zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - February 22, 2025

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - February 22, 2025

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Salt Typhoon Exploited Security Flaw to Target Telecommunication Networks
  • Clinical Research Firm Exposes 1.6 Million Patient Data
  • Stalkerware apps Cocospy and Spyic are exposing phone data of millions of people

Salt Typhoon Exploited Security Flaw to Target Telecommunication Networks

Source: https://thehackernews.com/2025/02/cisco-confirms-salt-typhoon-exploited.html

What happened: Chinese threat actor Salt Typhoon reportedly exploited a security flaw, CVE-2018-0171, and obtained legitimate victim login credentials in its campaign targeting major U.S. telecommunications companies.

Why it matters: Salt Typhoon maintained access to the compromised networks for three years, which indicates that the actor likely has a sophisticated cyber arsenal and also funding from the state sponsoring it. The actor also used a malware strain, which is an ELF binary written in Go, that erased logs and turned off logging, hiding evidence of its activity and making it harder for investigators to track it. The discovery of the tactics used in the telecommunications hack campaign could enable investigators to figure out the actor’s plan of action and develop measures to mitigate attacks.

Clinical Research Firm Exposes 1.6 Million Patient Data

Source: https://hackread.com/clinical-research-firm-expose-us-medical-survey-records/

What happened: A misconfiguration in a database associated with a Texas-based clinical research company exposed 1.6 million patient data to the internet. The database reportedly lacks authentication, encryption, and other protection exposing patient names, phone numbers, email addresses, current medications, and more.

Why it matters: The database includes sensitive clinical results—like reactions to certain vaccines, doctor’s names, birth control details, and more—which could be leveraged by threat actors to doxx and humiliate patients in financial extortion attempts. Additionally, clinical trials with less than ideal results are likely to be used against the company in the form of disinformation with the intention to damage its credibility and business unless the company fulfilled the threat actor’s demands.

Stalkerware apps Cocospy and Spyic are exposing phone data of millions of people

Source: https://techcrunch.com/2025/02/20/stalkerware-apps-cocospy-spyic-exposing-phone-data-of-millions-of-people/

What happened: A security vulnerability in the Cocospy and Spyic phone-monitoring apps exposed personal data, including messages, photos, and call logs of millions of people. The flaw also revealed the email addresses of users who signed up to plant the apps on devices for covert surveillance.

Why it matters: The bug compromises the security of devices affected by the apps, as well as the identities of those who sought to use the apps for surveillance purposes, exposing them to risks of being secretly monitored via calls, messages and other private activity. Unauthorized actors exploiting it could access sensitive data, including private information of individuals, potentially leading to identity theft, blackmail, harassment, or other forms of exploitation.

DEEP AND DARK WEB INTELLIGENCE

BreachForums user miyak0: Well-regarded threat actor "miyak0" has advertised VPN access to an unnamed UK-based business auditing company on predominantly English language dark web forum BreachForums.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2024-48510: Successful exploitation of this vulnerability in the vulnerable versions DotNetZip could allow an attacker to execute arbitrary code on the application server, if a specially crafted backup set is used for a restore.

Affected products: SiPass integrated V2.90 versions prior to V2.90.3.19; SiPass integrated V2.95 versions prior to V2.95.3.15.

Tags: DIB, tlp:green