Tech
Top 10 cyber security stories of 2025 | Computer Weekly
Artificial intelligence (AI) may have dominated wider tech headlines this year – and this held true in the cyber world as well – but at the same time, the security community’s concerns extend far beyond the risk implications of fully autonomous technology, as Computer Weekly’s annual top 10 round-up reflects.
Five years after Covid-19, it’s fair to say that the pandemic remade security, turning it from a specialist subject into something on which everyone has an opinion, and some of the biggest themes to emerge from the dark days of lockdown – remote work and supply chain security – remained talking points in 2025, too.
Another leitmotif was the emergence of quantum computing, and specifically the threat it poses to encryption, while in the US, radical shifts in policy under a new presidential administration had big ramifications for the industry.
Here are Computer Weekly’s top 10 cyber security stories of 2025.
We start with one of the more curious and long-running stories of the past year, the scandal surrounding North Korean operatives who obtained remote IT contractor positions with US companies to generate funds for the isolated regime. Towards the end of January, the US Department of Justice (DoJ) announced the indictment of five men – two North Koreans, a Mexican and two American citizens – in the case.
The prevalence of remote workers, especially since the Covid-19 pandemic, has made virtual job interviews a fact of life, and despite even more organisations issuing return to office (RTO) orders, many continue to hire for fully remote positions where their employees may rarely, if ever, physically meet. Threat actors have been quick to spot this gaping loophole in enterprise security, and human resources departments have been scrambling to respond.
The growth in speculation around the potential of quantum computing and its impact on the security world was a huge topic of conversation this year. In March, the UK’s National Cyber Security Centre (NCSC) published guidance to help support organisations as they get ready for quantum.
While its possibilities appear fantastic, in the medium term the dawn of quantum computing will render current encryption methods used to protect sensitive data obsolete, and the race is now on to develop effective post-quantum cryptography, or PQC. According to the NCSC, organisations should already be planning for PQC, ahead of technical upgrades in the early 2030s. The cyber agency wants the UK’s most at-risk organisations to have fully migrated to PQC by 2035 at the latest.
Supply chain security has become a fixture in the cyber world over the past few years, and the topic still dominated headlines in 2025. In May, the NHS’s digital chiefs wrote to their suppliers asking them to sign up to a cyber covenant.
The NHS has a long and troubled history of cyber attacks and data breaches – with attacks on partners such as OneAdvanced and Synnovis disrupting services and demonstrating the supply chain risks faced by healthcare organisations. The health service asked suppliers to commit to higher standards around supporting and patching systems, deploy multifactor authentication (MFA), always-on cyber monitoring and critical infrastructure logging, and immutable backups, among other things.
Even though it was established during his first administration, the US Cybersecurity and Infrastructure Security Agency (CISA) was not immune to the deep and sweeping cuts enacted by president Donald Trump as his second term kicked into high gear.
With longstanding officials ousted, budget cuts abounding, and threats to the long-running CVE programme that identifies and classifies dangerous vulnerabilities, the US cyber establishment was rocked to the core in 2025, with knock-on effects spreading beyond America’s borders.
With Microsoft’s longest-lived operating system, Windows 10, finally falling out of support in October, there were warnings for users across the UK during the summer of 2025 – prepare to upgrade now, or put your security at risk.
The NCSC’s chief technology officer, Ollie Whitehouse, said that not upgrading was akin to “incurring a debt at a high interest with the threat of forced repayment at a later date” as he implored organisations to upgrade their PC estates. The agency warned that, in addition to the difficulties users will see from being out of support, outdated and now unpatched Windows 10 systems will be prime targets for threat actors – harking back to the WannaCry incident in 2017, which exploited unpatched versions of Windows XP.
The UK government made progress on its Cyber Security and Resilience Bill in 2025, and was finally able to lay it before Parliament in November. Ahead of this, the usual round of consultations, debates and evidence-gathering sessions took place, and in July, the Home Office announced that a legal ban on making ransomware payments – covering hospitals and other public health bodies, public sector organisations such as councils and schools, and operators of critical national infrastructure (CNI), including datacentres – would be included.
Enacting a ransomware payment ban has broad support nationally – the majority of responses to a consultation on the matter supported it – but the subject remains a controversial one, with some sceptical that the ban will make critical UK organisations less attractive targets for cyber criminals and may actually make it harder for some to recover if and when they get hit.
The annual Black Hat cyber fair in Las Vegas brings together security professionals and hackers of all kinds, and always throws up a few oddities. This year, Cisco Talos researchers revealed a series of vulnerabilities – dubbed ReVault – affecting the security firmware and associated application programming interfaces (APIs) in Dell laptops.
During the course of their research, the Talos team discovered that if a vulnerable system was configured to accept a biometric fingerprint login, it was possible to tamper with the firmware so that the fingerprint reader would accept a non-human physical input. In what was surely a first for the security industry, the researchers posted a video online in which they defeated a laptop’s biometric security measures using a spring onion.
