ZeroFox Cyber Intelligence Daily Brief - January 20, 2025
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - January 20, 2025
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Europol Holds Largest-Ever Operation to Increase Seizures of Criminal Assets Worldwide
- U.S. Treasury Sanctions Chinese Company Involved in Salt Typhoon Hack
- CISA and FBI Release Updated Guidance on Product Security Bad Practices
Europol Holds Largest-Ever Operation to Increase Seizures of Criminal Assets Worldwide
What happened: Europol is collaborating with 80 experts globally to participate in Project A.S.S.E.T.—Asset Search & Seize Enforcement Taskforce—to increase the number of criminal assets seized globally. In total, 43 law enforcement agencies from 28 countries joined the operation, which, among other events, resulted in the freezing of EUR 200,000 (USD 2,05,797) in cryptocurrencies.
Why it matters: A major element of Project A.S.S.E.T. is the participation of financial actors from the private sector, especially organizations from the banking sector and cryptocurrency exchanges. One of the most successful outcomes of this operation was the seizure of EUR 27 million in cryptocurrencies alone. This operation also resulted in the seizure of 83 cryptocurrency addresses and wallets, 53 properties, eight of which were valued EUR 38.5 million, and more.
U.S. Treasury Sanctions Chinese Company Involved in Salt Typhoon Hack
Source: https://home.treasury.gov/news/press-releases/jy2792
What happened: The U.S. Treasury Department has sanctioned a Sichuan-based cybersecurity company, Sichuan Juxinhe, directly involved in the Salt Typhoon hack of multiple major U.S. telecommunication and internet service provider companies.
Why it matters: As highlighted in the most recent Annual Threat Assessment, state-backed cyber actors from China continue to pose significant and persistent threats to U.S. national security, foreign policy, and economic stability. Sichuan Juxinhe is alleged to have participated in a series of cyberattacks that compromised a substantial amount of American call log data. The exposure of such critical and sensitive information poses a high risk not only to individuals whose data has been compromised, including government officials and politicians but also to national security by potentially exposing confidential information to adversarial states.
CISA and FBI Release Updated Guidance on Product Security Bad Practices
What happened: CISA, in partnership with the Federal Bureau of Investigation (FBI), has released an update to joint guidance Product Security Bad Practices in furtherance of CISA’s Secure by Design initiative. This updated guidance incorporates public comments CISA received in response to a Request for Information, adding additional bad practices, context regarding memory-safe languages, clarifying timelines for patching Known Exploited Vulnerabilities (KEVs), and other recommendations.
Why it matters: This voluntary guidance provides an overview of product security bad practices that are considered exceptionally risky, particularly for software manufacturers who produce software used in service of critical infrastructure or national critical functions (NCFs). This guidance also provides recommendations for software manufacturers to mitigate these risks. The authoring organizations strongly encourage all software manufacturers to avoid product security bad practices by following the recommendations in this guidance.
DEEP AND DARK WEB INTELLIGENCE
Exploit user CeFarir0ne: Untested threat actor "CeFarir0ne" advertised an auction for RDP access with domain user rights to an unnamed U.S.-based law firm on predominantly Russian language dark web forum Exploit.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2024-56841: Threat actors can remotely exploit this vulnerability that could enable them to bypass username verification.
Affected products: Siemens Mendix LDAP: All versions prior to 1.1.2
Tags: DIB, tlp:green