CrowdStrike’s 2025 global threat reporting says financially motivated intrusions are accelerating, with average breakout time (lateral movement after initial access) dropping to 29 minutes and the fastest observed breakout time at 27 seconds; the report also describes attackers increasingly using social engineering, living-off-the-land techniques, and abuse of trusted systems to move across cloud, identity, enterprise, and unmanaged device boundaries, alongside a reported 37% year-over-year increase in cloud-focused attacks and a growing set of tracked adversaries (281 named groups plus additional activity clusters). Check Point Research’s 2025 retrospective similarly emphasizes that many 2025 operations relied on familiar techniques combined in new ways, highlighting themes such as early ToolShell exploitation assessed as Chinese-nexus activity against North American government targets and identity-centric intrusions (including AiTM credential theft) against US think-tank researchers.
Several other items in the set are not about these annual threat-report findings and instead cover separate topics: Romania’s cyber chief warning that ransomware incidents against critical infrastructure may align with Russian hybrid objectives; sector-level reporting that manufacturing remains heavily targeted by ransomware due to IT/OT interconnectivity and downtime pressure; and US law-enforcement/FBI reporting on a surge in ATM jackpotting losses and related indictments. Additional entries are primarily generic commentary, newsletters, or professional/educational content (e.g., quantum-preparedness opinion, Enigma/RSAC history piece, a weekly video briefing, a malware-newsletter link roundup, a recon how-to article, and a governance/career feature page) and do not substantively corroborate the specific annual threat-report story.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
On 2026-03-24, Mandiant published its M-Trends 2026 report, finding that the median time from initial compromise to attacker hand-off fell to 22 seconds in 2025. The report also said exploits remained the top initial infection vector, voice phishing rose sharply, and ransomware actors increasingly targeted backup, identity, and virtualization infrastructure.
On 2026-03-23, Cisco Talos published its 2025 Year in Review, reporting that adversary activity in 2025 increased in pace and scale. The report highlighted rapid exploitation of newly disclosed and long-known vulnerabilities, abuse of identity and trust systems, and targeting of centralized infrastructure and widely used software components for broader impact.
On February 24, 2026, CrowdStrike publicly released findings from its annual global threat report, highlighting faster intrusions, increased cloud targeting, and growing activity linked to North Korea and China. Adam Meyers warned that attacker speed was the most concerning trend and predicted AI would accelerate zero-day discovery and exploitation in the coming months.
The report said 82% of detected attacks in 2025 were malware-free, reflecting greater use of hands-on-keyboard techniques and legitimate tools. CrowdStrike also observed increased exploitation of zero-days in edge technologies and a 42% year-over-year rise in zero-days used before public disclosure.
CrowdStrike reported that cloud-focused intrusions increased 37% year over year in 2025, with activity attributed to nation-state groups surging 266%. The company said attackers often relied on valid or abused credentials to access trusted systems.
According to CrowdStrike's annual global threat report, financially motivated attackers in 2025 reduced their average breakout time to 29 minutes, with the fastest observed breakout time falling to 27 seconds. The finding indicates attackers were moving through victim networks significantly faster than before.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
helpnetsecurity.com
Open sourceblog.talosintelligence.com
Open sourcecyberscoop.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.