BotNet News

Your source for Online Security News

Cyberthreat News delivers a concise, timely summary of key cybersecurity trends and threats affecting your organization. The content includes security research, threat actor activity, and actionable insights gleaned from incident response or red team engagements. This newsletter is ideal for organizations that need to gain awareness of high-impact threats and vulnerabilities to prioritize and coordinate a rapid response.

In 2025, attackers increasingly use social engineering to gain unauthorized access and exploit unpatched vulnerabilities. Attacks such as the M&S data breach and a Scania insurance portal hack underscore the importance of multi-factor authentication (MFA) and identity monitoring. Meanwhile, the UK Ministry of Defence data breach and a hack on consumer genetic testing company 23andMe demonstrate how stolen credentials can put both internal and external customers at risk.

Many of the biggest attacks in 2025 started with compromised vendors or shared platforms. For example, the UK Ministry of Defence hack and breaches on Cartier, TxDOT, US Treasury, Snowflake, and more reveal how third-party vulnerabilities can cause disruptions. Other incidents like the Kazakhstan diplomatic spearphishing and China’s salty water global telecom espionage campaign highlight the need for proper vulnerability management, patching, and monitoring.

Other notable attacks included the massive hack of Bank Sepah that exposed million of customer records, and a ransomware attack on Kettering Health that disrupted internal systems and patient data across 14 medical centers, forcing procedure cancellations and ambulance diversions. And the exploitation of years-old flaws in the SAP NetWeaver zero-day and Microsoft SharePoint highlights the need to actively scan and manage patching across the entire enterprise software ecosystem.