惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Hugging Face - Blog
Hugging Face - Blog
Vercel News
Vercel News
C
Check Point Blog
G
Google Developers Blog
博客园 - 司徒正美
量子位
Engineering at Meta
Engineering at Meta
S
SegmentFault 最新的问题
Google DeepMind News
Google DeepMind News
F
Fortinet All Blogs
A
About on SuperTechFans
美团技术团队
D
DataBreaches.Net
Stack Overflow Blog
Stack Overflow Blog
Jina AI
Jina AI
Y
Y Combinator Blog
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Apple Machine Learning Research
Apple Machine Learning Research
J
Java Code Geeks
MongoDB | Blog
MongoDB | Blog
人人都是产品经理
人人都是产品经理
H
Hackread – Cybersecurity News, Data Breaches, AI and More
The Cloudflare Blog
U
Unit 42

The Register - Security: CSO

Anthropic's Mythos has The Kettle crew curious, skeptical 'People's Panel' to check if UK wants controversial Digital ID will cost £630K Top npm package backdoored to drop dirty RAT on dev machines Lightning-fast exploits mean patch fast, says Cisco Talos Smooth criminals talking their way into cloud environments, Google says Cybercrime up 245% since the start of the Iran war Scattered Lapsus$ Hunters seeks women to defraud helpdesks Every day in every way, passwords are getting worse CISA quietly updated ransomware flags on 59 flaws last year Deepfake job seeker applied to work for an AI security firm Deepfake job seeker applied to work for an AI security firm AI-powered cyberattack kits are 'just a matter of time' AI-powered cyberattack kits are 'just a matter of time' FortiGate SSO bug still exploitable despite December patch FortiGate SSO bug still exploitable despite December patch Judge tosses CrowdStrike shareholder suit over 2024 outage DRAM shortage may drive firewall prices higher: analysts Ransomware attacks kept climbing in 2025 as gangs refused to stay dead Around 1,000 systems compromised in ransomware attack on Romanian water agency 1,000 systems pwned in Romanian Waters ransomware attack Half of exposed React servers remain unpatched amid attacks CISA warns spyware crews are breaking into Signal and WhatsApp accounts FCC guts Salt Typhoon telco rules despite espionage risk CISA orders feds to patch Oracle Identity Manager zero-day SEC drops SolarWinds lawsuit that painted a target on CISOs everywhere SEC bails on SolarWinds lawsuit Palo Alto kit sees massive surge in malicious activity amid mystery traffic flood Palo Alto kit sees massive surge in malicious activity Countries use cyber targeting to plan strikes: Amazon CSO Overconfidence is the new zero-day as teams stumble through cyber simulations
Lightning-fast exploits mean patch fast, says Cisco Talos
Brandon Vigliarolo Brandon Vigliarolo · 2026-03-24 · via The Register - Security: CSO

CSO

Lightning-fast exploits make it essential to patch fast, ask questions later

Here's where you ought to spend your security billable hours budget this year

Strengthen your MFA policies, double-down on anti-phishing training, and for Jobs' sake, patch all your vulns right away. The past year of intelligence collected by Cisco's Talos threat hunters suggests that attackers are moving faster to exploit vulns, and fooling more staff than ever into giving up their credentials. 

Team Talos published its year in review on Monday, describing 2025 as a year of pace and scale that put sustained pressure on security teams around the world, in part thanks to attackers' use of artificial intelligence. 

Talos was shocked by how quickly criminals have been moving to exploit newly discovered vulnerabilities, pointing to December's React2Shell as the perfect example. Even though it was disclosed only in December, it quickly became the most-targeted vuln of the year.

"The vulnerability's immediate exploitation reflects near-instant weaponization, driven by automated tooling and widespread internet exposure, leaving defenders little to no time between disclosure and active abuse," Talos noted in the report. 

Talos also noticed that attackers were settling on identity control points as primary targets in 2025, with "the vast majority of top-targeted network infrastructure vulnerabilities" falling into this category. Compromising identity control tech like VPNs or application discovery controllers (ADCs) means attackers can easily move laterally, grant themselves enhanced access, bypass MFA, achieve persistence, and the like. In a similar vein, network management software, like vCenter Server, Cisco Security Manager, and Aria Operations for Networks, is often less tightly monitored than edge appliances, meaning that they're also easier to break into. 

As for how attackers are actually gaining access, phishing is still where it's at: 40 percent of intrusion response cases Talos investigated in 2025 began with a successful phish. 

The modern phishing lure is more sophisticated than ever. Gone are the misspellings, poor grammar, and other obvious errors, as AI helps attackers overcome language barriers and imitate real communications.

Core phishing lures - invoices, payments, document shares, meeting notices - remained consistent between 2024 and 2025, but the messages "looked less like generic spam and much more like everyday business, IT, and travel workflows that executives and employees routinely interact with," Talos said. Phishing messages also came from spoofed or compromised accounts 75 percent of the time last year, making it much harder to tell a sloppy attempt from a good one. 

The rising tide of AI, meanwhile, lifts all boats - including pirate ships. In 2025, baddies primarily used AI to improve on elements of existing attacks, but Talos predicts that AI will soon become a fundamental back-end part of cybercrime software, much like what's already happening in the commercial world. 

Good luck, cyber defenders

Cisco's report didn't include one single list of recommendations for cybersecurity professionals worried that the speed and craftiness of modern cybercrime will quickly overwhelm them, but there are some pretty important recommendations buried in the report, For example, security pros should prioritize network software and appliance patches for systems dealing with access management, when possible. 

More broadly, warns Talos, defenders will have smaller reaction windows and escalating consequences for even short-term exposure, so patch fast, and prioritize anything in the identity and access control spaces. 

As for helping end users help themselves, anti-phishing training is always welcome, but Talos noted that MFA "spray" attacks, where attackers try a bunch of common passwords, were also a considerable threat in 2025, and recommends ensuring that MFA systems have strong lockout policies, deploy conditioned access, enforce good password hygiene, and use strong session controls.

"Ultimately, Cisco Talos' 2025 report underscores that modern security requires a shift in focus from simply patching to securing the identity, supply chain, and management planes that govern the modern enterprise," Talos said of the report. 

In other words, get ready for a year of rethinking your security strategies. Attackers are definitely rethinking theirs. ®