Critical Surge in Zero-Day Weaponization by Nation-State Actors in North America
Nation-state actors are increasingly exploiting zero-day vulnerabilities in North America, targeting enterprise technologies and edge devices, with a notable rise in exploit broker transactions facilitating these attacks.
Executive Takeaway — TL;DR
- Category:
- Zero-Day Exploits
- Severity:
- Critical
- Actor Type:
- Nation-State
- Geography:
- North America
- Confidence:
- Confirmed
- Source:
- Raptor Cyber Intelligence
- Read Time:
- 5 min
Executive Summary
In early 2026, nation-state actors have escalated the exploitation of zero-day vulnerabilities within North America, focusing on enterprise-grade technologies and edge devices. This trend is accompanied by a significant increase in exploit broker transactions, enabling the rapid weaponization of previously unknown flaws.
Current Threat Landscape
In 2025, the Google Threat Intelligence Group (GTIG) identified 90 zero-day vulnerabilities exploited in the wild, with nearly half targeting enterprise-grade technologies—a record high. State-sponsored groups, particularly those with Chinese affiliations, have been the most prolific in leveraging these vulnerabilities, often focusing on networking and security tools, including edge devices that typically lack robust endpoint detection and response capabilities. (cybersecuritydive.com)
Notable Exploited Vulnerabilities
-
Fortinet FortiGate SSL-VPN RCE: An unauthenticated remote code execution zero-day within the SSL-VPN portal was exploited by a suspected state-sponsored cyber espionage group. The attackers utilized a novel heap-based overflow to bypass authentication on edge firewalls, operating silently for three months and installing custom implant firmware tailored to survive reboots and firmware upgrades, exfiltrating encrypted communications. (precogs.ai)
-
Microsoft Windows Vulnerabilities: In February 2026, Microsoft patched six actively exploited zero-day vulnerabilities affecting Windows Shell, Remote Desktop, and Office applications. These flaws allowed attackers to bypass security features, leading to unauthorized code execution and privilege escalation. (secure.com)
Exploit Broker Transactions
The market for zero-day vulnerabilities has matured, with specialized brokers facilitating the sale of these exploits to state actors and sophisticated ransomware groups. These brokers operate in private networks or the dark web, offering vulnerabilities for sale to cybercriminals, nation-states, or organizations. Prices for zero-day exploits vary depending on the severity and target, with high-profile vulnerabilities fetching large sums. This underground market makes zero-day vulnerabilities even more dangerous, as they can be weaponized and used by bad actors to inflict widespread damage. (atera.com)
Implications for North American Organizations
The increased exploitation of zero-day vulnerabilities by nation-state actors poses significant risks to North American organizations, particularly those relying on enterprise-grade technologies and edge devices. The rapid weaponization of these vulnerabilities, facilitated by exploit broker transactions, underscores the need for enhanced cybersecurity measures, including proactive vulnerability management, timely patching, and robust monitoring of network traffic to detect and mitigate potential threats.
Recommendations
-
Proactive Vulnerability Management: Implement comprehensive vulnerability scanning and assessment processes to identify and remediate potential zero-day vulnerabilities promptly.
-
Timely Patching: Establish a robust patch management strategy to ensure that all systems, especially those exposed to the internet, are updated with the latest security patches.
-
Enhanced Monitoring: Deploy advanced intrusion detection and prevention systems to monitor network traffic for signs of exploitation attempts.
-
Collaboration with Security Communities: Engage with cybersecurity information-sharing organizations to stay informed about emerging threats and best practices for defense.
By adopting these measures, organizations can strengthen their defenses against the evolving threat landscape posed by nation-state actors leveraging zero-day vulnerabilities.
Sources
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

Critical Zero-Day Vulnerability CVE-2026-93616 Exploited in Check Point Security Management Infrastructure

CISA Adds Three Linux Kernel Flaws to KEV Catalog Amid Active Exploitation Concerns

