zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - March 27, 2025

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - March 27, 2025

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Email Exchange Reveal New Insights into Alleged Oracle Data Breach
  • Google Releases Patches for Zero Day Bug; Users to Implement Immediately
  • Chinese APT FamousSparrow Linked to Cyberattacks on a U.S. Trade Group, Others

Email Exchange Reveal New Insights into Alleged Oracle Data Breach

Source: https://www.bleepingcomputer.com/news/security/oracle-customers-confirm-data-stolen-in-alleged-cloud-breach-is-valid/

What we know: Alleged leaked data samples and reported email exchanges between the threat actor and multiple sources suggest the Oracle’s cloud breach is likely authentic, despite the company’s denial.

Context: Last week, Oracle publicly denied claims made by threat actor “rose87168” about stealing 6 million user data. The hacker demanded over USD 200 million in crypto from Oracle in exchange for revealing how they breached the servers, which the company refused to pay.

Analyst note: If the threat actor’s claims of stealing 6 million users' data are true, it could likely leak exploitable sensitive information. It is also very likely that the threat posed to victims will decrease as organizations implement security measures to prevent further exploitation. To know more about the alleged cloud breach, read this ZeroFox advisory.

Google Releases Patches for Zero Day Bug; Users to Implement Immediately

Source: https://chromereleases.googleblog.com/2025/03/stable-channel-update-for-desktop_25.html

What we know: Google has patched a high-severity Chrome zero-day (CVE-2025-2783) vulnerability, which involved bypassing sandbox protections to deploy malware.

Context: The bug, linked to Operation ForumTroll, was used in phishing campaigns to infect victims with sophisticated malware against Russian organizations. Google has patched it in version 134.0.6998.177/.178.

Analyst note: It is likely that patching this vulnerability also disrupts the attackers’ entire exploit chain, preventing further infection. Patching this vulnerability likely limits continued exposure to threats and risks of copycat attacks, where other threat actors copy the initial attack.

Chinese APT FamousSparrow Linked to Cyberattacks on a U.S. Trade Group, Others

Source: https://thehackernews.com/2025/03/new-sparrowdoor-backdoor-variants-found.html

What we know: Chinese threat actor FamousSparrow has been found linked to cyberattacks on a U.S. trade group, a Mexican research institute, and a government organization reportedly in Honduras, running outdated messaging and collaborating platforms.

Context: The group used two new variants of the SparrowDoor backdoor, and ShadowPad malware popular among Chinese state-sponsored actors. It allegedly has some links to Chinese APT Earth Estries.

Analyst note: FamousSparrow targeted a U.S. trade group likely to surveil those closely associated with U.S. trade policy work. There’s a roughly even chance that the group is targeting the two Latin American countries due to their proximity and flow of data and trade with the United States.

DEEP AND DARK WEB INTELLIGENCE

BreachForums user miya: Well-regarded threat actor "miya" has advertised secure shell (SSH) access to an unnamed Canadian banker's association on BreachForums. Selling SSH access could provide interested threat actors with unauthorized access to conduct data breaches, establish remote code access, persistence, and more.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2025-26512: This bug in SnapCenter versions prior to 6.0.1P1 and 6.1P1 could enable an authenticated SnapCenter Server user to become an admin user on a remote system where a SnapCenter plug-in has been installed. An attacker with valid user credentials could escalate their privileges, potentially compromising the security of the remote system.

Affected products: SnapCenter versions prior to 6.0.1P1 and 6.1P1

Tags: DIB, tlp:green