zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - March 18, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - March 18, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • AT&T Says Leaked Data of 70 Million People Not From Its Systems
  • Lazarus APT Group Returned to Tornado Cash to Launder Stolen Funds
  • NHS Breach, HSE Bug Expose Healthcare Data in the British Isles

AT&T Says Leaked Data of 70 Million People Not From Its Systems

AT&T has denied claims that data on over 71 million people linked to AT&T circulating on dark web forums originated from its systems. The exposed data involves personally identifiable information like names, addresses, and encrypted Social Security numbers; however, AT&T denies any breach and says that the data does not originate from its systems. A news source speculates that this information could have been breached from a third-party service provider.

Lazarus APT Group Returned to Tornado Cash to Launder Stolen Funds

The North Korea-linked Lazarus APT group has reportedly resumed using the Tornado Cash platform to launder USD 23 million. Cybersecurity researchers have linked this to a USD 112.5 million theft from exchange HTX in November 2023. Tornado Cash was previously sanctioned by the US Treasury Department’s Office of Foreign Assets Control (OFAC) in August 2022. Despite the sanction, the group continued to use Tornado Cash and turned to Sinbad.io before it was seized by U.S. authorities. The researchers noted that the service operates through smart contracts on decentralized blockchains, making it immune to seizure and shutdown. Cryptocurrency exchanges and financial institutions are recommended to use wallet screening solutions to prevent transactions with sanctioned entities like Tornado Cash and the Lazarus Group.

NHS Breach, HSE Bug Expose Healthcare Data in the British Isles

A division of the National Health Service (NHS) Scotland experienced a cyberattack that may have exposed patient and employee data, while a researcher has disclosed a Salesforce configuration error that exposed the COVID vaccination data of millions of Irish citizens. The misconfiguration in Ireland's Health Service Executive (HSE) vaccination portal allowed regular patient accounts to access the system responsible for storing information about vaccine administration, including vaccination details and personal information about patients. The incident has prompted Salesforce to implement a built-in health scanner and more robust logging to detect vulnerabilities and prevent such errors in the future.

VULNERABILITIES

  • CVE-2022-47037: Siklu TG Terragraph devices before 2.1.1 allow attackers to discover valid, randomly generated credentials via GetCredentials.
  • CVE-2024-24539: FusionPBX before 5.2.0 does not validate a session.

BREACHES

Tags: DIB, tlp:green