Each year, cybersecurity companies publish a number of research reports focusing on different aspects of cybersecurity and breach trends. Below is a list of some of the most alarming statistics from several reports published throughout the year from various companies.
++
A recent survey of IT and security professionals conducted by data backup storage provider Object First found the industry’s workforce is facing a mental health crisis – 84% of those surveyed feel uncomfortably stressed at work due to IT security risks, while 78% fear they will be personally blamed for security incidents regardless of the circumstances. Additional alarming findings include:
- Emotional toll: 47% report feeling pressure from leadership to “fix everything” in the aftermath of a security incident, and nearly one in five (18%) feel hopeless and overwhelmed during and after a security incident.
- Turnover risk: 59% have considered or actively begun looking for new jobs due to work stress.
- What IT/security pros want: 74% said their data recovery tools are too complex to be used without security expertise, a challenge that adds to their workplace stress. 67% believe faster, higher-performing backup solutions that minimize downtime, and using tech independently tested by credible third parties, would significantly boost productivity and confidence in responding to cyberattacks.
- Insufficient organizational support: 50% feel their companies don’t consistently prioritize employee well being and mental health.
++
In research sourced by theCube in Q1 2025, and published by cyber resilience company Index Engines in their Resilience by the Numbers ebook:
- Only 4% of 600 organizations said they can ensure a clean, restorable copy of data for more than 90% of their mission-critical applications
- Just 17% of organizations have recovery requirements for all business systems and applications needed for mission-critical services are fully defined and documented.
- 83% Do not have a tested, defined plan to recover critical data after a cyberattack
++
What does ExaGrid see across IT data center customers around the world?
- 65% are backing up to primary storage disk without any specific security features for backup data
- 20% are using 2FA (two-factor authentication) to ensure that threat actors cannot use their passwords (only 20%)
- 5% store the recovery codes on the same computer/laptop that they save their passwords – if the threat actors obtain access, they get both
- The most scary stat is that the threat actors are ahead of most IT data centers, which is why there are so many successful attacks – the blood sucking vampires are currently winning
++
GitLab recently released its executive research report, The Economics of Software Innovation: $750B+ Opportunity at a Crossroads, conducted by The Harris Poll. The report found that while 89% of C-suite leaders predict agentic AI will become the standard within three years, the future won’t arrive without security and trust.
Key findings include:
- 85% of executives agree, “Agentic AI will create unprecedented security challenges for our organization to navigate.”
- Topping the list of concerns around the adoption of agentic AI are cybersecurity threats (52%), data privacy and security (51%), and maintaining governance (45%).
- The biggest blockers to increased investment in software innovation are: talent shortage, market uncertainty, skills gaps, regulatory concerns, and budget constraints.
++
New research from Apiiro on Fortune 50 enterprises shows AI coding assistants make teams 4X faster and 10X riskier. Over 10 months, AI-generated code introduced 10,000+ new security flaws per month, including spikes in privilege escalation and leaked cloud credentials.
Additional key findings from the report included:
- AI-assisted developers produced 3-4 more commits than their non-AI peers, bundled into fewer, much larger PRs that overload review and increase blast radius
- While trivial syntax errors dropped 76%, privilege escalation paths jumped 322% and architectural design flaws rose 153%
- AI-assisted developers leaked Azure keys and service principals nearly twice as often as their peers
Talkdesk 2025 Small Business Survey
- Among small businesses not yet using AI in customer service, 32% do not plan to adopt AI and 37% remain unsure.
- Concerns about adopting AI include relevance (59%), fear of losing the “personal touch” (30%), and perceived complexity (21%).
- Businesses with exposed remote desktop applications are 3x-8x more likely to experience a cyber incident. Common examples of remote desktop applications include: Remote Desktop Protocol, Virtual Network Computing, VMware Horizon, and AnyDesk.
- Businesses with exposed on-premises Exchange login pages are 4x more likely to experience a cyber incident. Common examples include: Exchange Remote Procedure Call (RPC), Exchange Control Panel (ECP), and Exchange Admin Center (EAC).
- Businesses with exposed virtual private network (VPN) login panels are 3x-4x more likely to experience a cyber incident. Common examples include: Cisco Adaptive Security Appliance, Fortinet FortiOS SSL VPN, Ivanti Connect Secure, and SonicWall SSL VPN.
The pattern is clear: Businesses are leaving critical technologies exposed and unprotected on the internet and cyber criminals are exploiting these weaknesses to carry out attacks.
