zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - February 13, 2025

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - February 13, 2025

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • CISA and FBI Warn of Malicious Cyber Actors Using Buffer Overflow Vulnerabilities to Compromise Software
  • APT44 Subgroups Target Critical Infrastructure Entities
  • 1.17 TB Data Leak Exposes Wi-Fi Passwords, IPs, and Device IDs from IoT Grow Light Firm

CISA and FBI Warn of Malicious Cyber Actors Using Buffer Overflow Vulnerabilities to Compromise Software

Source: https://www.cisa.gov/news-events/alerts/2025/02/12/cisa-and-fbi-warn-malicious-cyber-actors-using-buffer-overflow-vulnerabilities-compromise-software

What happened: CISA and the FBI have released a Secure by Design Alert, Eliminating Buffer Overflow Vulnerabilities, as part of their cooperative Secure by Design Alert series. “Eliminating Buffer Overflow Vulnerabilities” describes proven techniques to prevent or mitigate buffer overflow vulnerabilities through secure by design principles and best practices.

Why it matters: Buffer overflow vulnerabilities are a prevalent type of defect in memory-safe software design that could lead to system compromise. These vulnerabilities could lead to data corruption, sensitive data exposure, program crashes, and unauthorized code execution. Threat actors frequently exploit these vulnerabilities to gain initial access to an organization’s network and then move laterally to the wider network.

APT44 Subgroups Target Critical Infrastructure Entities

Source: https://www.bleepingcomputer.com/news/security/badpilot-network-hacking-campaign-fuels-russian-sandworm-attacks/

What happened: Subgroups of Russia-linked APT44 have been targeting global critical organizations in energy, oil and gas, shipping, and arms manufacturing sectors, and more, reportedly over the course of several years. The campaign, dubbed BadPilot, has two phases— where a threat actor first gains initial access into a company and then allows other APT subgroups to take over after compromise.

Why it matters: This phased approach to targeting high-profile companies indicates that the campaign is structured and focused on successfully conducting attacks. Information gathered from maintaining persistence and breaching systems over such a prolonged period is highly likely to provide Russia with ample information for future sabotage. The campaign’s targets, including companies in Ukraine, Europe, Central and South Asia, and the Middle East—regions that also involve some of Russia’s allies—likely indicates that Russia is using cyber operations to monitor surrounding countries closely.

1.17 TB Data Leak Exposes Wi-Fi Passwords, IPs, and Device IDs from IoT Grow Light Firm

Source: https://hackread.com/1tb-data-leak-expose-billions-iot-grow-light-records/

What happened: A massive 1.17 TB data leak affecting Mars Hydro—an Internet of Things (IoT) grow light manufacturer—has exposed details like Wi-Fi passwords, IP addresses, device IDs, email addresses, and smartphone details used to control the devices.

Why it matters: Threat actors could leverage this data in cyber espionage, man-in-the-middle attacks, extortion scams, or distributed denial-of-service attacks by exploiting the compromised IoT devices. They are also likely to use the exposed Wi-Fi credentials and device logs to jeopardize network access, potentially breaching IoT environments and users’ entire home or business networks. The data leak is also a likely indication that the threat actors could have leveraged unencrypted transmitted data, emphasizing how encryption can significantly reduce cyber threats to IoT devices.

DEEP AND DARK WEB INTELLIGENCE

Xss user odayman: Untested threat actor "odayman" has advertised source code of Chromium Extension and Loader malware on predominantly Russian language dark web forum xss.

VULNERABILITY AND EXPLOIT INTELLIGENCE

Ivanti vulnerabilities: Ivanti has released security updates for Ivanti Connect Secure (ICS), Ivanti Policy Secure (IPS), and Ivanti Secure Access Client (ISAC) to fix multiple vulnerabilities, including three critical flaws. Ivanti has received no reports of active exploitation and advises users to apply the updates promptly.

Affected products: The affected products are listed in this advisory.

CVE-2024-55591: This authentication bypass vulnerability affecting FortiOS and FortiProxy could allow a remote attacker to gain super-admin privileges via crafted requests to Node[.]js websocket module or via crafted CSF proxy requests.

Affected products: FortiOS versions 7.0.0 through 7.0.16; FortiProxy versions 7.0.0 through 7.0.19; FortiProxy versions 7.2.0 through 7.2.12

Tags: DIB, tlp:green