Widespread exploitation of perimeter technologies dominated activity, led by the WatchGuard Firebox zero-day CVE-2025-14733 affecting more than 115,000 exposed firewalls. Active attacks against Fireware OS appliances coincided with patch releases, highlighting continued targeting of network edge infrastructure.
Ransomware activity combined operational disruption with legal consequences, as Romania’s national water authority confirmed a ransomware incident impacting roughly 1,000 systems while services continued manually. Separately, a Ukrainian defendant admitted participation as a Nefilim affiliate, linking law enforcement action directly to past multinational ransomware campaigns.
Supply-chain and software trust abuse featured prominently across ecosystems. A malicious WhatsApp API package on npm, downloaded more than 56,000 times, enabled message interception and account takeover, while open-source monitoring tool Nezha was repurposed for post-exploitation control.
Consumer and enterprise data exposure remained significant. Pornhub disclosed risks of sextortion following a Mixpanel-linked breach affecting over 200 million historical Premium records, while Coupang reported unauthorised access impacting 33.7 million users over several months.
Malware campaigns increasingly leveraged signed or trusted delivery mechanisms. MacSync macOS malware was distributed through a signed Swift application that bypassed Gatekeeper checks, while Android operations combined droppers, SMS theft and RAT capabilities at scale.
Regulatory and enforcement responses intensified alongside technical incidents. Operation Sentinel, coordinated by Interpol and Europol, resulted in 574 arrests tied to BEC, extortion and ransomware, as governments including South Korea advanced stricter identity verification following large-scale fraud exposure.