ZeroFox Cyber Intelligence Daily Brief - May 1, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - May 1, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- UK Passes New Law to Secure Smart Devices By Disabling Default Passwords
- New Ransomware Group Apos Emerges on the Dark Web
- New Latrodectus Malware Attacks Use Microsoft and Cloudflare Themes
UK Passes New Law to Secure Smart Devices By Disabling Default Passwords
What happened: A new UK law, the Product Security and Telecommunications Infrastructure Act, requires manufacturers of smart devices to stop supplying devices that use default passwords and provide a minimum length of time for important security updates.
Why it matters: Default passwords subject devices to easy discovery on the internet, where these passwords are likely to be shared, leaving the devices vulnerable to cyberattacks. Such compromised devices can also be included in a botnet for further sophisticated takeovers and attacks.
New Ransomware Group Apos Emerges on the Dark Web
What happened: On April 30, ZeroFox analysts observed underground chatter about a new leak site operated by ransomware group Apos. The leak site allegedly lists four victims from France, Brazil, and India.
Why it matters: As previously discussed in ZeroFox advisories, bigger and known ransomware groups have decreased their attack tempo since law enforcement operations took down several major ransomware operations. Meanwhile, smaller groups, with members likely joining from the bigger ransomware groups, are becoming more active and prolific, prompting cybersecurity agencies to keep a closer eye on them.
New Latrodectus Malware Attacks Use Microsoft and Cloudflare Themes
What happened: Threat actors are increasingly deploying Latrodectus malware in phishing campaigns and to gain initial access to networks, by using Microsoft Azure and Cloudflare lures.
What this means: The malware reportedly makes it difficult for email security platforms to detect malicious emails. This malware strain is used as reply-chain phishing emails where they hijack legitimate email exchanges to reply with links to malicious attachments.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- XSS user XSS: Actor Announces Rutger Stealer
- Telegram user Cyber Partisans: Actor Claims to Have Leaked Data Associated with KGB Informants
VULNERABILITIES
- CVE-2024-33763: lunasvg v2.3.9 was discovered to contain a stack-buffer-underflow at lunasvg/source/layoutcontext.cpp.
- CVE-2024-33764: lunasvg v2.3.9 was discovered to contain a stack-overflow at lunasvg/source/element.h.
BREACHES
- Combolist: '1268X TUNNELBEAR VPN ACCOUNTS PREMIUM.txt' (750 Records): Email Address, Password
- Combolist: 'ipvanish.kiko.txt' (1,570 Records): Email Address, Password
Tags: DIB, tlp:green