ZeroFox Cyber Intelligence Daily Brief - May 24, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - May 24, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- ZeroFox Intelligence Brief - Competitive South African Elections Bring Physical and Cyber Risks
- First Nations Health Authority Detected and Interrupted Attack by INC Ransomware Group
- Malware Backdoor Found in Widely Used Courtroom Software Installer
ZeroFox Intelligence Brief - Competitive South African Elections Bring Physical and Cyber Risks
Source: https://www.zerofox.com/advisories/23588/
What happened: Post-independence South Africa is set to have its most competitive elections ever on May 29. The African National Congress (ANC) Party, which has governed South Africa since the end of apartheid in 1994, is highly likely to lose its majority for the first time.
Why it matters: Without a majority, the ANC will need to form a coalition to continue leading the government, which has made this campaign season especially contentious. Political parties hoping for the opportunity to make it into the government are likely escalating their campaign rhetoric online and threatening violence. After 30 years of controlling the government virtually unchallenged, the ANC will have difficulty forming a coalition with any of the main opposition parties and is campaigning similarly to maintain as large a share of the vote as possible.
First Nations Health Authority Detected and Interrupted Attack by INC Ransomware Group
What happened: First Nations Health Authority (FNHA) intercepted unauthorized access to its corporate network following a cybersecurity incident detected on May 13. Although encryption of FNHA's servers was prevented, the ongoing investigation uncovered that employee information and limited personal data were impacted. ZeroFox has observed INC ransomware posting the screenshots as evidence on its leak site.
Why it matters: FNHA's prompt response thwarted server encryption, but the exposure of employee information and personal data highlights the persistent threat to healthcare data security. The stolen data further poses the risk of identity theft and targeted cyberattacks against both employees and individuals affected. The incident reflects the concerning trend of healthcare organizations being recurrent targets of cyber threats.
Malware Backdoor Found in Widely Used Courtroom Software Installer
What happened: Europol is investigating a data breach impacting its Europol Platform for Experts where a threat actor exfiltrated For Official Use Only (FOUO) documents containing classified data. At the time of reporting, the website is offline, displaying a message that the service is “not available at the moment due to maintenance activities.” IntelBroker has claimed responsibility for the breach.
Why it matters: As the European Union’s law enforcement agency, Europol data exposed to threat actors could pose serious risks to the upcoming European Parliament elections. Adversaries might use the exposed data for spear phishing attacks targeting political entities and even in misinformation or disinformation campaigns.
DEEP AND DARK WEB INTELLIGENCE
Telegram user SN_Blackmeta: On May 23, 2024, threat actor group SN_Blackmeta announced its support to students of Yale University, protesting the university's solidarity with Israel. The threat actor threatened to disable all internal and external university systems including the applications associated with the university and all educational and financial services.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2024-4835: A cross-site scripting (XSS) condition exists in VS code editor (Web IDE). By leveraging this condition, an attacker can craft a malicious page to exfiltrate sensitive user information. GitLab has released versions 17.0.1, 16.11.3, and 16.10.6 for GitLab Community Edition (CE) and Enterprise Edition (EE) to patch this bug.
Affected products: GitLab versions 15.11 before 16.10.6, 16.11 before 16.11.3, and 17.0 before 17.0.1.
CVE-2020-17519: This improper access control vulnerability in Apache Flink allows attackers to read any file on the local filesystem of the JobManager through the REST interface of the JobManager process. All users are advised to upgrade to Flink 1.11.3 or 1.12.0 if their Flink instance(s) are exposed. This bug was added to CISA’s Known Exploited Vulnerabilities Catalog on May 23.
Affected products: Apache Flink versions 1.11.0, 1.11.1, and 1.11.2.
Tags: DIB, tlp:green