Nearly half of the attacks identified by Google in 2025 targeted companies, an unprecedented level.

The Google Threat Intelligence Group (GTIG) published its annual report on the exploitation of 0-day vulnerabilities worldwide on March 5, 2026. In 2025, researchers identified 90 attacks relying on previously unknown vulnerabilities. Of these, 43 targeted private sector companies, including 9 with financial motivations—both record figures.

Historically, the vast majority of 0-day attacks were carried out by state actors targeting other states or their institutions. The GTIG points to a shift in the threat landscape, notably the growing role of companies that supply spyware to governments or intelligence agencies. In 2025, these “legal” spyware tools enabled more 0-day attacks than those conducted directly by state actors.

The GTIG also notes an increase in exploited vulnerabilities affecting network equipment, edge devices (such as firewalls), and cloud infrastructures.

Stay tuned in real time
Subscribe to
the newsletter
By providing your email address you agree to receive the Incyber newsletter and you have read our privacy policy. You can unsubscribe at any time by clicking on the unsubscribe link in all our emails.
Stay tuned in real time
Subscribe to
the newsletter
By providing your email address you agree to receive the Incyber newsletter and you have read our privacy policy. You can unsubscribe at any time by clicking on the unsubscribe link in all our emails.