ZeroFox Weekly Intelligence Brief – June 17, 2024
|by Alpha Team

ZeroFox Weekly Intelligence Brief – June 17, 2024
ZeroFox’s Weekly Intelligence Briefing highlights the major developments and trends across the cyber threat landscape. ZeroFox Intelligence is derived from a variety of sources, including—but not limited to—curated open-source accesses, vetted social media, proprietary data sources, and direct access to threat actors and groups through covert communication channels. Information relied upon to complete any report cannot always be independently verified. As such, ZeroFox applies rigorous analytic standards and tradecraft in accordance with best practices and includes caveat language and source citations to clearly identify the veracity of our Intelligence reporting and substantiate our assessments and recommendations. All sources used in this particular Intelligence product were identified prior to 12:00 PM (EDT) on June 14, 2024; per cyber hygiene best practices, caution is advised when clicking on any third-party links.
Read the Brief
View the full report here
Hacktivists Target EU Political Parties in DDoS Attacks
What happened: Hacktivist group “HackNet” has claimed responsibility for distributed denial-of-service (DDoS) attacks on election-related sites and political parties, coinciding with the European Parliament elections. Network defenders have mitigated at least three DDoS attacks, including two significant attacks on June 5 and 6. The first attack peaked at 115 million requests per hour, while the second reached 44 million requests per hour. Both attacks targeted pro-Russian political parties Party for Freedom (PVV) and Forum for Democracy (FvD).
Pure Storage Discloses Data Breach Caused by Snowflake Workspace Compromise
What happened: Cloud storage systems and services provider Pure Storage has confirmed a data breach related to Snowflake, with a single data analytics workspace compromised. According to the security bulletin on its support page, the breach did not expose any customer data. The breach affected telemetry information used for customer support, including company names, email addresses, and software release versions. Pure Storage continues to monitor its systems and has found no further unusual activity or threats to its infrastructure. Researchers investigating the Snowflake credentials compromise have reported that the lack of multi-factor authentication (MFA) was a common factor in the breaches affecting Snowflake customers (including Santander and TicketMaster), although it is unclear if this was the case for Pure Storage.
Phone Scammers Impersonating CISA Employees
What happened: The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning against phone scammers utilizing names and titles to impersonate government employees, including CISA employees. CISA has emphasized that its staff will never request that individuals wire money, cash, cryptocurrency, or gift cards or issue instructions to keep a discussion secret.
Tags: tlp:green