ZeroFox Daily Intelligence Brief - April 14, 2025
|by Alpha Team

ZeroFox Daily Intelligence Brief - April 14, 2025
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Fortinet Releases Advisory on New Post-Exploitation Technique for Known Vulnerabilities
- Data Security Program Implements Export Control on U.S. Critical Data
- Qilin Ransomware Activity Spikes amid Shift Toward Corporate Targets
Fortinet Releases Advisory on New Post-Exploitation Technique for Known Vulnerabilities
What we know: Fortinet is alerting that a threat actor is actively exploiting known vulnerabilities (CVE-2024-21762, CVE-2023-27997, CVE-2022-42475) in FortiGate devices. The attacker is deploying a malicious file that enables unauthorized, read-only access to sensitive configuration data.
Context: The attack exploits previously patched vulnerabilities in SSL-VPN functionality. Fortinet has identified affected customers through telemetry and provided mitigation guidance.
Analyst note: Exposure of sensitive configurations and credentials could lead to wider network compromise. Users are advised to update to the patched FortiOS versions (7.6.2, 7.4.7, 7.2.11, 7.0.17, 6.4.16), reset credentials, and disable SSL-VPN.
Data Security Program Implements Export Control on U.S. Critical Data
What we know: The U.S. government has implemented the Data Security Program to safeguard the data of government entities and personally identifiable information (PII) of U.S. persons from foreign adversaries like China, Russia, Iran, and others.
Context: U.S. persons and businesses are expected to comply with the program, especially when dealing with information sharing with individuals and entities directly related to foreign governments or working under their influence or jurisdiction.
Analyst note: Data aggregators, entities working with the U.S. government, and social media companies are likely to be affected by the program. The Data Security Program is likely to create a trail of record on sale or share of information related to the U.S. government and persons enabling higher accountability in cases of misuse of information.
Qilin Ransomware Activity Spikes amid Shift Toward Corporate Targets
Source: https://cloud.zerofox.com/intelligence/advanced_dark_web/84556
What we know: ZeroFox has observed a significant increase in victims claimed by the Qilin ransomware group recently. The group has claimed at least 51 attacks since joining BreachForums.
Context: The Qilin ransomware group has been observed seeking corporate access on BreachForums, forming ties with a new actor, "Devman," and facing negative reputation due to allegations of targeting healthcare infrastructure.
Analyst note: Qilin is expanding its operations likely by leveraging its access to data being sold on BreachForums in its latest attacks. It will likely continue to add more victims to its leak site in the upcoming days.
DEEP AND DARK WEB INTELLIGENCE
BreachForums user Sythe: Untested threat actor "Sythe" has allegedly advertised scraped user data from paste sites such as Veinbin and Nebulabin on BreachForums. These sites have been inactive for an extended period. Exposed users of the affected sites are likely to be targeted by phishing and social engineering attacks. There is a roughly even chance of intellectual property theft of code snippets or scripts shared on the sites.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2025-23391: This vulnerability in SUSE Rancher—a Kubernetes management platform—enables a Restricted Administrator to reset the passwords of the administrators. The bug is likely to lead to account takeover, compromising the overall security framework of the affected system.
Affected products: Rancher versions from 2.8.0 before 2.8.14, from 2.9.0 before 2.9.8, from 2.10.0 before 2.10.4.
Tags: DIB, tlp:green