ZeroFox Cyber Intelligence Daily Brief - June 8, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - June 8, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Pro-Russia Hacktivists Plan to Attack “Pseudo-Democratic” EU Elections
- Russian Cyber Threats Loom Over Paris Olympics
- POC Exploit Code Published for 9.8-Rated Apache HugeGraph RCE Flaw
Pro-Russia Hacktivists Plan to Attack “Pseudo-Democratic” EU Elections
What happened: Pro-Russian hacktivist group NoName057(16) claims to be preparing for cyberattacks in the run-up to the European Parliament elections, calling the body “pseudo-democratic and thoroughly Russophobic.” The threat actor group also claimed that other groups like People's CyberArmy, Cyberdragon, and Usersec have joined in its plans to interfere with the elections.
Why it matters: Since the invasion of Ukraine in February 2022, EU countries have experienced a constant barrage of distributed denial-of-service (DDoS) attacks from pro-Kremlin hacktivist groups such as Killnet and NoName, as previously stated in ZeroFox’s report on the EU elections. The main targets are websites for public transit, financial institutions, and government agencies. These attacks are typically unsophisticated and cause minimal damage, and in most cases service is restored within a matter of hours.
Russian Cyber Threats Loom Over Paris Olympics
What happened: Cybersecurity researchers from tech giants have warned that the 2024 Paris Olympics are facing significant cyber threats from Russian threat actors, including espionage, disruption, and influence campaigns. These threats target event organizers, sponsors, ticketing systems, Paris infrastructure, athletes, and spectators.
Why it matters: The international event is at high risk for cyberespionage, ticket scams, and data theft, particularly from Russian groups, due to the presence of government officials and financial incentives. These groups could cause significant disruption and reputational damage. The use of AI in influence operations further complicates security, with researchers reporting on strategic attempts to destabilize the event and its stakeholders. For instance, a Russian actor released a feature-length film, "Olympics Has Fallen," using AI to impersonate Tom Cruise and discredit the International Olympic Committee (IOC).
POC Exploit Code Published for 9.8-Rated Apache HugeGraph RCE Flaw
What happened: Two proof-of-concept exploits for Apache HugeGraph's remote command execution vulnerability (CVE-2024-27348) have been disclosed publicly. This critical vulnerability (CVSS score 9.8) which affected Apache HugeGraph versions before 1.3.0 was patched by the Apache Software Foundation in late April.
Why it matters: Users who have not yet updated to the patched version are strongly advised to upgrade to Apache HugeGraph 1.3.0 promptly, as there's a risk of malicious actors leveraging the publicly available proof-of-concept exploit code. Exploitation of this flaw grants attackers full control over the HugeGraph server, allowing them to execute various malicious activities such as data theft, network reconnaissance, ransomware deployment, or other nefarious actions within the victim organization's infrastructure.
DEEP AND DARK WEB INTELLIGENCE
Telegram user Anonymous Egypt: Threat actor group Anonymous Egypt has claimed to have gained access to the Federal Authority for Government Human Resources, United Arab Emirates. The leaked data includes personal biographical information about citizens and tourists in the United Arab Emirates.
Tags: DIB, tlp:green