Knowledge

State of (in)security - Week 27, 2025

Take action: This week malware code was reported to have a vulnerability that can be exploited against the owners of the malware. Obviously, we don't really care if the criminals patch their software. But this is a prime example that all software can be flawed, and that input validation IS ALWAYS A GREAT IDEA.


Learn More

In the week between June 30, 2025, midnight and July 7, 2025, midnight we witnessed a total of:

  • 11 advisory/vulnerability events
  • 14 incident/data breach events

Week over Week comparison of week 27 2025 vs week 26 2025:

We also shared 3 practical knowledge items


Total impacted individuals via the events of the week

There were a total of 6,719,128 impacted individuals across 7 incidents, with the largest breach being the Australia's Qantas Airways suffers cyberattack affecting up to 6 million customers incident exposing 6,000,000 individuals. Since not all incidents report a number of impacted individuals, the real number is definitely higher than that.

Cause breakdown of incidents

CauseNumber of incidents
Malware, Ransomware and Related Attacks6
Software Vulnerability and SDLC Exploits2
Social Engineering and Phishing1
System Misconfiguration Exploits1
Third Party Compromise1

Industry breakdown of incidents

IndustryNumber of incidents
Healthcare2
Finance2
Non-profit/Charity2
Consulting/Professional Services2
Retail1
Government1
IT/Software/Technology1
Aviation1

 

Read the Event Details of the Week

Knowledge

Vulnerabilities

Incidents

State of (in)security - Week 27, 2025