ZeroHour
The Recordpublished ()ingested

Google says 90 zero-days exploited in 2025 as commercial vendor activity grows

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-0282
Unauthenticated RCE in Ivanti Connect Secure, Policy Secure, and ZTA Gateways

CVE-2025-0282 is a stack-based buffer overflow (CWE-121) in Ivanti Connect Secure, Policy Secure, and ZTA Gateways, reachable by unauthenticated network input. An attacker can trigger it remotely by sending crafted, unauthenticated traffic to a vulnerable gateway, overwriting stack memory and gaining code execution under the appliance's context. Successful exploitation yields unauthenticated remote code execution on the device, giving the attacker control of the VPN/secure-access gateway and a foothold into the protected network. Organizations running any of the affected Ivanti secure-access products are exposed; the source data specifies no version ranges, so defenders should consult Ivanti's advisory for exact affected and fixed releases. The flaw is being actively exploited: it was added to CISA KEV on 2025-01-08 with known ransomware use, and EPSS assigns a 100% probability of exploitation within 30 days (100th percentile), despite no public PoC being known.

Do: Apply the patched releases identified in Ivanti's advisory and follow CISA's required action: hunt for signs of compromise, remediate if indicators are found, and apply updates before returning any device to service. Because exploitation is active and ransomware use is known, treat any appliance that was internet-reachable before patching as potentially compromised (check integrity, rotate credentials). Exact fixed versions were not included in the source data, so verify the correct update path for your branch (including older Connect Secure/Policy Secure releases) against Ivanti's bulletin.

9.0100% KEV ransomware PoC ×3
  • Ivanti Connect Secure
  • Ivanti Policy Secure
  • Ivanti ZTA Gateways
largetens of thousands of internet-exposed appliances (likely 100,000+ total deployments including internal-only gateways)
CVE-2025-21590
Kernel Code Injection Flaw in Juniper Junos OS Exploited in the Wild

Juniper Junos OS contains an improper isolation or compartmentalization flaw (CWE-653) in the kernel that allows a local attacker with high privileges to inject arbitrary code and compromise the integrity of the device. The issue cannot be triggered from the Junos CLI, so exploitation requires shell access, such as via a compromised or rogue high-privileged account or as part of a chained attack. Code running in the kernel gives the attacker deep control of the device, enabling persistent tampering such as backdoors or rootkits. All Junos OS releases before the listed fix versions across the 21.2 through 24.2 branches are affected, covering Juniper's routing, switching, and security product lines. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-03-13, confirming exploitation in the wild, amid headlines reporting China-linked APT UNC3886 breaching Juniper routers with custom backdoors and rootkits.

Do: Upgrade affected systems to 21.2R3-S9, 21.4R3-S10, 22.2R3-S6, 22.4R3-S6, 23.2R2-S3, 23.4R2-S4, or 24.2R1-S2/24.2R2 per branch; releases older than 21.2 have no listed fix and require migration to a supported fixed release. Restrict shell/root access to trusted administrators and, given reported UNC3886 backdoor and rootkit activity on Juniper routers, audit devices for unexpected processes, modified system files, or unusual persistence in the Junos shell. U.S. federal agencies must apply the required remediation per BOD 22-01 due to the KEV listing.

6.72% KEV
  • Juniper Networks Junos OS All versions before 21.2R3-S9
  • Juniper Networks Junos OS 21.4 All 21.4 versions before 21.4R3-S10
  • Juniper Networks Junos OS 22.2 All 22.2 versions before 22.2R3-S6
  • +4 more
masson the order of 1M+ devices running affected Junos OS releases (Junos spans Juniper's global installed base of routers, switches, and firewalls at service…
CVE-2025-61882
Unauthenticated Takeover of Oracle E-Business Suite Concurrent Processing

CVE-2025-61882 is a critical (CVSS 9.8) authentication flaw (CWE-287) in the BI Publisher Integration component of the Oracle Concurrent Processing product within Oracle E-Business Suite. An unauthenticated attacker with network access over HTTP can exploit it remotely with no credentials and no user interaction, achieving a takeover of Oracle Concurrent Processing with high confidentiality, integrity, and availability impact. Any organization running Oracle E-Business Suite 12.2.3 through 12.2.14 is affected, especially instances reachable from the internet. The flaw is being actively exploited in the wild: the Cl0p data-theft group has used it to breach dozens of organizations (including Harvard University, with 1.3 TB of data leaked), CISA added it to the Known Exploited Vulnerabilities catalog on 2025-10-06 with known ransomware use, and EPSS puts its 30-day exploitation probability at 99.7%.

