---
title: "Threat Intel Content Update: 1/28/25"
description: Tidal Cyber's threat intelligence content updates for the week of 1/28/25- CISA's Latest Advisory, PlushDaemon
---

[Threat Intelligence Content Updates ](https://www.tidalcyber.com/threat-updates)

# [Threat Intel Content Update: 1/28/25](https://www.tidalcyber.com/threat-updates/threat-intel-content-updated-1/28/25)

 Written by [Tidal Cyber](https://www.tidalcyber.com/threat-updates/author/tidal-cyber) | Jan 28, 2025 5:52:52 PM

#### **CISA's Latest Advisory, PlushDaemon**

****Threat Content Highlights****

Threat Profiles, Objects, & Tags

- - - [New Campaign object](https://app.tidalcyber.com/campaigns/50a50a03-279b-455f-9a8d-38dc8e9b80fd) added to cover **[CISA’s latest advisory](https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-022a)**. Unspecified nation-state actors “chained” together exploits of multiple zero-day vulnerabilities in cloud service appliances in order to achieve initial access, remotely execute code, install webshells, and harvest credentials from victim networks. Tidal Cyber has added content around several high-profile vulnerability exploit campaigns in recent months, many of which involved abuse of “zero-day” vulnerabilities (vulnerabilities which were not previously known or disclosed) – these are all tracked under the dedicated [“0-Day Exploit” Tag](https://app.tidalcyber.com/tags/t/a98d7a43-f227-478e-81de-e7299639a355).
          - New “China-aligned” espionage Group **[PlushDaemon](https://app.tidalcyber.com/groups/3a97e7d2-d3f3-4a6c-bd5f-0e82fcc08ae6?tab=3)** added following recent reporting on a software supply chain compromise targeting a developer of VPN software.

[View full post](https://www.tidalcyber.com/threat-updates/threat-intel-content-updated-1/28/25)

```json
{
  "@context" : "http://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Tidal Cyber"
  },
  "dateModified" : "2025-01-28T17:52:52.377Z",
  "datePublished" : "2025-01-28T17:52:52Z",
  "headline" : "Threat Intel Content Update: 1/28/25",
  "image" : {
    "@type" : "ImageObject",
    "height" : 500,
    "url" : "https://21164103.fs1.hubspotusercontent-na1.net/hubfs/21164103/Threat%20Intelligence%20Content%20Update%20Social.jpg",
    "width" : 900
  },
  "mainEntityOfPage" : "https://www.tidalcyber.com/threat-updates/threat-intel-content-updated-1/28/25",
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "height" : 60,
      "url" : "/hs/hsstatic/content_shared_assets/static-1.4092/img/default-amp-logo.png",
      "width" : 60
    },
    "name" : "Threat Intelligence Content Updates"
  }
}
```