[November-18-2025] Daily Cybersecurity Threat Report

This report details a series of recent cyber incidents, providing key information for each event, including published URLs and associated screenshots, strictly based on the provided data.

1. Alleged Unauthorized Access to Industrial Flow Meter Interface

  • Category: Initial Access
  • Content: Group claims to have accessed the interface of a Ukrainian industrial flow-meter device, displaying administrative controls and event-log functions. The exposed system appears to be used for monitoring gas or liquid flow in a pipeline
  • Date: 2025-11-18T23:34:10Z
  • Network: telegram
  • Published URL: https://t.me/zpentestalliance/728
  • Screenshots: https://d34iuop8pidsy8.cloudfront.net/657676c8-f76a-48ad-b102-52ad63aa61b3.png
  • Threat Actors: Z-PENTEST ALLIANCE
  • Victim Country: Ukraine
  • Victim Industry: Unknown
  • Victim Organization: Unknown
  • Victim Site: Unknown

2. Alleged sale of unauthorized access to Syrian Journal for Science and Innovation

3. Alleged sale of unauthorized access to National Energy Research Center

4. Alleged sale of unauthorized access to Higher Commission for Scientific Research

5. Alleged sale of unauthorized access to multiple Public Universities Based In Indonesia

6. NATION OF SAVIORS targets the website of Blazet It Services Agency

7. Alleged sale of unauthorized access to National Fire Department of Colombia

8. Alleged sale of unauthorized access to an unidentified private hospital and medical center based in Mexico

9. Alleged data breach of Zoominfo

10. Zuber Aussenwelten AG falls victim to SAFEPAY Ransomware

11. Simmons Electrical Co. Ltd falls victim to SAFEPAY Ransomware

12. Alleged data breach of Ryanair

13. Spark Innovations falls victim to Qilin ransomware

14. Adesur SAS falls victim to SAFEPAY ransomware

15. Puerto Rico Warehousing Management Corp falls victim to SAFEPAY ransomware

16. Comprehensive Institute of Cavaglià falls victim to SAFEPAY ransomware

17. Grand Prairie Public Library falls victim to INC RANSOM Ransomware

18. CONTINUUM India LLP falls victim to INC RANSOM Ransomware

19. Bais Yaakov Elementary School falls victim to INC RANSOM ransomware

20. Alleged Data Breach of lifeweb

21. The Ripley Academy falls victim to INC RANSOM ransomware

22. BABAYO EROR SYSTEM targets the website of Ushine24

23. Zadro falls victim to INC RANSOM ransomware

24. Datenlotsen falls victim to INC RANSOM ransomware

25. Alleged leak of login access of Siem Reap province

26. Alleged sale of unauthorized admin access to unidentified business platform in India

27. Alleged Data breach of Ministry of Justice

28. Alleged unauthorized SCADA system access to an unidentified factory in Poland

29. Alleged Data Breach from Ayuntamiento de Béjar

30. Appalachian Community Federal Credit Union falls victim to Qilin ransomware

31. Alleged Data Breach from vidpaw

32. Innovex Holdings falls victim to SKIRA ransomware

33. Bleyl Engineering falls victim to Akira ransomware

34. Regional Business Systems Inc falls victim to Qilin ransomware

35. QuaLex Manufacturing falls victim to Qilin ransomware

36. Gandía Palace Hotel falls victim to Qilin ransomware

37. Alleged data leak of india college database

38. FDC Interiors falls victim to MEDUSA ransomware

39. General Distributing falls victim to MEDUSA ransomware

40. Alleged leak of login credentials from E-claim

41. Alleged leak of SQL vulnerability on the website of BAMES EXCELLENT School

42. Alleged sale of a SQL injection vulnerability in Registro civil Mexico

43. Alleged data breach of SAS Institute Inc.

44. INDIAN CYBER FORCE targets the website of Technical Education & Vocational Training Authority (TEVTA), Punjab

45. Alleged leak of login access of Cambridge Muslim Academy

46. Alleged sale of unauthorized admin access to unidentified shop in Australia

Conclusion

The incidents detailed in this report highlight a diverse and active landscape of cyber threats. Ransomware, Initial Access sales, and Data Breaches are prominent, affecting various sectors from Government Administration and Education to Healthcare, Aviation, and Financial Services. The events impact countries globally, including Ukraine, Syria, Indonesia, the USA, Colombia, India, and Thailand. The compromised data ranges from unauthorized administrative access and Web Application Firewalls (WAF) to large-scale data breaches involving personal and organizational records. Beyond data compromise, the report reveals significant activity in the sale of access and vulnerabilities, with threat actors like Pharaoh’s Team, innocentzero, SAFEPAY, INC RANSOM, and Qilin actively targeting critical infrastructure and public institutions. The nature of these incidents emphasizes the critical importance of robust cybersecurity measures to defend against a wide array of sophisticated and opportunistic attacks.