IR Trends Q4 2025: Exploitation remains dominant, phishing campaign targets Native American tribal organizations
ID: fca800f8-79de-562c-9b66-c42217b5ed0d
STIX ID: report--fca800f8-79de-562c-9b66-c42217b5ed0d
Feed Name: Cisco Talos
Cisco Talos Incident Response quarterly summary reports a sustained trend of threat actors exploiting public-facing applications (including Oracle EBS CVE-2025-61882 and React2Shell) and increased phishing activity (notably campaigns targeting Native American tribal organizations), documents active deployment of malware implants (BadCandy, AquaShell, XMRig) and widespread use of legitimate remote management tools and RMMs for persistence and exfiltration, and highlights ransomware activity led by Qilin alongside mitigation recommendations such as timely patching, robust MFA, centralized logging, and rapid incident response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