++
Drata’s 2025 State of GRC Report, which highlights trends, challenges, and an outlook on the future of compliance and risk management according to GRC professionals, uncovered that:
- 48% of GRC professionals struggle to keep pace with updates to existing compliance frameworks and identifying areas needing attention
- 45% of those surveyed are worried about balancing compliance and innovation, data privacy and protection, and maintaining operational resilience
- 100% of companies surveyed expect employees to increase their use of AI technologies in the next 12 months, yet only 10% have a GRC program fully prepared to manage it
- Manual interventions with GRC account for 14 hours per week on average
- Over 70% of respondents struggle with alert fatigue and false positives, and many participants reported receiving over 10,000 alerts daily.
- Only half of respondents rate the ROI of their SIEM solution as good
- Nearly 95% of teams considering a new SIEM list vendor lock-in as a primary reason for reevaluating their security stack
- Nearly three-quarters (73%) of critical infrastructure organizations cite the fast-moving AI ecosystem as their leading security concern
- Half of all data in the cloud is classified as sensitive, yet only 2% of organizations have encrypted 80% or more of it
- Almost two-thirds (63%) fear future decryption risks from post-quantum computing
- The average number of SaaS apps jumped from 83 to 102 in a year (up from 23% last year), multiplying the places attackers can access sensitive information
Stats:
- Applications face an average of 17 new vulnerabilities per month, with developer teams remediating an average of 6 per month.
- Attackers exploit new vulnerabilities in just 5 days, but it takes 84 days on average to patch even the most critical flaws.
- Application attacks are more prolific than ever before, with the average application targeted by attackers once every 3 minutes.
- The average application is exposed to 81 confirmed, viable attacks each month that evade other defenses, primarily driven by untrusted deserialization, method tampering, OGNL injection, and similar attacks, which can vary by industry and technology stack.
++
Black Kite released its report titled 2025 Manufacturing Report: Why Your Supply Chain is Your Biggest Cyber Risk, highlighting that manufacturing remains a prime ransomware target across companies of all sizes.
Stats:
- Among companies earning over $1 billion, manufacturing comprises a staggering 38.9% of ransomware victims.
- The trend continues for companies earning between $100 million and $300 million; manufacturing accounts for 30% of ransomware victims.
- Among companies with less than $20M, manufacturing is the second targeted industry at 17%. The demise of dominant groups like LockBit and AlphV has created a power vacuum, giving rise to new, less coordinated, and unpredictable players who often focus on smaller companies.
- The number of ransomware attacks on manufacturing companies keeps climbing, with a 9% increase compared to last year.
- 75% of manufacturing companies have critical vulnerabilities with a CVSS score of 8 or higher.
- 1.5x more hidden malware: For every known malicious file shared publicly, Stairwell uncovered 1.57 hidden variants lurking in the wild.
- Exploding complexity: The average threat report published by vendors now contains 18 known hashes, but Stairwell found 21 additional variants per report on average.
- False confidence is the real threat: Malware variants caused false negatives across AV and EDR tools – letting attackers persist by simply tweaking a file name or repacking code.
- Top “infected publishers”: Reports from Talos, Palo Alto Unit42, and Checkpoint led to the highest variant discovery counts, with Talos samples spawning 4,011 hidden variants.
- Mutation madness: Some publishers’ data showed extreme variant amplification e.g. SANS ISC reports produced 900% more variants and ESET over 480% more.
- Year-over-year infection creep: Despite fewer published reports in 2025, the malware discovered per file is growing – proof that continuous re-analysis keeps revealing new mutations.
- To avoid being haunted by vulnerabilities, developers, not security professionals, make up 70% of cyber range participants, emphasizing the need for secure coding content.
- Fresh blood dominates the field with 52% of learners having six years of experience or less, and those with 0-3 years showing the fastest learning velocity.
- The scariest and most-solved challenges mirror the OWASP Top 10, including broken access control, XSS, injection, and sensitive data exposure.
- OWASP Challenges continue to haunt cyber range participants, with vulnerabilities ranging from sensitive data exposure in beginner challenges, to reverse engineering and remote code execution in advanced ones, among the most missed challenge types, demonstrating the need for ongoing training for learners of all levels.
Additional key findings include:
- 83% of surveyed organizations adopting Zero Trust have successfully reduced security incidents, lowering remediation and support costs.
- 66% of organizations cite legacy systems as their biggest challenge to Zero Trust adoption.
- 72% of enterprises say new threats are their primary driver for continuously improving Zero Trust policies and practices.
- More than 50% of organizations discovered unexpected value in Zero Trust’s ability to improve user experience alongside security.
OpenText Cybersecurity’s 2025 Global Ransomware Survey takes a closer look at these trends. Key findings include:
- Ninety-five percent of organizations are confident in their ability to recover from a ransomware attack, but only 15% of those attacked fully recovered their data.
- Eighty-eight percent of survey respondents allow employees to use GenAI tools, yet less than half (48%) have a formal AI use policy.
- Fifty-two percent report increased phishing or ransomware due to AI; 44% have seen deepfake-style impersonation attempts.
