zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - January 14, 2025

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - January 14, 2025

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • CISA Publishes Guidance on Priority Considerations in Product Selection for OT Owners and Operators
  • Ensuring U.S. Security and Economic Strength in the Age of Artificial Intelligence
  • Cybercriminals Exploit YouTube and Popular Search Engine to Distribute Malware

CISA Publishes Guidance on Priority Considerations in Product Selection for OT Owners and Operators

Source: https://www.cisa.gov/news-events/alerts/2025/01/13/cisa-and-us-and-international-partners-publish-guidance-priority-considerations-product-selection-ot

What happened: CISA—along with the United States and international partners—released a Secure by Demand joint guidance. This guidance focuses on helping customers identify manufacturers dedicated to continuous improvement and achieving a better cost balance, as well as how operational technology (OT) owners and operators should integrate secure by design elements into their procurement process.

Why it matters: Critical infrastructure and industrial control systems are prime targets for cyberattacks, while many OT products are not designed and developed with Secure by Design principles and often have easily exploited weaknesses. The authoring agencies warn that threat actors, when compromising OT components, target specific OT products rather than specific organizations. When procuring products, OT owners and operators should select products from manufacturers who prioritize security elements identified in this guidance.

Ensuring U.S. Security and Economic Strength in the Age of Artificial Intelligence

Source: https://www.whitehouse.gov/briefing-room/statements-releases/2025/01/13/fact-sheet-ensuring-u-s-security-and-economic-strength-in-the-age-of-artificial-intelligence/

What happened: The Biden-Harris Administration aims to secure U.S. security and economic strength by releasing an Interim Final Rule on Artificial Intelligence (AI) Diffusion. It builds on previous chip controls by thwarting smuggling, closing other loopholes, and raising AI security standards.

Why it matters: The rule takes significant steps against countries of concern, constraining them from accessing advanced AI systems and the computing power used to train them. Powerful AI systems have the potential to exacerbate significant national security risks, including by enabling the development of weapons of mass destruction, supporting powerful offensive cyber operations, and aiding human rights abuses, such as mass surveillance. It is important to work with AI companies and foreign governments to put in place critical security and trust standards in their AI ecosystems.

Cybercriminals Exploit YouTube and Popular Search Engine to Distribute Malware

Source: https://www.darkreading.com/threat-intelligence/cyberattackers-infostealers-youtube-comments-google-search

What happened: Cybercriminals are exploiting YouTube and a popular search engine’s results to target individuals seeking pirated software. The cybercriminals pose as tutorial creators, offering seemingly legitimate software installation guides, but trick users into downloading malware from deceptive links in video descriptions or comments.

Why it matters: Cybercriminals are exploiting people's reliance on search engines and platforms like YouTube for learning and software downloads, particularly targeting those seeking pirated or cracked programs to avoid paying for costly software. By masquerading as legitimate guides or offering seemingly harmless download links in video descriptions and comments, these attackers are able to infect victims with malware, often leading to potential data theft, system compromises, and other severe consequences. The use of reputable file-hosting services, like Mediafire and Mega, to distribute malicious files further complicates detection and removal, making it harder for users to recognize the threat.

DEEP AND DARK WEB INTELLIGENCE

Telegram user Mysterious Team Bangladesh: Pro-Palestine hacktivist group Mysterious Team Bangladesh has stated its intention to target websites in Poland with DDoS attacks.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2024-50603: This vulnerability arises from insufficient input sanitization in certain API actions, allowing attackers to inject malicious commands into system-level processes. By crafting specific API requests, threat actors can remotely execute arbitrary commands without authentication.

Affected products: Aviatrix Controller before 7.1.4191 and 7.2.x before 7.2.4996

Tags: DIB, tlp:green