ZeroFox Daily Intelligence Brief - March 26, 2025
|by Alpha Team

ZeroFox Daily Intelligence Brief - March 26, 2025
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- File-Sharing Platform CrushFTP Users at Risk of Cyberattack; Patch Available
- Navigation Systems Face Rising Threats
- Geopolitical Focus: Major Geopolitical Happenings Around the World
File-Sharing Platform CrushFTP Users at Risk of Cyberattack; Patch Available
What we know: Enterprise-grade file sharing platform Crush FTP urged users to immediately patch an unauthenticated HTTP(S) port access vulnerability resolved on March 21, 2025, that could result in unauthorized access.
Context: The vulnerability does not affect those with a Demilitarized Zone (DMZ) feature of CrushFTP. In previous instances, CrushFTP servers in U.S. organizations have been targeted by politically-motivated actors. Similar file transfer platforms are also favourite targets of ransomware groups like the notorious Cl0p.
Analyst note: Organizations using the vulnerable versions of CrushFTP are likely at risk of cyber espionage or ransomware attacks. Targets of these potential attacks are very likely to be based in the United States, Germany, Canada, and the United Kingdom, among others.
Navigation Systems Face Rising Threats
Source: https://hackread.com/satellite-navigation-systems-jamming-spoofing-attacks/
What we know: International organizations are warning of increasing jamming and spoofing attacks on global navigation satellite systems (GNSS) that could pose a risk to aviation, maritime, and telecom safety across the globe.
Context: GNSS are networks of satellites, ground stations, and receivers that provide precise positioning, navigation, and timing (PNT) data. They are essential for global transportation, telecommunications, emergency response, infrastructure management, and others.
Analyst note: Jamming and spoofing attacks are components of the ongoing hybrid warfare utilized in various conflicts. Such attacks could disrupt flight navigation, communications, hinder military movements, and threaten civilian safety. Russia was accused of such interference last year.
Geopolitical Focus: Major Geopolitical Happenings Around the World
- Wildfires in southeastern South Korea have killed at least 18 people and injured 19. Over 27,000 have been evacuated, and several cultural heritage sites, including a 1,300-year-old Buddhist temple, have been destroyed.
- Following three days of peace talks in Saudi Arabia, Russia and Ukraine have separately agreed to a naval ceasefire in the Black Sea through deals with the United States.
- Without pressure from the United States, Israel will likely continue a moderate offensive in Gaza indefinitely. To read more about Israel, Gaza war, read this ZeroFox advisory. Meanwhile, Prime Minister Netanyahu's domestic political initiatives have sparked significant unrest in Israel.
DEEP AND DARK WEB INTELLIGENCE
Exploit user budda12: On March 25, 2025, well-regarded threat actor "budda12" advertised an auction for AmmyyAdmin access with administrator rights to an undisclosed international airport based in a Middle Eastern country on Exploit. The alleged access could enable a threat actor to control the systems of the international airport, which is in a conflict prone region, likely leading to repercussions including disruption in flights, travel, and communications.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2025-26633: Threat actor dubbed “EncryptHub” has reportedly exploited a newly patched zero-day and has exfiltrated data from compromised devices. This vulnerability involves improper neutralization in affected devices enabling unauthorized attackers to bypass a security feature locally. This attack could result in stolen data being sold on the Dark web or enable attackers to maintain persistence for surveillance and future attacks.
Affected products: The affected products are listed in this advisory.
Tags: DIB, tlp:green