Alarming Trend: 44% of 2024’s 75 Zero-Day Exploits Target Enterprise Security Products, Google Reveals


# Zero-Day Vulnerabilities Decline in 2024, Enterprise Products Increasingly Targeted

Google’s Threat Intelligence Group (GTIG) reports that zero-day vulnerabilities exploited in the wild decreased to 75 in 2024, down from 98 in 2023. Notably, 44% of these vulnerabilities targeted enterprise products, with 20 flaws specifically identified in security software and appliances.

The report highlights significant shifts in exploitation patterns: “Zero-day exploitation of browsers and mobile devices fell drastically, decreasing by about a third for browsers and by about half for mobile devices compared to last year.” Multiple zero-day exploit chains continue to primarily target mobile devices, accounting for approximately 90% of such attacks.

## Breakdown by Platform and Vendor

– Microsoft Windows: 22 zero-day flaws
– Android: 7 vulnerabilities (3 in third-party components)
– Google Chrome: 7 vulnerabilities
– Apple: 5 vulnerabilities (3 in Safari, 2 in iOS)
– Mozilla Firefox: 1 vulnerability

Among the 33 zero-days targeting enterprise software, 20 affected security and network products from vendors like Ivanti, Palo Alto Networks, and Cisco. GTIG researchers explained: “Security and network tools and devices are designed to connect widespread systems and devices with high permissions required to manage the products and their services, making them highly valuable targets.”

## Threat Actors Behind the Exploits

Of the 75 zero-days, 34 have been attributed to six threat activity clusters:

1. State-sponsored espionage (10): China (5), Russia (1), South Korea (1)
2. Commercial surveillance vendors (8)
3. Non-state financially motivated groups (5)
4. North Korean state-sponsored groups with dual espionage/financial motives (5)
5. Russian non-state groups conducting both financial attacks and espionage (2)

## Notable Attack Examples

Google discovered a malicious JavaScript injection on the Diplomatic Academy of Ukraine’s website in November 2024, exploiting CVE-2024-44308 and CVE-2024-44309 to gain unauthorized access to Microsoft login services.

Additionally, Google identified an exploit chain targeting Firefox and Tor browsers using CVE-2024-9680 and CVE-2024-49039 to escape the Firefox sandbox and deploy RomCom RAT, attributed to a threat actor known as CIGAR.

## Future Outlook

Casey Charrier, Senior Analyst at GTIG, noted: “Zero-day exploitation continues to grow at a slow but steady pace. However, we’ve also started seeing vendors’ work to mitigate zero-day exploitation start to pay off.” While historically targeted products show fewer exploits due to improved security measures, the shift toward enterprise products requires a broader range of vendors to enhance their security posture.

Share This Article