Skip to content
NEWSROOM

Q1 2025 in review: a volatile quarter of breaches, exploits, and escalation

01 April 2025·3 min read·Quarterly Review

As Q1 2025 comes to a close, the global cybersecurity landscape has already experienced a dramatic start to the year. From critical infrastructure breaches to state-backed ransomware activity and previously unknown exploits, this quarter demonstrated how quickly threat actors are evolving—and how thin the line is between internal compromise and global consequence.

Here’s a breakdown of the top cyber incidents from January to March 2025, along with emerging patterns we believe security officers should watch closely.

1.Cloudflare DNS disruption sparks BGP security debate

Date: January 11, 2025

Cloudflare’s DNS service (1.1.1.1) experienced a widespread outage, initially believed to be tied to a BGP hijack. Though later attributed to internal misconfigurations, the timing of a real BGP anomaly in Brazil reignited concerns about internet routing trust and the urgent need for RPKI adoption. Several telecoms in Latin America have since accelerated BGP security audits.

2.Critical SharePoint vulnerability (CVE-2025-21517) under active exploitation

Date disclosed: February 11, 2025

Microsoft confirmed a remote code execution vulnerability in SharePoint Server that allows authenticated API abuse to gain full system access.

By March, multiple threat intel sources confirmed active exploitation in financial and public sector networks, particularly in hybrid deployments.

Organizations using SharePoint Server were urged to patch immediately and audit lateral movement vectors.

3.Iranian-linked Pay2Key ransomware resurfaces with espionage undertones

Date of campaign detection: February 26, 2025

Pay2Key, a group tied to Iran’s cyber operations, returned with a stealthier, more targeted approach. Victims in energy, financial services, and logistics were compromised using VPN exploits and a retooled variant of their FoxShell backdoor—yet no ransom notes were delivered, suggesting covert data theft over extortion.

4.GitHub abused for supply chain payload delivery

Ongoing since January 2025

Security researchers exposed a growing trend: attackers are hiding malicious payloads inside Git repositories, then waiting for DevOps pipelines to pull them in.

This includes backdoored shell scripts and one-liners embedded in lesser-used branches or build folders.

The tactic has affected CI/CD chains, Docker builds, and infrastructure-as-code templates.

5.eSIM attack vector goes public

Disclosed: March 7, 2025

A new eSIM provisioning vulnerability was revealed, exposing how attackers can silently push forged eSIM profiles to targeted devices. The implications for mobile identity theft and secure communications compromise are still being assessed, but telecom providers have started auditing their GSMA Remote SIM Provisioning (RSP) systems in response.

Emerging patterns worth tracking

  • API exposure as the new RCE vector: From SharePoint to Salesforce plugins, authenticated APIs are now the most reliable attack surface for privilege escalation.
  • Ransomware without ransom: Groups like Pay2Key and others are using encryption tools as a cover for disruption or espionage, not monetization.
  • Git and open source abuse scaling fast: Developers are unknowingly importing threats—especially when scripts aren’t reviewed before execution.
  • Mobile attack surface is widening: From QR-based eSIM exploits to device-level SS7 bypass attempts, mobile networks may become Q2’s weak link.

Final word

If Q1 2025 was a stress test, it’s clear that long-trusted surfaces—BGP, APIs, Git, and even telecom profiles—are now active battlegrounds. The year ahead will depend not just on reaction, but on how fast defenders adapt their internal assumptions.