zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - April 8, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - April 8, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Social Engineering Attacks Targeting IT Help Desks in the Health Sector
  • Home Depot Confirms Third-Party Data Breach Exposed Employee Info
  • Israel's Justice Ministry Reviewing 'Cyber Incident' After Hacktivists' Claim Breach

Social Engineering Attacks Targeting IT Help Desks in the Health Sector

Reports confirm that IT help desks in the health sector are the recent target of threat actors who seek to gain unauthorized access to organizations through advanced social engineering tactics. Threat actors reportedly first approach IT help desks with phone calls from the target organization’s local area codes, posing as employees in financial roles such as revenue cycle or administrator positions. Claiming their phone is broken and unable to receive MFA tokens, they convince the help desk to enroll a new device in multi-factor authentication, thus gaining access to corporate resources. One of the mitigations involve healthcare organizations to conduct more thorough verification into callers when registering a new device and password resets.

Home Depot Confirms Third-Party Data Breach Exposed Employee Info

Home Depot has confirmed a data breach after one of its SaaS vendors mistakenly exposed a small sample of limited employee data. Approximately 10,000 employees' information such as corporate IDs, names, and email addresses, was leaked by IntelBroker on a dark web forum. Although the leaked data isn’t highly sensitive, it poses a risk for targeted phishing attacks against Home Depot employees. Home Depot has advised its employees to be cautious of emails requesting corporate credentials or other information and has urged them to report any suspicious emails to the company's IT department for verification. ZeroFox has also observed threat actor IntelBroker claiming to have leaked a database associated with Home Depot.

Israel's Justice Ministry Reviewing 'Cyber Incident' After Hacktivists' Claim Breach

A hacktivist against Israel’s war on Gaza has claimed responsibility for allegedly hacking its Justice Ministry’s servers and exfiltrating 300 GB of data. ZeroFox has observed that the stolen data involves personally identifiable information (PII) including official letters and documents, addresses, phone numbers, and emails. Authorities are still in the process of verifying the authenticity of the published data.

VULNERABILITIES

  • CVE-2024-23658: In camera driver, there is a possible use after free due to a logic error. This could lead to local denial of service with System execution privileges needed
  • CVE-2023-52342: In modem-ps-nas-ngmm, there is a possible undefined behavior due to incorrect error handling. This could lead to remote information disclosure no additional execution privileges needed

BREACHES

Tags: DIB, tlp:green