ZeroFox Cyber Intelligence Daily Brief - April 12, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - April 12, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Apple Alerts Users in 92 Nations to Mercenary Spyware Attacks
- CISA Issues Advisory to Mitigate Significant Risk from Nation-State Compromise of Microsoft Corporate Email System
- CISA Says Sisense Hack Impacts Critical Infrastructure Organizations
Apple Alerts Users in 92 Nations to Mercenary Spyware Attacks
Apple has sent notifications to iPhone users in 92 countries (including several that are currently preparing for elections), warning them against potential mercenary spyware attacks. The alerts did not disclose the remote attackers' identities or specific countries affected. Apple has stated that users were likely targeted based on their identity or activities. Notably, Apple had sent similar warnings to several journalists and politicians in India last year. The company previously identified the attackers as "state-sponsored" but now refers to them as "mercenary spyware attacks."
CISA Issues Advisory to Mitigate Significant Risk from Nation-State Compromise of Microsoft Corporate Email System
CISA has publicly issued Emergency Directive (ED) 24-02 to address the recent campaign by Russian state-sponsored cyber actor Midnight Blizzard to exfiltrate email correspondence of Federal Civilian Executive Branch (FCEB) agencies through a successful compromise of Microsoft corporate email accounts. It requires agencies to analyze the content of exfiltrated emails, reset compromised credentials, and take additional steps to secure privileged Microsoft Azure accounts. While ED 24-02 requirements only apply to FCEB agencies, other organizations may also have been impacted by the exfiltration of Microsoft corporate email and are encouraged to contact their respective Microsoft account team for any additional questions or follow-up.
CISA Says Sisense Hack Impacts Critical Infrastructure Organizations
The Cybersecurity and Infrastructure Security Agency (CISA) announced that Sisense, a data analytics company, has recently experienced a data breach. The agency is currently investigating this cyber incident and claims that it can affect critical infrastructure organizations. As a mitigation measure, customers are urged to reset any credentials connected with the company’s platform and services. At the time of writing, investigations have yet to reveal conclusive details of this breach.
Tags: DIB, tlp:green