Rapid7 Q3 Report: 88 Ransomware Groups, New Alliances
Rapid7 (NASDAQ: RPD) released its Q3 2025 Threat Landscape Report on November 12, 2025, highlighting rapid attacker adaptation, rising ransomware alliances, and growing use of generative AI by adversaries.
Key findings: newly exploited vulnerabilities fell 21% Q2→Q3 while attackers targeted older, unpatched CVEs including CVE-2025-53770 and Cisco ASA/FTD flaws; active ransomware groups rose to 88 from 65 in Q2; AI-enabled malware and nation-state supply-chain tactics increased.
Rapid7 (NASDAQ: RPD) ha pubblicato il Q3 2025 Threat Landscape Report il 12 novembre 2025, evidenziando una rapida adattabilità degli attaccanti, alleanze crescenti nel ransomware e un uso sempre maggiore di IA generativa da parte degli avversari.
Principali scoperte: le vulnerabilità recentemente sfruttate sono diminuite del 21% dal Q2 al Q3, mentre gli attaccanti hanno preso di mira vulnerabilità CVE più vecchie e non patchate, tra cui CVE-2025-53770 e difetti di Cisco ASA/FTD; i gruppi ransomware attivi sono aumentati a 88 da 65 nel Q2; il malware abilitato dall'IA e le tattiche di supply-chain a livello di stato-nazione sono aumentate.
Rapid7 (NASDAQ: RPD) publicó su Informe del Panorama de Amenazas del T3 2025 el 12 de noviembre de 2025, destacando la rápida adaptación de los atacantes, la creciente alianza entre ransomware y el uso cada vez mayor de IA generativa por parte de los adversarios.
Principales hallazgos: las vulnerabilidades recién explotadas cayeron un 21% de Q2 a Q3, mientras los atacantes atacaron CVEs más antiguos y no parcheados, incluyendo CVE-2025-53770 y fallos en Cisco ASA/FTD; los grupos de ransomware activos aumentaron a 88 desde 65 en el Q2; el malware habilitado por IA y las tácticas de cadena de suministro a nivel estatal aumentaron.
Rapid7 (NASDAQ: RPD) 은 2025년 11월 12일 Q3 2025 Threat Landscape Report 를 발표했으며, 공격자의 빠른 적응, 증가하는 랜섬웨어 동맹, 그리고 적대 세력의 생성형 AI 사용 증가를 강조했습니다.
주요 발견: Q2에서 Q3로 새로 악용된 취약점은 21% 감소했고, 공격자들은 CVE-2025-53770 및 Cisco ASA/FTD 취약점을 포함한 더 오래되고 패치되지 않은 CVEs를 노렸으며, 활성 랜섬웨어 그룹은 Q2의 65에서 88로 증가했습니다; AI 지원 악성코드와 국가 간 공급망 전술이 증가했습니다.
Rapid7 (NASDAQ: RPD) a publié son Rapport sur le Paysage des Menaces du T3 2025 le 12 novembre 2025, mettant en évidence l'adaptation rapide des attaquants, les alliances croissantes en matière de ransomware et l'utilisation croissante de l'IA générative par les adversaires.
Principaux constats : les vulnérabilités nouvellement exploitées ont chuté de 21% entre le T2 et le T3, tandis que les attaquants ciblaient des CVEs plus anciens et non corrigés, notamment le CVE-2025-53770 et les failles Cisco ASA/FTD ; les groupes de ransomware actifs sont passés de 65 à 88 au T2 ; les malwares activés par l'IA et les tactiques de chaîne d'approvisionnement à l'échelle des États-nations ont augmenté.
Rapid7 (NASDAQ: RPD) veröffentlichte seinen Threat Landscape Report für das Q3 2025 am 12. November 2025 und hob die schnelle Anpassung der Angreifer, wachsende Allianzen im Bereich Ransomware und den zunehmenden Einsatz generativer KI durch Angreifer hervor.
Schlüssel-Funde: Neue ausgenutzte Schwachstellen sanken im Q3 gegenüber Q2 um 21% , während Angreifer ältere, ungepatchte CVEs ins Visier nahmen, darunter CVE-2025-53770 und Cisco ASA/FTD-Schwachstellen; aktive Ransomware-Gruppen stiegen von 65 im Q2 auf 88 ; KI-gestützte Malware und Taktiken der staatlich geförderten Lieferkette nahmen zu.
