Google: Half of 2025’s 90 Exploited Zero-Days Aimed at Enterprises

2026-03-05T19:24:22Z8bd81197ab622cfb3d8ddba38b184c37012c5b1c488ca39bf8b8a906faceb984
2fa-phishingcatalyst-sd-wanchinaciscocisco-asacorunacredential-marketplacecve-2026-20122cve-2026-20128cybercrime-forumdata-breachenterprise-targetingevgenii-ptitsynexploited-vulnerabilityios-exploit-kitleakbaselexisnexis-incident','cyberinsurance','zurich-beazley-acq','fundnation-statephishingransomwaresecure-fmcsecure-ftdspyware-vendorstycoonzero-day

What happened

A SecurityWeek roundup: Google reports that half of 2025’s 90 exploited zero-days targeted enterprises, with spyware vendors and China prominent among stated leads. Cisco warns of additional in-the-wild Catalyst SD‑WAN exploits (adds CVE-2026-20128 and CVE-2026-20122) and released patches for 48 critical vulnerabilities across ASA, Secure FMC and FTD products. A nation-state iOS exploit kit named “Coruna”—originating with Russian state actors—has been observed powering broader criminal campaigns. Law enforcement actions and breaches: a Russian ransomware operator (Evgenii Ptitsyn) pleaded/guil

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityweek
Record identifier
8bd81197ab622cfb3d8ddba38b184c37012c5b1c488ca39bf8b8a906faceb984
Enrichment time
2026-03-05T19:24:22Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Google: Half of 2025’s 90 Exploited Zero-Days Aimed at Enterprises · Baitaphish