State of (in)security - Week 32, 2025
Take action: Never trust "secret profit methods" or anyone claiming to share money-making exploits - if someone really found a way to make 37% profit, they'd use it themselves, not share it. Never run unknown JavaScript code or programs from random sources, especially ones promising easy profits.
Learn More
In the week between Aug. 4, 2025, midnight and Aug. 11, 2025, midnight we witnessed a total of:
- 21 advisory/vulnerability events
- 20 incident/data breach events
Week over Week comparison of week 32 2025 vs week 31 2025:
- Advisories and incidents are up from the previous week. Advisories are up from 15 in week 31 to 21 in week 32. Incidents are up from 17 in week 31 2025 to 20 in week 32 2025.
- The number of known impacted individuals is up - from 456 thousan in week 31 to 6.658 million in week 32 2025.
We also shared 4 practical knowledge items
Total impacted individuals via the events of the week
There were a total of 6,658,997 impacted individuals across 5 incidents, with the largest breach being the Bouygues Telecom hit by cyberattack, exposing data of 6.4 million customers incident exposing 6,400,000 individuals. Since not all incidents report a number of impacted individuals, the real number is definitely higher than that.
Cause breakdown of incidents
| Cause | Number of incidents |
|---|---|
| Social Engineering and Phishing | 4 |
| Malware, Ransomware and Related Attacks | 3 |
| System Misconfiguration Exploits | 3 |
| Software Vulnerability and SDLC Exploits | 1 |
| Unauthorized access | 1 |
Industry breakdown of incidents
| Industry | Number of incidents |
|---|---|
| Healthcare | 3 |
| IT/Software/Technology | 3 |
| Education | 3 |
| Government | 2 |
| Media | 1 |
| Non-profit/Charity | 1 |
| Other | 1 |
| Retail | 1 |
| Aviation | 1 |
| Telecommunications | 1 |
| Consulting/Professional Services | 1 |
| Finance | 1 |
| Gas/Oil | 1 |
Read the Event Details of the Week
Knowledge
- active scam | Cryptocurrency theft through a program that victims need to run to allegedly profit from a bug in crypto exchange
- active attack | Hackers breach Salesforce instances of major corporations through voice phishing
- active attack | Mozilla warns of active phishing campaign targeting Firefox Add-on developers
- active attack | SonicWall Gen 7 firewalls targeted with SSL VPN Zero-Day vulnerability
Vulnerabilities
- critical vulnerability | Adobe releases emergency updates for Adobe Experience Manager Forms flaes after public PoC
- critical vulnerability | Authentication bypass flaw reported in Packet Power Infrastructure Monitoring devices
- critical vulnerability | CISA and Microsoft warn of an Exchange Server Hybrid flaw enabling attackers to compromise the Cloud instance
- critical vulnerability | ControlVault Vulnerabilities dubbed ReVault expose Dell business laptops to firmware-level attacks
- critical vulnerability | Critical authentication bypass flaw in Burk Technology ARC Solo Devices
- critical vulnerability | Critical authentication bypass flaw reported in Instantel Micromate industrial monitoring devices
- critical vulnerability | Critical buffer overflow flaw in Squid HTTP Proxy enables remote code execution
- critical vulnerability | Critical flaws in Trend Micro Apex One Management Console actively exploited
- critical vulnerability | Critical path traversal flaw reported in Delta Electronics DIAView industrial automation system
- ransomware | Critical remote code execution flaw in NestJS development tools enables attacks against developers
- critical vulnerability | Critical SQL Injection flaw reported in ADOdb PHP database library
- critical vulnerability | Critical vulnerabilities reported in EG4 electronics solar inverters
- critical vulnerability | Critical vulnerabilities reported in Tigo Energy Cloud connect advanced solar management platform
- critical vulnerability | Cursor IDE vulnerability enables persistent code execution through AI plugin trust bypass
- critical vulnerability | Google Looker Studio leaks "Unlisted" reports exposing them to unauthorised access
- critical vulnerability | Google releases August 2025 Android Security Update, patches six vulnerabilities, two critical, two exploited
- critical vulnerability | HashiCorp patches critical flaw in Vault allowing privileged code execution
- data breach | Researchers report critical flaws in CyberArk vaults
- critical vulnerability | Team82 Researchers report multiple flaws in Axis Communications CCTV Systems
- data breach | Vulnerability chain in NVIDIA Triton Inference Server enables complete AI server takeover
- ransomware | WinRAR vulnerability exploited in malware campaigns
Incidents
- data breach | Data of over 30,000 students Indian Institute of Technology Roorkee published online
- data breach | Another data broker leaves publicly accessible repository, leaks hundreds of thousands of personal records
- data breach | Pandora Jewelry confirms data breach caused by third-party platform attack
- data breach | Cisco reports data breach after voice Phishing attack compromises third-party CRM system
- data breach | U.S. Federal Judiciary confirms cyberattack exposing court records and confidential informant identities
- data breach | Warwick Students' Union configuration error leaks thousands of students' personal data
- data breach | Connex Credit Union reports data breach exposing personal info of 172,000 members
- data breach | Threat actors claim breach of over a dozen Malaysian government websites
- data breach | PBS reports data breach exposing data of almost 4,000 employees and affiliates
- data breach | KLM and Air France report data breach through third-party customer service system
- data breach | Google confirms data breach of Salesforce instance via voice phishing attack
- data breach | Venice Film Festival confirms data breach affecting accredited participants
- data breach | Healthcare devices exposed: over 1.2 million medical systems found misconfigured and accessible on the Internet
- data breach | Bouygues Telecom hit by cyberattack, exposing data of 6.4 million customers
- data breach | North Carolina Endodontic practice hit by email compromise and phishing, exposing patient data
- data breach | Doncaster care provider Hesley Group reports cyberattack exposing staff data and financial info
- data leak | TeaOnHer app, rival to the Tea safety app leaks driver's licenses and personal data of 53,000 users
- ransomware | Manassas Park City Schools hit by ransomware attack exposing student and staff info
- ransomware | New Zealand accounting firm TAS NZ Bay Limited hit by ransomware attack, data breach
- ransomware | Pakistan Petroleum Limited hit by ransomware attack