ZeroFox Cyber Intelligence Daily Brief - February 28, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - February 28, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- CISA, FBI, and HHS Release an Update to #StopRansomware Advisory on ALPHV Blackcat
- Pharmaceutical Giant Cencora Says Data was Stolen in a Cyberattack
- European Discount Retailer Loses USD 16.3 Million in Phishing Attack
CISA, FBI, and HHS Release an Update to #StopRansomware Advisory on ALPHV Blackcat
CISA, FBI, and the Department of Health and Human Services (HHS) have released an update to the joint advisory that provides new indicators of compromise (IOCs) and TTP associated with ALPHV Blackcat ransomware as a service (RaaS). The healthcare sector has been observed to be primarily targeted by ALPHV Blackcat affiliates. The agencies urged the network defenders to review the updated advisory to detect and protect malicious activity.
Pharmaceutical Giant Cencora Says Data was Stolen in a Cyberattack
Cencora disclosed a cyberattack where data was stolen from its corporate IT systems. The breach, when discovered, prompted immediate containment measures and collaboration with law enforcement, cybersecurity experts, and legal advisors for investigation. Cencora has reportedly not yet determined the potential impact on its finances or operations.
European Discount Retailer Loses USD 16.3 Million in Phishing Attack
European value retailer Pepco has suffered losses amounting to USD 16.3 million in cash after a sophisticated fraudulent phishing attack targeted its Hungarian business. The company has released an official statement acknowledging the attack, saying it is taking necessary immediate steps to investigate the situation. Pepco has also stated that the attack does not seem to have impacted any customer, supplier, or employee information and data. However, it is unsure if it can recover the lost funds.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- RansomHouse user RansomHouse: GCA Nederlan
- RansomHouse user RansomHouse: Webber International Universit
VULNERABILITIES
- CVE-2024-23850: In btrfs_get_root_ref in fs/btrfs/disk-io.c in the Linux kernel through 6.7.1, there can be an assertion failure and crash because a subvolume can be read out too soon after its root item is inserted upon subvolume creation.
- CVE-2024-23851: copy_params in drivers/md/dm-ioctl.c in the Linux kernel through 6.7.1 can attempt to allocate more than INT_MAX bytes, and crash, because of a missing param_kernel->data_size check. This is related to ctl_ioctl.
EXPLOITS
- CVE-2021-3145: In Ionic Identity Vault before 5, a local root attacker on an Android device can bypass biometric authentication.
- CVE-2021-40540: ulfius_uri_logger in Ulfius HTTP Framework before 2.7.4 omits con_info initialization and a con_info->request NULL check for certain malformed HTTP requests.
BREACHES
- Combolist: 'private_zabugor_0.txt' (14,998 Records): Email Address, Password
- Combolist: 'Gmail.txt' (124,878 Records): Email Address, Password
Tags: DIB, tlp:green