Cisco Talos Q2 Report: Phishing & Ransomware Dominate, with Qilin Using Deprecated PowerShell 1.0
ID: e2589e54-d2ba-55e9-889b-7847e9f3614f
STIX ID: report--e2589e54-d2ba-55e9-889b-7847e9f3614f
Feed Name: securityonline.info
Threat Score
Cisco Talos' Q2 2025 Threat Intelligence Report finds phishing remains the top initial access vector, credential harvesting has become a preferred monetization tactic, and ransomware accounted for half of engagements; the report details Qilin ransomware activity (new TTPs and data-exfiltration methods), abuse of PowerShell 1.0, and substantial operational impacts including a full Active Directory rebuild, with education the most-targeted sector this quarter.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
