The 2025 UK report is composed of 1,727 tips on cyber incidents over the course of the year that developed into a total of 429 cases that involved intervention by the NCSC IM team. The share of incidents ranked as "nationally significant" jumped from 89 in the prior year to 204 in the current one.
Microsoft warns of social engineering attacks dubbed “payroll pirates” resulting in lost wages after hackers divert employees’ earnings to threat actor-controlled bank accounts.
A third-party data breach has leaked personal information, including government IDs, from the messaging app Discord after threat actors breached a customer support vendor.
The endgame for AI chatbots was always integration of targeted ads, but Meta plans to do more than make Meta AI just another arm of its internet-spanning data collection network. The plan is for the chatbot to eventually function as a shopping assistant that can search for products and put them into shopping carts.
Daily fantasy sports and gambling platform DraftKings has confirmed that numerous user accounts were compromised following a series of credential stuffing attacks.
Security researchers at Wiz Research have discovered a critical vulnerability in the Redis in-memory database that could allow an attacker to gain remote code execution (RCE) capabilities and take over the host.
Both suspected state-backed foreign adversaries and more run-of-the-mill cyber criminals appear to mostly still be focused on using AI tools to make their existing operations faster, more efficient and more error-free. OpenAI's ChatGPT and other models appear to have fairly strong guardrails that are highly resistant to creation of malware or automation of attack operations.
North Korean hackers have now plundered $2 billion this year and an overall total of $6 billion in stolen crypto. The state-sponsored hacking teams have demonstrated creative means of penetrating crypto platforms and are responsible for at least 30 incidents in 2025, including a $1.46 billion theft from Bybit.
California’s $1.35 million penalty against Tractor Supply marks a turning point in retail privacy enforcement. Until now, many retailers assumed regulators were more interested in tech giants than store chains. That assumption is over.
Open-source software company Red Hat has confirmed a security breach on one of its GitLab instances after a threat actor claimed to have stolen nearly 570 GB of data from across various repositories.










