zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - June 21, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - June 21, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Barriers to Single Sign-On (SSO) Adoption for Small and Medium-Sized Businesses
  • Crooks Get Their Hands on Over 500,000 Radiology Patients' Records in Cyberattack
  • Chinese Cyber Espionage Targeting Telecom Operators in Asia Since 2021

Barriers to Single Sign-On (SSO) Adoption for Small and Medium-Sized Businesses

Source: https://www.cisa.gov/resources-tools/resources/barriers-single-sign-sso-adoption-small-and-medium-sized-businesses-identifying-challenges-and

What happened: CISA released a report to help small and medium businesses deal with the challenges of single-sign-on (SSO) adoption. The report also summarizes views of vendors and customers and provides a set of recommendations for encouraging SSO adoption.

Why it matters: SSO is a user authentication and access control system that allows users to access multiple applications, tools, and systems with just one set of credentials. By centralizing the authentication process, SSO streamlines identity management and simplifies the user experience by only needing to remember one username and password for all accounts. Furthermore, SSO can reduce password duplication across various platforms, consequently reducing the potential for password leakage.

Crooks Get Their Hands on Over 500,000 Radiology Patients' Records in Cyberattack

Source: https://www.theregister.com/2024/06/20/radiology_information_loss/

What happened: Consulting Radiologists, a Minnesota-based healthcare provider, experienced a cyberattack in February where digital intruders accessed the personal and medical information of over 500,000 patients. The healthcare provider has notified patients that currently there is no evidence of misuse of their disclosed information.

Why it matters: This breach is significant due to the scale and sensitivity of the compromised data such as names, addresses, dates of birth, Social Security numbers, health insurance information, and medical records impacting over half a million individuals across the upper Midwest America. The stolen information, including highly personal details and medical records, poses serious risks of identity theft, fraud, and potential misuse of medical services or prescriptions, perpetrate financial scams, and create sophisticated phishing attacks targeting affected individuals or related healthcare providers, and more.

Chinese Cyber Espionage Targeting Telecom Operators in Asia Since 2021

Source: https://thehackernews.com/2024/06/chinese-cyber-espionage-targets-telecom.html

What happened: China-linked threat actors have been observed in several campaigns where telecom operators of an Asian country were infiltrated. The attackers allegedly deployed backdoors on the networks of targeted companies and attempted to also steal credentials.

Why it matters: Researchers suspect that the attacks might be conducted independently, by a single threat actor using tools acquired from other groups, or by diverse actors collaborating on a single campaign. These cyber operations pose a serious threat to governments, business, and critical infrastructure networks. Such attacks can expose confidential data to malicious adversaries with geo-political and financial motives to interfere or cause significant damage to a country’s infrastructure.

DEEP AND DARK WEB INTELLIGENCE

Threat actor 888: Threat actor 888 claimed to have leaked a database associated with Accenture on the predominantly English-language dark web forum, “BreachForums." The threat actor noted that Accenture suffered a data breach from a third party company that exposed 32,826 employees/former employees data.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2024-0762: A new vulnerability (CVE-2024-0762) in Phoenix SecureCore UEFI firmware affects devices with various Intel CPUs. Lenovo has already issued updates to fix the flaw, dubbed 'UEFICANHAZBUFFEROVERFLOW.' This vulnerability allows attackers to execute code via a buffer overflow in the Trusted Platform Module (TPM) configuration of the firmware.

Affected products: Lenovo ThinkPad X1 Carbon 7th Gen, X1 Yoga 4th Gen devices, SecureCore firmware for Alder Lake, Coffee Lake, Comet Lake, Ice Lake, Jasper Lake, Kaby Lake, Meteor Lake, Raptor Lake, Rocket Lake, and Tiger Lake Intel CPUs

CVE-2024-34102: A critical vulnerability, CVE-2024-34102 (CVSS version 3.x score: 9.8), dubbed "CosmicSting," affecting Adobe Commerce and Magento websites, remains largely unpatched after a security update was released, leaving millions of sites vulnerable to attacks. Approximately three out of four affected sites are vulnerable to XML external entity injection (XXE) and remote code execution (RCE) attacks.

Affected products:

  • Adobe Commerce 2.4.7 and earlier, including 2.4.6-p5, 2.4.5-p7, 2.4.4-p8
  • Adobe Commerce Extended Support 2.4.3-ext-7 and earlier, 2.4.2-ext-7 and earlier, 2.4.1-ext-7 and earlier, 2.4.0-ext-7 and earlier, 2.3.7-p4-ext-7 and earlier.
  • Magento Open Source 2.4.7 and earlier, including 2.4.6-p5, 2.4.5-p7, 2.4.4-p8
  • Adobe Commerce Webhooks Plugin versions 1.2.0 to 1.4.0

Tags: DIB, tlp:green