logo

Exploits and vulnerabilities in Q2 2025

ID: 613c7509-d42e-535f-8596-1ac112d07ccb

STIX ID: report--613c7509-d42e-535f-8596-1ac112d07ccb

Feed Name: Securelist by Kaspersky

Threat Score
75/100

Date Published: 2025-08-27

Date Updated: 2026-04-29

Author: Alexander Kolesnikov

...
...

This report reviews Q2 2025 vulnerability registrations and exploitation telemetry: growing monthly CVE volumes, a rise in critical vulnerability publications, frequent exploitation of long-standing Microsoft Office and WinRAR flaws, active Linux privilege-escalation exploits, a Q2 TOP-10 of vulnerabilities used in APT attacks, and usage statistics for common C2 frameworks (Sliver, Metasploit, Havoc, Brute Ratel). It highlights high-impact issues (CVSS 10.0 CVEs, UEFI Secure Boot bypass, post-auth Roundcube deserialization, kernel driver stack overflow), documents real-world C2–vulnerability interactions, and recommends prompt patching, endpoint protection, and monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.