Cyberthreat News 2025
Attacks continue to escalate and evolve across a wide range of business sectors. From food supply chains to airport operations, breaches disrupt services and put customers’ data and trust at risk.
Sophisticated attackers and nation-states exploit vulnerabilities to steal information and money and to develop capabilities that can disrupt, destroy, or threaten delivery of essential services. It’s critical to protect cyber space by identifying attacks and shutting them down as quickly as possible.
Many of 2025’s most damaging incidents began with compromised vendors or shared platforms. For example, the breach of UNFI by hackers linked to the Cobalt group and the hack of cloud data platform Snowflake by a Scattered Spider team highlight how third-party vulnerability exposures can lead to disruptions. In addition, campaigns targeting M&S, Ukrainian government users, retailers, and healthcare SaaS platforms show how stolen credentials enable rapid access without triggering alarms. This trend underscores the critical need for MFA, identity monitoring, and user awareness.
As the threat landscape becomes more sophisticated, adversaries are eluding detection by weaponizing AI, leveraging cross-domain blind spots, and targeting unmanaged edge devices. This has resulted in more rapid exploitation and broader impacts. For instance, the SAP NetWeaver zero-day and Microsoft SharePoint exploitations reveal how flaws can be exploited within days and expose hundreds of organizations. Attackers can leverage these vulnerabilities to gain access to systems and take full control of critical infrastructure. These risks are exacerbated by the interconnected nature of the global economy and supply-chain networks.