zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - June 3, 2025

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - June 3, 2025

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • The North Face Targeted in Credential Stuffing Attack
  • Phishing Campaign Targets Executives Using Legitimate Tools
  • Bug in Vanta Exposes Data

The North Face Targeted in Credential Stuffing Attack

Source: https://www.bleepingcomputer.com/news/security/the-north-face-warns-customers-of-april-credential-stuffing-attack/

What we know: American outdoor retailer The North Face has suffered a credential stuffing attack, enabling cybercriminals to access customer accounts using reused login credentials. Meanwhile, luxury fashion brand Cartier has warned customers of a data breach that exposed personal information following a compromise of its systems.

Context: The North Face accounts lacking multi-factor authentication (MFA) were vulnerable to credential stuffing attacks, leading to the exposure of customer information. Personal information, like names, emails, addresses, and purchase history, was exposed but no payment data was compromised.

Analyst note: This attack follows a wave of ransomware incidents targeting retail and luxury brands. Cybercriminals will very likely keep targeting this lucrative sector for financial gain. Exposed customer personal data will likely lead to phishing and identity theft.

Phishing Campaign Targets Executives Using Legitimate Tools

Source: https://thehackernews.com/2025/06/fake-recruiter-emails-target-cfos-using.html

What we know: A spear-phishing campaign is targeting senior financial executives—at banking, energy, and insurance firms—with fake job offers.

Context: The campaign uses CAPTCHA-protected phishing links and evasion tools, deploying legitimate remote access tools, like NetBird.

Analyst note: The threat actor likely uses legitimate tools to avoid triggering security systems and bypass authentication checks to remain undetected longer, harvesting sensitive personal and corporate data.

Bug in Vanta Exposes Data

Source: https://techcrunch.com/2025/06/02/vanta-bug-exposed-customers-data-to-other-customers/

What we know: Vanta, a compliance company, has confirmed that a bug exposed private employee and integration data of some customers to other users.

Context: The exposed data included employee information and configuration details of multi-factor authentication.

Analyst note: This exposure—especially of multi-factor authentication details—could enable attackers to identify security weaknesses, tailor phishing campaigns, and carry out further unauthorized access and data breaches.

DEEP AND DARK WEB INTELLIGENCE

DarkForums user 303: Untested threat actor “303” has claimed to have leaked data associated with Deloitte on DarkForums. The threat actor allegedly leaked the source code and credentials associated with Deloitte's internal GitHub repository. If the claims are true, this breach could expose sensitive corporate information, potentially leading to further cyberattacks.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2025-21479, CVE-2025-21480, and CVE-2025-27038: Qualcomm has issued security patches for three zero-day vulnerabilities in its Adreno Graphics Processing Unit (GPU) driver. These flaws affect numerous chipsets and are currently being exploited in targeted attacks. If left unpatched, they could enable attackers to execute arbitrary code or gain unauthorized access, potentially compromising affected devices and sensitive data.

Affected products: The affected products have been listed in this advisory.

Tags: DIB, tlp:green