ZeroFox Cyber Intelligence Daily Brief - January 8, 2025
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - January 8, 2025
ZeroFox intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- “U.S. Cyber Trust Mark” Label to Check Cybersecurity of Internet-Connected Devices
- License Plate Recognition Systems Vulnerable to Possible Exploitation
- ICAO Investigates Potential Cyberattack After Hacker Claims to Steal 42,000 Documents
“U.S. Cyber Trust Mark” Label to Check Cybersecurity of Internet-Connected Devices
What happened: The White House has announced the launch of a cybersecurity label for internet-connected devices, known as the U.S. Cyber Trust Mark, to help Americans make more informed decisions about the cybersecurity of products.
Why it matters: Threat actors are increasingly targeting home security systems to unlock doors, or to tap into insecure home cameras to illicitly record conversations, emphasizing the need for stronger cybersecurity of home appliances. The U.S. Cyber Trust Mark label program allows electric appliances makers to test products against established cybersecurity criteria from the U.S. National Institute of Standards and Technology via compliance testing by accredited labs, and earn the Cyber Trust Mark label. This way providing American consumers can also assess the cybersecurity of products they choose to bring into their homes.
License Plate Recognition Systems Vulnerable to Possible Exploitation
Source: https://www.wired.com/story/license-plate-reader-live-video-data-exposed/
What happened: A hundred and fifty automated license-plate-recognition (ALPR) system in Nashville, Tennessee, exposed live video feeds and licence plate numbers of 1,000 vehicles. This system, originally meant to record data for law enforcement, is reportedly not secured by any credentials.
Why it matters: The ALPR system feed was misconfigured and exposed sensitive data to the internet as it was likely not set up on private networks. Without credentials to secure the feed, people's data remain highly vulnerable, as these systems capture detailed information, including locations, vehicle models, and personally identifiable markers like clothing and other visual details. These surveillance technologies collect and store personal information endangering civilian lives since criminals can likely easily access such data to stalk victims or even impersonate them.
ICAO Investigates Potential Cyberattack After Hacker Claims to Steal 42,000 Documents
Source: https://www.theregister.com/2025/01/07/icao_data_theft_investigation/
What happened: The United Nations' aviation agency, International Civil Aviation Organization (ICAO), is investigating a potential cyberattack after a hacker, operating under the alias "Natohub," claimed to have stolen 42,000 documents from its systems. The hacker alleges the data includes sensitive personal information.
Why it matters: Cybercriminals or hostile state actors are likely to leverage this sensitive data to carry out identity theft, phishing attacks, or unauthorized access to critical aviation systems and databases, potentially leading to fraud, theft of intellectual property, and severe threats to aviation security and public safety. Furthermore, the stolen data can likely expose vulnerabilities in systems, enabling cyberattacks on air traffic control, airport operations, or aircraft safety mechanisms. This can lead to widespread disruptions in global air travel, financial losses, and an increased risk of terrorist or criminal activities, particularly if the information is linked to government operations or international intelligence sharing.
DEEP AND DARK WEB INTELLIGENCE
- RAMP user anongod: Untested threat actor "anongod" has advertised Solana Blockchain zero-day exploit on predominantly Russian language dark web forum RAMP. According to anongod, the exploit allows one to become an owner of any connected account and make transactions without obtaining the private key.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2024-20154: In Modem, there is a possible out of bounds write due to a missing bounds check, likely enabling remote code execution. User interaction is not needed for exploitation.
Affected product: MediaTek has listed the affected chipsets in this advisory.
Tags: DIB, tlp:green