Knowledge

State of (in)security - Week 47, 2025

Take action: Don't manage authentication or trust with HTTP headers. They can be faked. If you do, make sure to remove your "special" HTTP header on the gateway or load balancer level.


Learn More

In the week between Nov. 17, 2025, midnight and Nov. 24, 2025, midnight we witnessed a total of:

  • 13 advisory/vulnerability events
  • 29 incident/data breach events

Week over Week comparison of week 47 2025 vs week 46 2025:

We also shared 1 practical knowledge items


Total impacted individuals via the events of the week

There were a total of 1,318,772 impacted individuals across 10 incidents, with the largest breach being the Data breach at French Urssaf Pajemploi service exposes datan of 1.2 million childcare workers incident exposing 1,200,000 individuals. Since not all incidents report a number of impacted individuals, the real number is definitely higher than that.

Cause breakdown of incidents

CauseNumber of incidents
Malware, Ransomware and Related Attacks9
Third Party Compromise3
Software Vulnerability and SDLC Exploits2
Unauthorized access2
Human bad security behaviour1

Industry breakdown of incidents

IndustryNumber of incidents
IT/Software/Technology8
Consulting/Professional Services4
Government4
Healthcare2
Retail2
Finance2
Utilities1
Construction/Realestate1
Education1
Energy1
Gas/Oil1
Aviation1

Read the Event Details of the Week

Knowledge

Vulnerabilities

Incidents

State of (in)security - Week 47, 2025