ZeroFox Cyber Intelligence Daily Brief - January 16, 2025
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - January 16, 2025
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Black Basta-Style Attack Floods Inboxes with Phishing Emails
- FTC Takes Action Against GoDaddy for Alleged Lax Data Security for Its Website Hosting Services
- CISA Releases AI Cybersecurity Collaboration Playbook
Black Basta-Style Attack Floods Inboxes with Phishing Emails
Source: https://hackread.com/black-basta-cyberattack-hits-inboxes-with-1165-emails/
What happened: Threat actors are mimicking Black Basta ransomware group’s tactics in a cyberattack, sending 1,165 emails to 22 inboxes in just 90 minutes. The attacks used a ransomware scam and flooded inboxes with emails about fake accounts and subscriptions to trick employees into installing remote access software.
Why it matters: The attacker likely mimicked Black Basta's tactics, aware of the group’s reputation as a prolific operator that has targeted numerous victims and leveraged methods like psychological manipulation to bypass security defenses. This attack represents a form of phishing, where attackers overwhelm targets with a rapid barrage of emails designed to confuse and exploit human error. By using familiar platforms, deceptive subject lines, and bypassing security filters, the attacker makes it difficult for users to distinguish legitimate communications from malicious ones, potentially leading to data breaches, financial losses, and operational disruptions.
FTC Takes Action Against GoDaddy for Alleged Lax Data Security for Its Website Hosting Services
What happened: The Federal Trade Commission will require web hosting company GoDaddy to implement a robust information security program to settle charges that the company failed to secure its website-hosting services against attacks that could harm its customers and visitors to the customers’ websites.
Why it matters: The FTC says that GoDaddy’s data-security failures resulted in several major security breaches between 2019 and 2022 in which bad actors gained unauthorized access to customers’ websites and data. These breaches exposed consumers visiting the websites to risks, including that consumers were redirected to malicious websites. Amongst others, the order will require GoDaddy to establish and implement a comprehensive information-security program that protects the security, confidentiality, and integrity of its website-hosting services.
CISA Releases AI Cybersecurity Collaboration Playbook
Source: https://www.cisa.gov/resources-tools/resources/ai-cybersecurity-collaboration-playbook
What happened: On January 14, CISA released the AI Cybersecurity Collaboration Playbook to guide organizations across the AI community to share AI-related cybersecurity information voluntarily with CISA and partners through the Joint Cyber Defense Collaborative (JCDC).
Why it matters: The JCDC AI Cybersecurity Collaboration Playbook facilitates voluntary information sharing across the AI community, including AI providers, developers, and adopters, to strengthen collective cyber defenses against emerging threats. The playbook also identifies actionable information-sharing categories applicable to broader critical infrastructure stakeholders and other sharing mechanisms. It is intended to foster operational collaboration among government, industry, and international partners and will be periodically updated to ensure adaptability to the dynamic threat landscape as AI adoption accelerates.
DEEP AND DARK WEB INTELLIGENCE
Xss user Maxim_Project_X: Untested threat actor "Maxim_Project_X" has advertised specific VPN access with administrator rights to an unnamed Thai internet services provider on predominantly Russian language dark web forum xss.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2025-0070: SAP has released security patches for 14 vulnerabilities. CVE-2025-0070 allows an authenticated attacker to obtain illegitimate access to the system by exploiting improper authentication checks, resulting in privilege escalation.
Affected products: The affected products have been listed in this update.
Tags: DIB, tlp:green