"Google Report Reveals China's Dominance in Government-Sponsored Zero-Day Exploitation

A zero-day vulnerability refers to a flaw in a system or device that has been identified but not yet patched.

China remains at the forefront of government-sponsored utilization of zero-day vulnerabilities, with cyber espionage groups in the nation exploiting 12 such vulnerabilities in 2023, marking an increase from seven in the previous year, as per a report released by Google on Wednesday.

A zero-day vulnerability refers to a flaw in a system or device that has been identified but not yet patched.

Advertisement

Throughout 2023, Google documented the exploitation of 97 zero-day vulnerabilities in the wild.

This figure represents a growth of over 50 percent compared to the previous year, although it falls short of the record set in 2021, which saw 106 such vulnerabilities exploited, according to findings from Google's Threat Analysis Group (TAG) in collaboration with cybersecurity firm Mandiant.

Advertisement

James Sadowski, Principal Analyst at Mandiant Intelligence, noted, “Attackers have redirected their attention to third-party components and libraries in 2023. Zero-day vulnerabilities within these components and libraries emerged as a primary attack surface, given that exploiting such vulnerabilities can have a widespread impact across multiple products.”

The team also observed a surge in adversary exploitation targeting enterprise-specific technologies in 2023, with a 64 percent increase in the total number of vulnerabilities compared to the previous year. Additionally, there has been a consistent rise in the number of enterprise vendors being targeted since 2019.

Advertisement

Notably, exploitation associated with financially motivated actors saw a proportional decrease last year.

According to the Google report, “Financially motivated actors exploited 10 zero-day vulnerabilities in 2023, constituting a smaller proportion of the total compared to what was observed in 2022.”

Advertisement

The report emphasizes the need for organizations to develop defensive strategies that prioritize addressing threats that pose the greatest risk of harm to both themselves and others.

Read also | Insights from Sam Altman: Elon Musk's Doubts on OpenAI's Success

Advertisement

Read also | Tim Cook Spreads Holi Cheer with Vibrant iPhone Capture

Advertisement