ZeroFox Cyber Intelligence Daily Brief - May 8, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - May 8, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- UK Ministry of Defence Breach Exposes Armed Forces' Data
- U.S. Releases International Cyberspace Strategy
- China-Linked Hackers Suspected in ArcaneDoor Cyberattacks Targeting Network Devices
UK Ministry of Defence Breach Exposes Armed Forces' Data
What happened: A recent breach in the UK's Ministry of Defence (MoD) compromised part of the Armed Forces payment network, exposing personal data of active, reserve, and retired personnel. The attack targeted an external system managed by a contractor, separate from the MoD's core network.
Why it matters: Even though the Ministry has clarified that salary payments and pensions for veterans were not affected by the attack, it has also said, “indications that this was the suspected work of a malign actor and we cannot rule out state involvement.” With 270,000 records exposed and possibilities of state involvement, the exposed information is likely to be used in future spearphishing or other cyberattacks.
U.S. Releases International Cyberspace Strategy
Source: https://www.securityweek.com/us-releases-international-cyberspace-strategy/
What happened: The new International Cyberspace and Digital Policy Strategy outlines guidelines for international engagement in technology diplomacy, emphasizing the need for detailed security and cybersecurity objectives and partnerships to achieve common cybersecurity goals.
Why it matters: The strategy emphasizes the need to combat cyber threats, malicious actors, and nation state threats while aligning data governance approaches with international partners, promoting responsible behavior in cyberspace, and enhancing the digital and cyber capacities.
China-Linked Hackers Suspected in ArcaneDoor Cyberattacks Targeting Network Devices
Source: https://thehackernews.com/2024/05/china-linked-hackers-suspected-in.html
What happened: China-linked threat actor tracked as UAT4356 (aka Storm-1849) is potentially linked to the recent cyber espionage campaign dubbed ArcaneDoor, which targeted perimeter network devices from various vendors, (including market leaders in the networking industry)—using custom malware Line Runner and Line Dancer.
Why it matters: The campaign underscores the increasing cybersecurity threat posed by state-sponsored actors, potentially those linked to China, targeting critical network infrastructure worldwide. This emphasizes the urgent need for organizations to patch vulnerabilities and implement robust intrusion detection systems, to mitigate the risk of future attacks.
DEEP AND DARK WEB INTELLIGENCE
Hacker Group Anonymous Arabia: On May 7, 2024, a pro-Palestine hacker group Anonymous Arabia claimed to have conducted a cyber attack against Saudi Electricity Company. The alleged reason for the attack is that Saudi Arabia has reportedly launched a crackdown on citizens who post anti-Israel content on social media. The original post can be found on the group's official Telegram channel: "hXXps://t[.]me/Anonymous_v7X."
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2024-4393: The Social Connect plugin for WordPress is vulnerable to authentication bypass. This is due to insufficient verification on the OpenID server being supplied during the social login through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the email.
Affected products: Versions up to, and including, 1.2.
Tags: DIB, tlp:green