web browsers such as Chrome and Safari facing a substantial number of zero-day exploits.

While acknowledging the progress made by end-user platform vendors such as Apple, Google, and Microsoft in mitigating vulnerabilities, the report underscores the necessity for sustained collaborative efforts to confront emerging cyber threats effectively.



More from this category

  • Information Technology
  • 12/12/2025
  • 08:11
Datavault AI Inc.

Datavault AI Inc. (NASDAQ: DVLT) Announces a Distribution Date of Dec. 24, 2025, for the Dream Bowl Meme Coin Tokens to All Eligible Record Equity Holders of Datavault AI and Holders of Common Stock of Scilex Holding Company

PHILADELPHIA, Dec. 11, 2025 (GLOBE NEWSWIRE) -- via IBN-- Datavault AI Inc. (NASDAQ: DVLT) (“Datavault AI” or the “Company”), a leader in data monetization, credentialing, and digital engagement technologies, today announced that its board of directors (the “Datavault Board”) has set Dec. 24, 2025, as the distribution date for the Dream Bowl 2026 Meme Coin token (the “Meme Coin”) to all eligible record equityholders of Datavault AI. Dec. 24, 2025, will also be the distribution date for Datavault AI’s voluntary distribution of Meme Coins to record holders of common stock of Scilex Holding Company (NASDAQ: SCLX), which is being made…

  • Information Technology
  • 12/12/2025
  • 05:26
Denodo Technologies Inc. ("Denodo")

Denodo Named a Leader in the 2025 Gartner® Magic Quadrant(TM) for Data Integration Tools for Six Consecutive Years

Denodo believes this recognition is due to the strength of its AI capabilities and the loyalty of its diverse customer basePALO ALTO, Calif., Dec. 11, 2025 (GLOBE NEWSWIRE) -- Denodo, a leader in data management, today announced that Gartner® has positioned the Company as a Leader for the sixth consecutive year in its 2025 Magic Quadrant for Data Integration Tools. “Data integration tools remain a fundamental architectural component as organizations increasingly seek improved capabilities to support their operational, analytical and AI use cases,” states Gartner. “This research helps data and analytics leaders make their decisions by analyzing 20 vendors in…

  • Information Technology
  • 11/12/2025
  • 21:11
Patton Electronics Co.

Patton Honored with Gold-Level Innovators Award

Cabling Installation & Maintenance has recognized Patton’s CopperLink® CL-SFP Ethernet Extender as among the structured cabling industry's most innovative cabling and communications technology products for 2025.CopperLink®... Going the Distance!“I would like to congratulate Patton on their gold-level honoree status.”Patrick McLaughlinChief EditorCabling Installation & MaintenanceGAITHERSBURG, Md., Dec. 11, 2025 (GLOBE NEWSWIRE) -- Patton—world-renowned US manufacturer of networking and communications technology—announced today that its CopperLink® CL-SFP “world’s smallest” Ethernet Extender has won the 2025 Innovators Award from Cabling Installation & Maintenance Magazine.The CL-SFP Ethernet Extender is celebrated among the most innovative products introduced in the year 2025.Judges. An esteemed and experienced panel of…

Media Outreach made fast, easy, simple.

Feature your press release on Medianet's News Hub every time you distribute with Medianet. Pay per release or save with a subscription.