ZeroFox Cyber Intelligence Daily Brief - June 29, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - June 29, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Threat Actor Claims to Target Abu Dhabi International Airport in a DDoS Attack
- Indonesia President Orders Audit of Data Centres After Cyberattack
- Oyster Backdoor Spreading via Trojanized Popular Software Downloads
Threat Actor Claims to Target Abu Dhabi International Airport in a DDoS Attack
Source: https://cloud.zerofox.com/intelligence/advanced_dark_web/66483
What happened: Threat actor SN_Blackmeta has claimed to have conducted a two-hour-long distributed denial-of-service (DDoS) attack against Zayed International Airport, also known as Abu Dhabi International Airport.
Why it matters: DDoS attacks against airports can lead to operational disruptions, financial losses, flight delays, cancellations, and interference with signaling, thereby potentially threatening lives. ZeroFox has also observed threat actor “GHOSTR” claiming to have breached certain systems of Arabian Travel Agency, one of the oldest travel agencies in the UAE, and exfiltrated some data. While ZeroFox cannot confirm if the two actors were politically motivated to conduct these alleged attacks, SN_Blackmeta has previously claimed alliance with the pro-Palestine stance. The UAE’s political inclinations will likely drive more threat actors opposed to its stance to target more of the country’s entities. Additionally, the UAE's rapid technological advancements and wealth make it an attractive target for financially motivated cybercriminals seeking ransom or data theft.
Indonesia President Orders Audit of Data Centres After Cyberattack
What happened: The recent breach into Indonesia’s data centers revealed that most of its data was not backed up prompting the president, Joko Widodo, to order an audit. The head of Indonesia's Development and Finance Controller (BPKP) confirmed that that audit will cover "governance and the financial aspect(s)."
Why it matters: At the time of writing, it is still unclear the threat group/actor behind this attack, although authorities observe that an existing malicious software called Lockbit 3.0 was used. LockBit has in the past been observed to target government agencies and cause city-wide disruptions. The recent uptick in activity could indicate that LockBit is attempting to regain its pre-takedown status through high-profile attacks, including a claim of such an attack on a prominent U.S. financial organization.
Critical Flaws in Gas Chromatographs Expose Major Security Risks
Source: https://thehackernews.com/2024/06/researchers-warn-of-flaws-in-widely.html
What happened: Recent revelations highlight severe security vulnerabilities in Emerson Rosemount gas chromatographs, including two command injection flaws and two separate authentication and authorization vulnerabilities. These flaws are present in GC370XA, GC700XA, and GC1500XA models running versions 4.1.5 and earlier. Emerson has released updated firmware to address these vulnerabilities.
Why it matters: The chromatograph, essential for critical gas measurements, is managed via MON software. MON facilitates configuration, data storage, and report generation, including chromatograms, alarm history, event logs, and maintenance logs. This integration enhances efficiency and reliability in gas measurement processes. Vulnerabilities in these machines, including command injection and authentication bypass vulnerabilities, pose severe risks by allowing attackers to gain admin capabilities, execute commands with root privileges, cause system disruptions, access sensitive data, and trigger denial-of-service (DoS) attacks. These vulnerabilities underline the importance of securing OT devices, as their compromise can lead to substantial operational impacts and potential safety hazards.
DEEP AND DARK WEB INTELLIGENCE
- Telegram user Moroccan Black Cyber Army: Pro-Palestine threat actor Moroccan Black Cyber Army group has announced that one of its team members was arrested by French intelligence and police. The group stated that it will continue its attacks against Israel and the French government upon their return.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2020-13965: A medium severity (CVSS score: 6.5) issue was discovered in Roundcube Webmail. There is XSS via a malicious XML attachment because text/xml is among the allowed types for a preview. CISA added this vulnerability to its Known Exploited Vulnerability (KEV) Catalog on 26 June, 2024.
Affected products: Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5.
Tags: DIB, tlp:green