2025's ransomware trends and zombie vulnerabilities

Talos Takes22mApril 7, 2026

Get the full intelligence

Search transcripts, export clips, track mentions, and explore all topics from “2025's ransomware trends and zombie vulnerabilities” inside PodZeus.

AI-Generated Summary

In this episode of Talos Takes, Amy and research lead Pierre Cadu dive into the 2025 Talos Year in Review, focusing on ransomware trends and persistent vulnerabilities. Manufacturing remains the top target due to high downtime tolerance and increasing convergence between IT and OT networks, creating new attack surfaces. Ransomware groups like Chilin, Akira, and Play maintained long-term momentum through consistent tactics, use of 'living off the land' tools, and effective affiliate compensation. The episode highlights how adversaries exploit standard admin tools like RDP, PSExec, and PowerShell, making visibility and context crucial for detection. January, traditionally a quiet month for ransomware, offers a rare window for defenders to reassess and retool—but the team stresses that proactive security should be continuous, not seasonal. The discussion then shifts to 'zombie vulnerabilities' like Log4J, which remain exploitable years after disclosure due to poor asset management and embedded legacy code. Finally, network infrastructure targets such as ADCs and VPNs are prized by attackers for their access to network architecture and authentication systems, especially when weak or single-factor authentication is in place. The episode concludes with a call to action: leverage the freely available year-in-review report to strengthen defenses.

Key Takeaways
1

Manufacturing is the top ransomware target due to high downtime sensitivity and growing IT/OT convergence.

2

Ransomware groups sustain operations through consistent tactics, affiliate incentives, and 'living off the land' tools.

3

January is a rare lull in ransomware activity—use it to plan, but maintain year-round security cycles.

4

Zombie vulnerabilities like Log4J persist due to poor asset management and embedded legacy code.

5

VPNs and management platforms are high-value targets because they provide access to network architecture and persistence.

…and 2 more takeaways available in PodZeus

Chapters
0:00
1 min

Introduction to the 2025 Talos Year in Review

Amy introduces the episode and the focus on ransomware trends and persistent vulnerabilities from the Talos 2025 Year in Review report.

1:00
2 min

Manufacturing as the Top Ransomware Target

Manufacturing has very low tolerance for downtime. They have very tight production schedules and resource requirements.

Highlight
3:00
4 min

Ransomware Groups: Chilin, Akira, and Play

Money is a powerful motivator. It gets them to do this whole thing and it gets all these other folks to, again, join them in this journey.

Highlight
7:00
5 min

Living Off the Land: Detecting Malicious Use of Admin Tools

Without that, you don't have a context. You can then start jumping at shadows if you go too far...

Highlight
12:00
5 min

The January Lull and Strategic Defense Planning

Don't let it be like, you know, how people have in their personal lives a new year's resolution where you really do it in January and then it kind of dies off in February, March, April.

Highlight
High-Impact Quotes
If it's single-factor authentication, don't do this at home, kids. Please make sure to have multi-factor deployed.
Pierre Cadu20:00
Viral: 90.0
Adversaries will also scan your environment happily, but they won't tell you what they're just going to come in and use it.
Pierre Cadu17:09
Viral: 88.0
Money is a powerful motivator. It gets them to do this whole thing and it gets all these other folks to, again, join them in this journey.
Pierre Cadu6:04
Viral: 85.0
Speakers

Host

Amy

Guest

Pierre Cadu
Topics Discussed
ransomware trends95%zombie vulnerabilities92%manufacturing sector targeting90%network infrastructure targeting89%living off the land tools88%vulnerability management87%it-ot convergence85%proactive defense cycles83%
People & Brands

Pierre Cadu

person

18xPositive

Amy

person

15xPositive

Talos

organization

12xPositive

Log4J

product

10xNegative

Chilin

organization

8xNegative

VPNs

product

6xNegative

SharePoint

product

6xNeutral

Play

organization

5xNegative

PowerShell

product

4xNeutral

Akira

organization

4xNegative

Get the full intelligence

Search transcripts, export clips, track mentions, and explore all topics from “2025's ransomware trends and zombie vulnerabilities” inside PodZeus.

Start discovering podcast insights today

Start with a 7-day trial and explore a growing catalog of popular podcasts. No credit card required.

No credit card required • 7-day trial • Cancel anytime