[October-23-2025] Daily Cybersecurity Threat Report

This report details a series of recent cyber incidents, providing key information for each event, including published URLs and associated screenshots, strictly based on the provided data.


  1. Alleged data sale of Wekiwi

  1. Alleged sale of admin-panel access to UK e-commerce site

  1. Institute of Real Estate Management (IREM®) falls victim to Qilin Ransomware

  1. HEZI RASH targets the website of Tecpack Solutions

  1. OCI International Holdings Limited falls victim to RansomHouse Ransomware

  1. Alleged data sale of International Social Survey Programme

  1. Kurogane Kasei Co. falls victim to RansomHouse Ransomware

  1. UniCursos falls victim to TENGU Ransomware

  1. Alleged data breach of Cocamar Cooperativa Agroindustrial

  1. Gericke Group falls victim to Qilin Ransomware

  1. SFOOD Inc. falls victim to RansomHouse Ransomware

  1. Pharaoh’s Team targets multiple subdomains of Hostinger

  1. ozsoft.com.au falls victim to LYNX Ransomware

  1. Alleged sale of unauthorized access to Fortinet systems (200 instances)

  1. Alleged sale of unauthorized access to Fortinet systems (300 instances)

  1. Pharaoh’s Team targets the website fgcsrl-containers.it

  1. STAR LÉGUMES falls victim to TENGU Ransomware

  1. Pharaoh’s Team targets the website feriascasa.com

  1. Pharaoh’s Team targets the website e-versicherungsb-ank.de

  1. Alleged data breach of Assemblée Nationale

  1. Pharaoh’s Team targets the website of Sellora

  1. Qatargas and Tar Company falls victim to TENGU Ransomware

  1. Alleged leak of Paypal accounts of USA

  1. Oscar Manresa Group falls victim to TENGU Ransomware

  1. Alleged leak of login access to Diebold Thailand Co., Ltd

  1. Al Rimal Foodstuff Industries FZC falls victim to TENGU Ransomware

  1. Alleged leak of login access to Faculty of Science and Digital Innovation, Thaksin University

  1. Alleged leak of login access to Thai-German Institute

  1. Alleged data leak of Gavriel Machal an unidentified Israeli law firm

  1. Paterson & Dowding Family Lawyers falls victim to Anubis Ransomware

  1. Goodfellow & Schuettlaw falls victim to Anubis Ransomware

  1. Alleged sale of Screen Connnect Alternative Remote Tool
  • Category: Malware
  • Content: The threat actor claims to be selling Screen Connnect Alternative Remote Tool, this malicious tool that can secretly control computers, extract sensitive information, and bypass security protections, this software could be used for cyberattacks, ransomware campaigns, or spying on networks.
  • Date: 2025-10-23T12:11:03Z
  • Network: openweb
  • Published URL: (https://forum.exploit.in/topic/268771/)
  • Screenshots:
  • Threat Actors: SICKOTRUSTED-URL
  • Victim Country: Unknown
  • Victim Industry: Unknown
  • Victim Organization: Unknown
  • Victim Site: Unknown

  1. Alleged sale of Google ads credit in UK

  1. Alleged leak of login access to Graduate Employment System of Rajamangala University of Technology Lanna
  • Category: Initial Access
  • Content: The group claims to have leaked access to Graduate Employment System of Rajamangala University of Technology Lanna.
  • Date: 2025-10-23T09:58:10Z
  • Network: telegram
  • Published URL: (https://t.me/nxbbsec/2906)
  • Screenshots:
  • Threat Actors: NXBB.SEC
  • Victim Country: Thailand
  • Victim Industry: Education
  • Victim Organization: graduate employment system of rajamangala university of technology lanna
  • Victim Site: rmutl.ac.th

  1. Alleged leak of login access to Payme

  1. Alleged leak of login access to NavTECH Co.,Ltd

  1. Alleged data breach of Warbirds Ukraine

  1. The Laxmi Niwas Palace falls victim to Nova Ransomware

  1. Alleged data breach of CityPlantes

  1. ACTi Corporation falls victim to EMBARGO Ransomware

  1. NOTRASEC TEAM targets the website dokkan.agency

  1. Alleged leak of login access to dokkan.agency

  1. Alleged data breach of iWeaver Pte. Ltd

  1. Alleged sale of RDP access to an unidentified Cryptocurrency company in South Korea

  1. Alleged leak of banking files

Conclusion

The incidents detailed in this report highlight a diverse and active landscape of cyber threats. Ransomware and Data Breaches are prominent, affecting various sectors across numerous countries, including Law Practice & Law Firms, E-commerce & Online Stores, and Information Technology Services in the USA, UK, China, and more. The compromised data ranges from sensitive customer records, financial information, to internal organizational data and intellectual property.

The report also reveals significant activity in Initial Access sales, with threat actors offering unauthorized access to admin panels, Fortinet systems, and internal networks, notably across Thailand. Furthermore, the sale of Malware, such as a Screen Connect Alternative Remote Tool, underscores the readily available offensive capabilities in the cyber underground.

The incidents collectively demonstrate that organizations across various industries and geographies face persistent threats from data exfiltration, unauthorized network access, and the proliferation of malicious tools. The nature of these incidents emphasizes the critical importance of robust cybersecurity measures, including strong access controls, data protection strategies, continuous vulnerability management, and proactive threat intelligence to defend against a wide array of sophisticated and opportunistic attacks.