Vulnerability & Exposure Management
CVEs, vulnerability prioritization, attack surface, CTEM
Reports in this theme

CrowdStrike 2026 Global Threat Report
The 2026 Global Threat Report highlights the rise of AI-accelerated adversaries, the increasing speed of eCrime breakout times, and the dominance of interactive intrusions. It emphasizes the need for rapid detection and response to counter evasive tactics, particularly in cloud and edge environments. The report also details the growing threat from China-nexus adversaries and the strategic use of AI in cyber operations.

2024 Year in Review
2024 saw a surge in identity-based attacks and exploitation of outdated vulnerabilities. Threat actors focused on unpatched systems, misconfigured infrastructure, and MFA weaknesses, leading to significant breaches. AI's role in cyber threats was limited, but its potential for future attacks is noted.

State of Cyber Security 2025
In-depth analysis of the 2024 cybersecurity landscape, highlighting trends in cybercrime, regulatory developments, and emerging threats. It emphasizes the increasing sophistication of phishing attacks, the rise of Phishing-as-a-Service (PhaaS), and the evolving threat of ransomware. The report also discusses the impact of AI on cybersecurity, the importance of regulatory frameworks like NIS2 and DORA, and recommendations for improving organizational security.

OT/ICS Cybersecurity Year in Review 2025
Dragos' 8th annual OT/ICS Cybersecurity Year in Review analyzes the 2024 threat landscape and shows OT is no longer a niche target: adversaries, hacktivists and ransomware crews are converging on industrial systems as geopolitical conflict continues. Dragos now tracks 23 threat groups (9 active in 2024) and identified two new ones — GRAPHITE (APT28-linked; hydro, energy, logistics, defense in Eastern Europe/Middle East, credential-phishing that bypasses 2FA, Ubiquiti EdgeRouter C2, growing use of legitimate internet services) and BAUXITE (oil & gas, electric, water/wastewater and chemical manufacturing across the US, Europe, Australia and Middle East). Russia-linked KAMACITE and ELECTRUM continue to collaborate on Ukraine-focused OT operations, with KAMACITE broadening spear-phishing (LummaStealer, TAT24-97 loader) to European ONG targets and ELECTRUM extending its wiper arsenal with AcidPour (an evolution of AcidRain, which had disrupted KA-SAT and German wind turbines). China-linked VOLTZITE remains the most critical group to track in critical infrastructure, exploiting internet-facing VPN/firewall bugs and using living-off-the-land techniques against SOHO routers and shared botnets (65% of sites assessed had insecure remote conditions). Ransomware attacks rose 87% year over year, hitting manufacturing hardest where downtime forces payment; CARR-style campaigns showed even basic HMI abuse over internet-exposed OT can cause tangible disruption. Vulnerability analysis: 22% of 2024 advisories had incorrect data, 22% were network-exploitable and perimeter-facing, 39% could cause both loss of view AND loss of control (down from 53%), and Dragos provided mitigations for 47% of advisories that shipped without any. The report reiterates the SANS ICS 5 Critical Controls and the "Now, Next, Never" framework as the best defense, and highlights supply chain / DLL-hijack risks, servo drives, and IoT in ICS as emerging research areas.

CrowdStrike 2025 Global Threat Report
The 2025 Global Threat Report highlights the growing sophistication of cyber adversaries, emphasizing the rise of enterprising adversaries leveraging generative AI, social engineering, and advanced tactics. It underscores the need for proactive defense strategies and AI-native approaches to counter evolving threats.
Create a free account to see every report in this theme.
