Knowledge

State of (in)security - Week 39, 2025

Take action: If you are considering using an MCP server, don't. They are extremely insecure and should not be trusted. If you do need them, implement blocking security review on ANY AND ALL IMPLEMENTATION AND CHANGES.


Learn More

In the week between Sept. 22, 2025, midnight and Sept. 29, 2025, midnight we witnessed a total of:

  • 8 advisory/vulnerability events
  • 22 incident/data breach events

Week over Week comparison of week 39 2025 vs week 38 2025:

We also shared 6 practical knowledge items


Total impacted individuals via the events of the week

There were a total of 704,204 impacted individuals across 8 incidents, with the largest breach being the Harrods luxury department store reports data breach caused by third-party incident incident exposing 430,000 individuals. Since not all incidents report a number of impacted individuals, the real number is definitely higher than that.

Cause breakdown of incidents

CauseNumber of incidents
Malware, Ransomware and Related Attacks6
Third Party Compromise5
System Misconfiguration Exploits4
Social Engineering and Phishing1
Software Vulnerability and SDLC Exploits1
Unauthorized access1

Industry breakdown of incidents

IndustryNumber of incidents
Healthcare4
Consulting/Professional Services4
Finance3
IT/Software/Technology2
Government2
Automotive1
Retail1
Education1
Entertainment/Leisure1
Insurance1
Other1

 

Read the Event Details of the Week

Knowledge

Vulnerabilities

Incidents

State of (in)security - Week 39, 2025