ZeroFox Cyber Intelligence Daily Brief - May 9, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - May 9, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Massive Webshop Fraud Ring Steals Credit Cards From 850,000 People
- Ascension Confirms Cyberattack
- Zscaler Takes Test Environment Offline While Investigating Claims of Cyberattack
Massive Webshop Fraud Ring Steals Credit Cards From 850,000 People
What happened: A sophisticated cybercrime operation known as BogusBazaar orchestrated a massive network of 75,000 fake online shops, targeting over 850,000 individuals in the U.S. and Europe. These fake shops tricked victims into making purchases, leading to the theft of credit card information and attempted fraudulent transactions of an estimated USD 50 million.
Why it matters: BogusBazaar's elaborate scheme exposes the evolving tactics of cybercriminals, showcasing their ability to manipulate online platforms and payment systems to steal sensitive information and defraud consumers on a massive scale. The reselling of stolen credit card details on the dark web amplifies the potential for further financial harm and identity theft for victims beyond the initial fraudulent transactions.
Ascension Confirms Cyberattack
Source: https://about.ascension.org/news/2024/05/network-interruption-update
What happened: Ascension, a private healthcare system, is investigating the scope of a cyberattack that has affected its clinical operations. The healthcare company recommends that its business partners suspend its connection to the Ascension environment till the issue is resolved.
Why it matters: Healthcare organizations are repeatedly targeted in ransomware attacks as threat actors are aware that hospitals store large amounts of sensitive and valuable patient data. Healthcare organizations are also known to give in more to ransomware demands to protect its patients and restore services immediately.
Zscaler Takes Test Environment Offline While Investigating Claims of Cyberattack
Source: https://trust.zscaler.com/zscaler.net/posts/18686
What happened: Zscaler has discovered an exposed isolated test environment on a test server that it took offline after rumors of a threat actor selling access to Zscaler systems spread online. The company has confirmed it found no evidence of incident or compromise to customer and production environments.
Why it matters: Through a dark web forum post, notorious threat actor IntelBroker claimed to be selling access to some systems of “one of the largest cybersecurity companies,” speculated to be Zscaler. IntelBroker has previously been linked to another breach of a test environment belonging to one of the biggest tech companies and a data breach that exposed some personal data of the U.S. House of Representatives members and staff.
DEEP AND DARK WEB INTELLIGENCE
Syndicat Group and Co | On May 8, 2024, pro-Palestine threat actor Syndicat Group has announced its collaboration with Marocain Cyber Forces, Pro-Palestine Hackers Movement (PPHM), Marocain1 black CyberArmy, and Hunt3rkill3rs1 hacktivist groups. The actors claim to work together against Israel.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2024-26026: F5 has addressed and released patches for a high-severity vulnerability in its BIG-IP Next Central Manager API. CVE-2024-26026 is an SQL injection vulnerability. A threat actor can exploit this to execute malicious SQL statements through the BIG-IP Next Central Manager API.
Affected products: BIG-IP Next Central Manager versions 20.0.1 - 20.1.0.
CVE-2024-21793: F5 has addressed and released patches for another high-severity vulnerability in its BIG-IP Next Central Manager API. CVE-2024-21793 is an OData injection vulnerability. A threat actor can exploit this to execute malicious SQL statements through the BIG-IP Next Central Manager API.
Affected products: BIG-IP Next Central Manager versions 20.0.1 - 20.1.0.
Tags: DIB, tlp:green