ZeroFox Cyber Intelligence Daily Brief - April 9, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - April 9, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- RansomHub Threatens to Leak 4 TB of Stolen Change Healthcare Data
- Targus Experiences Temporary Operational Disruption After Cyberattack
- 92,000 D-Link Network Attached Storage (NAS) Devices Under Attack
RansomHub Threatens to Leak 4 TB of Stolen Change Healthcare Data
Threat actor RansomHub has demanded a ransom from Change Healthcare and United Healthcare, in exchange for a database that ALPHV had previously claimed to have stolen. In its leak site update, the threat actor says that ALPHV, which has already taken the ransom from Change Healthcare and UnitedHealthcare, is not the owner of the stolen database. The database allegedly contains 4TB of data belonging to Change Healthcare clients, including Medicare, Tricare, CVS-CareMark, Loomis, Davis Vision, Health Net, MetLife, Teachers Health Trust, and tens of insurance companies details. The stolen data supposedly also includes millions of records of active US military/navy personnel PII, medical and dental records, payment information, claims information, insurance records, and many more.
Targus Experiences Temporary Operational Disruption After Cyberattack
Targus, a prominent mobile gadget and bag manufacturer, has been facing operational disruption after a cyberattack, according to its parent company B. Riley Financial. The attack, detected Friday, prompted a network shutdown to contain unauthorized access to Targus' file systems. While recovery efforts are underway, the company has not provided a timeline for restoration of the affected systems. Targus has pledged to cooperate with law enforcement but is yet to confirm if any data was stolen.
92,000 D-Link Network Attached Storage (NAS) Devices Under Attack
Over 92,000 outdated D-Link Network Attached Storage (NAS) devices are under attack due to an unpatched critical vulnerability (CVE-2024-3273). Cybercriminals are now exploiting this flaw with another vulnerability to deploy Mirai malware variants, like skid.x86, used to create botnets deployed in large-scale DDoS attacks. Security researchers identified the vulnerability two weeks ago, but D-Link has reportedly confirmed that end-of-life devices won't receive patches. According to sources, D-Link has urged users to replace affected devices, as the company provides no support or updates for these devices.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- RansomHub : Actor Claims to Possess Data From Change Healthcare and UnitedHealthcare Breach Previously Claimed by ALPH
- BreachForums user USDoD: Actor Claims to Leak Data From United States Environmental Protection Agency
VULNERABILITIES
- CVE-2024-30676: A Denial-of-Service (DoS) vulnerability exists in ROS2 Iron Irwini versions where ROS_VERSION is 2 and ROS_PYTHON_VERSION is 3.
- CVE-2024-30678: An issue has been discovered in ROS2 Iron Irwini ROS_VERSION 2 and ROS_PYTHON_VERSION 3, where the system transmits messages in plaintext.
EXPLOITS
- CVE-2020-8493: A stored XSS vulnerability in Kronos Web Time and Attendance (webTA) affects 3.8.x and later 3.x versions before 4.0 via multiple input fields (Login Message, Banner Message, and Password Instructions) of the com.threeis.webta.H261configMenu servlet via an authenticated administrator.
- CVE-2020-8495: In Kronos Web Time and Attendance (webTA) 3.8.x and later 3.x versions before 4.0, the com.threeis.webta.
BREACHES
- Combolist: '85K VPN EMAILPASS @HEROINWATER322.txt' (80,686 Records): Email Address, Password
- Combolist: 'join2.txt' (624 Records): Email Address, Password
Tags: DIB, tlp:green