Back in the quantum realm, two years after the debut of its Quantum Safe Programme (QSP), Microsoft reported steady progress on incorporating PQC algorithms into some of the foundational components underpinning the security of its product suite in August.
For a tech company as ubiquitous as Microsoft, quantum security is a non-negotiable – getting it wrong could lead to disaster – so Redmond wants to move fast and hopes to have its core services secured before the end of the 2020s. Its overall strategy rests on three core pillars: updating Microsoft’s own and third-party services, supply chain and ecosystem to be quantum-safe; supporting its customers, partners and ecosystems in this goal; and promoting global research, standards and services around quantum security.
In October, political chaos in Washington DC overflowed into the security realm when the federal government was forced to shut down after temporary funding measures failed to get through a deeply divided Congress. Unfortunately, this stalled progress on extending or replacing an Obama-era threat data sharing law, CISA 2015, which expired at the end of September.
CISA 2015 set out a framework for information sharing and offered liability protections to organisations sharing threat data and cyber intelligence in the public interest. Experts feared its absence would not only hurt collaboration between the public and private sectors, but also reduce the US’s ability to act as an effective counterweight to cyber criminals and other threat actors on the world stage. Although CISA 2015 has now been extended, the possibility of another shutdown in early 2026 could cause this story to rear its head again very soon.
Security professionals need only look at the monthly Patch Tuesday alerts to see how Microsoft’s technological dominance puts it at the centre of so many cyber security stories, and the firm frequently comes in for flak from those who think it is not doing enough to fulfil its security obligations. Such voices were in full flood at the end of 2025 when the Australian, Canadian and American cyber intelligence agencies took the step of co-signing an emergency alert and issuing a guide to securing Microsoft Exchange server instances, a key vector in many of history’s most impactful cyber incidents.
The document laid out several proactive protection techniques to be applied to on-premise Exchange Servers as part of hybrid environments, and the Americans described it as a “critical resource” for Microsoft users. But one observer, a former White House cyber policy expert, said that the fact a multilateral coalition felt obligated to produce such a resource was a “devastating commentary on Microsoft’s security posture”.
Tech
The Best Presidents’ Day Deals on Gear We’ve Actually Tested
Presidents’ Day Deals have officially landed, and there’s a lot of stuff to sift through. We cross-referenced our myriad buying guides and reviews to find the products we’d recommend that are actually on sale for a truly good price. We know because we checked! Find highlights below, and keep in mind that most of these deals end on February 17.
Be sure to check out our roundup of the Best Presidents’ Day Mattress Sales for discounts on beds, bedding, bed frames, and other sleep accessories. We have even more deals here for your browsing pleasure.
WIRED Featured Deals
Branch Ergonomic Chair Pro for $449 ($50 off)
The Branch Ergonomic Chair Pro is our very favorite office chair, and this price matches the lowest we tend to see outside of major shopping events like Black Friday and Cyber Monday. It’s accessibly priced compared to other chairs, and it checks all the boxes for quality, comfort, and ergonomics. Nearly every element is adjustable, so you can dial in the perfect fit, and the seven-year warranty is solid. There are 14 finishes to choose from.
Tech
Zillow Has Gone Wild—for AI
This will not be a banner year for the real estate app Zillow. “We describe the home market as bouncing along the bottom,” CEO Jeremy Wacksman said in our conversation this week. Last year was dismal for the real estate market, and he expects things to improve only marginally in 2026. (If January’s historic drop in home sales is indicative, that even is overoptimistic.) “The way to think about it is that there were 4.1 million existing homes sold last year—a normal market is 5.5 to 6 million,” Wacksman says. He hastens to add that Zillow itself is doing better than the real estate industry overall. Still, its valuation is a quarter of its high-water mark in 2021. A few hours after we spoke, Wacksman announced that Zillow’s earnings had increased last quarter. Nonetheless, Zillow’s stock price fell nearly 5 percent the next day.
Wacksman does see a bright spot—AI. Like every other company in the world, generative AI presents both an opportunity and a risk to Zillow’s business. Wacksman much prefers to dwell on the upside. “We think AI is actually an ingredient rather than a threat,” he said on the earnings call. “In the last couple years, the LLM revolution has really opened all of our eyes to what’s possible,” he tells me. Zillow is integrating AI into every aspect of its business, from the way it showcases houses to having agents automate its workflow. Wacksman marvels that with Gen AI, you can search for “homes near my kid’s new school, with a fenced-in yard, under $3,000 a month.” On the other hand, his customers might wind up making those same queries on chatbots operated by OpenAI and Google, and Wacksman must figure out how to make their next step a jump to Zillow.
In its 20-year history—Zillow celebrated the anniversary this week—the company has always used AI. Wacksman, who joined in 2009 and became CEO in 2024, notes that machine learning is the engine behind those “Zestimates” that gauge a home’s worth at any given moment. Zestimates became a viral sensation that helped make the app irresistible, and sites like Zillow Gone Wild—which is also a TV show on the HGTV network—have built a business around highlighting the most intriguing or bizarre listings.
