November 2025 Cybersecurity Roundup: AI Leaks, Akira Ransomware, and Malware Disruptions
In the November 2025 edition of his monthly security review, ESET Chief Security Evangelist Tony Anscombe highlights critical cybersecurity developments. A significant concern involves major AI companies inadvertently exposing sensitive credentials, such as API keys and tokens, in public GitHub repositories, as reported by cloud security firm Wiz. Meanwhile, a joint advisory from government agencies in the US, France, Germany, and the Netherlands revealed that the Akira ransomware group has generated $244 million in illicit proceeds. On the enforcement front, Europol and Eurojust led a coordinated operation that successfully disrupted several prolific malware families, including the Rhadamanthys infostealer, VenomRAT, and Elysium. The roundup also addresses emerging privacy and regulatory issues, specifically examining the safety concerns surrounding X’s new location feature and detailing the enforcement mechanisms for Australia’s ban on social media usage for children under sixteen. These stories collectively illustrate the evolving landscape of digital threats, ranging from corporate negligence and organized cybercrime to legislative efforts aimed at protecting user privacy and vulnerable populations in the digital sphere.
Wire timeline
November 2025 Cybersecurity Roundup: AI Leaks, Akira Ransomware, and Malware Disruptions
In the November 2025 edition of his monthly security review, ESET Chief Security Evangelist Tony Anscombe highlights critical cybersecurity developments. A significant concern involves major AI companies inadvertently exposing sensitive credentials, such as API keys and tokens, in public GitHub repositories, as reported by cloud security firm Wiz. Meanwhile, a joint advisory from government agencies in the US, France, Germany, and the Netherlands revealed that the Akira ransomware group has generated $244 million in illicit proceeds. On the enforcement front, Europol and Eurojust led a coordinated operation that successfully disrupted several prolific malware families, including the Rhadamanthys infostealer, VenomRAT, and Elysium. The roundup also addresses emerging privacy and regulatory issues, specifically examining the safety concerns surrounding X’s new location feature and detailing the enforcement mechanisms for Australia’s ban on social media usage for children under sixteen. These stories collectively illustrate the evolving landscape of digital threats, ranging from corporate negligence and organized cybercrime to legislative efforts aimed at protecting user privacy and vulnerable populations in the digital sphere.
WeLiveSecurity