ZeroFox Daily Intelligence Brief - March 3, 2025
|by Alpha Team

ZeroFox Daily Intelligence Brief - March 3, 2025
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- 25 Arrested in Global Hit Against AI-Generated Child Sexual Abuse Material
- Krpano Abused in SEO Poisoning Campaign; Affects Prominent Websites
- Polish Space Agency POLSA Hit by Cyberattack
25 Arrested in Global Hit Against AI-Generated Child Sexual Abuse Material
What we know: Law enforcement agencies across 19 countries have arrested 25 individuals connected to a criminal network involved in distributing child sexual abuse material (CSAM) created using artificial intelligence (AI).
Context: During the operation (Operation Cumberland), led by Danish law enforcement, 273 suspects were identified, and 173 electronic devices were seized. Authorities continue to prioritize the fight against child sexual exploitation through initiatives like Stop Child Abuse – Trace An Object.
Analyst note: Victims of this AI-generated CSAM could experience psychological distress and emotional trauma due to the exploitation and abuse depicted in the material. The distribution of such content can increase the risk of further harm and revictimization.
Krpano Abused in SEO Poisoning Campaign; Affects Prominent Websites
Source: https://hackread.com/over-350-high-profile-websites-hit-by-360xss-attack/
What we know: Threat actors have been observed exploiting a reflected XSS vulnerability (CVE-2020-24901) in the Krpano virtual tour framework, allowing them to inject malicious code and manipulate search engine results affecting over 350 websites.
Context: This activity is a part of the 360XSS campaign abusing the Krpano software. Krpano is a software tool that allows users to view images and videos in an immersive 360 degree view.
Analyst note: The attack used SEO poisoning to manipulate search results, pushing malicious or misleading content to high-ranking positions. By using familiar platforms, the attacker makes it difficult for users to distinguish legitimate communications from malicious ones, potentially leading to data breaches, financial losses, and operational disruptions.
Polish Space Agency POLSA Hit by Cyberattack
What we know: The Polish Space Agency (POLSA) experienced a cyberattack in which threat actors reportedly gained unauthorized access to its IT infrastructure.
Context: The targeted systems were secured, and authorities launched “intensive operational activities” to identify the perpetrators of the attack. Warsaw has previously accused Moscow of targeting Polish systems to destabilize the country, as Poland actively supplies military aid to Ukraine.
Analyst note: Given the Polish stance in the Russia-Ukraine war and POLSA’s close association with the European Space Agency (ESA), it is likely that the threat actors in this incident are politically motivated. Additionally, last month, a Polish astronaut was included in a crew that will participate in Ignis, a joint venture between POLSA and the ESA, thereby further solidifying Poland’s relationship with several European allies of Ukraine.
DEEP AND DARK WEB INTELLIGENCE
Xss user telecoms: Untested threat actor "telecoms" has advertised data breach of an unnamed French managed service provider (MSP) company on predominantly Russian language dark web forum xss. A breach at this company could expose sensitive process-related, client, and proprietary data leading to financial repercussions and more.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2024-57392: The buffer overflow vulnerability in Proftpd commit 4017eff8 allows a remote attacker to execute arbitrary code and can cause a denial of service (DoS). Threat actors abusing this vulnerability could cause systems to crash causing widespread operational difficulties.
Affected products: Proftpd commit 4017eff8 version 1.3.7a+dfsg-12+deb11u5
Tags: DIB, tlp:green