More recently, Zillow has spent billions aggressively pursuing new technology. One ongoing effort is upleveling the presentation of homes for sale. A feature called SkyTour uses an AI technology called Gaussian Splatting to turn drone footage into a 3D rendering of the property. (I love typing the words “Gassian Splatting” and can’t believe an indie band hasn’t adopted it yet.) AI also powers a feature inside Zillow’s Showcase component called Virtual Staging, which supplies homes with furniture that doesn’t really exist. There is risky ground here: Once you abandon the authenticity of an actual photo, the question arises whether you’re actually seeing a trustworthy representation of the property. “It’s important that both buyer and seller understand the line between Virtual Staging and the reality of a photo,” says Wacksman. “A virtually staged image has to be clearly watermarked and disclosed.” He says he’s confident that licensed professionals will abide by rules, but as AI becomes dominant, “we have to evolve those rules,” he says.
Right now, Zillow estimates that only a single-digit percentage of its users take advantage of these exotic display features. Particularly disappointing is a foray called Zillow Immerse, which runs on the Apple Vision Pro. Upon rollout in February 2024, Zillow called it “the future of home tours.” Note that it doesn’t claim to be the near-future. “That platform hasn’t yet come to broad consumer prominence,” says Wacksman of Apple’s underperforming innovation. “I do think that VR and AR are going to come.”
Zillow is on more solid ground using AI to make its own workforce more productive. “It’s helping us do our job better,” says Wacksman, who adds that programmers are churning out more code, customer support tasks have been automated, and design teams have shortened timelines for implementing new products. As a result, he says, Zillow has been able to keep its headcount “relatively flat.” (Zillow did cut some jobs recently, but Wacksman says that involved “a handful of folks that were not meeting a performance bar.”)
Tech
Do Waterproof Sneakers Keep the Slosh In or Out? Let WIRED Explain
Running with wet feet, in wet socks, in wet shoes is the perfect recipe for blisters. It’s also a fast track to low morale. Nothing dampens spirits quicker than soaked socks. On ultra runs, I always carry spares. And when faced with wet, or even snowy, mid-winter miles, the lure of weatherproof shoes is strong. Anything that can stem the soggy tide is worth a go, right?
This isn’t as simple an answer as it sounds. In the past, a lot of runners—that includes me—felt waterproof shoes came with too many trade-offs, like thicker, heavier uppers that change the feel of your shoes or a tendency to run hot and sweaty. In general, weatherproof shoes are less comfortable.
But waterproofing technology has evolved, and it might be time for a rethink. Winterized shoes can now be as light as the regular models, breathability is better, and the comfort levels have improved. Brands are also starting to add extra puddle protection to some of the most popular shoes. So it’s time to ask the questions again: Just how much difference does a bit of Gore-Tex really make? Are there still trade-offs for that extra protection? And is it really worth paying the premium?
I spoke to the waterproofing pros, an elite ultra runner who has braved brutal conditions, and some expert running shoe testers. Here’s everything you need to know about waterproof running shoes in 2026. Need more information? Check out our guide to the Best Running Shoes, our guide to weatherproof fabrics, and our guide to the Best Rain Jackets.
Jump To
How Do Waterproof Running Shoes Work?
On a basic level, waterproof shoes add extra barriers between your nice dry socks and the wet world outside. If you’re running through puddles deep enough to breach your heel collars, you’re still going to get wet feet. But waterproof shoes can protect against rain, wet grass, snow, and smaller puddles.
Gore-Tex is probably the most common waterproofing tech in footwear, but it’s not the only solution in town. Some brands have proprietary tech, or you might come across alternative systems like eVent and Sympatex. That GTX stamp is definitely the one you’re most likely to encounter, so here’s how GTX works.
The water resistance comes from a layered system that is composed of a durable water repellent (DWR) coating to the uppers with an internal membrane, along with other details like taped seams, more sealed uppers with tighter woven mesh, gusseted tongues, and higher, gaiter-style heel collars.
-
Entertainment1 week agoHow a factory error in China created a viral “crying horse” Lunar New Year trend
-
Tech1 week agoNew York Is the Latest State to Consider a Data Center Pause
-
Business3 days agoAye Finance IPO Day 2: GMP Remains Zero; Apply Or Not? Check Price, GMP, Financials, Recommendations
-
Tech1 week agoPrivate LTE/5G networks reached 6,500 deployments in 2025 | Computer Weekly
-
Tech1 week agoNordProtect Makes ID Theft Protection a Little Easier—if You Trust That It Works
-
Business1 week agoStock market today: Here are the top gainers and losers on NSE, BSE on February 6 – check list – The Times of India
-
Fashion3 days agoComment: Tariffs, capacity and timing reshape sourcing decisions
-
Business1 week agoMandelson’s lobbying firm cuts all ties with disgraced peer amid Epstein fallout



