ZeroFox Daily Intelligence Brief - May 20, 2025
|by Alpha Team

ZeroFox Daily Intelligence Brief - May 20, 2025
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- ZeroFox Intelligence Flash Report: Actor Seemingly Claims Responsibility for Recent Breaches
- Oracle Cloud Infrastructure Reported Down for Six Hours
- Sensitive Data Accessed in UK Legal Aid Agency Breach
ZeroFox Intelligence Flash Report: Actor Seemingly Claims Responsibility for Recent Breaches
Source: https://www.zerofox.com/advisories/33201/
What we know: Prominent threat actor “Machine1337” has claimed responsibility for at least seven recent cyberattacks allegedly involving unspecified data theft from Apple Inc., Steam, Huawei, Snapchat, and others.
Context: Separately, ZeroFox has observed a possible connection between the recent Coinbase data breach and the threat actor’s claims. The threat actor made the claims on Russian-speaking dark web forum xss and their Telegram channel.
Analyst note: Machine1337 is likely an English-speaking threat actor with links to other prominent threat actors like “Intelbroker,” “Zjj,” and the hacker collective “CyberN****rs.” It is likely that some of the alleged breaches claimed by the threat actor is a result of supply-chain compromise.
Oracle Cloud Infrastructure Reported Down for Six Hours
Source: https://www.theregister.com/2025/05/19/oci_outage_europe/
What we know: Oracle Cloud Infrastructure (OCI) was down for at least six hours in parts of Europe, according to recorded outages by Downdetector. The outage affected regions like Frankfurt, while a failover to Amsterdam was unsuccessful.
Context: The company has yet to confirm the outage. In March 2025, Oracle publicly denied reports of a data breach. However, it admitted in April that a breach did occur, although Oracle Cloud Infrastructure (OCI) was reportedly unaffected.
Analyst note: There is an unlikely chance that this outage is due to a cyberattack where the company had to limit its operations to limit the infection. It is likely that the previous breach exposed key data that enabled the same or a different threat actor to breach OCI.
Sensitive Data Accessed in UK Legal Aid Agency Breach
Source: https://www.gov.uk/government/news/legal-aid-agency-data-breach
What we know: A major cyberattack on the UK’s Legal Aid Agency has exposed sensitive data—including criminal records—dating back to 2010, affecting both applicants and legal professionals.
Context: The Ministry of Justice has confirmed that the attackers behind the breach exfiltrated personal data, including contact details, national IDs, criminal records, and financial information.
Analyst note: Threat actors are likely to abuse this data to conduct scams, exploit victims financially, and impersonate victims in identity fraud campaigns.
DEEP AND DARK WEB INTELLIGENCE
Exploit user rawmeat: Untested threat actor "rawmeat" has advertised remote desktop protocol (RDP) access with domain administrator rights to an unnamed U.S.-based retail company, generating USD 31.8 million in revenue, on Exploit. The bid for the access starts at USD 1,000. If the sale is legitimate, it is likely that the RDP access and admin rights are used in further ransomware attacks against the organization.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2025-4918 and CVE-2025-4919: The newly-patched zero-day vulnerabilities affect the Mozilla Firefox web browser. The two vulnerabilities are associated with out-of-bounds read/write issues in the JavaScript engine. There is a roughly even chance of the vulnerabilities aiding hackers in further cyberattacks to gain unauthorized access to confidential information stored on the target’s web browser, including credentials.
Affected products: Firefox versions before 138.0.4
Tags: DIB, tlp:green