Knowledge

State of (in)security - Week 42, 2025

Take action: When using GitHub Copilot or any AI coding assistant, never trust it to analyze code or comments from external contributors or public pull requests. There are ways to hide prompts which are not even tested for until exploited. Treat AI-generated code suggestions the same way you'd treat code from an untrusted developer—always verify packages, libraries, and code logic before implementing them in your projects.


Learn More

In the week between Oct. 13, 2025, midnight and Oct. 20, 2025, midnight we witnessed a total of:

  • 17 advisory/vulnerability events
  • 24 incident/data breach events

Week over Week comparison of week 42 2025 vs week 41 2025:

We also shared 3 practical knowledge items


Total impacted individuals via the events of the week

There were a total of 26,114,765 impacted individuals across 10 incidents, with the largest breach being the Prosper Marketplace reports data breach exposing 17.6 million people incident exposing 17,600,000 individuals. Since not all incidents report a number of impacted individuals, the real number is definitely higher than that.

Cause breakdown of incidents

CauseNumber of incidents
Malware, Ransomware and Related Attacks7
Third Party Compromise3
Software Vulnerability and SDLC Exploits2
Social Engineering and Phishing1
System Misconfiguration Exploits1

Industry breakdown of incidents

IndustryNumber of incidents
Education3
Manufacturing2
Other2
Retail2
IT/Software/Technology2
Construction/Realestate2
Government2
Healthcare2
Aviation2
Telecommunications1
Finance1
Food and Beverage1
Insurance1
Automotive1

 

Read the Event Details of the Week

Knowledge

Vulnerabilities

Incidents

State of (in)security - Week 42, 2025