A series of diverse and impactful cyberattacks were reported on November 29, 2025, affecting public safety, finance, and conflict zones. The INC Ransom group targeted OnSolve, the provider of the CodeRED emergency alert system used by local governments across the U.S., causing service disruptions. Concurrently, Wall Street financial institutions were responding to a breach at a key real estate data vendor, highlighting persistent third-party risks. In a geopolitically motivated attack, the Ukrainian Cyber Alliance (UCA) hacktivist group claimed to have conducted a destructive wipe of systems at Donbas Post, the Russian-operated postal service in occupied Ukraine. These incidents collectively demonstrate the multifaceted nature of the modern threat landscape.
This report summarizes three distinct, significant incidents that occurred during the last week of November 2025.
T1486 - Data Encrypted for Impact).T1485 - Data Destruction) deployed after gaining administrative access to the network.M1030 - Network Segmentation).Maintain regular, immutable, and offline backups to ensure recovery from a ransomware or data destruction attack.
Segment networks to prevent ransomware and wipers from spreading laterally from an initial point of compromise to critical systems.
Train employees to recognize and report phishing attempts, which are a common initial access vector for ransomware groups.
Implement a robust patch management program to close vulnerabilities in public-facing systems before they can be exploited by threat actors.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
Help others stay informed about cybersecurity threats