- Top AI-related concerns among respondents include data leakage (29%), AI-enabled attacks (27%), and deepfakes (16%).
- Two in five companies (40%) experienced a ransomware attack in the past year; nearly half of those were hit more than once.
The Gigamon 2025 Hybrid Cloud Security Survey found that:
- 47 percent of organizations report an increase in attacks specifically targeting their large language models (LLMs), while 58 percent are seeing a rise in AI-powered attacks.
- 58 percent say they have seen a surge in AI-powered ransomware, up from 41 percent in 2024.
- 97 percent of CISOs admit to making compromises in securing their hybrid cloud infrastructure.
WatchGuard and its Threat Lab researchers released findings from its latest Internet Security Report, a quarterly analysis focusing on the top malware, network, and endpoint security threats during the second quarter of 2025.
- In Q2, evasive, advanced malware increased 40% (quarter-over-quarter), highlighting encrypted channels as adversaries’ favored attack vector using Transport Layer Security (TLS), the encryption protocol behind most secure web traffic.
- Brand new, unique malware threats rose 26%, showing how common packing encryption, a type of malware evasion, is with threat actors. These polymorphic threats evade signature-based detection, driving higher hits by WatchGuard’s advanced services, such as APT Blocker (Advanced Persistent Threat Blocker) and IAV numbers.
- Two USB-based malware threats were identified: PUMPBENCH, a remote access backdoor and HIGHREPS, a loader. Both deployed a coin miner, XMRig, which mines Monero (XMR), and are likely tied to hardware wallet usage among crypto holders.
- Ransomware declined by 47%, reflecting a shift toward fewer but more impactful attacks on high-profile targets that result in larger consequences. Notably, the number of active extortion groups has increased, with Akira and Qilin being among the most aggressive.
- Zero-day malware continues to dominate, making up over 76% of all detections and nearly 90% of encrypted malware. These findings underscore the need for advanced detection capabilities beyond signatures, particularly for threats concealed within TLS traffic.
- 68% of consumers now use AI in their personal lives, increasing from 41% a year ago
- AI-driven phishing (39%) is the top concern for consumers, above fake apps (38%) and deepfake attacks (32%)
- 52% of consumers do not feel sufficiently informed or protected from scams by guidance from safety organizations or government institutions, suggesting a greater need for education
- Consumers say biometric authentication (34%) and multi-factor authentication (33%) are the top features that would increase their trust in online brands
According to Entrust, a global leader in identity-centric security solutions, fraud isn’t just rising, it’s evolving. Its recent Future of Global Identity Verification research report, developed in partnership with DocuSign, examined the increasing impact of identity fraud and the significant cost it’s imposing on organizations. Findings revealed:
- Identity fraud is a growing global threat global and across industries: Over two-thirds (69%) of organizations reported increased fraud attempts
- Identity fraud continues to cost organizations millions: On average, identity fraud costs organizations $7 million per year
- Organizations with over 5,000 employees have an average annual direct identity fraud cost of $13 million on average – and the costs grow by multiples as the size of organizations increases
- Among organizations with over 10,000 employees, 20% have an annual direct and indirect identity fraud cost of over $50 million
- Despite their best efforts, organizations are still vulnerable to fraud: 51% of organizations said fraud is more common when using a username and password than any other method while 21% reported fraud attempts against facial biometric liveness detection.
Imprivata recently released its 2025 State of Shared Mobile Devices in Healthcare Report. As mobile adoption grows in healthcare, the findings reveal a surprising gap: despite their essential role in care delivery, shared mobile devices are often ungoverned and unsecured, creating new points of failure in already strained clinical environments. Key findings include:
- 74% of shared-use devices are often left signed in after use, and 79% of staff admit to sharing credentials, putting sensitive patient data at risk.
- Data security is the most frequently cited challenge for shared-use device adoption in healthcare, flagged by 44% of respondents.
- Usernames and passwords remain the most common – but outdated – method for accessing shared mobile devices in healthcare, used by 26% of organizations despite security risks.
LevelBlue released findings from its 2025 Spotlight Report: Cyber Resilience and Business Impact in Manufacturing, which explored how the manufacturing industry is protecting itself from increasingly sophisticated attacks as more organizations integrate artificial intelligence (AI) for efficiency, optimized processes, and enhanced automation. Data reveals:
- Only 32% of manufacturing executives say they are equipped for AI-powered threats, and just 30% feel their organization is ready for deepfake attacks.
- Organizations are also facing an increase in distributed denial of service (DDoS) attacks amid rising geopolitical tensions, with only 37% of manufacturing executives reporting they are prepared for them.
- Data security and privacy are still the biggest challenges, with 54% of organizations reporting very low to moderate visibility into the software supply chain.
