Knowledge

State of (in)security - Week 45, 2025

Take action: If you have the Post SMTP plugin on WordPress, update to version 3.6.1 right now. Attackers are actively exploiting it to reset admin passwords and hijack sites.


Learn More

In the week between Nov. 3, 2025, midnight and Nov. 10, 2025, midnight we witnessed a total of:

  • 19 advisory/vulnerability events
  • 13 incident/data breach events

Week over Week comparison of week 45 2025 vs week 44 2025:

We also shared 5 practical knowledge items


Total impacted individuals via the events of the week

There were a total of 241,738 impacted individuals across 5 incidents, with the largest breach being the Ransomware attack on Central Jersey Medical Center exposes data of 131,000 patients incident exposing 131,000 individuals. Since not all incidents report a number of impacted individuals, the real number is definitely higher than that.

Cause breakdown of incidents

CauseNumber of incidents
Malware, Ransomware and Related Attacks4
Software Vulnerability and SDLC Exploits3
Human bad security behaviour1
System Misconfiguration Exploits1
Unauthorized access1

Industry breakdown of incidents

IndustryNumber of incidents
Finance3
Government2
Healthcare2
Media2
Consulting/Professional Services2
Gas/Oil1
IT/Software/Technology1

Read the Event Details of the Week

Knowledge

Vulnerabilities

Incidents

State of (in)security - Week 45, 2025