ZeroFox Cyber Intelligence Daily Brief - May 13, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - May 13, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- ZeroFox Intelligence Flash Report - Malicious AI-Enhanced Bot Announced for Sale
- CISA and Partners Release Advisory on Black Basta Ransomware
- Europol Confirms Data Breach Affecting Europol Platform for Experts
ZeroFox Intelligence Flash Report - Malicious AI-Enhanced Bot Announced for Sale
Source: https://www.zerofox.com/advisories/23517/
What happened: On May 6, 2024, untested threat actor “Average” started a thread in the Russian-speaking deep and dark web (DDW) community Exploit, advertising the development of a new artificial intelligence (AI)-powered one-time password (OTP) bot that can be leveraged in two-factor authentication (2FA) bypass attacks, as well as other social engineering activity.
Why it matters: The advertisement of this bot is almost certainly indicative of a growing interest in unrestricted AI tools within both DDW communities and open web communities. Throughout 2024, threat actors of varied motives and capabilities are very likely to increasingly seek tools able to enhance their ability to conduct malicious cyber activity.
CISA and Partners Release Advisory on Black Basta Ransomware
Source: https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-131a
What happened: A joint cybersecurity advisory on BlackBasta provides organizations tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) used by known Black Basta ransomware affiliates and identified through FBI investigations and third-party reporting.
Why it matters: Black Basta ransomware variant actors have encrypted and stolen data from at least 12 out of 16 critical infrastructure sectors, including the Healthcare and Public Health (HPH) Sector. Black Basta affiliates have impacted a wide range of businesses and critical infrastructure in North America, Europe, and Australia. As of May 2024, Black Basta affiliates have impacted over 500 organizations globally.
Europol Confirms Data Breach Affecting Europol Platform for Experts
What happened: Europol is investigating a data breach impacting its Europol Platform for Experts where a threat actor exfiltrated For Official Use Only (FOUO) documents containing classified data. At the time of reporting, the website is offline, displaying a message that the service is “not available at the moment due to maintenance activities.” IntelBroker has claimed responsibility for the breach.
Why it matters: As the European Union’s law enforcement agency, Europol data exposed to threat actors could pose serious risks to the upcoming European Parliament elections. Adversaries might use the exposed data for spear phishing attacks targeting political entities and even in misinformation or disinformation campaigns.
DEEP AND DARK WEB INTELLIGENCE
Dark Strom | On May 10, 2024, a threat actor group Dark Strom Team claimed to have carried out a cyber attack against Flickr, a U.S.-based photo-sharing platform.
VULNERABILITY AND EXPLOIT INTELLIGENCE
[CVE-2024-27793]: CVE-2024-27793 is a security vulnerability in the iTunes application for Windows 10 and Windows 11 users can allow malicious attackers to remotely execute arbitrary code on a vulnerable system. At the time of reporting the vulnerability has not been assigned a CVSS score. This issue is fixed in iTunes 12.13.2 for Windows.
Affected products: iTunes Windows versions prior to 12.13.2.
Tags: DIB, tlp:green