Knowledge

State of (in)security - Week 23, 2025

Take action: External packages can be compromised. Always vet them and make sure to use packages with a lot of contributors and and a lot of users. Avoid brand new packages and packages with a single contributor and NEVER just trust packages suggested by AI.


Learn More

In the week between June 2, 2025, midnight and June 9, 2025, midnight we witnessed a total of:

  • 14 advisory/vulnerability events
  • 23 incident/data breach events

Week over Week comparison of week 23 2025 vs week 22 2025:

We also shared 6 practical knowledge items


Total impacted individuals via the events of the week

There were a total of 212,914,054 impacted individuals across 9 incidents, with the largest breach being the Researchers discover unsecured database leaking 4 billion user records incident exposing 100,000,000 individuals. Since not all incidents report a number of impacted individuals, the real number is definitely higher than that.

Cause breakdown of incidents

CauseNumber of incidents
Malware, Ransomware and Related Attacks6
Software Vulnerability and SDLC Exploits3
System Misconfiguration Exploits3
Unauthorized access2
Human bad security behaviour1
Social Engineering and Phishing1

Industry breakdown of incidents

IndustryNumber of incidents
Government7
IT/Software/Technology5
Healthcare3
Telecommunications2
Retail2
Education1
Consulting/Professional Services1
Finance1

 

Read the Event Details of the Week

Knowledge

Vulnerabilities

Incidents

State of (in)security - Week 23, 2025