zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - June 11, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - June 11, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Iranian Data Leak Advertised on the Dark Web
  • London Hospitals Cyber Incident Causes Severe O Positive and O Negative Blood Shortage
  • Cylance Investigating Data Breach Linked to Third-Party Platform

Iranian Data Leak Advertised on the Dark Web

Source: https://www.zerofox.com/advisories/23708/

What happened: On June 4, untested English-speaking actor “irleaks” announced the sale of a large leaked data set pertaining to an independent Iranian government agency, the Hajj and Pilgrimage Organization, on the dark web Onniforums community. The leaked data will very likely attract threat collectives with geopolitical or ideological motivations, including hacktivist and state-sponsored groups hostile to Iran. Additionally, financially motivated threat actors, such as ransomware groups, will likely be interested.

Why it matters: The recent data leak is very likely related to the ongoing Israel-Hamas war, as threat actors likely identify a demand from geopolitically aligned actors for state-related data. It is likely that data leaks implicating both Israel and Iran will continue to be advertised by threat actors on dark web forums while the conflict persists. While the extent and content of the stolen information is unknown, its quantity and non-public nature means it will very likely be of interest to geopolitically or ideologically motivated threat actors. Therefore, it is very likely that the advertisement is aimed toward hacktivists, state cyber capabilities, and state-affiliated groups that are known to be opposed to Iran.

London Hospitals Cyber Incident Causes Severe O Positive and O Negative Blood Shortage

Source: https://www.nhsbt.nhs.uk/news/o-positive-and-o-negative-donors-asked-to-urgently-book-appointments-to-give-blood-following-london-hospitals-it-incident/

What happened: England's NHS Blood and Transplant (NHSBT) has urgently called for O positive and O negative blood donors to book appointments and donate following last week’s cyberattack on pathology provider Synnovis. Many non-urgent procedures have been canceled or redirected.

Why it matters: The attack disrupted services at multiple hospitals in London, making it difficult to quickly match blood donor and recipient types. This raises the risk of transfusion mismatches, which could lead to life-threatening complications. The London hospital incident is part of a series of ransomware attacks on healthcare organizations this year, which have compromised patient services and exposed sensitive data. The much-publicized and disruptive impact of attacking healthcare services makes these organizations lucrative targets for extortion, potentially endangering patient lives.

Cylance Investigating Data Breach Linked to Third-Party Platform

Source: https://www.bleepingcomputer.com/news/security/cylance-confirms-data-breach-linked-to-third-party-platform/

What happened: Cybersecurity company Cylance is investigating reports of a data breach that allegedly exposed 34 million emails and other sensitive data relating to customers, partners, and employees. BlackBerry Cylance’s investigations reportedly indicate that the breached data—accessed from a “third-party platform unrelated to BlackBerry”—is from 2015 to 2018 and does not involve any current Cylance customers or sensitive information. However, the company has verified that data being sold by threat actor Sp1d3r for USD 750,000 on a hacking forum is legitimate.

Why it matters: This data breach at Cylance highlights the alarming vulnerability of personal and corporate data in the digital age. According to sources, Cylance is a Snowflake customer, and the recent breaches at Santander and Ticketmaster have been linked to a Snowflake data breach. This underscores the potential for attackers to exploit weaknesses in cloud-based platforms, amplifying the scope and impact of breaches.

DEEP AND DARK WEB INTELLIGENCE

Threat actor "b1gb0y75" : Untested threat actor "b1gb0y75" advertised a postal-services-themed phishing kit for collecting credit card data on the predominantly Russian language Dark Web forum "Exploit." According to "b1gb0y75" the phishing kit was developed for spamming via SMS and email.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2024-4610: Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver allows a local non-privileged user to make improper GPU memory processing operations to gain access to already freed memory. This bug is being exploited in the wild.

Affected products: Bifrost GPU Kernel Driver versions from r34p0 through r40p0; Valhall GPU Kernel Driver versions from r34p0 through r40p0.

CVE-2024-36787: A bug in Netgear WNR614 N300 allows attackers to bypass authentication and access the administrative interface via unspecified vectors.

Affected products: Netgear WNR614 JNR1010V2 N300-V1.1.0.54_1.0.1

Tags: DIB, tlp:green