ZeroFox Cyber Intelligence Daily Brief - April 10, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - April 10, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Microsoft April 2024 Patch Tuesday Fixes 150 Security Flaws, 67 RCEs
- GHC-SCW Ransomware Attack Affects 533,000 People
- U.S. Government Consulting Firm Discloses Data Breach Exposing 340,000 Social Security Numbers
Microsoft April 2024 Patch Tuesday Fixes 150 Security Flaws, 67 RCEs
In April’s edition of Patch Tuesday, Microsoft has released updates on 150 flaws which includes 67 remote code execution bugs of which three (CVE-2024-29053, CVE-2024-21323, and CVE-2024-21322) are critical. Microsoft also fixed two zero-day vulnerabilities CVE-2024-26234 and CVE-2024-29988 reported to be exploited in the wild. Cybersecurity researchers observed that CVE-2024-26234 was a proxy driver spoofing vulnerability that was used by threat actors to install a backdoor and CVE-2024-29988 was a SmartScreen prompt security feature bypass vulnerability that was used by Water Hydra to target financial entities.
GHC-SCW Ransomware Attack Affects 533,000 People
Group Health Cooperative of South Central Wisconsin (GHC-SCW) has disclosed that a ransomware gang breached its network access and stole data that included protected health information (PHI) of over 500,000 individuals. The attacker attempted to encrypt GHC-SCW’s system but the organization’s IT department successfully secured the network. An investigation discovered that the attacker had copied some of GHC-SCW’s data, which included PHI such as name, address, telephone number, e-mail address, date of birth and/or death, Social Security Number, member number, and Medicare and/or Medicaid number. GHC-SCW has been working with the FBI and CISA to mitigate the risks associated with the breach and has implemented enhanced security measures. The Impacted individuals are advised to monitor all communications from healthcare providers.
U.S. Government Consulting Firm Discloses Data Breach Exposing 340,000 Social Security Numbers
Greylock McKinnon Associates (GMA), a consulting firm known for assisting businesses and government agencies such as the U.S. Department of Justice (DOJ) in litigation support, has disclosed a data breach exposing 341,650 Social Security numbers. GMA stated it suffered a cyberattack in May 2023, promptly initiating mitigation measures. It has also notified law enforcement and the DOJ. In its notification email to the victims, GMA mentioned that the breach does not affect their current Medicare benefits or coverage and that the victims are not “the subject of this investigation or the associated litigation matters.”
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- BreachForums user CiberInteligenciaSV: Actor Claims to Leak a Vulnerability For Stealing Volaris INVEX Cards
- BreachForums user Sanggiero: Actor Claims to Leak Data From SUGARGOO
VULNERABILITIES
CVE-2024-3119: A buffer overflow vulnerability exists in all versions of sngrep since v0.4.2, due to improper handling of 'Call-ID' and 'X-Call-ID' SIP headers. The functions sip_get_callid and sip_get_xcallid in sip.c use the strncpy function to copy header contents into fixed-size buffers without checking the data length. This flaw allows remote attackers to execute arbitrary code or cause a denial of service (DoS) through specially crafted SIP messages.
CVE-2024-3120: A stack-buffer overflow vulnerability exists in all versions of sngrep since v1.4.1. The flaw is due to inadequate bounds checking when copying 'Content-Length' and 'Warning' headers into fixed-size buffers in the sip_validate_packet and sip_parse_extra_headers functions within src/sip.c. This vulnerability allows remote attackers to execute arbitrary code or cause a denial of service (DoS) via crafted SIP messages.
BREACHES
- Combolist: 'www.calligaris.es.txt' (189,585 Records): Email Address, Password
- Combolist: 'star%20plus%202024.04.08%2023.14.00.txt' (103 Records): Email Address, Password
Tags: DIB, tlp:green