ZeroFox Cyber Intelligence Daily Brief - January 9, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - January 9, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Turkish APT Targets Private and Public Entities in Netherlands for Espionage
- NIST Warns of Security and Privacy Risks from Rapid AI System Deployment
- Ransomware Group Claims Attack on Capital Health; Says It Stole 10 Million Files
Turkish APT Targets Private and Public Entities in Netherlands for Espionage
Turkey-associated Advanced Persistent Threat (APT) group, tracked as Sea Turtle, Cosmic Wolf, Marbled Dust, Silicon, and Teal Kurma, has targeted critical public and private infrastructures in the Netherlands over the past year as a part of cyberespionage efforts. Sea Turtle has been exploiting systems in the target infrastructures, vulnerable to supply-chain and island-hopping attacks, to steal crucial data. The stolen information includes politically motivated information that the APT has presumably used for intelligence gathering or surveillance.
NIST Warns of Security and Privacy Risks from Rapid AI System Deployment
The U.S. National Institute of Standards and Technology (NIST) highlights privacy and security challenges linked to the increased deployment of artificial intelligence (AI) systems. NIST outlines potential threats, including adversarial manipulation of training data, exploitation of model vulnerabilities, and malicious interaction to extract sensitive information. As generative AI systems like OpenAI ChatGPT and Google Bard become integral to online services, AI models face risks such as corrupted training data, software vulnerabilities, data model poisoning, and privacy breaches due to prompt injection attacks.
Ransomware Group Claims Attack on Capital Health; Says It Stole 10 Million Files
On January 8, ZeroFox observed Lockbit 3.0 ransomware group claim to have targeted Capital Health in a cyberattack discovered at the end of last month. The threat group says it has stolen over 10 million files and more than “7 terabytes of medical confidentiality data" valued at USD 250,000 but has refrained from encryption to not interfere with patient care. Capital Health has also issued an official notification stating that it has restored the affected systems and that all healthcare facilities are available. The company is collaborating with forensic investigators to assess any plausible risk to patient and employee data.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- BreachForums user KromSec: Actor Claims to Leak Data From The Islamic Republic of Iran's Food and Drug Administration
VULNERABILITIES
- CVE-2023-6788: The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.8.1.
- CVE-2004-0458: mah-jong before 1.6.2 allows remote attackers to cause a denial of service (server crash) via a missing argument, which triggers a null pointer dereference.
EXPLOITS
- CVE-2023-22580: Due to improper input filtering in the sequalize js library, can malicious queries lead to sensitive information disclosure.
- CVE-2023-22851: Tiki before 24.2 allows lib/importer/tikiimporter_blog_wordpress.php PHP Object Injection by an admin because of an unserialize call.
BREACHES
- Combolist: '300kusa.txt' (298,680 Records): Email Address, Password
- Combolist: '8698 [Netflix].txt' (623 Records): Email Address, Password
Tags: DIB, tlp:green