Friday, September 11, 2026

Google Warns: Threat Actors Growing More Sophisticated, Exploiting Zero-Day Vulnerabilities

Google’s Mandiant team has released its M-Trends 2025 report, highlighting the increasing sophistication of threat actors, particularly China-nexus groups.

These adversaries are deploying custom malware ecosystems, exploiting zero-day vulnerabilities in security appliances, and utilizing proxy networks resembling botnets to evade detection.

Their tactics also include targeting edge devices lacking endpoint detection and response (EDR) capabilities and employing bespoke obfuscation techniques in malware.

This concerted effort to bypass traditional defenses enables prolonged persistence within compromised systems, posing significant challenges to cybersecurity teams worldwide.

Diverse Attack Vectors and Opportunistic Exploits

While high-complexity attacks are on the rise, Mandiant’s findings reveal that many successful breaches stem from simpler, opportunistic methods.

Stolen credentials, often harvested through infostealer operations, have surged to become the second most common initial infection vector, accounting for 16% of investigated incidents in 2024, trailing only exploits at 33%.

Additionally, attackers are capitalizing on missteps during cloud migrations and targeting unsecured data repositories to pilfer sensitive information.

The report also notes a steady increase in financially motivated threat groups, comprising 55% of active actors in 2024, while espionage-driven groups account for 8%.

Key industries under siege include financial services (17.4%), business and professional services (11.1%), and high tech (10.6%), underscoring the broad scope of these threats.

The M-Trends 2025 report, based on over 450,000 hours of incident response investigations from January to December 2024, uncovers other alarming trends.

Global median dwell time for adversaries has risen to 11 days from 10 in 2023, with longer durations (26 days) when external notifications trigger detection compared to a mere 5 days in ransomware cases where adversaries self-disclose.

Emerging threats include DPRK operatives posing as remote IT contractors to fund national agendas, Iran-nexus actors intensifying operations against Israeli targets, and increased exploitation of cloud-based single sign-on portals for widespread access.

Additionally, Web3 technologies like cryptocurrencies are becoming prime targets for theft and illicit financing.

Mandiant urges organizations to adopt a multi-layered security posture to counter these evolving threats.

Prioritizing fundamentals such as vulnerability management, least privilege principles, and system hardening is critical.

Implementing FIDO2-compliant multi-factor authentication for all accounts, especially privileged ones, can thwart credential theft.

Organizations should also bolster detection with advanced technologies, enhance logging and monitoring to shrink dwell times, and conduct threat hunting to uncover hidden compromises.

Cloud environments demand rigorous audits to address misconfigurations, while insider risks require stringent vetting and access controls, particularly for remote workers.

Staying abreast of threat intelligence and regularly updating security policies are equally vital to adapt to this dynamic landscape.

With these insights from the frontlines, Mandiant’s M-Trends 2025 serves as a crucial guide for defenders aiming to stay one step ahead of increasingly sophisticated adversaries.

Find this News Interesting! Follow us on Google NewsLinkedIn, & X to Get Instant Updates!

Aman Mishra
Aman Mishra
Aman Mishra is a Security and privacy Reporter covering various data breach, cyber crime, malware, & vulnerability.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign

A long-running pay-per-install (PPI) operation that used YouTube gaming...

VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data

Two security vulnerabilities in VLC media player versions 3.0.0...

CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

cPanel Urges Users to Patch ConfigServer Firewall Remote Code Execution Flaw

A recently disclosed vulnerability in ConfigServer Security & Firewall...

Hackers Weaponize AI Safety Guardrails to Hide Malware From LLM-Powered Security Scanners

Threat actors are adapting malware not only for conventional...

Hackers Exploit JFrog Artifactory Flaws to Bypass Authentication and Gain Admin Access

Threat actors are actively exploiting three vulnerabilities in JFrog...

Related Articles

Recent News