CallMiner’s annual 2025 CX Landscape Report highlighted a persistent disconnect between AI ambition and execution. While organizations are investing heavily in AI infrastructure, those investments don’t always translate into measurable value or outcomes. Key findings from the report include:
- AI adoption surges: 80% of organizations have at least partially implemented AI, compared to 62% in 2024.
- Third-party reliance: 51% rely entirely on third-party AI software, with those organizations more likely to have successful deployments (85%) than those building in-house (71%).
- Governance gaps: While 71% have AI governance resources, 67% still implement AI without adequate safeguards – and only 43% of governance teams are focused on defining AI strategy.
- Security concerns intensify: 52% of leaders worry about AI spreading misinformation (up from 44% in 2024), and 49% fear compliance risks (up from 38%).
- Employee enablement: 96% believe AI will unlock employee potential, with organizations using AI to assist agents in real time (47%), free up time for strategic work (43%), personalize outreach (43%), and enable customer self-service (40%).
Chainguard released its 2026 Engineering Reality Report in October 2025 which explores how friction-repetitive maintenance, fragmented tools, and burnout-continues to weigh heavily on the developer experience, while also revealing how AI and automation ease workloads to give software engineers more time for meaningful work.
- The pressures on modern engineering teams: Today’s software engineers are under mounting pressure to deliver new features quickly, maintain existing systems, and keep pace with a constantly shifting tool landscape. A majority of engineers (72%) said these demands make it difficult to find time to build new features, while 35% pointed to excessive workload and burnout as major obstacles to a positive work experience. This tension has made the developer experience a critical issue for organizations everywhere, with two-thirds (66%) of technology leaders reporting that they worry about retaining engineering talent. Against this backdrop, AI and automation have emerged as central to easing pressure, reducing toil, and creating space for innovation.
- Tedious tasks, code maintenance, and tool sprawl: 38% of engineers cited too many tedious tasks as a barrier to doing meaningful work, while another 38% pointed to the ongoing demands of code maintenance, such as upgrades, patches, and vulnerability management. Together, these routine tasks leave less room for creativity and innovation, contributing to a sense of stagnation among teams.
- AI and automation have hit critical mass, yet skepticism remains: 65% of organizations say most common engineering tasks are mostly or fully automated, leading to a positive developer experience. These tasks range from writing code to dealing with administrative tasks like internal communication. While 89% of respondents said AI saves them at least three hours per week, and 28% said they reclaim up to six hours, engineers’ enthusiasm for using AI is tempered by mixed signals from leadership. 55% of technology leaders said their engineers are encouraged to use AI, compared to only 46% of engineers who reported feeling the same level of support. Over 40% of respondents cited accountability, security, and privacy as barriers to wider adoption, underscoring the trust gap that still exists. Many also pointed to the rise of “shadow AI” – the use of unapproved tools trying to save time – as a risk factor within their organizations.
Chainguard also published The Cost of CVEs 2025 Report, revealing just how much organizations are spending to manage vulnerabilities, and how much they stand to gain by solving the problem at its root.
- Customers participating in this analysis saved an average of $2.1 million annually by outsourcing CVE remediation
- The overall average total benefit of outsourcing CVE management is $31,039,233, broken down into:
- Cost Savings: $2,107,061
- Increased Revenue: $5,063,378
- Faster Innovation: $12,991,683
- Decreased Risk: $15,588,774
- CVE remediation cost savings by industry:
- Healthcare: $1.9M average annual savings, Driven by regulatory pressure (e.g., HIPAA) and the need to remediate across both legacy and high-risk systems
- Technology: $1.0M average annual savings, Benefit from automated workflows that maintain SLAs and speed up product delivery
- Telecommunications & Infrastructure: $606K average annual savings, a lower volume of vulnerabilities but high impact; savings come from easing large-scale coordination challenges
- Unsurprisingly, enterprise organizations receive the highest total value unlocked for outsourcing CVE management at over $43 million on average, with the highest average benefits in the decreased risk ($25 million) and faster innovation ($18 million) cost areas.
Key findings include:
- Rising AI threats are placing an increased emphasis on prevention: 46% of firms experienced more targeted phishing attacks this year, and 43% fell victim to more deepfake impersonations. Furthermore, 83% cited local or cloud storage attacks as a top risk to their organization, second only to phishing attacks (84%).
- Fatigue is facing SecOps teams even as innovation expands: 69% say AI and other emerging technologies are responsible for increasing SecOps burnout. Specifically, 43% report being very or extremely concerned about the future impact of quantum computing on SecOps workloads.
- The growing need for preemptive data security: Data throughout the report makes the case for preemptive data security as the new industry imperative, advocating for proactive approaches like deep learning to stay ahead of sophisticated, AI-driven attacks.
