Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Threats and Vulnerabilities - Forescout’s 2025 Threat Roundup: 84% OT Surge Signals Expanding Cyber Chaos
Threats and Vulnerabilities News & Analysis Security Study & Research Threat Intelligence

Forescout’s 2025 Threat Roundup: 84% OT Surge Signals Expanding Cyber Chaos

Kirsten DoyleBy Kirsten DoyleFebruary 5, 20264 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Forescout's 2025 Threat Roundup
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

In 2025, attackers didn’t only target traditional areas of vulnerability; they went after those with the least defense and the most rapid change. These include new AI technologies, web applications, and operational technology (OT) for industries such as healthcare, manufacturing, energy, government, and finance.  

In fact, attacks against OT protocol rose by a whopping 84% with Modbus, Ethernet/IP, and BACnet at the forefront. IoT exploits increased to 19%, hitting cameras and video recorders the hardest, while network devices accounted for some 19% of all exploits. This is no surprise, because last year, IT, IoT, and OT saw broad expansion amid rapid infrastructure shifts. 

These were some of the findings of the recent 2025 Threat Roundup by Forescout Technologies – Vedere Labs. The research aims to provide an overview of the global threat landscape and key trends that cyber defenders should be aware of in 2026 by reviewing the attack telemetry and threat actor intelligence it collects.  

Most information comes from Vedere’s Adversary Engagement Environment (AEE), a group of online honeypots set up to attract attackers and track what they do. From January to December 2025, it logged over 900 million attacks, some of which targeted known vulnerabilities with specific CVE identifiers. 

The report said: “Monitoring traffic to and from OT assets is now as critical as monitoring IT traffic. Attackers are continuously probing these assets for weaknesses, and many organizations remain blind because they lack visibility into OT environments. Building automation protocols, and even widely deployed protocols, such as Modbus, are present in many organizations and should be treated as high-priority targets for risk monitoring and risk reduction.” 

Global Attack Distribution 

When it came to global attack distribution, the report found that cyberattacks originated from 214 countries, led, unsurprisingly, by China, Russia, and Iran. The top 10 nations accounted for 61% of malicious traffic (down 22% from 2024).  

The US was their main target, followed by India and Germany. Threat actors showed broader geographic spread and targeted critical sectors like manufacturing (16% actor growth), healthcare (13%), and energy (6%). 

The research revealed that in 2025, China-linked threat actors targeted medical systems and enterprise software, while researchers also tracked attacks on SOHO routers to build proxy botnets and ongoing activity against telecom and critical infrastructure. 

“Russia- and Iran-linked activity also included hacktivist-style personas, such as NoName057(16) and Handala Group. These groups often emphasize disruptive messaging and infrastructure impact and align operations with geopolitical flashpoints,” they added. 

Infrastructure and Tactics Evolution 

Infrastructure and tactics evolved, too. Abuse of Amazon and Google cloud infrastructure accounted for over 15% of attacks, up from 11% in 2024, driven by fast-changing Autonomous Systems amid law enforcement disruptions.  

Web apps were again the top target at 61%, followed by remote management protocols at 15%. Post-exploitation reconnaissance soared to 91% of activities, up from 25% in 2023. 

Vulnerability Trends 

CISA’s Known Exploited Vulnerabilities list grew 30% year-on-year to 242 entries, while Vedere Labs added 285 vulnerabilities to its own KEV list, a staggering 213% increase.  

It’s worth mentioning that nearly three-quarters (71%) of exploited flaws were absent from CISA’s catalog, including Langflow AI framework components, which could signal rising risks in AI tools and unpatched systems. 

However, Forescout offered this insight for defenders: “When deciding what to patch, and when, prioritize evidence of active exploitation alongside CVSS and other severity metrics. The CISA KEV catalog is a valuable baseline, but it does not capture the full exploited vulnerability landscape. Use additional threat intelligence to prioritize vulnerability risk mitigation, including Vedere Labs’ threat feeds and other trusted sources.” 

Mitigations and Defense 

According to Forescout, “Organizations should prioritize extending visibility, risk assessment and proactive controls across an expanding attack surface, including network perimeter assets, operational technology environments, healthcare systems, and IoT assets.” 

At a minimum, researchers advised organizations to:  

  • Ensure full visibility into these assets, including their presence on the network, the software they run, and their communication patterns.  
  • Understand asset risk profiles across vulnerabilities, weak configurations, exposure and other factors.  
  • Disable unused services and patch vulnerabilities to reduce the window of exploitation. 
  • Change default or easily guessable credentials and use strong, unique passwords for each asset.  
  • Enforce multifactor Authentication (MFA) whenever possible, especially for VPN access.  
  • Encrypt sensitive data in transit and at rest, especially personally identifiable information (PII), protected health information (PHI), and financial data. 
  • Avoid exposing unmanaged or legacy assets directly to the internet unless absolutely necessary.  
  • Apply IP-based access control lists to limit access to sensitive protocols, such as Modbus and BACnet, in OT networks.  
  • Segment the network to isolate IT, IoT and OT assets, limiting network connections to only authorized management and engineering workstations or to the minimum set of asset-to-asset communications required for operations. 

To read the full report, click here.  

Kirsten Doyle
Kirsten Doyle
Information Security Buzz News Editor

Kirsten Doyle has been in the technology journalism and editing space for nearly 24 years, during which time she has developed a great love for all aspects of technology, as well as words themselves. Her experience spans B2B tech, with a lot of focus on cybersecurity, cloud, enterprise, digital transformation, and data centre. Her specialties are in news, thought leadership, features, white papers, and PR writing, and she is an experienced editor for both print and online publications.

  • Kirsten Doyle
    AI-Powered Attacks Become Top Concern for Security Professionals, New Filigran Survey Reveals
  • Kirsten Doyle
    ShinyHunters targets Oracle PeopleSoft customers through critical zero-day
  • Kirsten Doyle
    SIG report: AI-generated code is linked to twice the security risk and rising technical debt
  • Kirsten Doyle
    Miasma worm spreads from Red Hat packages to Microsoft repositories

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Palo Alto warns of active exploitation of GlobalProtect authentication bypass flaw

June 2, 20263 Mins Read

How EM is boosting the career trajectory of VM analysts

May 19, 20266 Mins Read

Microsoft patches 138 vulnerabilities as AI-driven discovery accelerates

May 14, 20265 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}