ZeroFox Weekly Intelligence Brief – January 13, 2025
|by Alpha Team

ZeroFox Weekly Intelligence Brief – January 13, 2025
TLP:GREEN
ZeroFox’s Weekly Intelligence Briefing highlights the major developments and trends across the threat landscape, including digital, cyber, and physical threats. ZeroFox Intelligence is derived from a variety of sources, including—but not limited to—curated open-source accesses, vetted social media, proprietary data sources, and direct access to threat actors and groups through covert communication channels. Information relied upon to complete any report cannot always be independently verified. As such, ZeroFox applies rigorous analytic standards and tradecraft in accordance with best practices and includes caveat language and source citations to clearly identify the veracity of our Intelligence reporting and substantiate our assessments and recommendations. All sources used in this particular Intelligence product were identified prior to 12:00 PM (EST) on January 10, 2025; per cyber hygiene best practices, caution is advised when clicking on any third-party links.
Read the Brief
View the full report here
U.S. Sanctions Chinese Cybersecurity Firm Associated with State-Sponsored Hacks
What happened: The U.S. Department of the Treasury's Office of Foreign Assets Control (OFAC) sanctioned Integrity Technology Group, a Beijing-based cybersecurity firm, for its involvement in cyberattacks against U.S. targets. From the summer of 2022 to fall 2023, the Chinese hacking group Flax Typhoon used Integrity Tech’s infrastructure to launch cyber intrusions that compromised U.S. organizations, especially those within critical infrastructure sectors. This partnership allowed Flax Typhoon to send and receive stolen data through Integrity Tech’s systems, facilitating its cyber espionage activities.
“U.S. Cyber Trust Mark” Label to Certify Cybersecurity of Internet-Connected Devices
What happened: The voluntary cybersecurity labeling program for wireless interconnected smart products administered by the Federal Communications Commission (FCC) will help Americans make more informed decisions about the cybersecurity of products they bring into their homes–from baby monitors to security systems. In December 2024, several major electronics, appliance and consumer product manufacturers, retailers, and trade associations made voluntary commitments to increase cybersecurity for the products they sell.
Marketer Fined for False Claims About Making Websites Adhering to Accessibility Guidelines
What happened: The Federal Trade Commission (FTC) has ordered a software provider to pay USD 1 million to settle allegations that it misrepresented the ability of its AI-powered web accessibility tool to make any website compliant with the Web Content Accessibility Guidelines (WCAG) for people with disabilities. New York-based accessiBe Inc. and accessiBe Ltd. (accessiBe) market and sell a web accessibility software plug-in called accessWidget that the company has stated can make any website compliant with WCAG, a comprehensive set of technical criteria used to assess website accessibility. The company made the claims on its website,social media, and in articles on third-party websites formatted to look like impartial and objective reviews.
Tags: tlp:green