ZeroFox Cyber Intelligence Daily Brief - June 25, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - June 25, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- CISA Warns of Hackers Breaching Chemical Security Tool, Exposing Sensitive Data
- 30 Million Potentially Affected in Ticketek Australia Cloud Breach
- Actor Declared Its Intent to Target France and the Paris Olympics
CISA Warns of Hackers Breaching Chemical Security Tool, Exposing Sensitive Data
What happened: CISA’s Chemical Security Assessment Tool (CSAT) was breached between January 23-26, 2024, by hackers who deployed a web shell on a specific device. This breach potentially exposed sensitive data, including Top-Screen surveys, Security Vulnerability Assessments, Site Security Plans, and Personnel Surety Program submissions.
Why it matters: Even though CISA notes the lack of evidence for data theft, the potential risks of unauthorized access to highly sensitive information led to CISA notifying impacted entities. Besides, the breach exploited known vulnerabilities, emphasizing the importance of timely security updates and thorough incident response protocols to safeguard against such intrusions. Moreover, the Chemical Sector manufactures, stores, uses, and transports potentially dangerous chemicals on which other critical infrastructure sectors rely. Adversaries accessing sensitive information can lead to more serious attacks on critical infrastructure. Additionally, the accessed information is likely to attract the attention of state-sponsored actors, who might be interested in the sensitive data to use in attacks fuelled by more geopolitical motives.
30 Million Potentially Affected in Ticketek Australia Cloud Breach
Source: https://www.darkreading.com/cloud-security/30m-affected-tickettek-australia-cloud-breach
What happened: ShinyHunters claimed an attack on Ticketek where the threat group allegedly stole 30 million user data. According to its statement, no payment information has been breached but other information like customer names, dates of birth, and email addresses are likely to have been impacted.
Why it matters: This incident shares similarities with the Snowflake breach where a compromised third party was targeted by ShinyHunters as well. Recent third-party breaches indicate a growing trend that demonstrates an upward trajectory of stolen personally identifiable information (PII) that are vulnerable due to poor cybersecurity hygiene. A lack of multifactor authentication in place and regular password rotation has been attributed as the main factor in these breaches.
Actor Declared Its Intent to Target France and the Paris Olympics
Source: https://cloud.zerofox.com/intelligence/advanced_dark_web/66297
What happened: On June 23, pro-Russia threat actor Cyber Army Russia Reborn claimed to target France with distributed denial of service (DDoS) attacks. The threat actor claims that it will continue to conduct DDoS campaigns as the Paris Olympics approach with the support of allies like Noname057(16), Hacknet, People's CyberArmy.
Why it matters: Russian state-sponsored cyber threat activity poses the greatest risk to the Olympics, with the potential for disruptive and destructive operations targeting the Games. Such activities could include website defacements, DDoS attacks, deployment of wiper malware, and operational technology (OT) targeting. As a high-profile, large-scale sporting event with a global audience, the Olympics presents an ideal stage for these operations, significantly magnifying the impact of any disruptions, causing negative psychological effects, and damaging reputations.
DEEP AND DARK WEB INTELLIGENCE
BreachForums user emocat: On June 23, 2024, threat actor "emocat" claimed to have leaked data associated with Interpol Argentina on the predominantly English-language dark web forum, “BreachForums."
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2024-37032: Cybersecurity researchers are now warning of this critical flaw in Ollama's AI platform that can potentially allow remote code execution. The issue, dubbed Probllama, was fixed on May 7, 2024, after disclosure.
Affected products: Versions of Ollama before 0.1.34.
CVE-2024-6101: This flaw stems from an inappropriate implementation in V8 in Google Chrome that allows a remote attacker to perform out of bounds memory access via a crafted HTML page.
Affected products: Google Chrome versions prior to 126.0.6478.114
Tags: DIB, tlp:green