logo

IR Trends Q4 2025: Exploitation remains dominant, phishing campaign targets Native American tribal organizations

ID: fca800f8-79de-562c-9b66-c42217b5ed0d

STIX ID: report--fca800f8-79de-562c-9b66-c42217b5ed0d

Feed Name: Cisco Talos

Threat Score
78/100

Date Published: 2026-01-29

Date Updated: 2026-04-27

Author: Dave Liebenberg

...
...

Cisco Talos Incident Response quarterly summary reports a sustained trend of threat actors exploiting public-facing applications (including Oracle EBS CVE-2025-61882 and React2Shell) and increased phishing activity (notably campaigns targeting Native American tribal organizations), documents active deployment of malware implants (BadCandy, AquaShell, XMRig) and widespread use of legitimate remote management tools and RMMs for persistence and exfiltration, and highlights ransomware activity led by Qilin alongside mitigation recommendations such as timely patching, robust MFA, centralized logging, and rapid incident response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.