The year in network security was not a particularly dramatic one, defined in some strange way by the after effects of Salt Typhoon as opposed to any new and devastating attacks.
Outside of networks, enterprises did get a nasty surprise from the Salesforce supply chain attack, while the U.K. saw attacks on the British institutions of Jaguar Land Rover (JLR) and Marks & Spencer, which together gave a wake up for the European nation to gets it security attack together.
Ultimately, cybersecurity in the network space was defined by a little of the old, and a little of the new, primarily identity-based acquisitions setting up firms for the age of agentic AI.
In fact, one could say there were more acquisitions than attacks of a headline-grabbing nature in the network and telecom space, and that's firmly A Good Thing.
Read on for the top stories which defined the year in security.
Big deals showed big money in cybersec
Cybersecurity arguably became a bigger deal than ever in 2025, defining the two biggest financial acquisitions of the year with Google betting the farm on cloud cybersecutiry firm Wiz for $32 billion, and Palo Alto Networks coming in second with its $20 billion CyberArk play.
Announced in March, Google's bid for Wiz reflected booming growth in the enterprise cloud segment, which surged from approximately $81 billion in 2020, to an estimated $285 billion in 2024.
Palo Alto's CyberArk love-in, meanwhile, represented a shrewd bet thanks to all things agentic, where with a greater number of AI agents on the network, the harder it is working out who's human and who isn't.
Founded in 1999, the Israeli-headquartered CyberArk specializes in identity and privileged access management (IAM/PAM), with its end-to-end Identity Security Platform covering multiple identity types across varied environments.
Its wares filled out the Palo Alto's end-to-end strategy with its mainline suite, building on the identity-aware secure access service edge (SASE) additions to its Prisma Access platform via recent Talon Cyber Security and CloudGenix acquisitions, while offering an IAM/PAM alternative to Microsoft and Okta's identity stacks.
Whether network security is ready or even hungry for an all-in-one solution is another question, and one explored by SDxCentral with Forrester as well as Palo Alto's rivals in the security space.
The jury may still be out on that question, but it's hard to deny the influence Palo Alto's decision had, with other identity solutions suddenly popping up left, right, and center.
We're also still awaiting for the Wiz deal to close, and how that will affect it's branding. Looking at Google's previous cybersecurity acquisition of Mandiant, as now fully absorbed under the Alphabet umbrella, it's hard to imagine Wiz's landscape of pink hues, robots, and unicorns working well with the uniform Google white, red, and yellow. Existing Wiz customers may have to brace themselves for something a little more corporate in their cloud security services.
Read the full stories
Google bets the farm on cybersecurity with proposed $32B Wiz acquisition
Palo Alto Networks to snap up CyberArk in $20B+ mega deal
For more on end-to-end network security
Does network security need an all-in-one platform?
Shadow AI came out of the shadows
AI has led to the coining of various interesting terms in recent months. Vibe coding. Clanker. Slopsquatting (ew).
Arguably, the biggest new phrase in the business space was shadow AI: when employees bring in unknown or unvetted AI tools into the enterprise network space, and havoc ensues.
Microsoft, CrowdStrike, Cloudflare, and Zscaler all announced solutions to the security scourge, with the biggest news being SASE vendor Cato Networks bagging Aim Security for $50 million for its specializations in securing enterprise use of large language models (LLMs) and generative AI.
SDxCentral also went deep this year with a dive on shadow AI, in which experts revealed the biggest culprits behind shadow AI are actually adventurous (and perhaps reckless) network engineers.
Read the full story
Keeping shadow AI from the enterprise end zone
For more on shadow AI in 2025
Cato Networks acquires Aim Security and $50M in funding
Geopolitical goons
Salt Typhoon may have gone down in 2024, but it was hard to escape the legacy of that attack in 2025, nor the spectre of nation-state threats such as the People’s Republic of China (PRC)-affiliated exploit.
September saw a joint advisory issued by U.S. and allied security agencies revealing Typhoon actively targeted critical networks through a wider attack area than previously reported, exploiting known flaws on backbone routers, provider edge, and customer edge devices from Palo Alto Networks, Cisco, and others.
Darktrace, meanwhile, claimed a European telecom organization was targeted by Salt Typhoon in July.
More state-affiliated nastiness occurred with Fire Ant, a Chinese cyberespionage campaign targeting virtualization and network infrastructure, including VMware ESXi, vCenter servers, and F5 load balancers.
Speaking of F5, the cybersecurity firm admitted in October that a threat actor had breached its networks for more than a year, gaining “long-term, persistent access” to certain areas of its system.
This was preceded by news that a historical Cisco bug was revealed as being exploited by Russian espionage group Static Tundra, aka Berserk/Energetic Bear or Dragonfly, leading to an urgent FBI briefing in August.
Just when it couldn't get worse, the year ended with the revelation that two ex-Cisco Networking Academy trainees may have partly orchestrated Salt Typhoon.
As such, it wouldn't be remiss to expect 2026 to be another salty year for cybersecurity.
Read the full story
China-linked Salt Typhoon hacking threat engulfs entire networks
For more on nation-state threats
Chinese cyberespionage group targets VMware, F5 vulnerabilities
FCC to scale back cybersecurity red tape on ISPs
Historical Cisco bug ongoing victim of sleeper cell attack
That's a lot of DDoS
We all remember the major Amazon Web Services (AWS) outage this year. But did you know 2025 was also a minefield of distributed denial of service (DDoS) attacks?
September saw Cloudflare block not one but two DDoS attacks, the first a 11.5 Tb/s wave of “hundreds” of hyper-volumetric DDoS attacks attempting to take down entire networks and cloud systems.
That attempt was dwarfed by a 22.2 Tb/s DDoS attack, totaling 10.6 billion packets per second (PPS). According to Cloudflare, the attack was “twice as large as anything seen on the internet before.”
Microsoft made a similarly grandiose statement with what it described as the largest DDoS attack ever observed in the cloud.
The exploit measured at 15.72 Tb/s and 3.64 billion PPS, and was pinned down to a Turbo Mirai-class botnet called Aisuru, which targets IoT flaws via home routers and cameras.
Cloudflare – which wasn't immune to its own outages and self-inflicted DDoS fails – ended the year by reporting the last quarter saw 8.3 million DDoS attacks, reflecting a 40% year-over-year increase in threats to networks, equivalent to nearly 3,780 attacks per hour, and corresponding to 170% of the DDoS attacks mitigated by Cloudflare throughout 2024.
In other words, DDoS attacks got more brazen in 2025, and they ain't going nowhere, unfortunately.
Read the full story
Cloudflare stops massive 22.2 Tb/s DDoS attack
For more on DDoS in 2025
Cloudflare accidentally DDoS'ed itself in dashboard update gone wrong
DDoS attacks are massive and here to stay: Cloudflare
Microsoft thwarts massive 15.72 Tb/s attack in the cloud
DDoS attacks are outpacing networks as attack sizes rise by almost 70%
Comments