Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
actively-exploited-vulnerabilitygovernment-vulnerability-catalogperimeter-device-exposurerapid-weaponization

Rising exploitation pressure from zero-days and known exploited vulnerabilities

Updated 3mo agoFirst seen Mar 6, 20264 sources

Security reporting and research highlighted accelerating exploitation pressure on enterprises, driven by both zero-day activity and the growing backlog of known exploited vulnerabilities (KEVs). A Talos retrospective counted 48,196 CVEs in 2025 and 241 KEVs (up from 186 in 2024), with a notable share of KEVs originating from older CVEs and even vulnerabilities dating back to 2007—reinforcing that attackers continue to monetize long-lived weaknesses when patching and asset visibility lag. Talos also noted disproportionate exploitation targeting network edge infrastructure (e.g., firewalls/VPNs), underscoring the operational risk of unpatched or hard-to-patch appliances and legacy systems.

Separate threat reporting pointed to expanding attack volume and shifting attacker tradecraft that can amplify exploitation impact. Check Point data cited by Dark Reading said Latin America is seeing substantially higher weekly attack volume than the US (including higher proportions of ransomware and infostealer activity), consistent with adversaries concentrating on regions with faster digital adoption and lower security maturity. CSO Online also reported that the Coruna iOS exploit kit rapidly evolved from a targeted spyware capability into broader criminal use, illustrating how advanced exploitation tooling can commoditize quickly and increase the likelihood of opportunistic compromise across a wider victim set.

Share:
Rising exploitation pressure from zero-days and known exploited vulnerabilities
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
Mar 6, 20264mo ago

Cisco issues emergency patches for critical firewall flaws

CSO Online reported that Cisco released emergency patches for critical firewall vulnerabilities. The reference does not specify the affected products or CVE identifiers.

LeakBase marketplace taken offline in 14-country law enforcement operation

CSO Online reported that the LeakBase marketplace was disrupted and taken offline through a law enforcement operation involving 14 countries. No further operational details or exact takedown date were provided in the reference.

Mar 5, 20264mo ago

Coruna iOS exploit kit shifts to mass criminal use

CSO Online reported that the Coruna iOS exploit kit moved from a spy tool to a mass criminal campaign in under a year. The reference does not provide a more specific date for when the transition occurred.

Mar 1, 20264mo ago

Check Point reports Latin America averaging 3,100 weekly cyber threats

An unpublished March 2026 Check Point update shared with Dark Reading said organizations in Latin America were facing about 3,100 cyber threats per week on average, compared with just under 1,500 in the United States. The report also highlighted higher regional shares of ransomware, infostealers, banking malware, and botnet activity, with email serving as the dominant initial access vector in Latin America.

Dec 31, 20256mo ago

AI-related CVE count rises year over year in 2025

Talos said its keyword-based tracking found AI-related CVEs increased from 168 to 330 year over year in 2025. The company cautioned that CVE counts do not capture broader AI security risks such as jailbreaking or model inversion.

CISA KEV catalog grows to 241 entries during 2025

Cisco Talos reported that CISA's Known Exploited Vulnerabilities catalog reached 241 entries in 2025, up from 186 in 2024. Talos said many of the added exploited flaws were older CVEs, including some dating back to 2007.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

10 LINKEDOpen in app
Threat actors
1 linked
Malware
1 linked
Affected products
2 linked
IosIos
Organizations
6 linked
AT&TCisco SystemsCheck Point Software TechnologiesDark ReadingIntel 471C&M Software
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.