ZeroFox Daily Intelligence Brief - April 7, 2025
|by Alpha Team

ZeroFox Daily Intelligence Brief - April 7, 2025
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- CISA Releases Alert on Ivanti Patch for Flaw Exploited by China-Backed Threat Actor
- Former Employee at Chip Companies Reportedly Sold Secrets to Russian Operatives
- Toll Agency Phishing Scams Use SMS and iMessage to Steal Personal Data
CISA Releases Alert on Ivanti Patch for Flaw Exploited by China-Backed Threat Actor
What we know: CISA has released an advisory on an Ivanti vulnerability that a China-backed threat actor has been reportedly exploiting.
Context: Security patches for the vulnerability tracked as CVE-2025-22457 is available for Ivanti Connect Secure 22.7R2.6. Patches for Ivanti ZTA Gateways and Ivanti Policy Secure will be available on April 19 and 21, respectively.
Analyst note: Successful exploitation is likely to result in takeover of systems by threat actors. In the instance of an existing compromise on Connect Secure, solely updating to 22.7R2.6 is unlikely to secure the system. Threat hunting actions and a factory reset are advised before the update.
Former Employee at Chip Companies Reportedly Sold Secrets to Russian Operatives
Source: https://www.theregister.com/2025/04/04/amsl_russian_spy/
What we know: A former Russian employee at two semiconductor companies appeared in a Dutch court for reportedly leaking chip-making secrets to Russian intelligence. Authorities claim they met operatives in Russia, shared information via USB drives, and received EUR 40,000 (USD 44,000).
Context: The two companies are essential to the global tech industry for building machines that produce advanced computer chips and creating essential chips for cars, factories, and secure devices.
Analyst note: This theft could endanger technological advancements and compromise sensitive information, benefiting foreign intelligence services. Russia is likely to benefit by gaining access to advanced chip-making knowledge to strengthen its domestic semiconductor industry, which has been affected by sanctions and limited technology access.
Toll Agency Phishing Scams Use SMS and iMessage to Steal Personal Data
What we know: A phishing campaign mimicking official toll service portals, including E-ZPass and FasTrak, is using SMS and iMessage to steal personal and financial data.
Context: The messages bypass anti-spam protections, originating from random email addresses to appear legitimate. They often create a sense of urgency, claiming fees are overdue or licenses will be suspended if action is not taken immediately.
Analyst note: The stolen information is likely to be used in targeted attacks such as identity theft, financial fraud, social engineering attacks, and more. Moreover, the phishing messages create a sense of urgency, thereby making the victims more vulnerable to the scam.
DEEP AND DARK WEB INTELLIGENCE
Telegram user Coup Team: Threat actor group "Coup Team" claims to have conducted distributed denial-of-service (DDoS) against more than 50 U.S.-based websites under its ongoing operation #OpUSA, including nvd[.]nist[.]gov, the National Vulnerability Database (NVD) website. The attack allegedly lasted for three to five hours. Unavailability of vulnerability repositories, which NVD provides, through DDoS attacks could hinder vulnerability discovery, analysis, and mitigation.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2025-32013: This server-side request forgery (SSRF) vulnerability in LNbits—a cryptocurrency wallet account system—is likely to enable unauthorized access to internal resources of a wallet, like the seed phrase resulting in theft. There is a roughly even chance of this vulnerability being exploited as it is already public.
Affected products: LNbits' LNURL authentication handling functionality.
Tags: DIB, tlp:green