State of (in)security - Week 43, 2025
Take action: If you are installing any AI based tools locally, be aware that AI vendors are not that disciplined in updating those tools. For example Cursor or Windsurf AI-powered code editors, haven't been updated for months.
Learn More
In the week between Oct. 20, 2025, midnight and Oct. 27, 2025, midnight we witnessed a total of:
- 12 advisory/vulnerability events
- 12 incident/data breach events
We also shared 6 practical knowledge items
Week over Week comparison of week 43 2025 vs week 42 2025:
- Advisories and incidents are down. Advisories are down from 17 in week 42 to 12 in week 43 2025. Incidents are down from 24 in week 42 2025 to 12 in week 43 2025.
- The number of known impacted individuals is down - from 26 million in week 42 to 17.4 million in week 43 2025.
Total impacted individuals via the events of the week
There were a total of 17,455,441 impacted individuals across 5 incidents, with the largest breach being the Researchers publish aggregated infostealer data that exposed 183 Million email accounts and passwords incident exposing 16,400,000 individuals. Since not all incidents report a number of impacted individuals, the real number is definitely higher than that.
Cause breakdown of incidents
| Cause | Number of incidents |
|---|---|
| Malware, Ransomware and Related Attacks | 4 |
| Denial-of-Service Attacks | 1 |
| Human bad security behaviour | 1 |
| Software Vulnerability and SDLC Exploits | 1 |
| Third Party Compromise | 1 |
Industry breakdown of incidents
| Industry | Number of incidents |
|---|---|
| Energy | 2 |
| Government | 2 |
| Manufacturing | 1 |
| Other | 1 |
| Retail | 1 |
| Telecommunications | 1 |
| Aviation | 1 |
| Transport/Logistics | 1 |
| Hospitality/Events | 1 |
Read the Event Details of the Week
Knowledge
- active exploit | CISA warns of active exploitation of critical authentication bypass flaws in Kentico Xperience CMS
- active exploit | CISA warns of active exploitation of three years old Apple JavaScriptCore vulnerability
- active exploit | CISA warns of active exploitation of Windows SMB privilege escalation flaw
- active attack | Exploitation campaign targets multiple older critical vulnerabilities in WordPress sites
- active exploit | GlassWorm supply chain attack: Self-Propagating malware infects Visual Studio Code extensions
- active exploit | SessionReaper flaw in Adobe Magento actively exploited
Vulnerabilities
- critical vulnerability | CISA warns of critical authentication bypass flaw in Raisecomm RAX701-GC Series
- critical vulnerability | CISA warns of critical vulnerabilities in Rockwell Automation 1783-NATR
- critical vulnerability | Critical command injection flaw reported in Veeder-Root TLS4B automatic tank gauge system
- critical vulnerability | Critical command injection vulnerabilities in TP-Link Omada Gateways enable remote code execution
- critical vulnerability | Critical remote code execution flaw in LANSCOPE Endpoint Manager actively exploited
- critical vulnerability | Critical vulnerability discovered in End-of-Life ASKI Energy industrial controllers
- critical vulnerability | Google releases emergency security update for Chrome V8 Engine flaw
- critical vulnerability | Microsoft 365 Copilot vulnerability enables data theft through malicious Mermaid diagrams
- critical vulnerability | Microsoft releases emergency patches for actively exploited critical WSUS Deserialization flaw
- critical vulnerability | Multiple vulnerabilities reported in AutomationDirect Productivity Suite and PLCs, at least one critical
- critical vulnerability | Oracle releases October 2025 Critical Patch Update addressing 374 vulnerabilities
- critical vulnerability | Security researchers report critical security flaws in Cursor and Windsurf IDEs
Incidents
- data breach | Large-scale DDoS attack hits Russia's food safety agency, impacting nationwide agricultural product shipments
- data breach | Kaufman County, Texas suffers two separate data breaches in October 2025
- data breach | Toys "R" Us Canada reports data breach exposing customer information
- data breach | Millions of passengers potentially impacted in Dublin Airport data breach after Collins Aerospace ransomware attack
- data breach | Researchers publish aggregated infostealer data that exposed 183 Million email accounts and passwords
- data breach | OYO Hotel & Casino Las Vegas hit by cyberattack exposing data of almost 5,000 people
- data breach | FIA Driver categorisation website vulnerability exposes data of nearly 7,000 FIA drivers
- data breach | Origin Energy reports that employee stole credit card details of over 700 customers
- ransomware | Aussie Fluid Power reports cyberattack, ransomware group Anubis claims responsibility
- ransomware | Ransomware attack on fence wholesaler Jewett-Cameron exposes financial data and video meetings
- ransomware | Everest Ransomware gang claims breach of AT&T Careers platform and theft of 576,686 records
- ransomware | Ransomware attack on Askul disrupts Japanese retailers Muji and Loft