Skip to main content
VendorsCisco Talos

Cisco Talos

Cybersecurity reports and statistics published by Cisco Talos

8 categories1 reports

Research Reports

Reports and publications from Cisco Talos

Recent Statistics & Reports

Nearly 40% of the top-targeted vulnerabilities impacted end- of-life (EOL) devices.

5/27/2026
VulnerabilitiesEOL Devices

23% of CVEs directly impact network devices like VPN appliances, next-generation firewalls (NGFWs), load balancers, routers, and others.

5/27/2026
CVEsNetwork Devices

25% of the top-targeted vulnerabilities impact widely used frameworks and libraries.

5/27/2026
VulnerabilitiesFrameworksLibraries

32% of the top-targeted vulnerabilities are at least a decade old.

5/27/2026
Vulnerabilities

The number of device registration events reported by users as fraud increased 178% from 2024 to 2025.

5/27/2026
FraudFraudulent Device Registrations

Technology is the top-targeted industry at 36% for MFA spray attacks.

5/27/2026
MFA Spray AttacksTechnology

In 2025, attackers compromised victims via phishing emails in 40% of Talos IR cases.

5/27/2026
Phishing

Device compromise attacks where attackers register their own hardware as a trusted factor, increased by 178%.

5/27/2026
Device Compromise Attacks

In 2025, 35% of Talos IR phishing cases involved internal phishing.

5/27/2026
Internal Phishing

Application delivery controllers (ADCs) accounted for 22% of the top 50 targeted network devices.

5/27/2026
Network DevicesApplication Delivery Controllers

Qilin was the most seen ransomware variant in 2025.

5/27/2026
RansomwareQilin

60% of the top 20 terms appearing in phishing subject lines were the same in 2024 and 2025, such as “request,” “invoice,” “payment,” “email,” “fwd,” “message,” “report,” and “meeting.”

5/27/2026
PhishingPhishing Subject Lines

The majority of the 50 most-targeted network infrastructure vulnerabilities (66%) affect device-specific firmware.

5/27/2026
Network Infrastructure VulnerabilitiesDevice-Specific Firmware

According to their data leak site, in 2025, Qilin targeted more than 40 victims every month except January.

5/27/2026
RansomwareQilin

Akira and Play, ranked as second and third most prolific ransomware groups, respectively.

5/27/2026
RansomwareAkiraPlay

The popularity of the other groups in last year’s top five fell significantly this year, with LockBit 3.0 moving from first to 35th, RansomHub from second to eighth, and Hunter’s International from fifth to 28th.

5/27/2026
RansomwareLockBit 3.0RansomHub

January remains least active month for ransomware activity.

5/27/2026
RansomwareJanuary

Qilin affiliates take home a significant portion of their ransom payments (up to 80 - 85%), higher than typical RaaS payout structures.

5/27/2026
RansomwareQilinRaaS

In 2025, nearly a third of MFA spray attacks targeted identity and access management (IAM) applications.

5/27/2026
MFA Spray AttacksIAM

The number of investigations Talos conducted into China-nexus campaigns increased nearly 75% this year compared to 2024.

5/27/2026
China-nexus Campaigns