zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - March 15, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - March 15, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • French Government Department Suffers Data Breach Affecting 43 Million Individuals
  • Threat Actor Launches Website Highlighting Vulnerable Government Sites
  • SIM Swappers Hijacking Phone Numbers in eSIM Attacks

French Government Department Suffers Data Breach Affecting 43 Million Individuals

A French government department responsible for registering and assisting unemployed individuals disclosed a huge data breach to the country's data protection watchdog (CNIL), affecting up to 43 million citizens' personal information. While passwords and banking details remain secure, names, dates of birth, social security numbers, France Travail identifiers, email addresses, postal addresses, and phone numbers were reportedly exposed. Citizens have been urged to stay vigilant against phishing attacks and update passwords. On March 12, ZeroFox reported on DDoS attacks targeting several French government services and websites in its Cyber Intelligence Daily Brief and observed pro-Russia threat actor Anonymous Sudan claim responsibility for the attacks.

Threat Actor Launches Website Highlighting Vulnerable Government Sites

ZeroFox has observed threat actor “dawnofdevil” (a well reputed member of underground forum BreachForums) claiming to expose information about vulnerable government sites across 49 countries, including Australia, UAE, Brazil, and India. The threat actor announced that they will expose vulnerabilities and other data on a dark web site called Hell Paradise and has listed 1,000 vulnerabilities “for now,” all of which are critical and high severity vulnerabilities that can lead to remote code execution (RCE), local file inclusion (LFI), SQL injection (SQLi), and more.

SIM Swappers Hijacking Phone Numbers in eSIM Attacks

Attackers are now evolving their SIM swapping techniques to breach mobile accounts by gaining access to stolen, brute-forced, or leaked credentials. They exploit the ability to generate a QR code within the compromised mobile account to activate a new eSIM, allowing them to port the victim's number to another device. This process hijacks the victim's number, enabling attackers to steal access. Embedded Subscriber Identity Modules (eSIMs), which eliminates the need for a physical SIM card slot, is increasingly utilized by smartphone manufacturers and allows attackers to easily transfer the victim's phone number to their own device.

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

VULNERABILITIES

  • CVE-2024-1622: Due to a mistake in error checking, Routinator will terminate when an incoming RTR connection is reset by the peer too quickly after opening.
  • CVE-2024-1915: Incorrect Pointer Scaling vulnerability in Mitsubishi Electric Corporation MELSEC-Q Series and MELSEC-L Series CPU modules allows a remote unauthenticated attacker to execute malicious code on a target product by sending a specially crafted packet.

BREACHES

Tags: DIB, tlp:green