zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - April 14, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - April 14, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Home Depot Confirms Third-Party Data Breach Exposed Employee Info
  • Microsoft April 2024 Patch Tuesday Fixes 150 Security Flaws, 67 RCEs
  • Cyberespionage Malware Campaign Targets Android Users in South Asia

Home Depot Confirms Third-Party Data Breach Exposed Employee Info

Home Depot has confirmed a data breach after one of its SaaS vendors mistakenly exposed a small sample of limited employee data. Approximately 10,000 employees' information such as corporate IDs, names, and email addresses, was leaked by IntelBroker on a dark web forum. Although the leaked data isn’t highly sensitive, it poses a risk for targeted phishing attacks against Home Depot employees. Home Depot has advised its employees to be cautious of emails requesting corporate credentials or other information and has urged them to report any suspicious emails to the company's IT department for verification. ZeroFox has also observed threat actor IntelBroker claiming to have leaked a database associated with Home Depot.

Microsoft April 2024 Patch Tuesday Fixes 150 Security Flaws, 67 RCEs

Microsoft has released updates for 150 security flaws, which include 67 remote code execution bugs—of which three are critical. Microsoft also fixed two zero-day vulnerabilities (CVE-2024-26234 and CVE-2024-29988) reported to be exploited in the wild. CVE-2024-26234 is a proxy driver spoofing vulnerability that was used by threat actors to install a backdoor, and CVE-2024-29988 is a SmartScreen prompt security feature bypass vulnerability that was used by Water Hydra to target financial entities.

Cyber Espionage Malware Campaign Targets Android Users in South Asia

Cybersecurity researchers have discovered an active cyber espionage malware campaign targeting Android users in South Asia, specifically India and Pakistan. The campaign involves the distribution of malware via dedicated websites and apps on Google Play Store. The fake apps, which are functional, are disguised as messaging services, food ordering applications, and even a legitimate Indian hospital called Specialist Hospital. The malware strain deployed via these apps can take pictures, enumerate files in several directories, and gather sensitive data, including messages and GPS locations.

Tags: DIB, tlp:green