State of (in)security - Week 44, 2025
Take action: All Chromium based browsers (Chrome, Edge, Vivaldi, Opera, Brave...) are vulnerable to being crashed by just visiting a web page. And there is no fix. So be extremely careful clicking unknown links, ideally use Firefox or Safari since they are not vulnerable, and keep up with updates for Chromium based browsers.
Learn More
In the week between Oct. 27, 2025, midnight and Nov. 3, 2025, midnight we witnessed a total of:
- 9 advisory/vulnerability events
- 16 incident/data breach events
Week over Week comparison of week 44 2025 vs week 43 2025:
- Advisories are down and incidents are up. Advisories are down from 12 in week 43 to 9 in week 44 2025. Incidents are up from 12 in week 43 2025 to 16 in week 44 2025.
- The number of known impacted individuals is down - from 17.4 million in week 43 to 329 thousand in week 44 2025.
We also shared 3 practical knowledge items
Total impacted individuals via the events of the week
There were a total of 329,831 impacted individuals across 5 incidents, with the largest breach being the Blue Cross Blue Shield of Texas customers affected by Third-Party vendor data breach incident exposing 310,000 individuals. Since not all incidents report a number of impacted individuals, the real number is definitely higher than that.
Cause breakdown of incidents
| Cause | Number of incidents |
|---|---|
| Malware, Ransomware and Related Attacks | 4 |
| Third Party Compromise | 2 |
| Unauthorized access | 2 |
| Denial-of-Service Attacks | 1 |
| Human bad security behaviour | 1 |
| System Misconfiguration Exploits | 1 |
Industry breakdown of incidents
| Industry | Number of incidents |
|---|---|
| Healthcare | 4 |
| Education | 3 |
| Finance | 2 |
| Government | 1 |
| IT/Software/Technology | 1 |
| Automotive | 1 |
| Manufacturing | 1 |
| Consulting/Professional Services | 1 |
| Energy | 1 |
Read the Event Details of the Week
Knowledge
- active exploit | CISA warns of actively exploited flaws in Dassault DELMIA Apriso manufacturing software
- active exploit | CISA warns of actively exploited old Linux kernel vulnerability
- active exploit | Critical XWiki vulnerability exploited in crypto mining malware campaigns
Vulnerabilities
- critical vulnerability | Architectural flaw in Chromium Blink engine enables crashing of all Chromium based browsers just by visiting a web page
- critical vulnerability | Critical ASP.NET Core flaw affects QNAP NetBak PC Agent and Enterprise web applications
- critical vulnerability | Critical authentication bypass flaw reported in Ubiquiti UniFi Access
- critical vulnerability | Critical cross-site scripting flaw reported in Checkmk Monitoring Software
- critical vulnerability | Critical vulnerabilities reported in WordPress King Addons for Elementor plugin
- critical vulnerability | Google patches Wear OS vulnerability that enables silent SMS sending without user consent
- critical vulnerability | Google releases Chrome 142, patches 20 security flaws
- critical vulnerability | Multiple Dell Storage Manager vulnerabilities patched, at least one critical
- critical vulnerability | Path traversal vulnerability in Docker compose enables system compromise via malicious OCI artifacts
Incidents
- data breach | Beverly Hills Oncology medical group reports data breach exposing patient information
- data breach | GCash claims no breach of their systems after dark web listing, National Privacy Commission investigates
- data breach | Northern Montana Health Care reports third party data breach affecting patient data
- data breach | University of Pennsylvania email system compromised in cybersecurity incident
- data breach | NHS Lothian staff member charged following unauthorized access to patient medical records
- data breach | Coordinated cyberattacks disrupt polish payment infrastructure and travel services
- data breach | Iranian Intelligence-Linked cybersecurity academy suffers data breach exposing student records
- data breach | Blue Cross Blue Shield of Texas customers affected by Third-Party vendor data breach
- data breach | Sweden's power grid operator Svenska Kraftnät confirms ransomware attack, data breach
- data breach | Dentsu reports data breach at U.S. subsidiary Merkle exposing employee and client data
- data breach | Hackers claim breach of HSBC USA
- data breach | Copeland Auto Group email compromise exposes data of customers and employees from multiple car dealerships
- data leak | Security researcher reports data leak of US House Democrats' DomeWatch Resume Bank exposing data of over 7,000 job applicants
- ransomware | Qilin ransomware gang claims cyberattack on Malibu Boats Australia, alleging 160 GB data theft
- ransomware | Akira ransomware group claims breach of Apache OpenOffice
- ransomware | Right at Home reports ransomware attack exposing customer data