The latest Cisco Talos Threat Source newsletter reports a substantial 49% year-over-year growth in CVEs for Q2 2026, with nearly 200 new vulnerabilities tracked daily. While total disclosures are surging, Known Exploited Vulnerabilities (KEVs) have seen a more modest 13% increase. The data indicates that a significant portion of active threats still involves vulnerabilities from 2025 or earlier, highlighting a persistent gap between discovery and patching. To manage this volume, the report advocates for the use of the Exploit Prediction Scoring System (EPSS) to prioritize high-probability risks over raw CVSS scores.
In addition to statistical trends, Talos highlights the discovery of "msaRAT," a sophisticated Rust-based remote access trojan utilized by the Chaos ransomware group. This malware establishes covert command-and-control channels by hijacking browser processes via the Chrome DevTools Protocol, allowing it to evade traditional network detection. Other critical security events include the destructive database wipe of Romania’s land registry and the emergence of the "WP2Shell" exploit chain targeting WordPress sites, underscoring the ongoing volatility of the global threat landscape.
Top comments (0)