Cisco Talos Publishes 2025 Year in Review Report on Critical Cyber Threats

Summary: The 2025 Year in Review report identifies React2Shell as the most targeted CVE and Qilin as the dominant ransomware variant observed throughout the year.

Cisco Talos released its 2025 Year in Review report utilizing vast telemetry and incident data to analyze global threats. The Strategic Analysis team synthesized findings into a comprehensive report undergoing rigorous review before launch. Talos maintains an open access policy to keep the community safe without gating critical information.

React2Shell became the top targeted critical vulnerability in 2025. ToolShell ranked third, released in June but appearing frequently on the list of exploited critical common weaknesses.

Supply chain risks persist, as 25 percent of top 100 vulnerabilities affect widely used frameworks. Nearly one-third of MFA spray attacks targeted identity and access management applications specifically.

Phishing remains the dominant initial access vector, observed in 40 percent of all incident response cases. The Qilin ransomware variant saw over 40 victims monthly throughout the year, excluding January.

Key facts

  • React2Shell: Top targeted CVE in 2025
  • ToolShell: Third targeted CVE released in June
  • 25 percent of top 100 vulnerabilities affect frameworks
  • 40 percent of IR cases involved phishing attacks
  • Qilin: Most seen ransomware variant in 2025

Why it matters

Organizations must prioritize patch management updates and strengthen identity controls to counter specific trends highlighted in the full report. Supply chain vulnerabilities require immediate attention given the framework-level risks identified in the year-end analysis.

Key metrics

  • Top Targeted CVE: React2Shell - (2025 Review)
  • Phishing Attack Share: 40% % (IR Cases)
  • Supply Chain Risk: 25% % (Vulnerabilities on Top 100)