ZeroFox Weekly Intelligence Brief – March 29, 2025
|by Alpha Team

ZeroFox Weekly Intelligence Brief – March 29, 2025
ZeroFox’s Weekly Intelligence Briefing highlights the major developments and trends across the threat landscape, including digital, cyber, and physical threats. ZeroFox Intelligence is derived from a variety of sources, including—but not limited to—curated open-source accesses, vetted social media, proprietary data sources, and direct access to threat actors and groups through covert communication channels. Information relied upon to complete any report cannot always be independently verified. As such, ZeroFox applies rigorous analytic standards and tradecraft in accordance with best practices and includes caveat language and source citations to clearly identify the veracity of our Intelligence reporting and substantiate our assessments and recommendations. All sources used in this particular Intelligence product were identified prior to 6:00 AM (EDT) on March 27, 2025; per cyber hygiene best practices, caution is advised when clicking on any third-party links.
Read the Brief
View the full report here
Oracle Debacle: Oracle Denies Breach Claims; Evidence Suggest Otherwise
What we know:
- Alleged leaked data samples and reported email exchanges between the threat actor and multiple sources suggest the Oracle cloud breach is likely authentic, despite the company’s denial.
- Representatives from different companies mentioned in the sample data have reportedly confirmed the authenticity of the data associated with their respective organizations.
- Last week, Oracle publicly denied claims made by threat actor “rose87168” about having stolen six million users’ data.
- The hacker demanded over USD 200 million in crypto from Oracle in exchange for revealing how they breached the servers, which the company refused to pay.
Navigation Systems Face Rising Threats
What we know:
- International organizations are warning of increasing jamming and spoofing attacks on global navigation satellite systems (GNSS) that could pose a risk to aviation, maritime, and telecom safety across the globe.
Chinese Threat Actor Found Lurking in Asian Telecom Network for Four Years
What we know:
- China-linked threat actor “Weaver Ant” has been discovered lurking in the network of a major Asian telecommunications company for over four years, reportedly spying and collecting sensitive information.
Tags: tlp:green