ZeroFox Cyber Intelligence Daily Brief - March 8, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - March 8, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- ZeroFox Intelligence Flash Report - Threat Actors Target Israel over Possible Rafah Incursion
- Chinese National Residing in California Arrested for Theft of Artificial Intelligence-Related Trade Secrets from Google
- Play Ransomware Leaked 65,000 Swiss Government Documents
ZeroFox Intelligence Flash Report - Threat Actors Target Israel over Possible Rafah Incursion
Hacktivist group Handala claimed an attack against Israel’s Iron Dome missile defense system and a radar system tracking Israeli aircraft. The effects of this attack could disrupt Israel’s defense industry and military operations in Gaza if the leaked radar information is disclosed to Israel’s adversaries. The finding indicates that Handala is more incentivized and capable than other threat actors who have emerged since the war began in October. The group seems to be intent on continuing attacks against Israel, as well as increasing the impact of these attacks. Handala warned that its hacks could escalate if Israel moves ahead with its final incursion into Rafah, the last remaining city in Gaza yet to face an offensive. A ceasefire proposal between both sides is proving elusive, and Israel has given the start of Ramadan on March 10 as a key date for beginning the offensive.
Chinese National Residing in California Arrested for Theft of Artificial Intelligence-Related Trade Secrets from Google
An ex-software engineer at Google was indicted by a federal grand jury on four counts of theft of trade secrets related to artificial intelligence (AI) technology from Google. The former Google engineer allegedly stole technology related to Google's advanced supercomputing data centers, which support machine learning workloads for training and hosting large AI models. This technology includes both hardware and software components. The hardware involves advanced computer chips with high processing power necessary for machine learning tasks, while the software includes a sophisticated platform, including the Cluster Management System (CMS), which coordinates tasks within the data centers for efficient execution of machine learning workloads and hosting AI applications.
Play Ransomware Leaked 65,000 Swiss Government Documents
The Swiss government has confirmed that 65,000 government documents were leaked in a breach suffered by Swiss tech company Xplain. The Play ransomware gang breached the company on May 23, 2023, and published stolen data on a darknet portal. The majority of the leaked data impacted the administrative units of the Federal Department of Justice and Police (FDJP), and around 5,000 documents contained sensitive information. An investigation is ongoing, and the results and cybersecurity recommendations will be shared with the Federal Council.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- X (twitter) user Phobos Ransomware:
- Telegram user R00TK1T: Actor Announces Cyber Attack Against Lebanon
VULNERABILITIES
- CVE-2024-0914: A timing side-channel vulnerability has been discovered in the opencryptoki package while processing RSA PKCS#1 v1.5 padded ciphertexts. This flaw could potentially enable unauthorized RSA ciphertext decryption or signing, even without access to the corresponding private key.
- CVE-2023-52161: The Access Point functionality in eapol_auth_key_handle in eapol.c in iNet wireless daemon (IWD) before 2.14 allows attackers to gain unauthorized access to a protected Wi-Fi network. An attacker can complete the EAPOL handshake by skipping Msg2/4 and instead sending Msg4/4 with an all-zero key.
EXPLOITS
- CVE-2021-1499: A vulnerability in the web-based management interface of Cisco HyperFlex HX Data Platform could allow an unauthenticated, remote attacker to upload files to an affected device.
BREACHES
- Combolist: 'Shreder EUW.txt' (850,555 Records): Email Address, Password
- Combolist: 'emailsp%2025.txt' (210,604 Records): Email Address, Password
Tags: DIB, tlp:green