Sonatype recently released its Q3 2025 Open Source Malware Index, which analyzed 34,319 open source malware packages discovered by Sonatype across major open source registries including npm, PyPI, Hugging Face, and more.
Key findings from the Q3 2025 Open Source Malware Index include:
- In Q3 2025, Sonatype identified 34,319 new open source malware packages, representing a staggering 140% increase from Q2 2025.
- Top three industries blocking open source malware: Financial services 47%, business services 14% and energy & utilities (8%)
- Data exfiltration malware climbs 39% and now makes up 35% of all Q3 threats: there is a growing trend toward intelligence-gathering, espionage, and monetization of stolen data
- Dropper use grew by 2,887% to represent 38% of all Q3 threats, suggesting a shift towards more modular, persistent attack chains
ConnectWise released its State of SMB Cybersecurity report earlier this year. AI and the rise of remote work are transforming how businesses operate and how they are attacked. To explore these trends more in depth, ConnectWise partnered with market research agency Vanson Bourne to examine how small and midsized businesses (SMBs) are evolving their cybersecurity strategies and expectations of MSPs.
Key findings from the 2025 State of SMB Cybersecurity report include:
- SMBs underestimated their cybersecurity risk, leaving them underprepared and overexposed. As a result, many added unplanned budgets to ensure proper protection, with 58% spending more on cybersecurity in 2024 than originally anticipated.
- 83% of SMBs state that AI/GenAI increases the cybersecurity threat level for their organization. But only 51% have implemented security policies and practices for AI/GenAI.
- 57% of SMBs say that cybersecurity is now their organization’s top priority, compared to 43% in 2024, an increase of 14 percentage points in a single year.
Orca Security recently released its 2025 State of Cloud Security Report, revealing that most organizations are still struggling to manage basic risks even as their cloud environments grow larger and more complex. The findings highlight how long-standing vulnerabilities, misconfigurations, and exposure risks continue to leave critical data and systems open to attack. A few key data points include:
- 62% of organizations have at least one vulnerable AI package in their cloud environment, indicating widespread use of outdated or insecure dependencies.
- Each cloud asset averages 115 vulnerabilities, showing that patching and prioritization still lag behind adoption.
- 76% of organizations have at least one public-facing asset that enables lateral movement, meaning one exposed endpoint can give attackers a path into the network.
- 85% of organizations have plaintext secrets embedded in source code repositories, exposing credentials, tokens, and keys that can be easily exploited.
Osterman and Silverfort released research that reveals a critical disconnect in identity security. The report, “Strengthening Identity Security: Governance, Visibility, and Autonomous Remediation, reveals that while nearly 70% of organizations believe their defenses are “mature,” 80% actually lack complete visibility into identity threats. Key findings include:
- Over the last 12 months, 60% of identity leaders have seen adversaries become more interested in stealing and abusing compromised credentials, and almost 80% lack visibility into what NHIs/service accounts are actually doing.
- 72.1% of identity leaders report that the threat level of identity-related attacks has increased or remained unchanged in the past year.
- 4 out of 5 identity leaders don’t have full visibility into three critical risks:
- Service accounts behaving in unexpected ways.
- Authentication session tokens being used in abnormal locations.
- Compromised employee credentials for sale on the dark web.
- For organizations using tools to detect compromised credentials on the dark web, 60% claimed maturity, but only 22% could show evidence of it.
- For backup and recovery of identity platforms, 71% claimed maturity, but only 41% had the evidence to back it up.
Rapid7 Q1 2025 Incident Response findings reveal that
- 56% of all incidents in Q1 2025 involved valid accounts / no MFA as the initial access vector.
- Manufacturing organizations were targeted in more than 24% of incidents the Rapid7 IR team observed, by far the most targeted industry in Q1 2025.
- 40% of all incidents observed involved BunnyLoader, the Malware as a Service (MaaS) loader possessing a wealth of capabilities including clipboard and credential theft, keylogging, and the ability to deploy additional malware.
Just over half of that 40% total involved a fake CAPTCHA (commonly used for the purpose of victims executing malicious code), with malicious / compromised sites appearing in a quarter of BunnyLoader cases.
++
DTEX 2025 Cost of Insider Risks Global Report
The findings from a survey of 349 organizations highlight that the total annual cost of insider risk is continuing to climb, as well as other key findings such as:
- The average annual cost of an insider risk has risen to $17.4M USD
- In 2024, organizations spent an average of 81 days responding to an insider incident
- 55% of credential compromise incidents involved advanced social engineering tactics (i.e. AI-generated content)
- Insider attack activity costs are highest for health and pharma followed by technology and software.
++
Snyk’s 2025 report shows 88% of CISOs are concerned with the current state of U.S. cyber readiness.
A survey of 101 CISOs explored the intersection of AI security, federal policy changes, and software security strategies in the first 100 days of the new administration.
