ZeroFox Cyber Intelligence Daily Brief - January 17, 2025
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - January 17, 2025
ZeroFox intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- U.S.-Australia Joint Council Statement on Combating Online CSEA Following Safety by Design Workshop
- Russian State Actor Spear Phishing Campaign Targets WhatsApp Accounts
- ICAO Investigates Potential Cyberattack After Hacker Claims to Steal 42,000 Documents
U.S.-Australia Joint Council Statement on Combating Online CSEA Following Safety by Design Workshop
What happened: Australia’s eSafety Commissioner and Department of Homeland Security under the Australia – United States Joint Council on Combating Online Child Sexual Exploitation hosted over 20 technology, non-governmental, academic, and civil society sector organizations for a two-day workshop aimed at establishing new areas of collaboration to combat online child sexual exploitation and abuse (CSEA).
Why it matters: Held in person at the Homeland Security Investigations Lab in Washington, D.C., the workshop included presentations by industry leaders, roundtable discussions, and breakout groups. The Joint Council will build on the outputs of this workshop and continue to work with industry to develop a Safety by Design toolkit to ensure that child safety is prioritized at every stage in the development of online products and services, including in new and emerging artificial intelligence (AI) technologies. The toolkit is expected to collate best practices and share innovative approaches for companies to tackle online CSEA, while also exploring the challenges and limitations of adopting Safety by Design principles.
Russian State Actor Spear Phishing Campaign Targets WhatsApp Accounts
Source: https://thehackernews.com/2025/01/russian-star-blizzard-shifts-tactics-to.html
What happened: Russian state-sponsored threat actor Star Blizzard has launched a WhatsApp spear-phishing campaign, with a substantial portion of targets in government or diplomacy, defense policy, and Ukraine-related aid sectors. The attackers tricked victims using fake emails with QR codes into granting unauthorized access to their WhatsApp accounts, enabling data exfiltration via browser add-ons.
Why it matters: The nature of the campaign targets indicates that Star Blizzard is likely seeking sensitive and confidential information related to geopolitical affairs, especially regarding Ukraine. Besides, leveraging WhatsApp is reportedly a shift in the group’s tactics, techniques, and procedures (TTPs) to use a new access vector. This shift, which comes after a joint operation disrupted the group’s infrastructure and exposed its TTP, is likely a strategy to evade detection.
NSA Jointly Releases Recommendations for Closing the Software Understanding Gap
What happened: A report released by the National Security Agency (NSA), CISA, and others urges a national effort to better understand the behavior of software underpinning national security and critical infrastructure systems.
Why it matters: Currently, operators lack adequate capabilities for software understanding. These deficiencies stem from the software understanding gap—when technology manufacturers and developers build software that greatly outstrips their ability to understand it. A better software understanding is likely to effectively create software without defects, remediate them once discovered, maintain software at the speed and scale of mission relevance, and secure them against exploits.
DEEP AND DARK WEB INTELLIGENCE
- Telegram user NoName057(16):Pro-Russian hacktivist group "NoName057(16)" announced an alliance with threat actor group "French Hackers Squad."
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2024-20154: A heap-based buffer overflow flaw was found in the rsync daemon. This issue is due to improper handling of attacker-controlled checksum lengths (s2length) in the code. When MAX_DIGEST_LEN exceeds the fixed SUM_LENGTH (16 bytes), an attacker can write out of bounds in the sum2 buffer.
Affected product: Rsync daemon versions 3.2.7 through 3.4.0
Tags: DIB, tlp:green