Kaspersky reported that nearly half of Windows users and almost a third of macOS users encountered cyberthreats between November 2024 and October 2025, with significant increases in password stealer and spyware attacks. The highest rates of web threats were observed in the CIS region, while Africa saw the most local threats. Notably, password stealer detections surged by 132% in the Asia-Pacific region, and overall spyware attacks rose by 1.5 times compared to the previous year, highlighting a global escalation in both the volume and sophistication of cyberattacks.
In parallel, the cybersecurity landscape in late 2025 was marked by the emergence of new ransomware threats such as Kraken and Zorab, as well as high-profile incidents like the Korean Leaks operation, which targeted South Korea’s financial sector through a combination of ransomware-as-a-service and state-linked actors. Additionally, there were warnings about credential leaks via online code formatting tools and reports of cyberattacks on London councils, underscoring the diverse and evolving nature of cyber risks facing organizations worldwide.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
10 events from the most recent confirmed update back to the earliest known activity.
The 'Korean Leaks' operation was identified as a major hybrid campaign targeting South Korea's financial sector. Reporting connected the activity to the Qilin ransomware-as-a-service ecosystem and the North Korea-linked Moonstone Sleet group.
A warning was issued that users may expose credentials and other sensitive data by pasting them into online code-formatting tools, especially when those services allow content to be saved or shared. The issue highlighted a data-handling and supply-chain style risk in common web utilities.
Amazon Threat Intelligence reported that Iranian state-linked cyber intrusions were being used to collect intelligence in support of real-world military actions, including missile strikes. The finding underscored the convergence of cyber activity and kinetic operations.
Kensington & Chelsea, Westminster, and Hammersmith & Fulham councils disclosed a cyberattack that caused system outages. The UK NCSC and external cyber-incident specialists became involved in the response.
Zorab ransomware was reported using social engineering by posing as a decryptor for STOP Djvu infections. Victims who ran it had their files encrypted again with a .ZRB extension.
Kraken was identified as a significant ransomware-as-a-service operation targeting Windows, Linux, and VMware ESXi environments with customized encryptors. Reporting linked the group to remnants of the HelloKitty cartel.
Google introduced its Unified Security Recommended Program to recognize leading ISVs integrating with its AI-driven security ecosystem. The initiative was aimed at simplifying and strengthening enterprise cloud security adoption.
OWASP published its 2025 Top 10 list, updating the most significant web application security risks to reflect the evolving threat landscape. The release provided a new benchmark for application security priorities.
Europol and Eurojust coordinated Operation Endgame to dismantle more than 1,025 servers linked to the Rhadamanthys infostealer, Venom RAT, and Elysium botnet. The action represented a major law-enforcement disruption of criminal infrastructure.
A major Cloudflare outage on November 17–18 caused widespread disruption to internet services globally. The incident was highlighted as one of the most significant cybersecurity-related operational events of the month.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
securelist.com
Open sourcethecyberthrone.in
Open sourcesecuritysenses.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.