zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - May 15, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - May 15, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Hack of France Sports Minister’s X Account Highlights Olympics Cyberthreats
  • Santander Reports Customer, Employee Data Breach in Spain, Chile, Uruguay
  • Singing River Health System Updates on August 2023 Data Breach; 895,000 Affected

Hack of France Sports Minister’s X Account Highlights Olympics Cyberthreats

Source: https://www.washingtonpost.com/sports/olympics/2024/05/13/paris-olympics-cyberattacks-x-account-hacked/

What happened: The X (former Twitter) account of French Sports Minister Amélie Oudéa-Castéra was hacked, with her profile photo changed and bizarre messages sent out, prompting concerns and intervention from both X and France's cybersecurity agency ANSSI as Paris prepares to host the 2024 Olympics.

Why it matters: The hack of the French Sports Minister's X account amid Olympic preparations sheds light on the potential vulnerabilities that major events like the Olympics face in the digital age. To leave a mark on the global stage, hacktivists and threat actors across the world view these events as prime targets to disrupt proceedings, aiming to steal sensitive data, conduct DDoS or ransomware attacks paralyzing key systems, carry out phishing schemes targeting officials and participants, or make political statements.

Santander Reports Customer, Employee Data Breach in Spain, Chile, Uruguay

Source: https://www.reuters.com/technology/cybersecurity/santander-reports-customer-employee-data-breach-spain-chile-uruguay-2024-05-14/

What happened: Threat actors have breached one of Santander’s databases containing data of some Spain, Chile and Uruguay customers and former employees. The bank confirms that operations are not affected, and that customers can carry out transactions as they would since credentials were not stored in the impacted database.

Why it matters: Santander is one the largest banking institutions in the Euro zone making it a key target for threat actors to exfiltrate data in order to make ransom demands. Although customer credentials were not accessed, the unspecified breached employee details may be enough to gauge the bank’s internal processes, business operations, and technologies it uses to safeguard assets.

Singing River Health System Updates on August 2023 Data Breach; 895,000 Affected

Source: https://www.bleepingcomputer.com/news/security/singing-river-health-system-data-of-895-000-stolen-in-ransomware-attack/

What happened: The Singing River Health System has now provided an update on the data breach it suffered in the August 2023 data breach, stating that the breach exposed the data of 895,204 people. In September 2023, ZeroFox intelligence observed the Rhysida ransomware group claiming responsibility for the attack.

Why it matters: The Rhysida ransomware group is notorious for targeting healthcare entities, including children’s hospitals. Threat actors can misuse the exposed data from healthcare systems to target customers in malicious attacks like spear phishing, extortion scams, and blackmail. Such ransomware attacks also cause considerable financial losses to healthcare firms and have far-fetched repercussions. For example, the ransomware attack on Change Healthcare resulted in damages exceeding USD 1 billion and caused ripples across the U.S. healthcare industry, disrupting payments and facilities for a month.

DEEP AND DARK WEB INTELLIGENCE

  • Threat actor aaron bushnell: On May 14, 2024, a pro-Palestine threat actor aaron bushnell claimed to have infiltrated the confidential servers of the Canadian Dalhousie University on the predominantly English-language dark web forum, “BreachForums." The alleged reason for the attack is that the university allegedly did not show its support for the Palestine cause.

VULNERABILITY AND EXPLOIT INTELLIGENCE

  • CVE-2024-30051: In its latest batch of Patch Tuesday updates, Microsoft has released fixes for 61 flaws and three actively exploited or publicly disclosed zero days. CVE-2024-30051 is an actively exploited Windows DWM Core Library flaw that lets an actor gain SYSTEM privileges.

Affected products: The affected products and versions have been listed by Microsoft in this security update.

  • CVE-2024-27834: An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication by exploiting this vulnerability. The issue was addressed with improved checks. This issue is fixed in iOS 17.5 and iPadOS 17.5, tvOS 17.5, Safari 17.5, watchOS 10.5, macOS Sonoma 14.5.

Affected products: Safari Versions Below 17.5.

Tags: DIB, tlp:green