ZeroHour
Cisco Talospublished ()ingested

Cisco Talos 2025 Year in Review

highRansomwareimportance 57
Full article234 words · extracted from blog.talosintelligence.com · click to collapse

How adversaries adapted in 2025

The Cisco Talos 2025 Year in Review is a deep dive into the tactics, techniques, and procedures that shaped adversary operations globally. Created by defenders. For defenders.

Download Now


Areas of analysis:



Ransomware attacks by month

January remains the least active month for ransomware activity, potentially offering a window for defenders to test readiness.


Looking for more? Check out the Splunk “Top 50 Cybersecurity Threats” report.

Recent

April 28, 2026 - March 23, 2026

April 28, 2026 09:23

Five defender priorities from the Talos Year in Review

With attackers moving faster than ever, it’s easy to feel overwhelmed. This blog breaks down five practical priorities from the Cisco Talos 2025 Year in Review to help defenders focus and prioritize, amidst all the noise.

April 21, 2026 08:00

Phishing and MFA exploitation: Targeting the keys to the kingdom

In 2025, attackers increasingly targeted weaknesses in multi-factor authentication (MFA) workflows, and phishing attacks leveraged valid, compromised credentials to launch lures from trusted accounts. The trends focused entirely on trust, or the lack thereof, in everyday business operations.

April 7, 2026 06:00

Year in Review: Vulnerabilities old and new and something React2

The year was characterized by an unending beat-down on infrastructure that relied on older enmeshed dependencies (e.g., Log4j and PHPUnit), while React2Shell rocketed to the highest percentage of attacks for the entire year within the last three weeks of 2025.

Text extracted automatically; images, tables and formatting may be missing. Original: https://blog.talosintelligence.com/2025yearinreview/