Knowledge

State of (in)security - Week 49, 2025

Take action: The key advisory from this week is PATCH React and Next.js! If you're running React 19.x or Next.js 15.x/16.x (or frameworks using React Server Components like Waku or Redwood), attackers are already hacking your systems. Prioritize patching right now.


Learn More

In the week between Dec. 1, 2025, midnight and Dec. 8, 2025, midnight we witnessed a total of:

  • 14 advisory/vulnerability events
  • 17 incident/data breach events

Week over Week comparison of week 49 2025 vs week 48 2025:

We also shared 6 practical knowledge items


Total impacted individuals via the events of the week

There were a total of 5,629,552 impacted individuals across 4 incidents, with the largest breach being the Data breach at 700Credit exposes 5.6 million records from auto financing applications incident exposing 5,600,000 individuals. Since not all incidents report a number of impacted individuals, the real number is definitely higher than that.

Cause breakdown of incidents

CauseNumber of incidents
Software Vulnerability and SDLC Exploits4
Malware, Ransomware and Related Attacks3
System Misconfiguration Exploits2
Human bad security behaviour1
Third Party Compromise1
Unauthorized access1

Industry breakdown of incidents

IndustryNumber of incidents
Healthcare5
Finance3
Government2
Education2
IT/Software/Technology2
Retail2
Telecommunications1

 

Read the Event Details of the Week

Knowledge

Vulnerabilities

Incidents

State of (in)security - Week 49, 2025