ZeroFox Cyber Intelligence Daily Brief - April 5, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - April 5, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- City of Hope Data Breach Impacts Over 820,000 Patients
- Google Releases Patches for Two Pixel Zero-Day Flaws Exploited by Forensics Firms
- Cyberattack on Japanese Lens Firm Leads to System Disruption; Production Halted
City of Hope Data Breach Impacts Over 820,000 Patients
Cancer treatment and research center City of Hope suffered a data breach last year that exposed the sensitive information of over 820,000 patients. The impacted data varies per individual and includes information such as name, contact information, date of birth, Social Security Number, driver’s license or other government identification, financial details, health insurance information, medical records, and medical history information. The healthcare organization has offered two years of identity monitoring service coverage at no cost to impacted individuals. The impacted individuals are advised to remain vigilant to protect against potential fraud and identity theft by reviewing account statements and monitoring credit reports. An investigation is ongoing to determine the nature and scope of the data breach.
Google Releases Patches for Two Pixel Zero-Day Flaws Exploited by Forensics Firms
Google has fixed two Google Pixel zero-day vulnerabilities that threat actors can leverage to unlock phones without using a PIN and gain access to stored data. CVE-2024-29745 (CVSS score: 7.2/10.0) is an information disclosure flaw in the Pixel's bootloader. The fix involves clearing memory during fast boot mode boot-up and letting USB connectivity activate only after this memory clearing, making potential attacks ineffective. CVE-2024-29748 (5.5/10.0) is an elevation of privilege bug in the Pixel firmware. According to the April 2024 bulletin for Pixel devices, users can deploy these patches by updating their software to the latest version.
Cyberattack on Japanese Lens Firm Leads to System Disruption; Production Halted
Hoya Corp, a major Japanese lens manufacturer, halted production of various products due to a system failure caused by likely unauthorized access to its servers. The company detected the issue in one of its overseas offices and confirmed disruptions despite efforts to contain them. Hoya is investigating potential data breaches and collaborating with authorities to restore operations. Its consumer eyeglass lens unit, Hoya Vision Care Co., apologized for ceasing orders due to the system failure. Details on potential impacts on other products remain undisclosed.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- Telegram user Moroccan Cyber Force: Actor Claims Cyber Attack Against Cargo 380
- Telegram user UserSec: Actor Allegedly Stolen United States Government Data
VULNERABILITIES
- CVE-2023-5973: Brocade Web Interface in Brocade Fabric OS v9.x and before v9.2.0 does not properly represent the portName to the user if the portName contains reserved characters. This could allow an authenticated user to alter the UI of the Brocade Switch and change ports display.
- CVE-2024-3321: A vulnerability classified as problematic has been found in SourceCodester eLearning System 1.0. This affects an unknown part of the component Maintenance Module. The manipulation of the argument Subject Code/Description leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-259389 was assigned to this vulnerability.
BREACHES
- Combolist: 'blutv.com.txt' (13,980 Records): Email Address, Password
- Combolist: 'emailsp.txt' (139,309 Records): Email Address, Password
Tags: DIB, tlp:green