zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - November 28, 2023

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - November 28, 2023

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Ardent Health Services Reports Information Technology Security Incident
  • Russia’s Federal Air Transport Agency Hacked; Ukraine Claims Responsibility
  • Joint Guidelines Released by CISA and U.K. NCSC to Ensure Secure AI Development

Ardent Health Services Reports Information Technology Security Incident

Ardent Health Services faced a ransomware attack forcing it to take its network offline. Ardent continues to work with law enforcement and third parties to restore its electronic medical records and other information. At the time of reporting, investigations are yet to produce conclusive findings on the scope of the attack and its implications. Ardent continues to provide care to some of its patients while the rest are redirected to other healthcare units.

Russia’s Federal Air Transport Agency Hacked; Ukraine Claims Responsibility

The Defence Intelligence of Ukraine, operating under the Defense Ministry, is claiming responsibility for conducting a “successful complex special operation in cyberspace,” through which it has acquired confidential documents from the Federal Air Transport Agency of Russia, Rosaviatsia. Rosaviatsia oversees flight safety and maintains a record of all emergency events that take place during the operation of Russian aviation. The dataset obtained from the cyberattack reportedly includes “daily reports of Rosaviatsia for the entire Russian Federation for more than a year and a half.”

Joint Guidelines Released by CISA and U.K. NCSC to Ensure Secure AI Development

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the U.K. National Cyber Security Centre (NCSC) announced the publication of new guidelines, co-signed by 23 domestic and international cybersecurity organizations, for the development of secure artificial intelligence (AI) systems. These guidelines are centered around taking ownership of security consequences, radical transparency and accountability, and establishing security as the top priority. They are applicable to all AI systems and emphasize the importance of following “secure by design” principles.

Tags: DIB, tlp:green