ZeroFox Cyber Intelligence Daily Brief - February 16, 2025
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - February 16, 2025
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- CISA and FBI Warn of Malicious Cyber Actors Using Buffer Overflow Vulnerabilities to Compromise Software
- APT44 Subgroups Target Critical Infrastructure Entities
- Europol Urges FInancial Firms and Policy Makers to Quantum-Safe Cryptography
CISA and FBI Warn of Malicious Cyber Actors Using Buffer Overflow Vulnerabilities to Compromise Software
What happened: CISA and the FBI have released a Secure by Design Alert, Eliminating Buffer Overflow Vulnerabilities, as part of their cooperative Secure by Design Alert series. “Eliminating Buffer Overflow Vulnerabilities” describes proven techniques to prevent or mitigate buffer overflow vulnerabilities through secure by design principles and best practices.
Why it matters: Buffer overflow vulnerabilities are a prevalent type of defect in memory-safe software design that could lead to system compromise. These vulnerabilities could lead to data corruption, sensitive data exposure, program crashes, and unauthorized code execution. Threat actors frequently exploit these vulnerabilities to gain initial access to an organization’s network and then move laterally to the wider network.
APT44 Subgroups Target Critical Infrastructure Entities
What happened: Subgroups of Russia-linked APT44 have been targeting global critical organizations in energy, oil and gas, shipping, and arms manufacturing sectors, and more, reportedly over the course of several years. The campaign, dubbed BadPilot, has two phases— where a threat actor first gains initial access into a company and then allows other APT subgroups to take over after compromise.
Why it matters: This phased approach to targeting high-profile companies indicates that the campaign is structured and focused on successfully conducting attacks. Information gathered from maintaining persistence and breaching systems over such a prolonged period is highly likely to provide Russia with ample information for future sabotage. The campaign’s targets, including companies in Ukraine, Europe, Central and South Asia, and the Middle East—regions that also involve some of Russia’s allies—likely indicate that Russia is using cyber operations to monitor surrounding countries closely.
Europol Urges FInancial Firms and Policy Makers to Quantum-Safe Cryptography
What happened: On 7 February 2025, Europol hosted a Quantum Safe Financial Forum (QSFF) event, during which the QSFF issued a call to action for financial institutions and policymakers, urging them to prioritize the transition to quantum-safe cryptography.
Why it matters: The QSFF warns of the increasing risk posed by “Store now, decrypt later” (SNDL) attacks, where malicious actors collect encrypted data with the intention of decrypting it in the future using quantum computing. Sensitive financial information, including long-term investment strategies and confidential agreements, could be compromised if urgent security measures are not taken. The QSFF emphasizes that action towards a quantum-safe financial ecosystem should be taken promptly to protect the industry from significant risks, financial losses, and reputational damage.
Tags: DIB, tlp:green