Knowledge

State of (in)security - Week 46, 2025

Take action: The development of AI tool is still very much rushed, with insufficient security testing and a lot of copy-paste from other framework. All this because it's a rush to production, not building a secure product. The end user will probably suffer most. In general, be very conservative with AI frameworks, test a lot and patch very fast. And remember that AI apps are also vulnerable to all the classic web application vulnerabilities that have nothing to do with AI.


Learn More

In the week between Nov. 10, 2025, midnight and Nov. 17, 2025, midnight we witnessed a total of:

  • 20 advisory/vulnerability events
  • 20 incident/data breach events

Week over Week comparison of week 46 2025 vs week 45 2025:

We also shared 4 practical knowledge items


Total impacted individuals via the events of the week

There were a total of 52,582 impacted individuals across 4 incidents, with the largest breach being the Somalia's E-Visa system breached, exposing data of over 35,000 applicants incident exposing 35,000 individuals. Since not all incidents report a number of impacted individuals, the real number is definitely higher than that.

Cause breakdown of incidents

CauseNumber of incidents
Software Vulnerability and SDLC Exploits5
Malware, Ransomware and Related Attacks5
Social Engineering and Phishing2
Human bad security behaviour2
Unauthorized access2
System Misconfiguration Exploits1
Third Party Compromise1

Industry breakdown of incidents

IndustryNumber of incidents
Government5
IT/Software/Technology5
Healthcare2
Food and Beverage1
Manufacturing1
Non-profit/Charity1
Consulting/Professional Services1
Other1
Education1
Finance1

 

Read the Event Details of the Week

Knowledge

Vulnerabilities

Incidents

State of (in)security - Week 46, 2025