Do: Apply Oracle's released patch or mitigations for CVE-2025-61882 to affected E-Business Suite 12.2.3-12.2.14 deployments as instructed by the vendor; per CISA KEV requirements, federal agencies must follow BOD 22-01 guidance or discontinue use if mitigations are unavailable. Until patched, limit internet exposure of EBS and its BI Publisher/Concurrent Processing HTTP endpoints, and review web and application logs for unauthenticated access and signs of Cl0p-style data theft or follow-on ransomware.

9.8100% KEV ransomware
  • Oracle E-Business Suite (Oracle Concurrent Processing, BI Publisher Integration component) 12.2.3 - 12.2.14
largetens of thousands of EBS environments worldwide across an estimated ~5,000+ customer organizations (est.)
CVE-2025-61884
Unauthenticated SSRF in Oracle E-Business Suite Configurator

Oracle Configurator, a component of Oracle E-Business Suite, is affected by a server-side request forgery (SSRF) flaw in its Runtime UI component (CVE-2025-61884). The flaw is easily exploitable: an unauthenticated attacker with network access over HTTP can trigger the server to make attacker-controlled requests, compromising Oracle Configurator and gaining unauthorized access to critical data or complete access to all data accessible to Oracle Configurator. The CVSS 3.1 score is 7.5 (high) with confidentiality-only impact, meaning the flaw primarily exposes sensitive data rather than altering or destroying it. All supported Oracle E-Business Suite 12.2.x releases from 12.2.3 through 12.2.14 are affected, and Oracle has issued an emergency security update in response. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-10-20 with known ransomware use, and EPSS assigns a 97.8% probability of exploitation in the next 30 days (100th percentile).

Do: Apply the fixes from Oracle's emergency security update for CVE-2025-61884 across all E-Business Suite 12.2.3-12.2.14 environments, prioritizing internet-exposed instances; U.S. federal agencies must remediate per BOD 22-01 or follow applicable cloud-service guidance by the KEV due date. Until patched, restrict untrusted network access to the Configurator Runtime UI (HTTP) and monitor EBS logs and outbound server-side requests for signs of exploitation. Given the confirmed ransomware association, hunt for follow-on activity such as unusual data access or lateral movement originating from EBS servers.

7.596% KEV ransomware PoC
  • Oracle E-Business Suite - Oracle Configurator (Runtime UI component) 12.2.3 through 12.2.14
largetens of thousands of enterprise deployments overall; several thousand Oracle E-Business Suite instances exposed to the internet
CVE-2025-8088
WinRAR Path Traversal (CVE-2025-8088) Enables Arbitrary Code Execution

A path traversal flaw (CWE-35) in the Windows version of WinRAR allows attackers to achieve arbitrary code execution by delivering a specially crafted archive file that writes outside the expected location when it is opened or processed. Because the CVSS 4.0 vector indicates a local attack requiring user interaction, victims are typically infected by extracting or previewing a malicious archive received via phishing, a malicious download, or another delivery channel. A successful attacker gains the privileges of the user running WinRAR, providing an initial foothold that has been used for both espionage and ransomware operations. Anyone running the Windows version of WinRAR — one of the most widely deployed Windows desktop utilities — is affected, and CPE data additionally lists dtSearch as an affected vendor. Exploitation is confirmed in the wild by nation-state actors (e.g., the China-linked Amaranth-Dragon group per related reporting) and criminal actors including ransomware operators; the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-08-12 and carries a near-maximal 94.6% EPSS score.

Do: Update WinRAR to the latest patched release from RARLAB on all Windows endpoints, prioritizing remediation per CISA KEV and BOD 22-01 requirements, and verify that dtSearch deployments bundling the affected component are also updated. Because exploitation requires a user to open or extract a crafted archive, warn users to treat unexpected archive files delivered by email or download with suspicion. Given confirmed ransomware use, hunt across user workstations — not just exposed servers — for suspicious archive-based infections and confirm the patched WinRAR version is installed.

8.494% KEV ransomware
  • RARLAB WinRAR
  • dtsearch
masshundreds of millions of Windows users/devices (est.; RARLAB has historically claimed user counts in the hundreds of millions)
Full article940 words · extracted from therecord.media · click to collapse

Commercial surveillance vendors are increasingly leading the charge in exploiting zero-day vulnerabilities according to a new report.

Google Threat Intelligence Group said it tracked 90 zero-day vulnerabilities that were exploited by a variety of actors last year, surpassing the 78 that were used by threat actors in 2024. The company defines zero-days as vulnerabilities that were maliciously exploited in the wild before a patch could be released publicly.

Of the 90 zero-days tracked last year, GTIG was able to directly attribute exploitation for 42 of them — finding that 18 were either definitively or likely used by commercial surveillance vendors. Fifteen were deployed or likely deployed by state-sponsored espionage groups based in China, Russia, the UAE and other countries. 

