Security Stop Press : Most Zero-Day Exploitations Are Espionage

Paul Stradling • April 3, 2024

Security Stop Press : Most Zero-Day Exploitations Are Espionage

A recent analysis by Google’s Threat Analysis Group (TAG) and Google Cloud’s Mandiant has suggested that government-backed threat actors are more likely to be behind most exploitations of zero-day vulnerabilities than money-motivated cyber criminals. 


In the report outlining the findings of the analysis, of the 58 zero-days in 2023 that could be attributed to the threat actor’s motivations, 48 of them were found to be attributable to government-backed advanced persistent threat (APT) groups conducting espionage activities. Only 10 were attributed to financially motivated cyber criminals, e.g. ransomware gangs. 



The report singled out the People’s Republic of China (PRC) as the state leading the way for government-backed exploitation.

Featured Article : AI Isn't Slashing Jobs or Wages (Yet)
May 7, 2025
Despite the whirlwind of hype, new research suggests that generative AI chatbots like ChatGPT and Claude have, so far, made barely a ripple in the labour market, leaving jobs and wages largely untouched.
Tech Insight : How Marks & Spencer Was Brought To A Standstill
May 7, 2025
In this Tech Insight, we look at how a major ransomware attack on M&S could happen, who was behind it, how it caused such widespread disruption, and what it means for the company, its customers, and the wider UK retail sector.
More Posts