zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - April 23, 2025

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - April 23, 2025

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • CryptoDead Exposes The New York Times Source Code in Alleged Breach
  • UK Veteran Retailer M&S Reports Cyber Incident as Customer Complaints Mount
  • Geopolitical Focus | Major Terrorist Attacks and Other Notable Global Events

CryptoDead Exposes The New York Times Source Code in Alleged Breach

Source: https://cloud.zerofox.com/intelligence/advanced_dark_web/84973

What we know: On April 22, 2025, ZeroFox observed untested threat actor "CryptoDead" claiming to leak 270 GB data associated with The New York Times on LeakBase.

Context: The alleged leak includes New York Times's source code, around 5,000 repositories, and 3.6 million files.

Analyst note: It is very likely that CryptoDead has released the same 270 GB data that was previously leaked in early 2024, which also allegedly comprised 5,000 repositories and 3.6 million files. The leaked data is likely to be used for unauthorized access, content manipulation, theft of proprietary data, and potential reputational, financial, and legal consequences.

UK Veteran Retailer M&S Reports Cyber Incident as Customer Complaints Mount

Source: https://www.bleepingcomputer.com/news/security/marks-and-spencer-confirms-a-cyberattack-as-customers-face-delayed-orders/

What we know: UK-based retail giant Marks and Spencer (M&S) has informed customers of possible delays with their click and collect orders owing to an unspecified “cyber incident.”

Context: Customers have been raising complaints since at least April 19, 2025, on social media sites about delayed orders, problems with returns and contactless payments, being refused purchase using gift cards, and more. The cyber incident also coincides with the Easter holiday season.

Analyst note: There is a roughly even chance that M&S is dealing with a ransomware attack affecting at least one system in its vast network, which could also lead to phishing attacks targeting customers.

Geopolitical Focus | Major Terrorist Attacks and Other Notable Global Events

  • Pakistan-linked The Resistance Front claimed responsibility for the April 22 terror attack in Pahalgam, Jammu and Kashmir (India), that killed at least 26 tourists, including a Navy officer and an Intelligence Bureau officer—coinciding with the U.S. Vice President JD Vance’s stay in India and Prime Minister (PM) Narendra Modi’s visit to Saudi Arabia. PM Modi cut short his trip, returned to Delhi, and held an urgent security briefing at the airport to address this situation.
  • Shortly after the Pahalgam terror attack, the Indian Army neutralized at least two terrorists trying to infiltrateIndia-administered Baramulla, Jammu and Kashmir. Vast reserves of weapons, ammunition, and more were recovered.
  • Authorities have released sketches of some of the terrorists, providing a likelihood of their appearances as a manhunt is underway to apprehend them.
  • A wildfire in New Jersey has spread to 3,200 acres, forcing 3,000 evacuations, endangering over 1,300 structures, and shutting down a major highway. No injuries were reported and a nearby nuclear plant remains secure.

DEEP AND DARK WEB INTELLIGENCE

Telegram user R00TK1T: On April 22, 2025, threat actor "R00TK1T" claimed to have breached American tech company Dell and Chinese drone company “DJI." R00TK1T claimed access to sensitive information including vulnerabilities, order IDs, dates & times, customer names, tracking numbers, and more. Access to such data is likely to result in active exploitation of vulnerabilities and phishing attempts using PII through customer orders.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2025-42599: On April 22, 2025, threat actor "R00TK1T" claimed to have breached American tech company Dell and Chinese drone company “DJI." R00TK1T claimed access to sensitive information including vulnerabilities, order IDs, dates, times, customer names, tracking numbers, and more. Access to such data is likely to result in active exploitation of vulnerabilities and phishing attempts using personal information through customer orders.

Affected products: Affects all Active! versions up to Build 6.60.05008561

Tags: DIB, tlp:green