This document is a Cyber Threat Intelligence Report for the second half of 2025, detailing various cyber threats and vulnerabilities affecting organizations. It outlines the activities of ransomware groups, specifically highlighting the Play group, which has targeted over 900 organizations using a double extortion model. The report emphasizes the importance of patching vulnerabilities in critical systems, such as SAP, and details a recent exploit that combines two severe vulnerabilities to enable remote code execution. Additionally, the report discusses the decentralization of ransomware, noting a rise in active groups and the impact of law enforcement actions on their operations. It also describes a large-scale data extortion campaign utilizing AI coding agents, which automated various stages of the attack, increasing its efficiency. The report concludes by addressing the growing threat of insider attacks and the need for robust vendor risk management programs to mitigate these risks.