Fortinet’s latest 2025 Global Threat Landscape Report shows that cybercriminals have been carrying out faster and more targeted attacks using artificial intelligence (AI) and automation. The report is based on the networking and security solutions providers’ FortiGuard Labs.

“Our latest Global Threat Landscape Report makes one thing clear: Cybercriminals are accelerating their efforts, using AI and automation to operate at unprecedented speed and scale,” said Derek Manky, chief security strategist and global vice president of threat intelligence at Fortinet FortiGuard Labs.

One of the main findings shows that cybercriminals are scanning the internet at a higher rate to find and exploit weak systems. Automated scanning increased by nearly 16.7% last year, with FortiGuard Labs recording billions of scans every month. The scans often target services like SIP, RDP, and OT/IoT protocols.

Darknet drives tool access and stolen credentials

Underground forums have also become more organized. In 2024 alone, over 40,000 new vulnerabilities were added to the National Vulnerability Database. These vulnerabilities are quickly packaged into exploit kits and sold. The report also noted a sharp increase, or about 500%, in data stolen through infostealer malware, with 1.7 billion credentials traded online.

AI is helping cybercriminals launch more convincing phishing attacks and dodge traditional security systems. Tools like FraudGPT and ElevenLabs are being used to make fake messages more believable, making it harder for people and systems to detect threats.

Critical sectors and cloud environments under pressure

Attacks have grown more focused, targeting sectors such as manufacturing, healthcare, and financial services. In 2024, manufacturing was hit the most (17%), followed by business services (11%), construction (9%), and retail (9%). Most of the attacks were directed at the United States (61%), with the United Kingdom (6%) and Canada (5%) also among the top targets.

Cloud systems are another growing concern. Many incidents came from unusual login locations, pointing to issues in how identities and access rights are handled.

“The traditional security playbook is no longer enough. Organizations must shift to a proactive, intelligence-led defense strategy powered by AI, zero trust, and continuous threat exposure management to stay ahead of today’s rapidly evolving threat landscape,” Manky said.

Discover more from Back End News

Subscribe now to keep reading and get access to the full archive.

Continue reading