News: 1769694805

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Patch or perish: Vulnerability exploits now dominate intrusions

(2026/01/29)


What good is a fix if you don't use it? Experts are urging security teams to patch promptly as vulnerability exploits now account for the majority of intrusions, according to the latest figures.

Cisco Talos said exploited flaws were behind nearly 40 percent of all intrusions in Q4 2025, and the speed at which attackers were harnessing those weaknesses should serve as a wake-up call for defenders.

This marks the second quarter in a row that exploits led the charge for initial access, but represented a drop from Q3's rate of 62 percent, which was driven largely by widespread [1]ToolShell attacks .

[2]

More recently, the team pointed to the [3]Oracle EBS and [4]React2Shell vulnerabilities as examples of two high-profile vectors that continued to fuel the trend, both of which were taken up by attackers within hours of disclosure.

[5]

[6]

Talos stated in its [7]report : "In both cases, exploitation activity occurred around the time the vulnerability became public, demonstrating actors' speed in capitalizing on these opportunities as well as the inherent risks of internet-facing enterprise applications and default deployments embedded in widely used frameworks."

The Register reported at the time that a functional proof-of-concept exploit for React2Shell began circulating online within 30 hours of disclosure, for example.

[8]

Likewise, AWS said Chinese state-backed attackers were exploiting the maximum-severity bug "within hours or days of disclosure."

[9]Cyberattack on Poland's power grid could have turned deadly in winter cold

[10]Ransomware crims forced to take off-RAMP as FBI seizes forum

[11]Everybody is WinRAR phishing, dropping RATs as fast as lightning

[12]Fortinet unearths another critical bug as SSO accounts borked post-patch

Whether organizations heed this warning is another matter, however. Patching systems, especially in large organizations, can be a painful process, but according to a BitSight analysis in 2024, private sector admins are [13]taking months, not hours, to patch the most serious flaws .

Unsurprisingly, phishing was also among the most common ways in which attackers gained access to a victim's network, coming in second place just behind bug exploits with 32 percent of access cases.

Some notable phishing examples included two possibly-related campaigns targeting Native American tribal organizations.

Talos was involved with both of those, and the team saw successful phishes lead to email account compromises and attackers using their newfound access to launch internal and external follow-on phishing emails.

[14]

The going advice is relatively unchanged from the usual stuff: patch systems quickly; implement MFA and – crucially – methods of detecting MFA abuse; and ensure systems are gathering the required logs so that responders have something to work with when they arrive on the scene.

Also, when you can't patch expeditiously, limit public exposure of these vulnerable endpoints until a time when they can be protected.

Finally, for some good news, ransomware is down to 13 percent of cases from 20 percent in Q3, and 50 percent in Q1 and Q2. Plus, no new criminal groups were seen either.

While that sounds positive, Talos said it probably just means groups are consolidating – big gangs score big takes, while smaller outfits fall by the wayside. Stay frosty. ®

Get our [15]Tech Resources



[1] https://www.theregister.com/2025/07/21/massive_security_snafu_microsoft/

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2aXuSfMhTaLxIF_PVcqtWvgAAA0g&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://www.theregister.com/2025/10/07/clop_oracle_ebs/

[4] https://www.theregister.com/2025/12/05/react2shell_pocs_exploitation

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44aXuSfMhTaLxIF_PVcqtWvgAAA0g&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33aXuSfMhTaLxIF_PVcqtWvgAAA0g&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[7] https://blog.talosintelligence.com/ir-trends-q4-2025/

[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44aXuSfMhTaLxIF_PVcqtWvgAAA0g&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[9] https://www.theregister.com/2026/01/29/cyberattack_poland_power_grid/

[10] https://www.theregister.com/2026/01/28/fbi_seizes_ramp_forum/

[11] https://www.theregister.com/2026/01/28/winrar_bug_under_attack/

[12] https://www.theregister.com/2026/01/28/fortinet_forticloud_vuln/

[13] https://www.theregister.com/2024/05/07/cisas_vulnerability_deadlines/

[14] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33aXuSfMhTaLxIF_PVcqtWvgAAA0g&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[15] https://whitepapers.theregister.com/



Anonymous Coward

All things being equal it's all moving to The Cloud until a new fad comes along, which means you can do what Netscape originally envidsaged (and for which it was put to death by Microsoft); the browser is your tool.

Which doesn't need to run on Windows..

Phishing attack - how to help take down

alain williams

If you receive some phishing email please forward it to report@phishing.gov.uk . These are some good guys in government somewhere who take down the web sites that are often behind these attempts. To do this they need to know what is out there.

**** IMPORTANT **** ALL USERS PLEASE NOTE ****

Due to a recent systems overload error your recent disk files have been
erased. Therefore, in accordance with the UNIX Basic Manual, University of
Washington Geophysics Manual, and Bylaw 9(c), Section XII of the Revised
Federal Communications Act, you are being granted Temporary Disk Space,
valid for three months from this date, subject to the restrictions set forth
in Appendix II of the Federal Communications Handbook (18th edition) as well
as the references mentioned herein. You may apply for more disk space at any
time. Disk usage in or above the eighth percentile will secure the removal
of all restrictions and you will immediately receive your permanent disk
space. Disk usage in the sixth or seventh percentile will not effect the
validity of your temporary disk space, though its expiration date may be
extended for a period of up to three months. A score in the fifth percentile
or below will result in the withdrawal of your Temporary Disk space.