[September-23-2025] Daily Cybersecurity Threat Report

This report details a series of recent cyber incidents, providing key information for each event, including published URLs and associated screenshots, strictly based on the provided data.


  1. Alleged data breach of University of Perpetual Help System DALTA

  1. Alleged data breach of Paul Rossi Law Offices

  1. Alleged sale of unauthorized access to backup systems of an unidentified organization
  • Category: Initial Access
  • Content: The group claims to have selling access to an unidentified organization. The compromised system contains a massive database of 10.7 terabytes distributed among documents, security systems, audio files, video materials, over 100 gigabytes of additional data.
  • Date: 2025-09-23T13:09:19Z
  • Network: telegram
  • Published URL: https://t.me/n2LP_wVf79c2YzM0/1727
  • Screenshots:
  • Threat Actors: Infrastructure Destruction Squad
  • Victim Country: Unknown
  • Victim Industry: Unknown
  • Victim Organization: Unknown
  • Victim Site: Unknown

  1. Alleged Data Leak of Korean law firm

  1. Alleged sale of US citizens’ records

  1. Alleged data breach of Malvern Hills District Council

  1. Alleged data leak of an unidentified Thailand furniture industry

  1. Alleged data breach of ICICI Bank, USA

  1. Alleged unauthorized access to unidentified utility system of a residential building in Ukraine

  1. Alleged data breach of Mai Linh Group

  1. Alleged data leak of Indonesia Ministry & President Personal Data

  1. Alleged data leak of Iron March

  1. Alleged unauthorized access to an unidentified boiler system in Poland

  1. Alleged data sale of Assurance Maladie

  1. Alleged data leak of Tia.gov.np

  1. Alleged data breach of Department of Education – Philippines (DepEd)

  1. Alleged sale of 0day Nodes Cloudflare
  • Category: Vulnerability
  • Content: The threat actor claims to be selling a 0day vulnerability in Cloudflare CDN nodes that enables CDN bypass when chained with Host Header Injection (HHI). The exploit allows direct access to origin servers, bypassing protection mechanisms, and is demonstrated in a proof-of-concept video comparing normal and exploited behavior.
  • Date: 2025-09-23T06:23:43Z
  • Network: openweb
  • Published URL: https://forum.exploit.in/topic/266829/
  • Screenshots:
  • Threat Actors: APT_Hunter
  • Victim Country: Unknown
  • Victim Industry: Unknown
  • Victim Organization: Unknown
  • Victim Site: Unknown

  1. Alleged data breach of Vtenext

  1. Alleged data sale of Feathers Fashion

  1. Alleged data sale of Ministry of Education, Research and Technology Indonesia

  1. Alleged data breach of Zen Tower Corporation of the Philippines

  1. Alleged data breach of Foodiv

  1. CLOBELSECTEAM targets the website of Komite Pemantauan Pelaksanaan Otonomi Daerah

  1. Alleged data breach of Universidad de Piura

  1. Alleged data leak of Cambodian mobile numbers

  1. Alleged data breach of Vercel

  1. Alleged sale of VPN access to an unidentified organization in USA

  1. Alleged sale of VPN access to an unidentified organization in Denmark

  1. Alleged data leak of 1 Million Swiss Phone Numbers

  1. Alleged data leak of classified Algerian eSIM Policy Directive

  1. Alleged data leak of German and Austrian Phone Numbers

The cyber incidents documented in this report reveal a dynamic threat landscape with a variety of malicious activities. Data breaches and leaks are widespread, impacting a range of sectors including education, law, banking, and government administration across multiple countries like the Philippines, USA, UK, Thailand, Indonesia, Ukraine, Poland, France, Vietnam, Peru, Cambodia, Switzerland, Denmark, Algeria, and Germany . The compromised data is extensive, ranging from personal user details, financial records, and classified documents to sensitive operational data and administrative credentials .

Beyond data breaches, the report highlights a significant market for initial access, with threat actors offering unauthorized entry to utility systems, corporate networks, and government infrastructure. The report also details the sale of vulnerabilities, such as a 0-day exploit targeting Cloudflare CDN nodes. These incidents collectively underscore the persistent threat of data exfiltration, unauthorized network access, and the availability of malicious tools, emphasizing the critical need for robust cybersecurity defenses, including strong access controls, continuous vulnerability management, and proactive threat intelligence to combat these varied and opportunistic attacks.