Hello 0-days, my old friend: A 2024 zero-day exploitation analysis
cloud.google.com/blog/topi…
GTIG tracked 75 zero-day vulnerabilities exploited in the wild in 2024. We
divided the reviewed vulnerabilities into two main categories: end-user
platforms and products (e.g., mobile devices, operating systems, and browsers)
and enterprise-focused technologies, such as security software and
appliances.
Vendors continue to drive improvements that make some zero-day exploitation
harder, demonstrated by both dwindling numbers across multiple categories and
reduced observed attacks against previously popular targets. At the same time,
commercial surveillance vendors (CSVs) appear to be increasing their
operational security practices, potentially leading to decreased attribution
and detection.
We see zero-day exploitation targeting a greater number and wider variety of
enterprise-specific technologies, although these technologies still remain a
smaller proportion of overall exploitation when compared to end-user
technologies. While the historic focus on the exploitation of popular end-user
technologies and their users continues, the shift toward increased targeting
of enterprise-focused products will require a wider and more diverse set of
vendors to increase proactive security measures in order to reduce future
zero-day exploitation attempts.