Rapid7 (ناسداك: RPD) أصدرت تقرير مشهد التهديدات للربع الثالث من 2025 في 12 نوفمبر 2025، مسلطة الضوء على سرعة تكيف المهاجمين، وتحالفات ransomware المتنامية، وتزايد استخدام الذكاء الاصطناعي التوليدي من قبل الخصوم.
النتائج الرئيسية: انخفضت الثغرات الجديدة التي تم استغلالها بنسبة 21% من الربع الثاني إلى الربع الثالث، في حين استهدف المهاجمون ثغرات CVE أقدم وغير مُعَطّلة بما في ذلك CVE-2025-53770 وعيوب Cisco ASA/FTD؛ ارتفع عدد مجموعات ransomware النشطة إلى 88 من 65 في الربع الثاني؛ ازدادت البرمجيات الخبيثة المدعومة بالذكاء الاصطناعي وتكتيكات سلسلة الإمداد على مستوى الدول.
BOSTON, Nov. 12, 2025 (GLOBE NEWSWIRE) -- Rapid7 , a leader in threat detection and exposure management, today released its Q3 2025 Threat Landscape Report , revealing how threat actors are accelerating the race between vulnerability disclosure and exploitation, consolidating ransomware power structures, and increasingly weaponizing artificial intelligence to evade detection. The report draws from Rapid7’s Intelligence Hub, AttackerKB, incident response, and managed detection and response (MDR) telemetry, offering data-driven insight into how adversaries are evolving and how defenders can adapt.
“Ransomware has evolved significantly beyond its early days to become a calculated strategy that destabilizes industries,” said Raj Samani, Chief Scientist at Rapid7. “In addition, the groups themselves are operating like shadow corporations. They merge infrastructure, tactics, and PR strategies to project dominance and erode trust faster than ever.”
Critical vulnerability exploitation speeds up as old weaknesses persist
Rapid7’s quarterly analysis shows that the total number of newly exploited vulnerabilities trended downward, dropping 21% from Q2 to Q3. However, adversaries doubled down on older, unpatched weaknesses, including CVEs more than a decade old, indicating that historic exposures remain potent attack vectors.
The mass exploitation of critical vulnerabilities in Microsoft SharePoint (CVE-2025-53770) and Cisco ASA/FTD products underscores the narrowing window between patch disclosure and in-the-wild attacks.
“The moment a vulnerability is disclosed, it becomes a bullet in the attacker’s arsenal,” said Christiaan Beek, senior director of threat intelligence and analytics at Rapid7. “Attackers are no longer waiting. Instead, they’re weaponizing vulnerabilities in real time and turning every disclosure into an opportunity for exploitation. Organizations must now assume that exploitation begins the moment a vulnerability is made public and act accordingly.”
Ransomware activity spikes with new alliances and innovative tactics
The quarter also saw 88 active ransomware groups, up from 65 in Q2 and 76 in Q1, signaling an increase in activity as well as underscoring these groups’ fluidity. Groups like Qilin, SafePay, and WorldLeaks led a wave of alliances targeting industries like business services, manufacturing, and healthcare, and experimenting with fileless operations, single-extortion data leaks, and affiliate service offerings such as ransom negotiation assistance, where a more senior member of the group partners with a less experienced player to extort the victim.
Generative AI lowers barriers as nation-state campaigns redefine cyber warfare
The report details how generative AI is lowering the barrier for creating convincing phishing campaigns and enabling adaptive malware, such as LAMEHUG, which can dynamically generate new commands.
Meanwhile, nation-state operators from Russia, China, and Iran refine their tactics, blurring the line between espionage and disruption by targeting supply chains and identity systems with an emphasis on stealth and persistence.
To read a full copy of the report, visit .
the Rapid7 Threat Landscape Report
The Rapid7 Threat Landscape Report is a quarterly analysis of global adversary behavior drawn from the company’s managed detection and response operations, vulnerability intelligence platforms, and threat research telemetry. The Q3 2025 edition provides one of the most comprehensive views of the global threat ecosystem: from ransomware and zero days to state- operations and AI-driven attacks.
Rapid7 Media Relations Alice Randall Director, Global Communications [email protected] (857) 216-7804
Rapid7 Investor Ryan Gardella / Ryan Flanagan ICR , Inc [email protected] (617) 865-4277
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
