• About Us
  • Advertising
  • Digital Magazine
  • Supplements
  • Media Pack
  • Privacy Policy
  • Contact us
CXO Insight Middle East
  • News
  • Opinion
  • Business
    • Industries
      • Transport
      • Retail
      • Government
      • Real Estate
      • Education
      • Energy
      • Banking and Finance
    • Channel
  • Future
    • Tech
    • Gadgets
    • Science
    • Space
    • Sustainability
  • Events
    • Channel Awards
      • 2025
      • 2024
      • 2023
    • Channel Insights Summit 2025
    • Insight Innovation Summit
    • CXO50 Oman
    • CXO50
      • 2026
      • 2025
    • ICT Awards
      • Dubai 2025
      • Saudi Arabia
    • Cyber Strategists Summit
    • Cloud Connect 2025
    • All events
  • Digital Magazine
  • GITEX x AI EVERYTHING
No Result
View All Result
CXO Insight Middle East
  • News
  • Opinion
  • Business
    • Industries
      • Transport
      • Retail
      • Government
      • Real Estate
      • Education
      • Energy
      • Banking and Finance
    • Channel
  • Future
    • Tech
    • Gadgets
    • Science
    • Space
    • Sustainability
  • Events
    • Channel Awards
      • 2025
      • 2024
      • 2023
    • Channel Insights Summit 2025
    • Insight Innovation Summit
    • CXO50 Oman
    • CXO50
      • 2026
      • 2025
    • ICT Awards
      • Dubai 2025
      • Saudi Arabia
    • Cyber Strategists Summit
    • Cloud Connect 2025
    • All events
  • Digital Magazine
  • GITEX x AI EVERYTHING
No Result
View All Result
CXO Insight Middle East
No Result
View All Result

Cisco Talos report: Legitimate credentials remain a prime target for cybercriminals

by CXO Staff
September 9, 2025
in Future, News, Tech

Phishing remains the top initial access method, despite a 40 per cent decline from Q1 to Q2

Cisco Talos report: Legitimate credentials remain a prime target for cybercriminals

Cisco Talos’ Q2 2025 report reveals a notable shift in attacker objectives and methods. Although phishing activity declined by 40 per cent compared to Q1, it remained the leading initial access method for threat actors, with most campaigns focused on credential theft. Attackers increasingly relied on compromised internal or trusted business partner email accounts to deliver convincing messages that bypass security measures and gain victims’ trust.

This quarter, 75 per cent of observed phishing attacks originated from compromised internal or trusted business partner email accounts. Many users were tricked into entering their credentials and MFA tokens on sophisticated fake login pages, enabling attackers to steal valuable information for use in further attacks or for sale on underground markets.

Fady Younes, Managing Director for Cybersecurity, Cisco Middle East & Africa
Fady Younes, Managing Director for Cybersecurity, Cisco Middle East & Africa

New ransomware observations

Ransomware was responsible for 50 per cent of all incidents in Q2. Talos IR observed Qilin and Medusa ransomware for the first time, while also responding to previously seen Chaos ransomware.

In its first encounter with Qilin ransomware, Talos documented previously unseen tools and tactics. The Qilin attack began with stolen credentials, followed by lateral movement using remote access tools. Attackers employed a unique encryptor and new exfiltration techniques, including CyberDuck for data theft and Backblaze for command and control. They established persistence by creating automated processes to restart the ransomware after reboots and logins, resulting in extensive system damage and requiring a full rebuild and organisation-wide password resets.

Talos’ analysis further suggests that the Qilin group may be expanding its affiliate network or accelerating its operations.

Attacks using old scripting language

A concerning trend is the use of the outdated PowerShell v1.0 scripting language in a third of ransomware attacks, taking advantage of its lack of security features such as script logging and antivirus integration. Cisco Talos advises organisations to mandate PowerShell 5.0 or higher to mitigate these risks.

Education sector most targeted

The education sector emerged as the most targeted industry globally in Q2 2025, a significant change from the previous quarter. High levels of ransomware activity were also observed in manufacturing, construction, and public administration.

Multi-factor authentication: enable and monitor

Over 40 per cent of the second quarter’s incidents involved MFA issues, such as misconfiguration, absence, or bypass. Cisco Talos recommends enabling and closely monitoring MFA to prevent misuse and strengthen organisational security.

Fady Younes, Managing Director for Cybersecurity at Cisco Middle East, Africa, Türkiye, Romania and CIS, stated, “Cybercriminals are increasingly exploiting trust, whether through compromised partner accounts, misconfigured security tools, or outdated systems. The latest Talos findings underscore that credentials remain a prime target, and organisations must not only enable multi-factor authentication but also continuously validate and monitor its effectiveness. Building cyber resilience requires a proactive approach where people, processes, and technologies work together to minimise risk and strengthen defences against evolving threats.”

Tags: Cisco TalosCybersecurityreport
ShareTweet

Related Posts

HUAWEI Mate 80 Pro opens for pre-orders in UAE
News

HUAWEI Mate 80 Pro opens for pre-orders in UAE

March 23, 2026

Huawei has announced the launch of the HUAWEI Mate 80 Pro, the latest addition to its iconic Mate Series, showcasing...

Cohesity integrates Sophos-powered malware scanning
Future

Cohesity integrates Sophos-powered malware scanning

March 23, 2026

Cohesity announced the availability of next-generation malware scanning powered by Sophos, integrated natively into Cohesity Data Cloud. Cohesity Data Cloud...

Discussion about this post

Latest Issue

HUAWEI Mate 80 Pro opens for pre-orders in UAE

HUAWEI Mate 80 Pro opens for pre-orders in UAE

March 23, 2026
Cohesity integrates Sophos-powered malware scanning

Cohesity integrates Sophos-powered malware scanning

March 23, 2026
Fortinet advances its security operations platform

Fortinet advances its security operations platform

March 23, 2026

The most trusted source of strategic intelligence for IT decision makers in the Middle East.

About

  • About Us
  • Advertising
  • Digital Magazine
  • Supplements
  • Media Pack
  • Contact Us

Policies

  • Privacy Policy
© 2025 – CXO Insight Middle East. All Rights Reserved.
Facebook-f X-twitter Linkedin
Separated they live in Bookmarksgrove right at the coast of the Semantics, a large language ocean. A small river named Duden.

About

  • About Us
  • Site Map
  • Contact Us
  • Career

Policies

  • Help Center
  • Privacy Policy
  • Cookie Setting
  • Term Of Use

Join Our Newsletter

© 2024 – CXO Insight Middle East. All Rights Reserved.

Facebook-f Twitter Youtube Instagram

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Join our mailing list
Sign up here to get the latest news, updates and special offers delivered directly to your inbox.
No Result
View All Result
  • News
  • Opinions
  • Business
    • Industries
      • Transport
      • Retail
      • Government
      • Real Estate
      • Education
      • Energy
      • Banking and Finance
  • Channel
  • Future
    • Tech
    • Gadgets
    • Science
    • Space
    • Sustainability
  • Events
    • Channel Awards
      • 2025
      • 2024
      • 2023
    • Channel Insights Summit 2025
    • Insight Innovation Summit
    • CX50 Oman
    • CXO50
      • 2026
      • 2025
    • ICT Awards
      • Dubai
      • Saudi Arabia
    • Cyber Strategists Summit
    • Cloud Connect 2025
    • All events
  • Videos
  • GITEX x AI Everything
  • Digital Magazine

© 2025 - CXO Insight Middle East. All Rights Reserved.