Key findings include:
- 70% of organizations experienced a cyberattack since January of 2025 that has involved AI, such as AI-powered automation or an AI attack vector
- 1 in 5 (20%) CISOs see their ability to detect sophisticated AI-powered threats as the most significant security gap at their organization.
- 96% of CISOs are ‘extremely’ or ‘somewhat’ concerned about AI-generated code introducing hidden vulnerabilities into their software and
- 85% of CISOs noted that the rollback of prior AI executive orders had a ‘significant’ or ‘moderate’ change on their AI risk posture, but 90% of CISOs agree (strongly/slightly) that the new administration’s cybersecurity policies will make their organization more secure.
++
Lookout’s Q2 2025 Mobile Threat Landscape Report revealed a 20% increase in mobile phishing exposure for enterprise employees from Q1 to Q2 2025. Other key findings include:
- 1,273,091 enterprise phishing and web attacks occurred in Q2 2025, a 90% increase from Q2 2024 – nearly double from last year.
- 15% of iOS devices with mobile device management (MDM) were exposed to mobile phishing attacks, a 2% increase from Q1 2025
- 15.7% of employees encountered global phishing and malicious content for iOS devices, compared to 8.5% for Android devices
- 38.1% of devices still have out of date OS
++
Illumio’s 2025 Global Cloud Detection and Response Report
- Lateral Movement Dominates: Nearly 90% of respondents experienced a cybersecurity incident involving lateral moment.
- Missed alerts and the devastating outcomes: 92% of organizations have experienced a security incident due to missed or uninvestigated alerts.
- False positive alerts taking time away from real issues: Security teams spend over 14 hours a week on average on false positives due to lack of visibility, tool sprawl, and outdated detection.
- CDR tools adoption and the reality: 83% of orgs deploy multiple CDR tools, however, 92% report challenges with current capabilities.
++
HUMAN Security’s 2025 Guide to Adopting Agentic Commerce demonstrated that AI agents are reshaping online shopping by finding and purchasing products for user raising the risk as decisions and data move at machine speed, beyond human oversight. We must now continually assess all internet traffic on whether to trust or not because real security depends on context, intent, and constant reevaluation.
- In just eight months of 2025, agentic internet traffic increased more than 1,300%, driven largely by the releases of commercial agents and agentic browsers, and now accounts for more web traffic than all humans combined and this is just the start.
- 87% of all pages browsed by agents were related to products, meaning online retailers must now incorporate them into commerce strategy to stay competitive.
- Perplexity’s Comet Browser has become the top source of agent-driven activity, generating 50.3% of agentic traffic in September, vs. ChatGPT Agent’s 43.2%, underscoring how quickly the agentic AI market is evolving. ChatGPT’s recent release of Atlas will have similar results.
- 3.9% of agent interactions involved account-related pages, like login screens or account settings, meaning automated login attempts can compromise accounts at scale and distort both trust and analytics.
++
Cybersecurity Awareness Month 2025 Poll
The findings from a Bitwarden survey of over 1,000 US parents with children ages 2 to 20 found that
- 78% of parents across all households are concerned about their child falling victim to an AI-enhanced scam that mimics voices, crafts personalized messages, or generates convincing phishing content.
- Despite these concerns, nearly half (43%) of parents haven’t talked with their kids about how to recognize AI-enabled threats.
- 44% of Gen Z parents report their child or family experiencing malware or a virus from downloads.
- Among Gen Z parents specifically, adoption of key defenses lags: more than half do not use a password manager (56%), and nearly two-thirds (64%) report not using a VPN.
- 42% of children ages 3-5 have unintentionally shared personal data online.
- 35% of families have experienced a phishing scam via text/email/chat, and 25% have had a game or social media account hacked.
- After a spike from 1,577 observed victims in Q4 2024 to 2,063 in Q1 2025, there was a reduction to 1,591 victims in Q2. However, the Q1 surge was likely driven by ransomware group Cl0p’s mass exploitation campaigns. Once removed from the picture, there is an emerging consistent average of approximately 1,500-1,600 observed victims each quarter from Q4 2024 to Q3 2025.
- The diversity of named extortion groups continues to grow, reaching another all-time high of 77 active groups in Q3. This represents an 8% increase quarter-over-quarter, and a 57% year-over-year increase.
- In Q3, we saw a 126% increase in manufacturing organizations suffering a ransomware attack, with 252 publicly claimed victims compared to Q2 2025 (200).
PreCrime Labs threat trend analysis shows that when recurring or high-visibility global events take place, there’s a measurable spike in related domain registrations. While many of these registrations occur immediately before the event, others are registered years in advance. This trend was particularly obvious when we observed that 10% of the almost 500 domains analyzed related to the 2026 FIFA World Cup included registrations for World Cup events as far out as 2034.
