Threats & Adversaries · Phishing / BEC

Voice Phishing Drives 11% of Intrusions in 2025

Mandiant reports voice-based phishing calls accounted for 11% of intrusions in 2025. Threat groups tied to The Com and Scattered Spider offshoots used the tactic in large campaigns that targeted Salesforce customers. Email phishing fell to 6%, while exploited vulnerabilities remained the top initial access vector at 32%.

2 sources · Mar 24

CVE-2025-53770

NVD KEV

Known exploited · CISA KEV

CVSS 9.8 CRITICAL: deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to… Known ransomware campaign use. EPSS 100% (100th percentile).

CISA federal remediation date Jul 21 · date passed

CVE-2025-61882

NVD KEV

Known exploited · CISA KEV

CVSS 9.8 CRITICAL: vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration). Known ransomware campaign use. EPSS 100% (100th percentile).

CISA federal remediation date Oct 27 · date passed

CVE-2025-31324

NVD KEV

Known exploited · CISA KEV

CVSS 10 CRITICAL: sAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing… Known ransomware campaign use. EPSS 100% (100th percentile).

CISA federal remediation date May 20 · date passed

Timeline

Sources

Vendor digest: Microsoft

Part of the PlainSec briefing for 2026-03-25

Every edition of this story: Voice Phishing Drives 11% of Intrusions in 2025

More from today