logo

From the field to the report and back again: How incident responders can use the Year in Review

ID: e57c9bd7-86f1-5bda-9299-e6f3c17e0f95

STIX ID: report--e57c9bd7-86f1-5bda-9299-e6f3c17e0f95

Feed Name: Cisco Talos

Threat Score
70/100

Date Published: 2026-04-09

Date Updated: 2026-04-27

Author: Jerzy ‘Yuri’ Kramarz

...
...

Cisco Talos' Year in Review distills IR engagements and telemetry into prioritized trends and operational guidance: identity-based attacks (60% of Talos IR cases) and Active Directory abuse are dominant, MFA bypass and device compromise are rising, specific vulnerabilities (e.g., React2Shell, ToolShell) are heavily exploited, ransomware (notably Qilin) and evolving phishing/AI-enabled threats remain major risks; the report emphasizes validating detections, mapping to MITRE ATT&CK, and exercising response plans.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.