The year was characterized by an unending beat-down on infrastructure that relied on older enmeshed dependencies (e.g., Log4j and PHPUnit), while React2Shell rocketed to the highest percentage of attacks for the entire year within the last three weeks of 2025.
First seen on blog.talosintelligence.com
Jump to article: blog.talosintelligence.com/year-in-review-vulnerabilities-old-and-new-and-something-react2/
![]()

