Cisco Talos 2025 Year in Review
Full article234 words · extracted from blog.talosintelligence.com · click to collapse
How adversaries adapted in 2025
The Cisco Talos 2025 Year in Review is a deep dive into the tactics, techniques, and procedures that shaped adversary operations globally. Created by defenders. For defenders.
Areas of analysis:
Ransomware attacks by month
January remains the least active month for ransomware activity, potentially offering a window for defenders to test readiness.
Looking for more? Check out the Splunk “Top 50 Cybersecurity Threats” report.
Recent
April 28, 2026 - March 23, 2026
April 28, 2026 09:23
Five defender priorities from the Talos Year in Review
With attackers moving faster than ever, it’s easy to feel overwhelmed. This blog breaks down five practical priorities from the Cisco Talos 2025 Year in Review to help defenders focus and prioritize, amidst all the noise.
April 21, 2026 08:00
Phishing and MFA exploitation: Targeting the keys to the kingdom
In 2025, attackers increasingly targeted weaknesses in multi-factor authentication (MFA) workflows, and phishing attacks leveraged valid, compromised credentials to launch lures from trusted accounts. The trends focused entirely on trust, or the lack thereof, in everyday business operations.
April 7, 2026 06:00
Year in Review: Vulnerabilities old and new and something React2
The year was characterized by an unending beat-down on infrastructure that relied on older enmeshed dependencies (e.g., Log4j and PHPUnit), while React2Shell rocketed to the highest percentage of attacks for the entire year within the last three weeks of 2025.
Text extracted automatically; images, tables and formatting may be missing. Original: https://blog.talosintelligence.com/2025yearinreview/