zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - February 6, 2025

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - February 6, 2025

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • CISA Releases Guidance on Edge Devices
  • Ugandan Officials Detained in Connection to Major Bank Theft
  • LE Operation Targets Neo-Nazi Child Exploitation Ring Linked to Online Abuse Network

CISA Releases Guidance on Edge Devices

Source: https://www.cisa.gov/news-events/alerts/2025/02/04/cisa-partners-asds-acsc-cccs-ncsc-uk-and-other-international-and-us-organizations-release-guidance

What happened: CISA and others released guidance to help organizations protect their network edge devices and appliances, such as firewalls, routers, virtual private networks (VPN) gateways, Internet of Things (IoT) devices, internet-facing servers, and internet-facing operational technology (OT) systems.

Why it matters: Firewalls, routers, VPN gateways, and internet-facing servers are prime targets for attackers. Strengthening their security reduces the risk of unauthorized access and lateral movement within networks. The focus on firewalls, VPN gateways, IoT, OT, and internet-facing servers can likely address the attack vectors foreign adversaries and cybercriminals exploit to infiltrate networks. Implementing these security measures are likely to prevent costly breaches, minimize legal liabilities, and protect organizational reputation from damage due to cyber incidents.

Ugandan Officials Detained in Connection to Major Bank Theft

Source: https://www.reuters.com/world/africa/uganda-detains-9-finance-ministry-officials-over-central-bank-hack-2025-02-05/

What happened: Ugandan police detained nine finance ministry officials for their alleged involvement in the November 2024 hacking of the central bank’s electronic systems, resulting in the theft of 62 billion shillings (USD 16.87 million). The cybercriminals that carried out the attacks, reportedly called "Waste," accessed the Bank of Uganda’s IT systems to transfer the funds elsewhere, previously reported to be Japan.

Why it matters: The detention of Uganda's finance officials shows how corruption drives major criminal activities, which resulted in the diversion of substantial funds away from the country. The possible involvement of offshore accounts likely indicates the presence of a much larger operation involving other countries and criminals involved in money laundering schemes, possibly involving shell companies and offshore accounts. Without secure internal systems, insider activities like this could eventually target the country’s critical infrastructure.

LE Operation Targets Neo-Nazi Child Exploitation Ring Linked to Online Abuse Network

Source: https://www.europol.europa.eu/media-press/newsroom/news/law-enforcement-targets-online-cult-communities-dedicated-to-extremely-violent-child-abuse

What happened: U.S. Homeland Security Investigations has arrested two men linked to “CVLT,” a neo-Nazi child exploitation ring that coerced at least 16 minors worldwide into producing child sexual abuse material and self-harm images. The collaborative law enforcement operation targeted leaders who administered CVLT’s violent online abuse network.

Why it matters: CVLT specifically targeted vulnerable victims, including minors suffering from mental health issues or a history of sexual abuse, and encouraged them to engage in increasingly dehumanizing acts, leading to fatal outcomes. Victims subjected to such abuse are very likely to experience trauma for the rest of their lives. The intersection of child abuse crimes with easily accessible internet and digital spaces exposes minors to such life-threatening and exploitative networks.

DEEP AND DARK WEB INTELLIGENCE

Exploit user DNI: Untested threat actor "DNI" advertised an auction for Fortinet VPN access bundle to three unnamed distinct U.S.-based companies on Exploit.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2024-53104: This is a Linux Kernel out-of-bounds write vulnerability, which, according to CISA, are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise.

Affected products: Linux version 2.6.26

Tags: DIB, tlp:green