ZeroFox Cyber Intelligence Daily Brief - June 4, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - June 4, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Russia Amps up Efforts to Disrupt Paris Olympics with Disinformation
- Collection Agency FBCS Ups Data Breach Tally to More Than 3 Million People
- Researchers Uncover RAT-Dropping npm Package Targeting Gulp Users
Russia Amps up Efforts to Disrupt Paris Olympics with Disinformation
What happened: Researchers have observed Russian threat actors, including Storm-1679 and Storm-1099, amp up disinformation campaigns to target France and the upcoming Paris Olympics. The campaign aims to besmirch the International Olympic Committee (IOC) while creating an impression of potential violence disrupting the international event.
Why it matters: Storm-1679 and Storm-1099 have reportedly been devising Olympic-specific disinformation campaigns since June 2023. These efforts are likely to invite more state-linked activity targeting the IOC and the Olympics, undermining the legitimacy of the committee and French security forces. Disinformation campaigns, if not checked, can also be used for fear-mongering among the audience and the participants, thereby affecting turnout and participation.
Collection Agency FBCS Ups Data Breach Tally to More Than 3 Million People
What happened: Debt collection agency Financial Business and Consumer Solutions (FBCS) has updated the number of individuals affected by a February data breach to over 3 million people. The data accessed by the threat actors include full names, Social Security numbers, dates of birth, account information, and driver's license.
Why it matters: People impacted by the FBCS data breach are now at higher risk for phishing, fraud, and social engineering attacks. They are advised to exercise caution with their communications and closely monitor their bank account activity to detect any suspicious transactions or activities. It is very likely that the intended use of this data is social engineering and other fraudulent activity, with a likely chance it has already been leveraged in attacks by financially-motivated threat actors.
Researchers Uncover RAT-Dropping npm Package Targeting Gulp Users
Source: https://thehackernews.com/2024/06/researchers-uncover-rat-dropping-npm.html
What happened: Cybersecurity researchers have discovered a suspicious package named "glup-debugger-log" on the npm package registry, designed to deploy a remote access trojan (RAT) on compromised systems, specifically targeting users of the gulp toolkit.
Why it matters: This discovery highlights the ongoing threat posed by malware infiltrating open-source ecosystems. Users, especially developers relying on npm packages, are at risk of compromise, leading to potential data breaches, system hijacking, and unauthorized access to sensitive information. Additionally, the sophisticated nature of this RAT underscores the evolving tactics of cybercriminals, who continuously innovate to create stealthier and more potent malware. Such attacks not only jeopardize individual users but also pose significant risks to organizations.
DEEP AND DARK WEB INTELLIGENCE
Hacktivist groups BlackMaskers and SylhetGang | Hacktivist groups BlackMaskers and SylhetGang announced a massive cyberattack against UAE websites. They claimed to have targeted the UAE’s Cyber Security Council and Emirates Snack Foods.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2017-3506: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebLogic Server accessible data as well as unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data.
Affected products: Oracle WebLogic Server versions 10.3.6.0, 12.1.3.0, 12.2.1.0, 12.2.1.1 and 12.2.1.2.
Tags: DIB, tlp:green