zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - May 7, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - May 7, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • LockBit Seized Site Resurrected by Law Enforcement
  • City of Wichita Shuts Down Networks Following Weekend Ransomware Attack
  • Critical Tinyproxy Flaw Opens Over 50,000 Hosts to Remote Code Execution

LockBit Seized Site Resurrected by Law Enforcement

Source: https://cloud.zerofox.com/intelligence/advanced_dark_web/63678

What happened: Law enforcement has revived the LockBit leak site that it had seized with notifications hinting towards new information about the group, including the identity of the person running the ransomware operation.

Why it matters: The LockBit takedown operation was a significant blow to the group responsible for approximately 30% of all ransomware activities in 2023. Since then, the group has been struggling to regain its foothold in the cybercrime arena. Law enforcement revealing crucial information about the group is likely to curb further disruptive activities.

City of Wichita Shuts Down Networks Following Weekend Ransomware Attack

Source: https://www.bleepingcomputer.com/news/security/city-of-wichita-shuts-down-it-network-after-ransomware-attack/

What happened: Following a ransomware attack, the City of Wichita, Kansas, was forced to shut down parts of its networks to prevent the ransomware from spreading to other devices. At the time of reporting, it is unknown whether any data has been exfiltrated.

Why it matters: Ransomware attacks can have tangible effects on a city’s critical infrastructure and such attacks can expose crucial information on the dark web, accessible to threat actors and even state-sponsored actors. After the cyberattack on Wichita, payment systems for the City, including those for paying the water bill and court citations and tickets, are reportedly down.

Critical Tinyproxy Flaw Opens Over 50,000 Hosts to Remote Code Execution

Source: https://thehackernews.com/2024/05/critical-tinyproxy-flaw-opens-over.html

What happened: A critical vulnerability (CVE-2023-49606) has been discovered in the tinyproxy software. More than half of the 90,310 hosts with a Tinyproxy service exposed to the internet are reportedly vulnerable to this flaw in the HTTP/HTTPS proxy tool.

What it means: This vulnerability can be triggered by an unauthenticated HTTP request, allowing an attacker to exploit it without authentication. By sending a carefully crafted HTTP Connection header, an unauthenticated threat actor can induce memory corruption, which in turn may enable remote code execution. The majority of publicly-accessible hosts susceptible to this vulnerability are located in the United States (32,846), South Korea (18,358), China (7,808), France (5,208), and Germany (3,680).

DEEP AND DARK WEB INTELLIGENCE

High Society and Cyber Army Russia Reborn | On May 5, 2024, a newly formed pro-Russia group High Society hacktivist collective and Cyber Army Russia Reborn claimed to have launched a cyber attack against the United States electrical and nuclear industries.

Tags: DIB, tlp:green