zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - February 1, 2025

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - February 1, 2025

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Europol Warns Consumers to Be Mindful About Fake Medicines Offered Online
  • Broadcom Releases Patches for VMware Aria Flaws
  • State-Backed Hackers Exploit an AI Chatbot for Reconnaissance and Espionage

Europol Warns Consumers to Be Mindful About Fake Medicines Offered Online

Source: https://www.europol.europa.eu/media-press/newsroom/news/europol-warns-consumers-to-be-mindful-about-fake-medicines-offered-online

What happened: Europol coordinated Operation SHIELD V between April and November 2024, in which authorities from 30 countries joined forces to target the trafficking of counterfeit and misused medicines, as well as illicit doping substances. Europol, the European Union Intellectual Property Office (EUIPO), and the European Medicines Agency (EMA) have teamed up to raise awareness about fake medicines and protect consumers from this threat.

Why it matters: Fake medicines traded in the European Union are on the rise. Social media and online marketplaces, both on the surface and on the dark web, continue to be central to the trade of counterfeit pharmaceuticals, putting consumers at risk of serious health consequences such as ineffective treatment, and harmful side effects, while also unknowingly supporting criminal networks involved in the counterfeit trade. Pharmaceutical crime generates enormous financial losses for legitimate companies, undermines brand credibility, and also endangers investments in research.

Broadcom Releases Patches for VMware Aria Flaws

Source: https://thehackernews.com/2025/01/broadcom-patches-vmware-aria-flaws.html

What happened: In a recent update, Broadcom has patched five security vulnerabilities (CVE-2025-22218, CVE-2025-22219, CVE-2025-22220, CVE-2025-22221, and CVE-2025-22222) affecting VMware Aria Operations and Aria Operations for Logs.

Why it matters: Threat actors could exploit these vulnerabilities to inject malicious scripts into affected systems, perform unauthorized actions, and steal credentials. If not promptly patched, these vulnerabilities could expose organizations using the affected products to various types of malicious cyberattacks, which could have a wide range of repercussions on the firms’ finances and reputation. These bugs have been patched in VMware Aria Operations and Aria Operations for Logs version 8.18.3.

State-Backed Hackers Exploit an AI Chatbot for Reconnaissance and Espionage

Source: https://www.theregister.com/2025/01/31/state_spies_google_gemini/

What happened: Iranian, Chinese, North Korean, and Russian threat actors are reportedly abusing a popular AI chatbot for reconnaissance, phishing, vulnerability research, and espionage, with Iran accounting for most of the observed activity. The chatbot’s security measures have reportedly prevented malicious actions, such as malware generation.

Why it matters: Iranian spies reportedly accounted for 75 percent of observed use among state-backed threat actors, while Chinese, North Korean, and Russian groups also used the AI for content creation, cyber operations, and influence campaigns. Since Iran-linked actors exhibited the highest activity, it is likely they are preparing for future attacks. Although large language models (LLMs) are designed to provide information about any topic, active monitoring is essential to limit criminally-motivated activity allowing threat actors to effectively carry out or plant their malicious activities.

DEEP AND DARK WEB INTELLIGENCE

Xss user infra: Untested threat actor "infra" advertised a dataset allegedly belonging to an undisclosed UAE-based company on predominantly Russian language dark web forum xss.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2025-0477: The vulnerability exists due to a weak encryption methodology and can likely allow a threat actor to extract passwords belonging to other users of the application.

Affected products: All versions of FactoryTalk AssetCentre before V15.00.001.

Tags: DIB, tlp:green