Domains often mirror social media and real-world trend cycles, with clear spikes observed around major events such as the FIFA World Cup, the Los Angeles wildfires, Texas flooding, and global trade tariffs. Similarly, cryptocurrency-themed domains have shown rapid emergence and disappearance, displaying registration patterns tied to trending topics and public attention.
In a recent dataset analyzing 800 retail-related domains with respect to the upcoming holiday season, the month of September alone accounted for 67% of all suspicious registrations.
Within this retail dataset, around 5% of domains were linked to casino, betting, and slot-based scams, highlighting the blurring line between financial phishing and entertainment-themed fraud, an emerging threat area warranting deeper study.
- Status of security debt: 60% of organizations release code daily or faster, but 46% still rely on manual processes to queue code for testing, resulting in 62% of applications not being tested at all, leaving massive security debt
- AI is a double-edged sword: 96% of organizations use AI coding assistants with 63% believing AI makes code more secure, while 57% say it introduces new risks. Alarmingly, 11% admit to using AI tools without permission.
- Overconfidence vs. reality: 89% of professionals are confident they can manage AI risks, despite incomplete coverage and noisy testing pipelines.
- Tool sprawl impacts ROI: 71% report their security alerts are ‘noise’, such as false positives or duplicates, derailing workflows and undermining investment.
- Security seen as a speed bump: 81% of respondents say security slows down development, creating friction between dev and security teams.
RSAC: RSAC’s H2 2025 Cyber Workforce Report – RSAC’s H2 2025 report unveils the top challenges facing cybersecurity leaders and the emerging trends shaping the industry conversation. Scary stats include:
AI will drive more than 50% of all application security startups in 2026. AI-generated code introduces new vulnerabilities that security teams must vet proactively.
CISOs underinvesting in workforce development in 2026 risk costly team departures in 2027, forcing a sudden “snap-back” of investment in 2028.
Insurance premiums are rising again in 2026, despite slight declines in 2023-2025, due to ransomware payouts rebounding. The average firm in 2026 will pay 145% more than in 2020 for the same cyber insurance coverage.
++
Rubrik: Rubrik Zero Labs Spring 2025 Report analyzes the state of data security across AI, cloud, SaaS and on-premise environments. Scary stats include:
90% of IT and security leaders reported cyberattacks. Additionally, nearly 20% of organizations saw more than 25 attacks – an average of one breach every other week
One-third of companies have been forced to make leadership changes as a result of cyberattacks and breaches, while 40% reported increased security measures/costs
Data sprawl and complexity in the cloud are complicating security. IT leaders are most challenged by securing sensitive data across multiple environments, and threat actors are exploiting hybrid cloud systems relentlessly.
Threat actors don’t just want in; they want to lock you out. One-third of IT and security leaders report that threat actors were completely successful in harming backup and recovery options, thus aiding their ransomware extortions.
++
Bitsight: Bitsight’s TRACE Security Research Team published the 2025 State of the Underground report, which analyzes cybercrime on the deep and dark web in 2024. Scary stats include:
25% increase in ransomware attacks (as measured by unique victims on leak sites) in 2024, as the amount of ransomware group leak sites increased by 53%.
43% increase in data breaches shared on underground forums, with US orgs accounting for 20% of victims – with Professional, Scientific and Technical Services as the most-targeted sector
2.9 billion unique sets of compromised credentials leaked in 2024 (up from 2.2 billion in 2023).
14.5 million compromised credit cards listed on underground markets in 2024, marking a 20% YoY increase.
++
CyberArk: CyberArk’s 2025 Identity Security Landscape reveals how organizations are inadvertently creating a new identity-centric attack surface through growing use of AI and cloud.
Machine identities outnumber humans by more than 80 to 1
88% of respondents said that, in their organization, the definition of a ‘privileged user’ applies solely to human identities – but 42% of machine identities have privileged or sensitive access.
61% do not have identity security controls in place to secure cloud infrastructure and workloads.
++
Abnormal AI: Abnormal AI’s H1 2025 Threat Report details how weaponized generative AI, easily accessible personal data, and hacking tools on the dark web are fueling a surge in BEC and VEC attacks, resulting in a:
54% YOY increase in BEC attacks
88% likelihood of a BEC attack in any given week in 2024
70% weekly chance of a VEC attack-up 10% from last year
Abnormal’s H1 report also reveals that smaller organizations (less than 1,000 inboxes) saw the sharpest rise, with a 70% weekly risk of BEC attacks-up 14% from 2023. Meanwhile, enterprises (50,000+ inboxes) now face a 98% weekly risk of at least one attack. Here’s the industry breakdown:
Media & entertainment: 82% weekly risk of VEC attacks
Construction & engineering: 80%
Retail, consumer goods, manufacturing: 79%
AvePoint’s The State of AI in 2025: Go Beyond the Hype to Navigate Trust, Security, and Value
- 90.6% of organizations claim effective information management programs, but only 30.3% have implemented effective data classification systems. The nightmare: Most don’t know what data they have or where it lives.
