On October 14, 2025, Windows 10 died with its boots on. Microsoft ended free support for the operating system that had carried the world for a decade — while somewhere between a third and half of all Windows PCs on earth were still running it. The parallel was lost on nobody who lived through 2017: WannaCry had taught the industry, at full volume, exactly what happens to unsupported Windows at scale. Now the industry scheduled a rerun and sold tickets.
Microsoft softened the cliff-edge with an Extended Security Updates program — one more year of patches for a fee, free for consumers who signed in with a Microsoft account and synced their settings, and free outright in parts of Europe after consumer groups pushed back. But ESU was a bridge, not a destination, and the destination for millions of perfectly working machines that failed Windows 11's hardware bar was either the recycling heap or a long, slow slide into unpatched risk. Security teams spent the month doing what they always do at funerals: counting the relatives. Every ATM, kiosk, lab instrument, and factory terminal still showing that familiar Start menu became a line item on somebody's risk register.
The lesson of the month was not that Microsoft turned off updates. It's that the industry had eight years of warning after WannaCry and still arrived at the deadline with half its fleet on the wrong side. Software ends. Budgets that pretend otherwise are just pre-approving the next disaster.
A nation-state in the vendor's build room
On October 15, F5 — whose BIG-IP appliances sit in front of applications at most of the world's large enterprises and governments — disclosed that a nation-state actor had maintained long-term access to its product development environment, stealing BIG-IP source code and details of unpatched vulnerabilities. Washington treated it like a five-alarm fire: CISA issued Emergency Directive 26-01 the same day, ordering every federal agency to patch F5 devices by October 22 and warning of an "imminent threat" of full network compromise. The uncomfortable arithmetic: an attacker with a security vendor's source code and its private bug list doesn't need to find the door — they were handed the blueprints.
15.72 terabits against a single address
On October 24, Microsoft's Azure network absorbed the largest cloud DDoS attack ever observed to that point: 15.72 Tbps and nearly 3.64 billion packets per second, fired at a single IP address in Australia. The gun was Aisuru — a Mirai-descended botnet of more than 500,000 hijacked routers, cameras, and assorted smart junk, the same swarm that had hit Cloudflare with 22.2 Tbps in September. Eight years after Mirai's debut, the world's insecure-by-default devices were still being conscripted — just in vastly greater numbers, with vastly fatter home broadband behind them.
The day us-east-1 sneezed
It wasn't an attack, but October 20 belongs in the security story anyway: a DNS automation fault in AWS's Northern Virginia region cascaded for the better part of a day, taking down banking apps, airlines, games, and government services across the world. For resilience planners it was the cheapest possible tabletop exercise — a live demonstration that "the cloud" is, in places, one very important building — and it kicked off a quarter in which every major provider would take a turn proving the point.
The longest long tail
Few countries felt the Windows 10 deadline like India, home to some of the world's longest-lived PCs. The install base that powers ATMs, ration-shop kiosks, school labs, small-town CA offices, and government counters skews old, budget-bound, and ineligible for Windows 11's hardware bar — and much of it crossed October 14 with no ESU enrolment and no replacement plan. India had been here before: its XP fleet was among WannaCry's softest targets in 2017. October quietly set the same table again, and every bank and PSU risk officer who remembered 2017 knew exactly what was being served.
⏳ Time capsule — October 2025
- Bitcoin touched an all-time high above $126,000 in the month's first week — the crash came later.
- Thieves took the Louvre's crown jewels in a seven-minute daylight heist, reminding everyone that physical security has bad months too.
- OpenAI launched Atlas, its AI browser — and prompt-injection instantly became a mainstream security conversation.
- The season's hottest enterprise worry, per every conference stage: what happens when AI agents get credentials.
Everything ended at once
October 2025 reads, with hindsight, like the month the industry's deferred bills arrived together: the OS debt (Windows 10's half-migrated fleet), the vendor-trust debt (F5's stolen blueprints, which kept security teams auditing appliance estates well into 2026), the IoT debt (Aisuru went on to break its own record within weeks), and the concentration debt (AWS's stumble was followed within a month by Azure's and Cloudflare's own outages — none of them attacks, all of them lessons). The Windows 10 long tail behaved exactly as history predicted: ESU bought the diligent a year, and everyone else joined the most attractive unpatched population on the internet. WannaCry's ghost, it turns out, keeps office hours.