zerofox logo
Advisories

ZeroFox Weekly Intelligence Brief – January 29, 2024

|by Alpha Team

banner image

ZeroFox Weekly Intelligence Brief – January 29, 2024

TLP:GREEN

ZeroFox’s Weekly Intelligence Briefing highlights the major developments and trends across the cyber threat landscape. ZeroFox Intelligence is derived from a variety of sources, including—but not limited to—curated open-source accesses, vetted social media, proprietary data sources, and direct access to threat actors and groups through covert communication channels. Information relied upon to complete any report cannot always be independently verified. As such, ZeroFox applies rigorous analytic standards and tradecraft in accordance with best practices and includes caveat language and source citations to clearly identify the veracity of our Intelligence reporting and substantiate our assessments and recommendations. All sources used in this particular Intelligence product were identified prior to 12:00 PM (EDT) on January 26, 2024; per cyber hygiene best practices, caution is advised when clicking on any third-party links.

Read the Brief

View the full report here.

SIM Swapping Used to Breach SEC’s X Account

What happened: The U.S. Securities and Exchange Commission (SEC) has confirmed unauthorized access and activity on its @SECGov X account, revealing that the breach resulted from a SIM swap attack on the associated cell phone number. In this attack, the unauthorized party gained control of the phone number through the telecom carrier, allowing them to receive voice and SMS communications. However, no evidence suggests access to SEC systems, data, devices, or other social media accounts.

Mother of All Breaches Reveals 26 Billion Records

What happened: A massive data leak has been uncovered, containing a staggering 12 terabytes of data from numerous past breaches, totaling 26 billion records. This extensive leak encompasses user data from platforms like LinkedIn, Weibo, Tencent, and others. Reportedly, Tencent’s data amounted to 1.5 billion records leaked, followed by the second largest, Weibo — 504 million records. This breach consolidates records from thousands of meticulously compiled and reindexed leaks and privately traded databases.

Hacktivist Group ‘UserSec' Announces Recruitment for New Defacement Training Team

What happened: On January 25, 2024, threat actor UserSec announced on its Telegram channel that it is recruiting candidates for a new defacement training team with the promise of becoming a permanent member of the defacement team if successful. In addition to reviewing “almost all methods of defacing a website,” UserSec offers to teach users how to obtain administrative panels of websites, search for subdomains, and how to look for XSS and SQL vulnerabilities. UserSec claims to be recruiting three users in total, with an entrance fee of USD 100 each.

Tags: tlp:green