Knowledge

State of (in)security - Week 17, 2025

Take action: Be very conscious about third party vulnerabilities. There are a lot of vulnerable libraries that we are using, and even some that hackers have actively breached and injected malicious code. Keep third party code in your risk plan, and try to monitor it regularly. It's hard, but checking will let you sleep better.


Learn More

In the week between April 21, 2025, midnight and April 28, 2025, midnight we witnessed a total of:

  • 19 advisory/vulnerability events
  • 16 incident/data breach events

Week over Week comparison of week 17 2025 vs week 16 2025:

We also shared 5 practical knowledge items


Total impacted individuals via the events of the week

There were a total of 396,281 impacted individuals across 8 incidents, with the largest breach being the Onsite Mammography data breach exposes data of 357K individuals incident exposing 357,265 individuals. Since not all incidents report a number of impacted individuals, the real number is definitely higher than that.

Cause breakdown of incidents

CauseNumber of incidents
Human bad security behaviour2
System Misconfiguration Exploits2
Third Party Compromise2
Unauthorized access2
Malware, Ransomware and Related Attacks1

Industry breakdown of incidents

IndustryNumber of incidents
Government4
Healthcare3
Telecommunications2
IT/Software/Technology1
Retail1
Transport/Logistics1
Consulting/Professional Services1
Utilities1
Education1
Finance1

Read the Event Details of the Week

Knowledge

Vulnerabilities

Incidents

State of (in)security - Week 17, 2025