The two groups focused their efforts on different technologies, with state-sponsored groups prioritizing edge devices and security appliances like routers or firewalls that enable access to an organization’s network. 

Commercial surveillance vendors primarily targeted mobile devices and browsers — aiming to sell tools that allow for the breach of personal technology. Mobile device zero-days have fluctuated wildly over the last three years, dropping from 17 to 9 between 2023 and 2024, and then rebounding to 15 in 2025. 

Microsoft technology had the largest number of zero-days followed by Google and Apple, according to the report.  

Screenshot 2026-03-03 at 2.55.34 PM.png

Nation-state targeting

Throughout 2025, government agencies across the U.S. and Europe raised alarms about zero-day vulnerabilities in security tools from companies like Ivanti, Cisco, Fortinet and others. 

The GTIG report focuses on zero-days developed by espionage groups based in the People’s Republic of China, noting that in comparison to other state-backed actors, Chinese groups “remained the most prolific users of zero-day vulnerabilities in 2025.”

The groups “continued to focus heavily on security appliances and edge devices to maintain persistent access to strategic targets.”

Edge devices have been repeatedly targeted by state-backed groups because many routers, switches and security appliances sit on the perimeter of an organization's infrastructure and typically lack endpoint detection and response security coverage — serving as a blind spot for defenders. 

One month ago, U.S. officials ordered all federal civilian agencies to remove edge devices that no longer receive vendor updates to firmware or other security patches.

GTIG noted its previous reporting on a campaign involving the Brickstorm malware that was attributed to Chinese state-backed groups. The researchers warned that the campaign marked a “new paradigm for zero-day exploitation where data theft has the potential to enable long-term zero-day development.” 

“Instead of just exfiltrating sensitive client data, the threat actors targeted intellectual property from the victim companies, potentially including source code and proprietary development documents,” the researchers said. 

“This IP could be used to discover new vulnerabilities in the vendor's software, not only posing a threat to the victims themselves but also to victims’ downstream customers.”

Key examples of Chinese exploitation included Juniper Networks’ CVE-2025-21590 and Ivanti’s CVE-2025-0282. The report adds that there have been shifts in Chinese behavior regarding zero-days. 

Chinese groups typically provided zero-days to a small group of well-resourced threat actors but now “an increasing number of activity clusters are exploiting vulnerabilities closer to public disclosure, indicating that PRC-nexus espionage operators have potentially reduced the time to both develop exploits and distribute them among otherwise separate groups.”

Commercial vendors and criminals

Mobile operating system exploitation saw increases in the number of zero-days last year in part because commercial surveillance vendors created exploit chains involving three or more vulnerabilities. 

Google has long warned of the increasing role commercial surveillance vendors are playing in the zero-day industry, highlighting the work of companies like Intellexa in providing “extremely capable spyware to high paying customers” that “erode civil liberties and human rights.”

“This is reflected not only in the gradual proliferation of exploit code targeting specific vulnerabilities, but also by the shrinking gap between the public disclosure of n-day vulnerabilities and their widespread exploitation by multiple groups,” they wrote. 

Boris Cipot, senior security engineer at security firm Black Duck, said that the exploits and capabilities outlined in the report are becoming more widely accessible and less confined to traditional intelligence services. 

When asked who the end user is for zero-days developed by commercial vendors, Clement Lecigne, security engineer at GTIG, said most of the companies they track “primarily sell to nation-states.”

GTIG also tracked nine zero-days developed and exploited by financially-motivated hackers, including a headline-grabbing bug impacting Oracle E-Business Suite that was developed by a hacker claiming affiliation with the Clop extortion cybercriminal group. The group sent extortion emails to hundreds of organizations after exploiting CVE-2025-61882 and CVE-2025-61884 in August 2025. 

The researchers also found overlaps between state-sponsored groups and financially-motivated actors, noting that it saw hackers connected to Russia-based group Evil Corp using CVE-2025-8088 to distribute malware.

The same bug was also used in attacks by the RomCom group — which has conducted both financially-motivated attacks and espionage operations. 

GTIG senior vulnerability intelligence analyst Casey Charrier said the new landscape “is largely defined by expanded access to zero-day capabilities, interwoven with the drastic movement we’ve seen over multiple years towards exploitation of more diversified vendors and products, a shift from which threat actors are certainly seeing success.” 

“The struggle to protect highly privileged edge devices remains a critical gap; security flaws in these high-value assets continue to serve as leverage for wide-scale exploitation,” Charrier said.

No previous article

No new articles

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/google-says-90-zero-days-exploited-apt-spyware-vendors