ZeroFox Daily Intelligence Brief - May 23, 2025
|by Alpha Team

ZeroFox Daily Intelligence Brief - May 23, 2025
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Global Dark Web Crackdown Targeting Online Drug and Criminal Networks
- U.S Charges 16 Including Two Russians in DanaBot Malware Case
- CISA and Partners Release New Best Practices Guide for Securing AI Data
Global Dark Web Crackdown Targeting Online Drug and Criminal Networks
What we know: A global law enforcement operation has made 270 arrests of dark web vendors and buyers across ten countries, dismantling networks trafficking in drugs, weapons, and counterfeit goods.
Context: The suspects had conducted thousands of sales on illicit marketplaces, using encryption tools and cryptocurrencies. Additionally, authorities have seized over EUR 184 million (approx. USD 207 million) in cash, cryptocurrencies, and more.
Analyst note: It is likely that dismantled criminal networks could spawn further networks and marketplaces with improved defences to evade detection better. However, the arrests could provide law enforcement with key intelligence on future threats and the tactics of similar offenders.
U.S Charges 16 Including Two Russians in DanaBot Malware Case
What we know: The United States charged 16 individuals for developing and using the DanaBot malware which infected over 300,000 devices around the world and resulted in over USD 50 million in damages from ransomware and fraud.
Context: The malware, controlled by a Russia-based cybercrime network, enabled theft of account credentials, browsing history, crypto wallet information, and more. In a separate case, the U.S. also charged another Russia-based cybercriminal linked to the Qakbot malware.
Analyst note: There is a roughly even chance that other cybercriminals involved in the malware operations or having bought malware-as-a-service (MaaS) from the indicted groups are caught.
CISA and Partners Release New Best Practices Guide for Securing AI Data
What we know: CISA and partners have released a joint cybersecurity guide, “AI Data Security: Best Practices for Securing Data Used to Train & Operate AI Systems,” emphasizing data security's key role in ensuring accurate, trustworthy AI (artificial intelligence) outcomes.
Context: The guide outlines key data security risks across the AI lifecycle. It recommends robust data protection, proactive risk management, and enhanced threat detection in AI-enabled systems.
Analyst note: As AI systems become more integrated into essential operations, security of the data that powers organizations become crucial, since cybercriminals exploit vulnerabilities to manipulate such systems. Protecting data will help prevent attacks that compromise system integrity, disrupt operations, or enable malicious AI-driven activities.
DEEP AND DARK WEB INTELLIGENCE
184M credentials leaked: Cybersecurity researchers have found a misconfigured cloud server holding 184 million exposed login credentials, likely gathered via infostealer malware. The unsecured database included logins for email, social media sites, banks, health services, and government portals, posing a major risk to users. This can likely lead to identity theft, financial fraud, and unauthorized access to sensitive personal and governmental data.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2025-34027, CVE-2025-34026, and CVE-2025-34025: These three vulnerabilities in some Versa Networks products enable remote attackers to bypass authentication, achieve remote code execution, and access system endpoints. Versa Networks has reportedly released the patches. The vulnerabilities if left unpatched are likely to enable hackers to steal credentials and disrupt operations.
Affected products: Versa Concerto SD-WAN orchestration platform
Tags: DIB, tlp:green