As Q1 2025 comes to a close, the global cybersecurity landscape has already experienced a dramatic start to the year. From critical infrastructure breaches to state-backed ransomware activity and previously unknown exploits, this quarter demonstrated how quickly threat actors are evolving—and how thin the line is between internal compromise and global consequence.
Here’s a breakdown of the top cyber incidents from January to March 2025, along with emerging patterns we believe security officers should watch closely.
1.Cloudflare DNS disruption sparks BGP security debate
Date: January 11, 2025
Cloudflare’s DNS service (1.1.1.1) experienced a widespread outage, initially believed to be tied to a BGP hijack. Though later attributed to internal misconfigurations, the timing of a real BGP anomaly in Brazil reignited concerns about internet routing trust and the urgent need for RPKI adoption. Several telecoms in Latin America have since accelerated BGP security audits.
2.Critical SharePoint vulnerability (CVE-2025-21517) under active exploitation
Date disclosed: February 11, 2025
Microsoft confirmed a remote code execution vulnerability in SharePoint Server that allows authenticated API abuse to gain full system access.
By March, multiple threat intel sources confirmed active exploitation in financial and public sector networks, particularly in hybrid deployments.
Organizations using SharePoint Server were urged to patch immediately and audit lateral movement vectors.
3.Iranian-linked Pay2Key ransomware resurfaces with espionage undertones
Date of campaign detection: February 26, 2025
Pay2Key, a group tied to Iran’s cyber operations, returned with a stealthier, more targeted approach. Victims in energy, financial services, and logistics were compromised using VPN exploits and a retooled variant of their FoxShell backdoor—yet no ransom notes were delivered, suggesting covert data theft over extortion.
4.GitHub abused for supply chain payload delivery
Ongoing since January 2025
Security researchers exposed a growing trend: attackers are hiding malicious payloads inside Git repositories, then waiting for DevOps pipelines to pull them in.
This includes backdoored shell scripts and one-liners embedded in lesser-used branches or build folders.
The tactic has affected CI/CD chains, Docker builds, and infrastructure-as-code templates.
5.eSIM attack vector goes public
Disclosed: March 7, 2025
A new eSIM provisioning vulnerability was revealed, exposing how attackers can silently push forged eSIM profiles to targeted devices. The implications for mobile identity theft and secure communications compromise are still being assessed, but telecom providers have started auditing their GSMA Remote SIM Provisioning (RSP) systems in response.
Emerging patterns worth tracking
- API exposure as the new RCE vector: From SharePoint to Salesforce plugins, authenticated APIs are now the most reliable attack surface for privilege escalation.
- Ransomware without ransom: Groups like Pay2Key and others are using encryption tools as a cover for disruption or espionage, not monetization.
- Git and open source abuse scaling fast: Developers are unknowingly importing threats—especially when scripts aren’t reviewed before execution.
- Mobile attack surface is widening: From QR-based eSIM exploits to device-level SS7 bypass attempts, mobile networks may become Q2’s weak link.
Final word
If Q1 2025 was a stress test, it’s clear that long-trusted surfaces—BGP, APIs, Git, and even telecom profiles—are now active battlegrounds. The year ahead will depend not just on reaction, but on how fast defenders adapt their internal assumptions.
