zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - February 11, 2025

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - February 11, 2025

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • 8Base Leak Site Seized
  • Handala Hack Team Claims to Leak 350,000 Documents Linked to Israeli Police
  • Cyberattack Disrupts Lee Enterprises' Business Operations, Investigation Underway

8Base Leak Site Seized

Source: https://cloud.zerofox.com/intelligence/advanced_dark_web/80956

What happened: An international law enforcement operation has seized the dark web leak site of the 8Base ransomware group. The Bavarian State Criminal Police Office has also seized the “criminal content” of the site, while Thai authorities have reportedly arrested four European suspects.

Why it matters: An official notification has not been released to the public yet, which likely indicates that more law enforcement action, like weeding out other key members, can be expected in the near future. Although the site has been seized, it is likely that the unapprehended members of 8Base will reemerge under a different name or affiliate with existing threat groups to continue their operations.

Handala Hack Team Claims to Leak 350,000 Documents Linked to Israeli Police

Source: https://cloud.zerofox.com/intelligence/advanced_dark_web/81006

What happened: Politically motivated threat actor group Handal Hack Team has claimed to have leaked 2.1TB of data allegedly associated with the Israeli police force. The dataset supposedly contains around 350,000 documents comprising the force’s “most guarded secrets.”

Why it matters: The group’s pro-Palestine stance and suspected ties to Iranian intelligence indicate the likely motivation behind this attack. Moreover, the group has previously targeted several high-profile Israeli entities, further demonstrating its political stance. If the nature and ownership of the data are what the group claims, it is likely to expose sensitive and confidential details that could attract other politically aligned actors and expose the affected entities to threats of further malicious attacks.

Cyberattack Disrupts Lee Enterprises' Business Operations, Investigation Underway

Source:https://www.bleepingcomputer.com/news/security/cyberattack-disrupts-lee-newspapers-operations-across-the-us/

What happened: Lee Enterprises, one of the major newspaper groups in the United States, suffered a cyberattack on February 3, causing a significant outage that disrupted its operations, including the printing and delivery of newspapers. The company is investigating the extent of the data affected and has notified law enforcement.

Why it matters: Reporters and editors were unable to access files due to issues with VPN connections, further complicating the recovery process. With newsrooms disrupted, the credibility and timely reporting of news could be compromised, leading to a breakdown in the service readers depend on. Sensitive data—such as personal information of employees, financial records, or subscriber details—were likely stolen during the attack, which could lead to identity theft, financial fraud, or targeted attacks.

DEEP AND DARK WEB INTELLIGENCE

430,000 affected in healthcare data breach: Two late-2024 data breaches affecting healthcare entities in the United States exposed the data of 430,000 individuals, the impacted entities have confirmed.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2025-25064: Carrying a CVSS score of 9.8, this bug in Zimbra’s Collaboration software could enable threat actors to access information under certain conditions. Zimbra has released a security update to address this flaw, along with a few others.

Affected products: ZimbraSync Service SOAP versions prior to 10.0.12 and 10.1.4

Tags: DIB, tlp:green