Mandiant reported multiple large intrusions in 2025 driven by phone-based social engineering. Groups tied to The Com and Scattered Spider used voice phishing against Salesforce customers; email phishing declined as exploited vulnerabilities remained the top initial access vector.
CVSS 9.8 CRITICAL: deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to… Known ransomware campaign use. EPSS 100% (100th percentile).
CISA federal remediation date Jul 21 · date passed
CVSS 9.8 CRITICAL: vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration). Known ransomware campaign use. EPSS 100% (100th percentile).
CISA federal remediation date Oct 27 · date passed
CVSS 10 CRITICAL: sAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing… Known ransomware campaign use. EPSS 100% (100th percentile).
CISA federal remediation date May 20 · date passed