zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - March 1, 2025

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - March 1, 2025

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Telegram Channels Linked to Russian Groups Incite Violence Against Muslim People
  • Hackers Sued for Exploiting AI to Create Deepfakes with Explicit Content
  • Massive AMS Exposure Puts Critical Infrastructure at Risk

Telegram Channels Linked to Russian Groups Incite Violence Against Muslim People

Source: https://www.theguardian.com/news/2025/feb/28/russia-linked-telegram-channels-offering-to-pay-for-attacks-on-mosques

What happened: A network of Telegram channels with Russian links has been encouraging UK residents to commit violent attacks on mosques and Muslim people, offering cryptocurrency in return. These groups have been connected to recent Islamophobic incidents, including graffiti and bomb-making material.

Why it matters: Physical issues like hate crimes and violence are increasingly being fueled and amplified through cyber platforms, with extremist groups distributing harmful materials such as bomb-making recipes and 3D-printed weapon designs via Telegram channels. The use of cryptocurrency makes it harder for authorities to track, disrupt, or prevent these transactions. These extremist calls for violence can likely escalate into more severe physical attacks, potentially deepening fear and division within communities, if no action is taken.

Hackers Sued for Exploiting AI to Create Deepfakes with Explicit Content

Source: https://www.theregister.com/2025/02/28/microsoft_names_and_shames_4/

What happened: A technology giant has sued ten individuals for allegedly stealing credentials for a cloud service and developing tools to bypass security guardrails in its generative AI services, enabling users to create deepfake explicit videos. Four of the ten were named in an amended complaint, with others still unidentified.

Why it matters: The accused individuals resold access to accounts of a popular cloud service platform and facilitated the creation of deepfakes that included explicit content and images of celebrities. AI misuse like this generates deceptive information that could fuel harassment, blackmail, and misinformation, posing a significant threat to those depicted in these types of content. Such incidents are examples of how actors with malicious intent could violate privacy and weaponize synthetic media to cause severe repercussions, including targeted hatred, reputational damage, and physical harm.

Massive AMS Exposure Puts Critical Infrastructure at Risk

Source: https://www.bleepingcomputer.com/news/security/over-49-000-misconfigured-building-access-systems-exposed-online/

What happened: Over 49,000 misconfigured access management systems (AMSs) worldwide are reportedly exposing unencrypted employee data, including names, emails, phone numbers, biometric data, photographs, work schedules, and access logs online. Building managers have been advised to take AMSs offline, secure them behind firewalls and VPNs, enforce multi-factor authentication, encrypt biometric data, and apply software updates. Why it matters: Attackers could infiltrate critical facilities by modifying access credentials, adding fake employees, or disabling legitimate users, endangering government buildings, power plants, and other infrastructure. Many building managers have reportedly not responded to security notifications, likely leaving their systems vulnerable to exploitation despite researchers' recommendations for mitigation.

DEEP AND DARK WEB INTELLIGENCE

BreachForums user Rey: Well-regarded and established threat actor "Rey" has claimed to have leaked data associated with Renesas Electronics Corporation, Japan, on BreachForums.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2025-1662: The URL Media Uploader plugin for WordPress is vulnerable to Server-Side Request Forgery. This enables authenticated attackers, with author-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

Affected products: URL Media Uploader versions through 1.0.0

Tags: DIB, tlp:green