Exploits and vulnerabilities in Q2 2025
ID: 613c7509-d42e-535f-8596-1ac112d07ccb
STIX ID: report--613c7509-d42e-535f-8596-1ac112d07ccb
Feed Name: Securelist by Kaspersky
This report reviews Q2 2025 vulnerability registrations and exploitation telemetry: growing monthly CVE volumes, a rise in critical vulnerability publications, frequent exploitation of long-standing Microsoft Office and WinRAR flaws, active Linux privilege-escalation exploits, a Q2 TOP-10 of vulnerabilities used in APT attacks, and usage statistics for common C2 frameworks (Sliver, Metasploit, Havoc, Brute Ratel). It highlights high-impact issues (CVSS 10.0 CVEs, UEFI Secure Boot bypass, post-auth Roundcube deserialization, kernel driver stack overflow), documents real-world C2–vulnerability interactions, and recommends prompt patching, endpoint protection, and monitoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
