Google says spyware makers and China-linked groups dominated zero-day attacks last year

2026-03-06T07:24:01Z54f73289c7ffd7b04bcda72294498b58c6101452fa9454e181379cb8b72c2781
API-key-theftChina-linkedChromeGeminiGhostSocksGitHubIranLexisNexisMuddyWaterOpenClawPerplexity-CometRATReact2Shellbackdoorchatbot-datadata-breachenterprise-techinformation-stealermalwareprivilege-escalationransomwaresupply-chainsurveillance-cameraszero-day

What happened

The Register security roundup highlights a surge in high-impact incidents: Google reported record zero-day exploitation in 2025 (enterprise tech heavily targeted, with China-linked actors prominent), while Iran-linked MuddyWater/MOIS implants have been found embedded in multiple US networks. Other notable items include widespread IoT/surveillance camera targeting, fake OpenClaw installers delivered via malicious GitHub links (information-stealers and GhostSocks), a confirmed LexisNexis Legal & Professional data breach reportedly via a React2Shell exploit, and a high-severity Chrome/Gemini bug/

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
theregister_security
Record identifier
54f73289c7ffd7b04bcda72294498b58c6101452fa9454e181379cb8b72c2781
Enrichment time
2026-03-06T07:24:01Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Google says spyware makers and China-linked groups dominated zero-day attacks last year · Baitaphish