Knowledge

State of (in)security - Week 51, 2025

Take action: We've seen secrets in code, but storing PII in code repository is totally weird, especially when you think of the code repository of just program code and forget the data files. Never store PII in code repository. There are so many ways to expose it. And make sure to delete data of former customers unless you are legally required to keep it.


Learn More

In the week between Dec. 15, 2025, midnight and Dec. 22, 2025, midnight we witnessed a total of:

  • 17 advisory/vulnerability events
  • 16 incident/data breach events

Week over Week comparison of week 51 2025 vs week 50 2025:

We also shared 5 practical knowledge items


Total impacted individuals via the events of the week

There were a total of 28,239,967 impacted individuals across 6 incidents, with the largest breach being the SoundCloud reports data breach exposing millions of user accounts incident exposing 28,000,000 individuals. Since not all incidents report a number of impacted individuals, the real number is definitely higher than that.

Cause breakdown of incidents

CauseNumber of incidents
Malware, Ransomware and Related Attacks6
Physical Device theft or attack1
Software Vulnerability and SDLC Exploits1
Third Party Compromise1
Unauthorized access1

Industry breakdown of incidents

IndustryNumber of incidents
Healthcare5
IT/Software/Technology2
Other2
Government2
Construction/Realestate1
Retail1
Consulting/Professional Services1
Education1
Finance1

 

Read the Event Details of the Week

Knowledge

Vulnerabilities

Incidents

State of (in)security - Week 51, 2025