State of (in)security - Week 40, 2025
Take action: Mass firing of people after a cybersecurity incident is just the type of culture which will not help long term. The most the organization can expect is everyone to start pushing the problem onto someone else and covering their behinds.
Learn More
In the week between Sept. 29, 2025, midnight and Oct. 6, 2025, midnight we witnessed a total of:
- 12 advisory/vulnerability events
- 17 incident/data breach events
Week over Week comparison of week 40 2025 vs week 39 2025:
- Advisories are up and incidents are down. Advisories are up from 8 in week 39 to 12 in week 40. Incidents are down from 22 in week 39 2025 to 17 in week 40 2025.
- The number of known impacted individuals is down - from 704 thousand in week 39 to 29 thousand in week 40 2025.
We also shared 4 practical knowledge items
Total impacted individuals via the events of the week
There were a total of 29,485 impacted individuals across 1 incidents, with the largest breach being the Fort Wayne Medical Education Program hit ransomware attack, affects almost 30,000 people incident exposing 29,485 individuals. Since not all incidents report a number of impacted individuals, the real number is definitely higher than that.
Cause breakdown of incidents
| Cause | Number of incidents |
|---|---|
| Malware, Ransomware and Related Attacks | 6 |
| Third Party Compromise | 3 |
| Software Vulnerability and SDLC Exploits | 2 |
| Social Engineering and Phishing | 1 |
| Unauthorized access | 1 |
Industry breakdown of incidents
| Industry | Number of incidents |
|---|---|
| IT/Software/Technology | 5 |
| Healthcare | 4 |
| Government | 2 |
| Food and Beverage | 1 |
| Insurance | 1 |
| Automotive | 1 |
| Media | 1 |
| Consulting/Professional Services | 1 |
| Finance | 1 |
Read the Event Details of the Week
Knowledge
- active exploit | CISA reportd active exploitation of Meteobridge command injection flaw
- active exploit | CISA warns of active exploitation of critical Sudo flaw
- active exploit | Hackers exploit VMware Zero-Day for privilege escalation since October 2024
- active attack | Scanning campaign targets critical Palo Alto GlobalProtect vulnerability
Vulnerabilities
- critical vulnerability | Command Injection vulnerabilities reported in Unitree Robots
- critical vulnerability | Critical authentication bypass flaw in Termix Docker image exposes SSH credentials
- critical vulnerability | Critical privilege escalation flaw in Red Hat OpenShift AI enables cluster takeover
- critical vulnerability | Critical remote code execution flaw patched in Western Digital My Cloud NAS devices
- critical vulnerability | Critical remote code execution vulnerabilities reported in TOTOLINK X6000R routers
- critical vulnerability | Eight-Year-Old critical security flaw discovered in Unity Engine, requires urgent patching for thousands of games
- critical vulnerability | Google releases update for Chrome multiple flaws
- critical vulnerability | High-Severity stored XSS reported in MyCourts platform, can be combined to steal session cookies
- critical vulnerability | JWT signature verification bypass enables account takeover in Formbricks
- critical vulnerability | Oracle releases emergency patch for E-Business Suite as ransomware gang pushes extortion campaign
- critical vulnerability | OS command Injection flaw reported in MegaSys Enterprises Telenium Online web application
- critical vulnerability | Remote code execution flaw reported in DrayTek Vigor router models
Incidents
- data breach | Platinum Federal Credit Union reports employee email compromise, data breach
- data breach | Murray-Calloway county hospital reports third party breach exposing patient information
- data breach | Cyberattack compromises FEMA and Border Protection employee data through CitrixBleed 2.0 flaw
- data breach | Medusa ransomware group claims breach of Comcast Corporation, demands $1.2 Million ransom
- data breach | Harbor Mental Health Services reports data breach exposing patient and employee data
- data breach | Superior Vision Services hit by email phishing attack, exposes data of health plan members
- data breach | Ransomware attack on dealership software provider Motility exposes data of 766,000 customers
- data breach | Red Hat confirms security incident after claims of GitLab repository breach claims
- data breach | Israeli hospital hit by ransomware attack during Yom Kippur
- data breach | Renault reports that UK customer data was exposed in Third-Party cyberattack
- data breach | Discord reports breach at third-party customer service provider exposing user information
- data breach | Legal Practice Board of Western Australia hit by ransomware, exposing legal practitioner data
- data breach | US Air Force is investigating SharePoint related data breach exposing personnel health and personal data
- data breach | Federal cybersecurity contractor AttainX hit by ransomware attack, exposing personal and financial data
- data breach | Fort Wayne Medical Education Program hit ransomware attack, affects almost 30,000 people
- ransomware | Cyberattack forces Japan's Asahi brewery Asahi to suspend operations
- ransomware | Oracle E-Business Suite customers targeted in extortion email campaign