ZeroFox Cyber Intelligence Daily Brief - February 10, 2025
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - February 10, 2025
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Europol Urges FInancial Firms and Policy Makers to Quantum-Safe Cryptography
- HSHS Notifies 882,000 Patients of August 2023 Cyberattack
- Malicious ML Models on Hugging Face Exploit Pickle Flaws to Bypass Security
Europol Urges FInancial Firms and Policy Makers to Quantum-Safe Cryptography
What happened: On 7 February 2025, Europol hosted a Quantum Safe Financial Forum (QSFF) event, during which the QSFF has issued a call to action for financial institutions and policymakers, urging them to prioritise the transition to quantum-safe cryptography.
Why it matters: The QSFF warns of the increasing risk posed by ‘Store now, decrypt later’ (SNDL) attacks, where malicious actors collect encrypted data today with the intention of decrypting it in the future using quantum computing. Sensitive financial information, including long-term investment strategies and confidential agreements, could be compromised if urgent security measures are not taken. The QSFF emphasises that action towards a quantum-safe financial ecosystem should be taken promptly to protect the industry from significant risks, financial losses, and reputational damage.
HSHS Notifies 882,000 Patients of August 2023 Cyberattack
What happened: Hospital Sisters Health System (HSHS) has notified over 882,000 patients that a data breach in August 2023 exposed their personal and health information. While the attack showed signs of a ransomware incident, no ransomware group has yet claimed responsibility, and an external investigation has been launched to assess the full impact.
Why it matters: The healthcare sector is increasingly targeted by threat groups because it holds valuable, sensitive data that is often easier to monetize than other sectors. The breach compromised sensitive patient information, including names, addresses, medical records, Social Security numbers, and health insurance details. This exposure could lead to identity theft, financial fraud, insurance fraud, phishing attacks, targeted scams, or be sold on the dark web.
Malicious ML Models on Hugging Face Exploit Pickle Flaws to Bypass Security
Source:https://thehackernews.com/2025/02/malicious-ml-models-found-on-hugging.html
What happened: Cybersecurity researchers have discovered two malicious machine learning (ML) models on Hugging Face that used "broken" pickle files to bypass security detection. These PyTorch models contained platform-aware reverse shells connecting to hard-coded IP addresses and evaded Picklescan due to unconventional 7z compression.
Why it matters: The two models contain malicious Python code that deployed platform-aware reverse shells—which is a technique dubbed nullifAI aimed at evading security safeguards—thereby enabling malicious code to run despite error messages. Although the attack is mostly considered to be a proof-of-concept, it opens gateways for threat actors to target the ML supply chain using flawed serialization methods. Hugging Face has since updated the affected open-source utility.
DEEP AND DARK WEB INTELLIGENCE
BreachForums user IntelBroker: Well-regarded and established threat actor "IntelBroker" has claimed to have leaked a database associated with Inkafarma, a Peru-based company that provides pharmacy products for online shopping, on BreachForums.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2025-0994: Trimble Cityworks contains a deserialization vulnerability. This could allow an authenticated user to perform a remote code execution attack against a customer's Microsoft Internet Information Services (IIS) web server.
Affected products: Trimble Cityworks versions prior to 15.8.9; Cityworks with office companion versions prior to 23.10
Tags: DIB, tlp:green