VendorsCisco Talos
Cisco Talos
Cybersecurity reports and statistics published by Cisco Talos
8 categories1 reports
Recent Statistics & Reports
Nearly 40% of the top-targeted vulnerabilities impacted end- of-life (EOL) devices.
5/27/2026•
VulnerabilitiesEOL Devices
23% of CVEs directly impact network devices like VPN appliances, next-generation firewalls (NGFWs), load balancers, routers, and others.
5/27/2026•
CVEsNetwork Devices
25% of the top-targeted vulnerabilities impact widely used frameworks and libraries.
5/27/2026•
VulnerabilitiesFrameworksLibraries
32% of the top-targeted vulnerabilities are at least a decade old.
5/27/2026•
Vulnerabilities
The number of device registration events reported by users as fraud increased 178% from 2024 to 2025.
5/27/2026•
FraudFraudulent Device Registrations
Technology is the top-targeted industry at 36% for MFA spray attacks.
5/27/2026•
MFA Spray AttacksTechnology
In 2025, attackers compromised victims via phishing emails in 40% of Talos IR cases.
5/27/2026•
Phishing
Device compromise attacks where attackers register their own hardware as a trusted factor, increased by 178%.
5/27/2026•
Device Compromise Attacks
In 2025, 35% of Talos IR phishing cases involved internal phishing.
5/27/2026•
Internal Phishing
Application delivery controllers (ADCs) accounted for 22% of the top 50 targeted network devices.
5/27/2026•
Network DevicesApplication Delivery Controllers
Qilin was the most seen ransomware variant in 2025.
5/27/2026•
RansomwareQilin
60% of the top 20 terms appearing in phishing subject lines were the same in 2024 and 2025, such as “request,” “invoice,” “payment,” “email,” “fwd,” “message,” “report,” and “meeting.”
5/27/2026•
PhishingPhishing Subject Lines
The majority of the 50 most-targeted network infrastructure vulnerabilities (66%) affect device-specific firmware.
5/27/2026•
Network Infrastructure VulnerabilitiesDevice-Specific Firmware
According to their data leak site, in 2025, Qilin targeted more than 40 victims every month except January.
5/27/2026•
RansomwareQilin
Akira and Play, ranked as second and third most prolific ransomware groups, respectively.
5/27/2026•
RansomwareAkiraPlay
The popularity of the other groups in last year’s top five fell significantly this year, with LockBit 3.0 moving from first to 35th, RansomHub from second to eighth, and Hunter’s International from fifth to 28th.
5/27/2026•
RansomwareLockBit 3.0RansomHub
January remains least active month for ransomware activity.
5/27/2026•
RansomwareJanuary
Qilin affiliates take home a significant portion of their ransom payments (up to 80 - 85%), higher than typical RaaS payout structures.
5/27/2026•
RansomwareQilinRaaS
In 2025, nearly a third of MFA spray attacks targeted identity and access management (IAM) applications.
5/27/2026•
MFA Spray AttacksIAM
The number of investigations Talos conducted into China-nexus campaigns increased nearly 75% this year compared to 2024.
5/27/2026•
China-nexus Campaigns