zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - June 10, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - June 10, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Hacktivists Target EU Political Parties in DDoS Attacks
  • ZeroFox Intelligence Flash Report - ShinyHunters: An Insight into Future Extortion Tactics?
  • 750,000 People's Data Stolen in Frontier Communications Attack in April

Hacktivists Target EU Political Parties in DDoS Attacks

Source: https://www.bleepingcomputer.com/news/security/ddos-attacks-target-eu-political-parties-as-elections-begin/

What happened: Hacktivist group HackNet has claimed responsibility for Distributed Denial-of-Service (DDoS) attacks on election-related sites and political parties in the Netherlands, coinciding with the European Parliament elections. Agencies were able to thwart the attacks comprising three DDoS attack waves, peaking at 115 million and 44 million requests per hour.

Why it matters: Hacktivist attacks are more likely to be a general nuisance than a direct disruption in the election process or interference in the results. However, hacktivists can influence political landscapes and voter opinions, inconveniencing people and besmirching the electoral process, especially when the EU elections are underway. More hacktivists are likely to jump on the bandwagon and conduct such attacks during the election, thereby reflecting the increasing trend of politically motivated cyberattacks targeting democratic processes.

ZeroFox Intelligence Flash Report - ShinyHunters: An Insight into Future Extortion Tactics?

Source: https://www.zerofox.com/advisories/23697/

What happened: Threat actors have allegedly stolen the data of an unknown number of organizations via a compromise of the cloud data platform Snowflake. ZeroFox cannot yet independently confirm or deny the extent to which Snowflake is involved or how the alleged accessing of a demo environment could lead to the breach of multiple downstream customers.

Why it matters: ZeroFox anticipates there is a likely chance that other as-yet-unnamed organizations have also had data leaked, but may have chosen to buy back their data, or threat actors have yet to list it. The alleged breach of the cloud data platform Snowflake, and subsequent sale of data from alleged customers, may provide threat actors with a blueprint for the development of digital extortion tactics in the near future. The omission of encrypting payloads from extortion attacks will likely become increasingly popular amongst established extortion collectives—and will likely facilitate a larger pool of threat actors not historically involved in extortion to enter the digital extortion space.

750,000 People's Data Stolen in Frontier Communications Attack in April

Source: https://www.theregister.com/2024/06/07/frontier_communications_filing_cyberattack/

What happened: American telecommunications company Frontier Communications has disclosed that a data breach (which was reported in the April 20 issue of ZeroFox’s Cyber Cyber Intelligence Daily Brief) affected over 750,000 individuals and exposed sensitive personal data, such as Social Security numbers, addresses, dates of birth, credit scores, and phone numbers of customers. Last week, ZeroFox observed a post on the Ransomhub ransomware leak site targeting Frontier Communications, with a claim to have stolen 2 million customers’ data.

Why it matters: The exposed personal data creates opportunities for identity theft and fraud, potentially causing financial harm to affected individuals. Additionally, the stolen data can be leveraged for future cyberattacks, including phishing scams and targeted malware distribution, exploiting the compromised information to gain unauthorized access to accounts or perpetrate further breaches. Furthermore, the ransomware group's approach to selling stolen data, similar to their tactics following Christie's attack, indicates a pattern of criminal behavior aimed at monetizing illicitly obtained information. Meanwhile, the FCC has proposed new rules for internet routing security, requiring Broadband providers to report their efforts in addressing vulnerabilities in the Border Gateway Protocol (BGP).

DEEP AND DARK WEB INTELLIGENCE

BreachForums: On June 10, Zerofox observed that both Tor and clearnet sites of BreachForums, a major English-language cybercrime forum, were not operational. The group’s official Telegram channel, “BF announcement”, as well as “ShinyHunters” appears to be down. Telegram chats in the channel named “Jacuzzi 2.0” were deleted.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2024-4577: In PHP versions 8.1. before 8.1.29, 8.2. before 8.2.20, 8.3. before 8.3.8, when using Apache and PHP-CGI on Windows, if the system is set up to use certain code pages, Windows may use "Best-Fit" behavior to replace characters in command line given to Win32 API functions. PHP CGI module may misinterpret those characters as PHP options, which may allow a malicious user to pass options to PHP binary being run, and thus reveal the source code of scripts, run arbitrary PHP code on the server, etc.

Affected products: PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3. before 8.3.8.

CVE-2024-28996: The SolarWinds Platform was determined to be affected by a SWQL Injection Vulnerability. Attack complexity is high for this vulnerability.

Affected products: SolarWinds Platform 2024.1 SR 1 and previous versions.

Tags: DIB, tlp:green