Vulnerabilità ed exploit · Exploit zero-day
Zero-day colpiscono dispositivi enterprise nel 2025 Google Threat Intelligence Group ha tracciato 90 zero-day sfruttati nel 2025. Quasi la metà (48%) ha preso di mira tecnologie enterprise, incluse firewall, VPN e piattaforme di virtualizzazione. State-sponsored groups hanno favorito edge e security appliances; commercial surveillance vendors hanno mirato mobile e browser.
7 fonti · 6 mar
CVE in questo aggiornamento
19 CVE
Distribuite tra Connect Secure, Policy Secure, Neurons for ZTA gateways e altri pacchetti correlati.
4 critiche · 13 alte · 2 medie · 0 basse
19 in CISA KEV · 17 con EPSS sopra 1%
1 con codice di exploit pubblico funzionante o integrato
Severità più alta: CVE-2025-43300 · 10.0 CRITICAL
EPSS più alto: CVE-2025-0282 · 100%
Mostriamo le prime 10 per KEV, EPSS e severità.
Cronologia 6 mar Segnalato da Infosecurity Magazine 5 mar Segnalato da TechCrunch Security 2 gen Scadenza federale CISA per CVE-2025-14174 superata12 dic CVE-2025-14174 aggiunto al KEV CISA1 dic Scadenza federale CISA per CVE-2025-21042 superata10 nov Scadenza federale CISA per CVE-2025-61884 superata27 ott Scadenza federale CISA per CVE-2025-61882 superata20 ott CVE-2025-61884 aggiunto al KEV CISA6 ott CVE-2025-61882 aggiunto al KEV CISA11 set Scadenza federale CISA per CVE-2025-43300 superata2 set Scadenza federale CISA per CVE-2025-8088 superata21 ago CVE-2025-43300 aggiunto al KEV CISA12 ago CVE-2025-8088 aggiunto al KEV CISA22 lug CVE-2025-6558 aggiunto al KEV CISA17 apr Scadenza federale CISA per CVE-2025-2783 superata27 mar CVE-2025-2783 aggiunto al KEV CISA14 feb Scadenza federale CISA per CVE-2025-23006 superata24 gen CVE-2025-23006 aggiunto al KEV CISA15 gen Scadenza federale CISA per CVE-2025-0282 superata8 gen CVE-2025-0282 aggiunto al KEV CISAFonti 6 mar Infosecurity Magazine
Zero‑Day Attacks on Enterprise Software Reach Record High
Almost a quarter of the zero days detected by Google in 2025 targeted security and networking appliances
originale 6 mar Cybersecurity Dive
Nearly half of exploited zero-day flaws target enterprise-grade technology
A report by Google Threat Intelligence Group warns that AI will be used to speed and scale attacks in 2026.
originale 5 mar TechCrunch Security
Google says half of all zero-days it tracked in 2025 targeted buggy enterprise tech | TechCrunch
Enterprise software was a major focus of zero-day activity during 2025, with security and networking devices, like firewalls, VPNs, and virtualization platforms among the most targeted by malicious hackers.
originale Riepilogo fornitore: Microsoft
Riepilogo fornitore: Cisco
Riepilogo fornitore: Fortinet
Riepilogo fornitore: Ivanti
Riepilogo fornitore: VMware
Part of the PlainSec briefing for 2026-03-07
Every edition of this story: Zero-day colpiscono dispositivi enterprise nel 2025
Altro da oggi
Vulnerabilità ed exploit · Exploit zero-day
Zero-day colpiscono dispositivi enterprise nel 2025 Google Threat Intelligence Group ha tracciato 90 zero-day sfruttati nel 2025. Quasi la metà (48%) ha preso di mira tecnologie enterprise, incluse firewall, VPN e piattaforme di virtualizzazione. State-sponsored groups hanno favorito edge e security appliances; commercial surveillance vendors hanno mirato mobile e browser.
7 fonti · 6 mar
CVE in questo aggiornamento
19 CVE
Distribuite tra Connect Secure, Policy Secure, Neurons for ZTA gateways e altri pacchetti correlati.
4 critiche · 13 alte · 2 medie · 0 basse
19 in CISA KEV · 17 con EPSS sopra 1%
1 con codice di exploit pubblico funzionante o integrato
Severità più alta: CVE-2025-43300 · 10.0 CRITICAL
EPSS più alto: CVE-2025-0282 · 100%
Mostriamo le prime 10 per KEV, EPSS e severità.
Cronologia 6 mar Segnalato da Infosecurity Magazine 5 mar Segnalato da TechCrunch Security 2 gen Scadenza federale CISA per CVE-2025-14174 superata12 dic CVE-2025-14174 aggiunto al KEV CISA1 dic Scadenza federale CISA per CVE-2025-21042 superata10 nov Scadenza federale CISA per CVE-2025-61884 superata27 ott Scadenza federale CISA per CVE-2025-61882 superata20 ott CVE-2025-61884 aggiunto al KEV CISA6 ott CVE-2025-61882 aggiunto al KEV CISA11 set Scadenza federale CISA per CVE-2025-43300 superata2 set Scadenza federale CISA per CVE-2025-8088 superata21 ago CVE-2025-43300 aggiunto al KEV CISA12 ago CVE-2025-8088 aggiunto al KEV CISA22 lug CVE-2025-6558 aggiunto al KEV CISA17 apr Scadenza federale CISA per CVE-2025-2783 superata27 mar CVE-2025-2783 aggiunto al KEV CISA14 feb Scadenza federale CISA per CVE-2025-23006 superata24 gen CVE-2025-23006 aggiunto al KEV CISA15 gen Scadenza federale CISA per CVE-2025-0282 superata8 gen CVE-2025-0282 aggiunto al KEV CISAFonti 6 mar Infosecurity Magazine
Zero‑Day Attacks on Enterprise Software Reach Record High
Almost a quarter of the zero days detected by Google in 2025 targeted security and networking appliances
originale 6 mar Cybersecurity Dive
Nearly half of exploited zero-day flaws target enterprise-grade technology
A report by Google Threat Intelligence Group warns that AI will be used to speed and scale attacks in 2026.
originale 5 mar TechCrunch Security
Google says half of all zero-days it tracked in 2025 targeted buggy enterprise tech | TechCrunch
Enterprise software was a major focus of zero-day activity during 2025, with security and networking devices, like firewalls, VPNs, and virtualization platforms among the most targeted by malicious hackers.
originale Riepilogo fornitore: Microsoft
Riepilogo fornitore: Cisco
Riepilogo fornitore: Fortinet
Riepilogo fornitore: Ivanti
Riepilogo fornitore: VMware
Part of the PlainSec briefing for 2026-03-07
Every edition of this story: Zero-day colpiscono dispositivi enterprise nel 2025
Altro da oggi