ZeroFox Cyber Intelligence Daily Brief - June 28, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - June 28, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- ZeroFox Intelligence Flash Report - IntelBroker Sells Zero-Day Vulnerability Leveraged in Recent Attacks
- Arkansas-Based Evolve Bank Confirms Cyber Attack and Data Breach
- CISA Releases Seven Industrial Control Systems Advisories
ZeroFox Intelligence Flash Report - IntelBroker Sells Zero-Day Vulnerability Leveraged in Recent Attacks
Source: https://www.zerofox.com/advisories/23980/
What happened: Prominent and well-regarded threat actor “IntelBroker” registered an account on the popular illicit hacking forum BreachForums—one day after removing themselves from the platform. IntelBroker has been observed promoting illicit access to networks and data breaches across various industries.
Why it matters: Shortly after returning to the forum, IntelBroker began advertising numerous illicit network accesses and data breaches targeting high-profile organizations from a multitude of industries. The majority of these attacks alluded to the exploitation of an unspecified vulnerability targeting Atlassian software. On June 16, IntelBroker advertised the sale of a zero-day vulnerability that targets Atlassian Jira software via remote code execution. This was purchased by an unknown actor between June 20 and June 24, though it is unlikely that IntelBroker received the exorbitant asking price of USD 800,000. The details provided in the announcement of the three attacks were almost certainly intended to serve as an advertisement or proof of concept (POC) for the zero-day vulnerability.
Arkansas-Based Evolve Bank Confirms Cyber Attack and Data Breach
What happened: Evolve Bank and Trust confirmed a cybersecurity incident that resulted in customers' data being released on the dark web. The bank has engaged appropriate law enforcement agencies to help in its current investigation and response efforts.
Why it matters: The exposure of sensitive employee information could lead to identity theft, fraud, phishing attacks, and other malicious activities. The compromised banking data poses a severe threat to customer privacy and financial security.
CISA Releases Seven Industrial Control Systems Advisories
What happened: CISA recently issued seven advisories addressing vulnerabilities, and exploits in Industrial Control Systems (ICS). These advisories highlight security issues such as authentication bypass, remote code execution (RCE), injection of malicious scripts, and unauthorized access to sensitive information within SCADA (Supervisory Control and Data Acquisition) systems.
Why it matters: The impact of these vulnerabilities extends beyond mere security breaches. Successful exploitation of these vulnerabilities could lead to unauthorized control of critical infrastructure, manipulation of operational data, and exposure of sensitive information. In the context of industrial control environments, any compromise poses significant risks to operational safety, reliability, and regulatory compliance. Moreover, these systems often manage essential services, making them prime targets for malicious actors seeking to disrupt operations or steal valuable intellectual property. Patching these vulnerabilities is crucial to mitigating the risks posed by malicious exploitation. By applying the recommended security updates and mitigations outlined in the CISA advisories, organizations can prevent attackers from bypassing authentication, executing remote code, injecting malicious commands, or gaining unauthorized access to critical systems.
DEEP AND DARK WEB INTELLIGENCE
Threat actor group Team ARXU: Threat actor group Team ARXU has claimed to sell 13.6 million users' data from multiple Indian banks. The leaked package includes customers' information such as account number, account name, IFSC code, phone number, and email addresses.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2024-5655: An issue was discovered in GitLab CE/EE affecting all versions starting from 15.8 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows an attacker to trigger a pipeline as another user under certain circumstances.
Affected products: All GitLab CE/EE versions from 15.8 through 16.11.4, 17.0.0 to 17.0.2, and 17.1.0 to 17.1.0.
CVE-2022-24816: JAI-EXT is an open-source project which aims to extend the Java Advanced Imaging (JAI) API. Programs allowing Jiffle script to be provided via network request can lead to a Remote Code Execution as the Jiffle script is compiled into Java code via Janino, and executed. In particular, this affects the downstream GeoServer project. Version 1.2.22 will contain a patch that disables the ability to inject malicious code into the resulting script. Users unable to upgrade may negate the ability to compile Jiffle scripts from the final application, by removing janino-x.y.z.jar from the classpath. CISA added this vulnerability to its Known Exploited Vulnerability (KEV) Catalog on 26 June, 2024.
Affected product: GeoServer project version 1.2.22.
Tags: DIB, tlp:green