ZeroFox Cyber Intelligence Daily Brief - June 20, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - June 20, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Kraken Bug Bounty Program Patches Isolated Bug
- CDK Global Investigating Cyber Incident
- T-Mobile Denies Hack, Links Leaked Data to Vendor Breach
Kraken Bug Bounty Program Patches Isolated Bug
Source: https://blog.kraken.com/product/security/kraken-bug-bounty-program-patches-isolated-bug
What happened: Cryptocurrency exchange has fixed a bug in its deposit and funding systems that potentially allowed users to artificially inflate their balances. Kraken has asserted that no client assets were impacted or vulnerable leading up to this disclosure; however, a malicious attacker could have effectively printed assets in their Kraken account for a period of time because of the now-patched bug.
Why it matters: Even though the bug was reportedly fixed within minutes of discovery, and no client assets were at risk, the security issue did allow attackers to print assets. Three accounts, including one linked to a researcher, reportedly exploited the flaw to gain assets worth USD 3 million. This incident demonstrates the potential risks of misuse of bug bounty programs for personal gain rather than ethical disclosure. Moreover, it is likely to attract more malicious adversaries to exploit crypto platforms, posing a threat to cryptocurrency users.
CDK Global Investigating Cyber Incident
What happened: CDK Global temporarily shut down all its systems to investigate a recent cyber incident. The company has restored its core dealer management system and digital retailing solutions since the incident.
Why it matters: CDK is a car dealership software-as-a-service provider, and a cyber incident on its systems may have a likely impact on its clients. Clients may especially be vulnerable since they configure an always-on VPN to their SaaS provider's data centers, enabling their locally installed applications to access the platform, which could allow threat actors to access its networks. The company is currently conducting investigations to assess if the cyber incident has had any bearing on its clients as well.
T-Mobile Denies Hack, Links Leaked Data to Vendor Breach
What happened: T-Mobile has refuted claims of a breach and denied any theft of source code after a threat actor alleged selling stolen data from the company; the company has attributed the issue to a potential breach at a third-party service provider. ZeroFox has observed threat actor IntelBroker claiming to have leaked a database associated with T-Mobile on the web forum BreachForums.
Why it matters: The alleged breach of T-Mobile by IntelBroker is significant due to the potential exposure of sensitive data such as source code, SQL files, and certifications. If validated, this breach could compromise T-Mobile's proprietary technology and infrastructure, posing security risks to its operations and customer information. Threat actors can further exploit vulnerabilities, perform unauthorized access or modifications, and potentially launch attacks such as data breaches, espionage, or identity theft. They could also use the information for competitive advantage, blackmail, or compromise other systems connected to the data.
DEEP AND DARK WEB INTELLIGENCE
- BreachForums user Sp1d3r: Threat actor Sp1d3r, known for Snowflake-related data breaches, sold millions of students' information from Los Angeles Unified School District and Edgenuity on the predominantly English-language dark web forum, BreachForums. The threat actor claims to be selling 4 million students' data including name, address, family name, financials, grades, performance scoring, discipline details, and parent/student online login credentials.
VULNERABILITY AND EXPLOIT INTELLIGENCE
- CVE-2019-6268: CISA has released an industrial control advisory highlighting a high severity path traversal vulnerability in RAD Data Communications products. Successful exploitation of this bud can let an attacker obtain files from the operating system by crafting a special request.
Affected products: All versions of RAD Data Communications SecFlow-2.
- CVE-2022-41328: This improper limitation of a pathname to a restricted directory vulnerability allows a privileged attacker to read and write files on the underlying Linux system via crafted CLI commands. This along with two other bugs (CVE-2022-22948 and CVE-2023-20867) are being leveraged by a China-nexus threat actor to sustain prolonged system access.
Affected products: Router models: Fortinet FortiOS version 7.2.0 through 7.2.3, 7.0.0 through 7.0.9 and before 6.4.11.
Tags: DIB, tlp:green