zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - April 17, 2025

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - April 17, 2025

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • CISA Flags Threat from Exposed Credentials in Legacy Oracle Environment
  • Apple Releases Emergency Zero-Day Patches. Update Now!
  • BidenCash Leaks 910K Credit Cards on Russian Dark Web Forum

CISA Flags Threat from Exposed Credentials in Legacy Oracle Environment

Source: https://www.cisa.gov/news-events/alerts/2025/04/16/cisa-releases-guidance-credential-risks-associated-potential-legacy-oracle-cloud-compromise

What we know: CISA is warning of possible unauthorized access to a legacy Oracle cloud environment. The exposure of credential material threatens organizations and individuals if credentials are reused or embedded across systems.

Context: Recently, Oracle released over 300 security patches in its second critical patch update of 2025. Patching existing vulnerabilities and implementing cybersecurity best practices are essential to mitigate this risk.

Analyst note: Threat actors could exploit exposed reused credentials to move laterally, escalate privileges, or maintain persistent access—leading to data theft, service disruption, and further supply chain attacks.

Apple Releases Emergency Zero-Day Patches. Update Now!

Source: https://www.bleepingcomputer.com/news/security/apple-fixes-two-zero-days-exploited-in-targeted-iphone-attacks/

What we know: Apple released emergency zero-day patches for iOS, macOS, tvOS, iPadOS, and visionOS devices, after warning of an “extremely sophisticated attack” against “specific targets.”

Context: The vulnerabilities were found in CoreAudio (CVE-2025-31200) and RPAC (CVE-2025-31201). The bugs enabled remote code execution (RCE) on a device through an infected audio stream, and by bypassing Pointer Authentication (PAC) affecting device memory.

Analyst note: The bugs likely enabled attackers to spy on user activity, steal photos, passwords, eavesdrop using the microphone, and even take over the device. The vulnerabilities were likely being used in politically-motivated espionage.

BidenCash Leaks 910K Credit Cards on Russian Dark Web Forum

Source: https://hackread.com/bidencash-market-leak-credit-cards-russian-forum/

What we know: Dark web carding marketplace BidenCash has leaked 910,380 stolen credit card records on Russian dark web forum xss. The dump includes card numbers, CVVs, and expiration dates, but no names or personal data.

Context: BidenCash claimed the data was scraped from various forums and Telegram groups, to showcase its “anti-public system,” which filters out already circulated cards.

Analyst note: The leaked data—even without names or personal data—could be used in card-not-present (CNP) fraud like online purchases and subscription abuse, with attackers testing small charges before escalating or reselling verified cards.

DEEP AND DARK WEB INTELLIGENCE

Xss user OpenProcess: Untested threat actor "OpenProcess" has advertised Fortinet VPN access with local administrator rights to an undisclosed Austrian company on xss. This is likely to lead to unauthorized access to sensitive data, installation of malware, and privilege escalation.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2025-24054: This already patched Windows vulnerability is being actively exploited by attackers. It is an NTLM hash disclosure bug that requires minimal user interaction to enable attackers to steal authentication credentials. It is likely to enable attackers to impersonate a user even without the original password and gain the user rights, known as pass-the-hash attack.

Affected products: The affected products is listed here.

Tags: DIB, tlp:green