Home Cyber Security

Enterprise Tech Becomes Prime Target as Zero-Day Exploits Shift in 2024

Zero-day vulnerabilities remain a powerful weapon in the hands of cyber attackers—but in 2024, their aim shifted significantly toward the enterprise.

That’s the headline finding from Google’s Threat Intelligence Group (GTIG), which this week published its annual review of zero-day exploitation trends. The report, “Hello 0-Days, My Old Friend,” tracked 75 zero-day vulnerabilities exploited in the wild last year. While that’s a decline from 2023’s 98 cases, it still surpasses the 63 recorded in 2022, confirming a long-term trend: attackers aren’t slowing down.

But what’s changing is who they’re targeting—and how.

Enterprise Security Tech in the Crosshairs

According to GTIG, enterprise software, networking tools, and security appliances are becoming high-priority targets. In 2024, 44% of all known zero-day exploits affected enterprise-focused technologies, up from 37% the year before.

“These platforms often operate with elevated privileges and limited monitoring, making them attractive entry points for attackers,” the report states. “They can serve as central hubs for access and persistence.”

Security and networking tools—once considered part of the defence perimeter—are now being weaponised. GTIG highlighted vulnerabilities in widely deployed products from vendors like Ivanti, Palo Alto Networks, and Cisco, which were repeatedly targeted.

Though the total number of enterprise-targeted vulnerabilities dipped slightly, the shift in proportion is significant. It suggests that attackers are focusing their efforts on infrastructure that gives them the broadest potential access, particularly where traditional endpoint detection and response (EDR) tools offer limited visibility.

Browsers, Mobile Platforms See Fewer Exploits

In contrast, consumer-facing platforms saw a relative reprieve. Exploits in web browsers declined by roughly one-third in 2024, with Chrome remaining the most targeted. Mobile vulnerabilities were also down by about 50%, though Android remained a focus—particularly through third-party hardware and software components.

Windows, however, bucked the downward trend. The ubiquitous OS saw a rise in zero-day exploitation for the third consecutive year, with 22 vulnerabilities exploited in 2024, up from 16 in 2023 and 13 in 2022.

GTIG attributes this to Windows’ continued dominance across enterprise and personal environments—making it an enduring favourite for both espionage and financially motivated actors.

Who’s Behind the Exploits?

Of the 75 zero-days tracked, 34 were attributed to specific actors. The majority—18—were linked to espionage operations, either by nation-states or commercial surveillance vendors.

Chinese-aligned threat groups were responsible for five campaigns, most of which targeted network infrastructure, consistent with broader cyberespionage tactics. North Korea was also linked to five exploits, notably combining state-directed espionage with financially motivated attacks.

Commercial surveillance vendors (CSVs), including firms like Cellebrite, were associated with physical-access zero-day chains targeting mobile platforms—often for law enforcement or intelligence clients.

On the cybercrime front, groups like the suspected FIN11 cluster continued to exploit file transfer tools in enterprise environments for extortion purposes. Zero-day exploitation remains a favoured tool when speed and stealth are essential for financial return.

Lessons for the Industry

Despite the year-on-year drop in total zero-day numbers, GTIG warns against complacency. The same classes of vulnerabilities—command injection, use-after-free, cross-site scripting—remain popular and effective. Attackers are simply shifting tactics to exploit infrastructure that offers more bang for their buck.

“Vulnerabilities in enterprise-focused products are now exploited at similar rates to end-user platforms,” GTIG notes. “This is a wake-up call for vendors to invest more in secure development practices, proactive threat modelling, and coordinated disclosure programs.”

As cyber threats evolve, defenders must think more like attackers—identifying and protecting the soft spots in their infrastructure before someone else does.

The full GTIG report is available now via Google’s Threat Intelligence blog. A follow-up webinar later this month will provide deeper analysis and recommendations for enterprise security leaders.