ZeroFox Cyber Intelligence Daily Brief - June 3, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - June 3, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Snowflake Investigating Data Breach Affecting Customers
- AI Company "Hugging Face" Detects Unauthorized Access to Its Spaces Platform
- Email Addresses and Other Information of Several European Politicians on Dark Web
Snowflake Investigating Data Breach Affecting Customers
What happened: Cloud data platform Snowflake is investigating a recent breach and has denied claims that it was “caused by compromised credentials of current or former Snowflake personnel.” A joint statement, made alongside two prominent cybersecurity firms, highlighted no evidence of platform vulnerability or misconfiguration and suggested a targeted campaign against users with single-factor authentication. Snowflake promptly notified potentially affected customers.
Why it matters: Such breaches demonstrate the interconnectedness of cybersecurity vulnerabilities across different platforms and services. This interconnected chain of attacks highlights the cascading effects of compromised credentials, where access to one system can be leveraged to breach others. The stolen data, including sensitive personal and financial information, poses significant risks for individuals and organizations alike, with potential consequences ranging from identity theft to financial fraud, and more.
AI Company Hugging Face Detects Unauthorized Access to Its Spaces Platform
Source: https://huggingface.co/blog/space-secrets-disclosure
What happened: Hugging Face, an AI company, recently disclosed unauthorized access to its Spaces platform. The number of affected users has not been revealed, and the incident is under further investigation. Hugging Face has notified law enforcement agencies and data protection authorities about the breach.
Why it matters: Previous research revealed vulnerabilities in Hugging Face's Safetensors conversion service, which could allow hijacking of AI models submitted by users and staging supply chain attacks. If a malicious actor compromised Hugging Face's platform, they could potentially access private AI models, datasets, and critical applications, causing extensive damage and posing significant supply chain risks.
Email Addresses and Other Information of Several European Politicians on Dark Web
Source: https://www.securityweek.com/information-of-hundreds-of-european-politicians-found-on-dark-web/
What happened: Researchers found email addresses, dates of birth, addresses, and social media accounts of British and EU politicians on the dark web. The data leak — compromising about 900 email addresses — impacted British politicians the most, including senior government and opposition figures.
Why it matters: Among the email addresses exposed, researchers matched 697 of them with plain-text passwords. If any politician reused one of these compromised passwords for their official email account, it could pose a significant security risk. Moreover, with the UK and the EU elections on the horizon, malicious threat actors are likely to use the exposed data in targeted phishing attacks, extortion scams, influence campaigns, and intimidation efforts.
DEEP AND DARK WEB INTELLIGENCE
Pro-Russia Threat Actor Flying Yeti: Russia-aligned threat actor Flying Yeti’s attempted month-long phishing campaign targeting Ukraine was thwarted.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2024-4358: In Progress Telerik Report Server an unauthenticated attacker can gain access to Telerik Report Server restricted functionality via an authentication bypass vulnerability.
Affected products: Progress Telerik Report Server version 2024 Q1 (10.0.24.305) or earlier.
CVE-2024-34579: This vulnerability allows remote malicious users to execute arbitrary code on affected installations of Fuji Electric Alpha5 Smart. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of C5V files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.
Affected product: Fuji Electric Alpha5 Smart
Tags: DIB, tlp:green