ZeroFox Cyber Intelligence Daily Brief - June 26, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - June 26, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- ZeroFox Intelligence Brief - Cyber Threats to UK Elections
- Russian Satellite Interference Under Review After International Complaints
- Indonesia Refuses to Pay USD Eight Million Ransom After Cyberattack
ZeroFox Intelligence Brief - Cyber Threats to UK Elections
Source: https://www.zerofox.com/advisories/23903/
What happened: ZeroFox assesses that foreign threat actors pose a significant risk to the upcoming UK elections, potentially influencing public opinion via multiple avenues—including distributing disinformation campaigns, hacking voter databases, or attempting to disrupt voting processes. The threat to the UK elections from misinformation and disinformation is also likely to be high and could affect the election outcomes.
Why it matters: As was the case in the 2019 elections, the greatest disinformation threat comes from contesting political parties within the country. There have been targeted political ads, intensified by higher campaign spending limits and artificial intelligence (AI). The 2024 UK elections are taking place during a period of massive weaponization of cyberspace for covert, as well as overt, digital influence and intimidation campaigns. Many of the cyber instances ZeroFox discovered (including the propagation of deepfakes, tactical disclosure of “technically legitimate” half-truths in malinformation campaigns, and stealthy-yet-mass-scale disinformation campaigns) are at least partially designed to influence voter behavior to narrow the margin of a Labour victory or a Conservative defeat. ZeroFox discovered geopolitical and financially motivated data breaches and distributed denial-of-service (DDoS) attacks conducted by so-called “hacktivists'' tied to the election as well.
Russian Satellite Interference Under Review After International Complaints
Source: https://www.reuters.com/world/un-body-reviews-allegations-russian-satellite-interference-2024-06-25/
What happened: The International Telecommunications Union (ITU) is reviewing complaints from Ukraine and European countries about satellite interference impacting navigation services and television broadcasts. The interference, which includes GPS jamming and broadcasting violent images on children's TV channels, has prompted Ukraine and other nations to request ITU intervention to stop the disruptions.
Why it matters: Global satellite networks are lucrative targets for state-sponsored adversaries, acting with geopolitical intentions, spreading propaganda and influencing target populaces. Besides, such cyberattacks can lead to more tangible threats. The jamming of GPS signals can significantly disrupt air traffic control, potentially endangering lives and impacting commerce. The manipulation of television broadcasts to insert violent war images is likely a psychological warfare weapon to harm people directly. Moreover, accusations of sabotage between Russia and NATO countries further complicate international relations amid the ongoing Russia-Ukraine war. An active attempt to interfere with another country’s satellites spells the possibility of such geopolitical tensions spilling over into the realms of cybersecurity and space.
Indonesia Refuses to Pay USD Eight Million Ransom After Cyberattack
What happened: A cyberattack on Indonesia’s data centers impacted close to 200 government agencies and have left many of its systems down, some of which are now becoming operational again. The threat actors responsible have demanded USD eight million in return for the decryptor. The Indonesian government is reportedly refusing to pay the ransom demand.
Why it matters: The ransomware used to withhold the information is currently suspected to be LockBit 3.0 ransomware. LockBit has been observed in the past to mostly target governments and critical infrastructure. The recent uptick in activity could indicate that LockBit is attempting to regain its pre-takedown status through high-profile attacks, including a claim of such an attack on a prominent U.S. financial organization. ZeroFox has detected over 650 victims of LockBit ransomware in the past year, of which close to 20 percent targeted the government and critical infrastructure sectors.
DEEP AND DARK WEB INTELLIGENCE
Telegram user Blackjack: A pro-Ukraine hacktivist group Blackjack has claimed to have processed 120 TB of data stolen from aviation enterprise PJSC “Agregat”, a Russia-based manufacturer of hydraulic and pneumatic systems for aircrafts that caters to a Russian military organization.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2024-29176: Certain Dell PowerProtect DD versions contain a buffer overflow vulnerability. A remote low privileged attacker could potentially exploit this vulnerability, leading to an application crash or execution of arbitrary code on the vulnerable application's underlying operating system with privileges of the vulnerable application.
Affected products:
- Dell PowerProtect DD version prior to 8.0
- Dell PowerProtect DD version prior to LTS 7.13.1.0
- Dell PowerProtect DD version prior to LTS 7.10.1.30
- Dell PowerProtect DD version prior to LTS 7.7.5.40
CVE-2024-5181: A command injection vulnerability exists in the mudler/localai version 2.14.0. The vulnerability arises from the application's handling of the backend parameter in the configuration file, which is used in the name of the initialized process. An attacker can exploit this vulnerability by manipulating the path of the vulnerable binary file specified in the backend parameter, allowing the execution of arbitrary code on the system. This issue is due to improper neutralization of special elements used in an OS command, leading to potential full control over the affected system.
Affected product: Mudler/localai version 2.14.0.
Tags: DIB, tlp:green