zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - May 28, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - May 28, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Sav-Rx Discloses Data Breach Impacting 2.8 Million Americans
  • Pakistani Hackers Target Indian Critical Infrastructure
  • Check Point VPNs Under Attack by Hackers

Sav-Rx Discloses Data Breach Impacting 2.8 Million Americans

Source: https://www.bleepingcomputer.com/news/security/sav-rx-discloses-data-breach-impacting-28-million-americans/

What happened: Sav-Rx, a prescription management company, experienced a data breach in 2023 where personal data, including names and Social Security Numbers, of over 2.8 million people in the United States was stolen due to an external system breach.

Why it matters: Sav-Rx's data breach illustrates the pervasive threat to personal data within healthcare systems. With sensitive information like Social Security Numbers compromised, affected individuals are at risk of identity theft and other forms of cyberattacks. The healthcare company had engaged third-party cybersecurity experts to secure their systems and conduct a comprehensive investigation, ensuring minimal disruption to business operations.

Pakistani Hackers Target Indian Critical Infrastructure

Source: https://thehackernews.com/2024/05/pakistan-linked-hackers-deploy-python.html

What happened: Cybersecurity researchers have discovered Pakistani APT group Transparent Tribe targeting the Indian government, defense, and aerospace sectors in a spear phishing campaign with cross-platform malware written in Python, Golang, and Rust.

Why it matters: Transparent Tribe is persistently targeting critical sectors vital to India's national security. The group's evolving tactics include cross-platform programming, open-source tools, and web services. Its actions and targets align with escalating India-Pakistan geopolitical tensions, suggesting a strategic motive. Threats from malicious cyber actors, such as Transparent Tribes, will likely persist and heighten amid the ongoing Indian general elections.

Check Point VPNs Under Attack by Hackers

Source: https://blog.checkpoint.com/security/enhance-your-vpn-security-posture?campaign=checkpoint&eid=guvrs&advisory=1

What happened: Check Point has warned about an ongoing campaign targeting its customers remote-access VPN environments. Attackers are exploiting old local accounts with weak password-only authentication to gain unauthorized access to enterprise environments.

Why it matters: The increased interest of threat actors in exploiting remote-access VPNs poses a significant threat to enterprise security. These attacks aim to gain access to organizational assets and users, potentially leading to data breaches and compromise of critical infrastructure. Network admins should keep a check on old and unused accounts and implement additional authentication layers to prevent such attacks.

DEEP AND DARK WEB INTELLIGENCE

Threat actor group The Five Families | Threat actor group The Five Families announced that it has successfully accessed the systems of the United Arab Emirates government and obtained confidential information from various ministries. The threat actor has access to 150 GB of data put on sale.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2024-5035: A bug with a CVSS score of 10 exposes affects TP-Link Archer C5400X gaming routers. A network service called "rftest" is vulnerable to unauthenticated command injection on ports TCP/8888, TCP/8889, and TCP/8890. By successfully exploiting this flaw, remote unauthenticated attackers can gain arbitrary command execution on the device with elevated privileges. TP-Link has fixed this vulnerability in Archer C5400X(EU)_V1_1.1.7 Build 20240510.

Affected products: Archer C4500X: through 1_1.1.6.

Tags: DIB, tlp:green