Security researchers have uncovered a "silent breach" in which over 16 billion login credentials were leaked, affecting users worldwide. The breach reportedly went largely unnoticed, underscoring severe risks for both individuals and organizations, and prompting urgent advice on password security and account hygiene.
Source: Forbes Security
Third-Party Breaches Double, Heightening Supply Chain Cyber Risks
According to the 2025 Verizon DBIR, breaches involving third-party providers have doubled from 15% to nearly 30%, with ripple effects across multiple sectors. SecurityScorecard warns that most organizations’ supply chain risk management practices are lagging behind the evolving threat landscape, making the supply chain a primary vector for large-scale attacks.
Source: Help Net Security
Android Threats Soar 151% Since Start of 2025
Android devices have experienced a dramatic surge in malware attacks, with threat levels rising by 151% since the beginning of the year. Security analysts warn users to adopt stricter device security and update settings, as malware campaigns grow more sophisticated and target increasingly large numbers of mobile devices.
Source: MalwareBytes Blog
Critical Citrix, Cisco, and Linux Vulnerabilities Under Active Attack
Multiple actively-exploited vulnerabilities, including "CitrixBleed 2" (CVE-2025-5777) impacting Citrix NetScaler, CVE-2023-20198 affecting Cisco IOS XE, and a privilege escalation flaw (CVE-2025-6019) in Linux distributions, are being leveraged by attackers. Threat actors are also allegedly selling zero-day exploits for Oracle E-Business Suite, Chrome for Android, and Fortinet FortiGate firewalls on underground forums.
Source: Cyble
Ahold Delhaize Data Breach Impacts 2.2 Million People in Ransomware Attack
The grocery retail giant Ahold Delhaize suffered a ransomware attack exposing sensitive personal data of over 2.2 million individuals. This incident highlights the escalating damage ransomware gangs can inflict and the potential for far-reaching data leaks across corporate and consumer networks.
Source: SecurityWeek
Canada Bans Hikvision Over National Security Fears
The Canadian government has ordered Chinese surveillance equipment manufacturer Hikvision to cease all operations in the country and banned its products from government use, citing national security concerns. The move underscores a growing global trend to restrict use of foreign-sourced security technologies in critical infrastructure.
Source: SecurityWeek
AI Agents Pose New Insider Threat Risks For Enterprise
Security experts warn that AI agents, often deployed with broad permissions and limited oversight, are emerging as significant insider threats—especially in regulated industries such as healthcare. Over-permissioned, under-monitored AI-driven automation could enable HIPAA violations or data breaches if not subject to robust identity governance and monitoring protocols.
Source: Help Net Security
You May Also Be Interested In...