zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - May 2, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - May 2, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • CISA and Partners Release Fact Sheet to Defend OT Operations
  • Hôpital de Cannes - Simone Veil in France Refuses to Pay Ransom to LockBit
  • Dropbox Discloses Threat Actor Stole Customer Data from Digital Signature Product

CISA and Partners Release Fact Sheet to Defend OT Operations

What happened: Cybersecurity Infrastructure and Security Agency (CISA), in collaboration with other partners, published a joint fact sheet to address cyber operations conducted by pro-Russia hacktivists who aim to compromise industrial control systems (ICS) and small-scale operational technology (OT) systems in North American and European critical infrastructure sectors, including water and wastewater systems, dams, energy, and food and agriculture sectors.

What this means: The pro-Russia hacktivist activity appears mostly limited to unsophisticated techniques that manipulate ICS equipment to create nuisance effects. However, investigations have identified that these actors are capable of techniques that pose physical threats against insecure and misconfigured OT environments. CISA and partners encourage OT operators in critical infrastructure sectors to apply the recommendations listed in the fact sheet to defend against this activity.

Hôpital de Cannes - Simone Veil in France Refuses to Pay Ransom to LockBit

What happened: The French hospital Hôpital de Cannes - Simone Veil (CHC-SV) has refused to pay the ransom that the LockBit 3.0 ransomware gang demanded. ZeroFox intelligence has observed an update on LockBit 3.0’s leak site targeting CHC-SV.

Why it matters: Ransomware groups have been increasingly targeting the healthcare industry, with a recent major one being the attack on Change Healthcare, where the two groups demanded ransoms from the victim company. The consequences of CHC-SV refusing to pay LockBit 3.0’s ransom demands remain unclear. After LockBit’s takedown in February, the group has been unable to conduct any majorly significant attacks.

Dropbox Discloses Threat Actor Stole Customer Data from Digital Signature Product

What Happened: Dropbox has disclosed that unauthorized access was detected in the Dropbox Sign (formerly HelloSign) production environment. The threat actor has accessed Dropbox Sign customer information. An investigation is ongoing to mitigate risks associated with the attack.

Why it matters: The unauthorized access compromised sensitive customer data, including personally identifiable information (PII) such as emails, usernames, phone numbers, hashed passwords, authentication credentials, and more. This raises concerns about the potential misuse of this information by malicious actors, such as identity theft or phishing attacks targeting affected users.

DEEP AND DARK WEB INTELLIGENCE

moma: On April 29, threat actor moma announced the sale of the zero-day exploit for a Zyxel VPN device on the predominantly Russian-language dark web forum xss.

RANSOMWARE INTELLIGENCE

In the past 24 hours, ZeroFox has detected 17 ransomware attacks mostly on the manufacturing industry, primarily orchestrated by LockBit, of which over 75% of the victims were from the U.S./Canada region.

BOTNET INTELLIGENCE

ZeroFox observed that around 32.62% of the detected infections belonged to the RedLine family.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2023-7028: A critical severity flaw has been discovered in GitLab CE/EE in which user account password reset emails could be delivered to an unverified email address.

Affected products: All versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 prior to 16.3.7, 16.4 prior to 16.4.5, 16.5 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2

CVE-2024-1753: A flaw was found in Buildah (and subsequently Podman Build) which allows containers to mount arbitrary locations on the host filesystem into build containers. A malicious Containerfile can use a dummy image with a symbolic link to the root filesystem as a mount source and cause the mount operation to mount the host root filesystem inside the RUN step. The commands inside the RUN step will then have read-write access to the host filesystem, allowing for full container escape at build time.

Affected products: Podman v4.0->v4.9.3, and v5.0

Tags: DIB, tlp:green