zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - June 12, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - June 12, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Pure Storage Discloses Data Breach Caused by Snowflake Workspace Compromise
  • City of Cleveland Shuts down IT Systems After Cyberattack
  • Massive Global DNS Probing by Chinese Actor SecShow

Pure Storage Discloses Data Breach Caused by Snowflake Workspace Compromise

Source: https://www.theregister.com/2024/06/11/pure_storage_snowflake_breach/

What happened: Pure Storage confirmed a breach involving its Snowflake data analytics workspace, adding it to the list of victims affected in the Snowflake cyberattack. Pure Storage has confirmed that although some telemetry information, including company names and email addresses, was exposed, the breach did not compromise customer data.

Why it matters: The threat analysis firm hired to investigate the Snowflake breach has attributed it to threat actor group UNC5537. The firm further stated that the adversary has hacked into 165 organizations with the help of stolen Snowflake credentials. In a report released earlier this month, ZeroFox also warned that more organizations, besides TicketMaster and Santander, might have had data leaked. It is also important to note that the breach sets precedents for future digital extortion tactics, with a trend toward omitting payload encryption to attract more threat actors.

City of Cleveland Shuts down IT Systems After Cyberattack

Source: https://www.bleepingcomputer.com/news/security/city-of-cleveland-shuts-down-it-systems-after-cyberattack/

What happened: The City of Cleveland took its citizen-facing services, like public offices and City Hall, down after a cyberattack. Ongoing investigations reveal the incident has not impacted any essential services like healthcare and utility.

Why it matters: Investigations are still underway to determine the type of cyberattack. No threat actor has claimed the attack and neither has any ransom been demanded, at the time of writing. However, the City of Cleveland has a population of two million and is considered to be a significant economic center in Ohio. Forcing the city to take some of its services offline could mean backlogs and delays which could cause financial losses.

Massive Global DNS Probing by Chinese Actor SecShow

Source: https://thehackernews.com/2024/06/chinese-actor-secshow-conducts-massive.html

What happened: Cybersecurity researchers have identified a Chinese actor, SecShow, conducting large-scale Domain Name System (DNS) probing since June 2023. SecShow operates from the China Education and Research Network (CERNET), a project funded by the Chinese government.

Why it matters: The researchers have warned that the probes in question targeting DNS responses at open resolvers could facilitate future malicious activities. Threat actors can use open DNS resolvers in various cyberattacks, such as distributed denial-of-service (DDoS) attacks. SecShow's use of IP Address Spoofing Techniques raises concerns about data gathering for undisclosed purposes, highlighting the risks of transparency and security. The activity mirrors another China-linked threat actor, Muddling Meerkat, known to demonstrate a pattern of prolonged, undetected probing.

DEEP AND DARK WEB INTELLIGENCE

Telegram user SN_Blackmeta: On June 10 and 11, 2024, threat actor group "SN_Blackmeta" conducted a distributed denial of service (DDoS) attack against various services of Microsoft. This allegedly affected the domain's functioning for a duration of 1-2 hours.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2023-50868: In its latest batch of Patch Tuesday updates, Microsoft has released fixes for 51 flaws including five denial of service vulnerabilities. CVE-2023-50868 allows remote attackers to cause a denial of service (CPU consumption for SHA-1 computations) via DNSSEC responses in a random subdomain attack, aka the "NSEC3" issue. The RFC 5155 specification implies that an algorithm must perform thousands of iterations of a hash function in certain situations.

Affected products: The affected products and versions have been listed by Microsoft in this security update.

CVE-2024-23110: Multiple stack-based buffer overflow vulnerabilities [CWE-121] in the command line interpreter of FortiOS may allow an authenticated attacker to execute unauthorized code or commands via specially crafted command line arguments.

Affected products: FortiOS 7.4 through 7.4.2, FortiOS 7.2 through 7.2.6, FortiOS 7.0 through 7.0.13, FortiOS 6.4.0 through 6.4.14, FortiOS 6.2.0 through 6.2.15, FortiOS 6.0 all versions.

Tags: DIB, tlp:green