zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - June 19, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - June 19, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • IntelBroker Leaks Database Allegedly Belonging to AMD
  • ZeroFox Intelligence Flash Report - New Malicious Tool Advertises Comprehensive Personal Information
  • CISA and Partners Release Guidance for Modern Approaches to Network Access Security

IntelBroker Leaks Database Allegedly Belonging to AMD

Source: https://cloud.zerofox.com/intelligence/advanced_dark_web/66005

What happened: On June 18, ZeroFox Intelligence observed IntelBroker leaking a database allegedly associated with Advanced Micro Devices (AMD), a well-known U.S.-based semiconductor manufacturing company, on BreachForums. The actor claims the compromised data includes future AMD products, Spec sheets, employee databases, customer databases, property files, ROMs, source code, firmware, and finances. AMD is currently investigating the said claims.

Why it matters: The semiconductor industry is a lucrative target for notorious cyber threat actors due to an increasing demand for semiconductor chips from multiple industries. It faces heightened cyberattack risks due to its valuable intellectual property, intensified by geopolitical tensions and restrictions on advanced chipmaking technology. The leaked database with alleged information on AMD’s future products highlights this threat, as the database is likely to attract actors sponsored by states looking to lessen their dependence on other countries for their semiconductor needs.

ZeroFox Intelligence Flash Report - New Malicious Tool Advertises Comprehensive Personal Information

Source: https://www.zerofox.com/advisories/23756/

What happened: A positive-reputation actor known as “spam_assistant” has announced a new tool called Data Fusion in the dark web forum Exploit. According to the advertisement, Data Fusion is capable of providing buyers with a significant amount of both personally identifiable information (PII) pertaining to individuals and organizational tax data.

Why it matters: Unlike similar deep and dark web (DDW) services offering the sale of PII, Data Fusion is allegedly capable of creating bespoke background reports that summarize the requested data. PII such as that advertised by spam_assistant is an integral aspect of many forms of cyberattack. Personal details are used to inform and enhance sophisticated social engineering attacks, such as spear phishing and business email compromise, or to enable fraudulent activity like identity theft and tax-related scams.

CISA and Partners Release Guidance for Modern Approaches to Network Access Security

Source: https://www.cisa.gov/news-events/alerts/2024/06/18/cisa-and-partners-release-guidance-modern-approaches-network-access-security

What happened: CISA recently released guidelines—Modern Approaches to Network Access Security—in partnership with the Federal Bureau of Investigation (FBI) and other national security organizations. The guidance urges business owners to undertake stronger security solutions such as zero trust, secure service edge (SSE), and secure access service edge (SASE).

Why it matters: These guidelines have a better chance at helping organizations to better understand the vulnerabilities, threats, and practices associated with traditional remote access and VPN deployment, as well as the inherent business risk posed to an organization’s network by remote access misconfiguration.

DEEP AND DARK WEB INTELLIGENCE

Telegram user Hunt3r Kill3rs: On June 17, 2024, threat actor group Hunt3r Kill3rs claimed to have infiltrated several systems of Schneider Electric, a Germany-based company that offers digital automation and energy management.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2024-37079: It is a critical (CVSS score: 9.8) heap-overflow vulnerability in vCenter Server's DCERPC protocol allows remote code execution via crafted packets. VMware has released the details of this bug’s patch in an advisory issued on June 18.

Affected product: VMware vCenter Server.

CVE-2024-37080: It is a critical (CVSS score: 9.8) heap overflow vulnerability in vCenter Server's DCERPC protocol, akin to CVE-2024-37079, that enables remote code execution with crafted packets. VMware has released the details of this bug’s patch in an advisory issued on June 18.

Affected product: VMware vCenter Server.

Tags: DIB, tlp:green