Excite Cyber ECDC Threat Intelligence Report – Q4 2025

Share This Post

The fourth quarter of 2025 demonstrated an escalating convergence of nation-state espionage, ransomware innovation, and supply-chain exploitation across the Asia–Pacific region. As geopolitical tensions intensify and digital dependencies deepen, threat actors have pivoted from opportunistic attacks to systematic campaigns targeting trust architectures—identities, cloud infrastructure, and third-party integrations that underpin modern enterprise operations.

This period witnessed critical zero-day exploitation at unprecedented scale, exemplified by the React2Shell vulnerability achieving a maximum CVSS score of 10.0, alongside sophisticated supply-chain compromises such as the Salesloft Drift incident affecting over 700 organisations globally.
Ransomware operations continued their evolution away from traditional encryption-based extortion toward data-theft campaigns, with Qilin emerging as the most prolific group, approximately 1,000 victims throughout 2025.

For Australia and the broader APAC region, Q4 underscored the necessity of strengthened cloud governance, rigorous third-party risk management, and enhanced monitoring of software supply chains. The quarter’s developments signal that cyber threats are no longer confined to perimeter
breaches—they now exploit the fundamental trust relationships that enable digital business operations.

More To Explore

cyber-security

Excite Cyber Whitepaper – Data Loss Prevention (DLP) as an Enabler for Secure AI Adoption

AI has moved from experiment to operating model, but its real value—and risk—comes down to your data. With 75% of knowledge workers already using AI tools, often without IT oversight, shadow AI is driving a costly wave of breaches that organisations can’t afford to ignore. This whitepaper cuts through the anxiety to show how Microsoft Purview gives you the discovery, classification, and policy controls to make AI safe and productive, turning data security from a blocker into an AI enabler.

cyber-security

Excite Cyber Threat Intelligence Report – Q1 2026

Q1 2026 has been defined by speed. Storm-1175, a financially motivated affiliate of the Medusa ransomware-as-a-service operation, has emerged as the quarter’s most aggressive threat to Australian businesses, weaponising newly disclosed vulnerabilities in internet-facing systems and moving from initial breach to full ransomware deployment in as little as 24 hours.

Enter your details to download your ECDC Threat Intelligence Report