Security News > 2022 > April > Google tracked record 58 exploited-in-the-wild zero-day security holes in 2021

Google's bug hunters say they spotted 58 zero-day vulnerabilities being exploited in the wild last year, which is the most-ever recorded since its Project Zero team started analyzing these in mid-2014.
"With this record number of in-the-wild zero-days to analyze we saw that attacker methodology hasn't actually had to change much from previous years," wrote Google security researcher Maddie Stone in Project Zero's third annual review of exploited programming blunders.
A little depressing for network and system defenders, perhaps, however Stone puts a glass-half-full spin on the numbers: "We believe the large uptick in in-the-wild zero-days in 2021 is due to increased detection and disclosure of these zero-days, rather than simply increased usage of exploits."
In the annual review, Stone highlighted 52 of the zero-day exploited vulns that Googlers tracked.
While Project Zero tracked a record number of exploited zero-day bugs in 2021, there are "Key targets" missing from this list, Stone noted.
Unless software vendors pledge to publicly disclose all potentially exploited vulnerabilities, and follow through with this promise, the public doesn't know if a given product has no known security holes under attack - or if the company just isn't sharing that information.
News URL
https://go.theregister.com/feed/www.theregister.com/2022/04/20/google_zero_days/
Related news
- Google Reports 75 Zero-Days Exploited in 2024 — 44% Targeted Enterprise Security Products (source)
- URGENT: Microsoft Patches 57 Security Flaws, Including 6 Actively Exploited Zero-Days (source)
- Patch Tuesday: Microsoft Fixes 57 Security Flaws – Including Active Zero-Days (source)
- Google Acquires Wiz for $32 Billion in Its Biggest Deal Ever to Boost Cloud Security (source)
- Google to purchase Wiz for $32 billion in cloud security play (source)
- Google fixes Chrome zero-day exploited in espionage campaign (source)
- Google fixes exploited Chrome sandbox bypass zero-day (CVE-2025-2783) (source)
- Zero-Day Alert: Google Releases Chrome Patch for Exploit Used in Russian Espionage Attacks (source)
- Google fixes Android zero-days exploited in attacks, 60 other flaws (source)
- Google's got a hot cloud infosec startup, a new unified platform — and its eye on Microsoft's $20B+ security biz (source)