Mandiant reports voice-based phishing calls accounted for 11% of intrusions in 2025. Threat groups tied to The Com and Scattered Spider offshoots used the tactic in large campaigns that targeted Salesforce customers. Email phishing fell to 6%, while exploited vulnerabilities remained the top initial access vector at 32%.
CVSS 9.8 CRITICAL: deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to… Known ransomware campaign use. EPSS 100% (100th percentile).
CISA federal remediation date Jul 21 · date passed
CVSS 9.8 CRITICAL: vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration). Known ransomware campaign use. EPSS 100% (100th percentile).
CISA federal remediation date Oct 27 · date passed
CVSS 10 CRITICAL: sAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing… Known ransomware campaign use. EPSS 100% (100th percentile).
CISA federal remediation date May 20 · date passed