- 68.7% of organizations have slowed the rollout of generative AI assistants due to inaccurate AI output, and more than two-thirds of respondents express significant concern for the impact of inaccurate outputs on employee judgment. The terror: AI hallucinations are eroding trust in employee decision-making.
- 89.6% of organizations use built-in or third-party reports to track how generative AI assistants are used and how well they perform. But far fewer look at the human or business impact using interviews or other qualitative methods. The blind spot: They’re measuring the tool, not the damage.
- Organizations that approve only one generative AI tool are the least aware of what other tools employees are using – 18.7% admit they don’t know. In contrast, for organizations that approve of 2-3 tools, only 10-13% don’t know what their employees are using. The shadow IT horror: Restrictive policies breed invisible threats.
- Data security concerns like unauthorized exposure of sensitive data due to AI are the second highest concern creating a barrier to genAI rollout (68.5%). The haunting fear: Shadow AI means shadow data leaks.
++
Darktrace’s 2025 Cyber Threat Landscape Mid-Year Review showcases just how fast cyber threats are evolving. From AI-generated phishing emails to ransomware targeting SaaS platforms, attackers are using new tricks to bypass defenses and hit high-value targets. Here are some of the most alarming trends from the first half of 2025:
- 12.6 million malicious emails were detected in just five months, with over 25% targeting VIPs.
- 32% of phishing emails contained unusually high volumes of text, pointing to AI-generated content.
- 1 million QR code phishing emails were spotted in February alone.
- ClickFix attacks emerged, tricking users into executing PowerShell code disguised as CAPTCHA prompts.
- Ransomware-as-a-Service (RaaS) groups like Qilin, RansomHub, and Lynx surged in activity.
- SaaS-targeted ransomware began encrypting files in platforms like Salesforce, bypassing traditional defenses.
- Known vulnerabilities (CVEs) were exploited months after patches were released-like the SimpleHelp flaw used by Medusa ransomware.
- Raspberry Robin, a worm first seen in 2021, remains active and continues evolving.
- Nation-state actors such as BlindEagle and LapDogs ORB targeted Latin America and U.S. government systems.
++
Keeper Security’s Insight Report: AI in Schools – Balancing Adoption With Risk
- 41% of schools have experienced AI-related cyber incidents, including phishing campaigns, misinformation and harmful student-generated content.
- Nearly 30% of schools reported instances of harmful AI content, such as deepfakes created by students.
- While 86% of institutions allow students to use AI tools and 91% permit faculty use – most schools only have guidelines with no formalized policies.
- 90% of education leaders expressed some level of concern about AI-related cybersecurity threats.
- Only one in four respondents felt “very confident” in recognizing AI-enabled threats like deepfakes or AI-driven phishing.
Fortinet 2025 Insider Risk Report: The Hidden Cost of Everyday Actions
- 77% of organizations experienced insider-related data loss over the last 18 months, with 21% reporting more than 20 incidents during that period. For many, insider incidents are not isolated events but recurring challenges that drain resources and erode trust.
- The financial impact is significant. Forty-one percent of respondents reported that their most serious insider incident cost between $1 million and $10 million, while another 9% reported losses even higher. These costs include immediate remediation and downtime as well as regulatory penalties and reputational damage.
++
Noma Security – Gal Moyal, Office of the CTO
- The use of ClickFix in various malware campaigns has taken off in the first 6 months of 2025, with a 500% increase, accounting for 8% of the attacks reported.
- Phishing now accounts for 77% of all attacks, up from 60% in 2024. This increase is likely due to attackers using AI to increase the phishing volume in the threat landscape.
- In 2025, the rate of vulnerabilities is on track to be 900 per week, an increase from 2024’s 768 security issues per week.
Cockroach Labs’ State of Resilience 2025 Report
- Only 20% of respondents describe their organization as fully prepared for outages.
- 92% of the executives surveyed report their teams must occasionally deprioritize essential work in order to address unplanned downtime or outages.
- 95% of the executives surveyed say they are aware of at least one existing, unresolved operational weakness within their technical estate that puts their organization at risk.
One of the scariest trends we’re seeing is how unprepared SMEs are to manage third-party risk. According to multiple industry studies, over 60% of data breaches now originate from a third-party vendor. And yet, most small and mid-sized businesses lack any structured TPRM program. This gap creates an enormous opportunity, and responsibility, for MSPs and MSSPs to step in. By embedding continuous third-party risk management into their services, they can not only protect their clients’ ecosystems but also demonstrate tangible, proactive value that goes far beyond reactive security measures.






