Reporting highlighted the widening gap between vulnerability volume and real-world exploitation: a VulnCheck analysis of 2025 data found more than 40,000 new vulnerabilities disclosed, but only ~1% (422) were exploited in the wild, reinforcing that CVSS alone is increasingly insufficient for prioritization. The same reporting emphasized that network edge devices remain a disproportionately common intrusion point (cited as 191 of 672 products impacted by new known-exploited vulnerabilities), reflecting attacker preference for internet-facing, privileged-access technologies and long-lived codebases.
Separate coverage underscored broader risk trends rather than a single incident: the PCI Security Standards Council warned that threats to payment systems are accelerating and require faster global coordination and evolving standards, while a CSIS incident roundup documented multiple 2025 events including Medusa’s claimed breach of SimonMed Imaging (~1.2M patients) and other ransomware, hacktivist, and APT activity. Additional items in the set were largely non-specific or promotional (a newsletter/webinar plug, venture-capital market coverage, and a mixed CSO page that includes a “fake Zoom meeting” malware story but without enough detail here to tie it to the other reporting), and do not describe the same discrete security event as the vulnerability-exploitation and payments-risk reporting.

See which actors are running it and whether you're in range.
7 events from the most recent confirmed update back to the earliest known activity.
VulnCheck released a report summarizing 2025 vulnerability exploitation trends, highlighting network edge devices as a preferred intrusion point and noting concentration among vendors such as Microsoft, Ivanti, Fortinet, VMware, SonicWall, and Oracle. The report argued that the core problem is technology resilience and the widening gap between attacker capability and defensive capacity.
The PCI Security Standards Council published its first-ever annual report covering 2025, saying change in payment systems is accelerating and threats are becoming more sophisticated. The report emphasized transparency, global coordination, and continued updates to standards, training, and compliance efforts.
BridgePay Network Solutions disclosed a ransomware attack that led to extended service disruptions, illustrating ongoing cyber risk in the payments sector. The exact incident date is not provided in the references.
A cluster of four Microsoft SharePoint zero-days — CVE-2025-53770, CVE-2025-53771, CVE-2025-49706, and CVE-2025-49704 — was exploited at scale in 2025. VulnCheck said the campaign initially compromised more than 400 organizations, including multiple U.S. federal departments.
VulnCheck identified React2Shell in React Server Components as the most targeted vulnerability of 2025, with hundreds of public exploits appearing quickly and dozens of organizations affected. The report cited it as an example of rapid weaponization and broad attacker interest.
According to VulnCheck, 422 vulnerabilities, about 1% of those published in 2025, were observed being exploited in real-world attacks. The finding underscored the need for defenders to prioritize based on exploitation activity rather than CVSS scores alone.
VulnCheck reported that over 40,000 vulnerabilities were newly published across 2025, reflecting continued growth in the volume of disclosed software flaws. The report said only a small fraction would later be exploited in the wild.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.