zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - June 30, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - June 30, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • ZeroFox Intelligence Brief - Cyber Threats to UK Elections
  • 30 Million Potentially Affected in Ticketek Australia Cloud Breach
  • Apple Addresses Bluetooth Vulnerability in AirPods Security Patch

ZeroFox Intelligence Brief - Cyber Threats to UK Elections

Source: https://www.zerofox.com/advisories/23903/

What happened: ZeroFox assesses that foreign threat actors pose a significant risk to the upcoming UK elections, potentially influencing public opinion via multiple avenues—including distributing disinformation campaigns, hacking voter databases, or attempting to disrupt voting processes. The threat to the UK elections from misinformation and disinformation is also likely to be high and could affect the election outcomes.

Why it matters: As was the case in the 2019 elections, the greatest disinformation threat comes from contesting political parties within the country. There have been targeted political ads, intensified by higher campaign spending limits and artificial intelligence (AI). The 2024 UK elections are taking place during a period of massive weaponization of cyberspace for covert, as well as overt, digital influence and intimidation campaigns. Many of the cyber instances ZeroFox discovered (including the propagation of deepfakes, tactical disclosure of “technically legitimate” half-truths in malinformation campaigns, and stealthy-yet-mass-scale disinformation campaigns) are at least partially designed to influence voter behavior to narrow the margin of a Labour victory or a Conservative defeat. ZeroFox discovered geopolitical and financially motivated data breaches and distributed denial-of-service (DDoS) attacks conducted by so-called “hacktivists'' tied to the election as well.

30 Million Potentially Affected in Ticketek Australia Cloud Breach

Source: https://www.darkreading.com/cloud-security/30m-affected-tickettek-australia-cloud-breach

What happened: ShinyHunters claimed an attack on Ticketek, where the threat group allegedly stole 30 million user data. According to Ticketek’s statement, no payment information has been breached but other information like customer names, dates of birth, and email addresses are likely to have been impacted.

Why it matters: This incident shares similarities with the Snowflake breach where a compromised third party was targeted by ShinyHunters as well. Recent third-party breaches indicate a growing trend that demonstrates an upward trajectory of stolen personally identifiable information (PII) that are vulnerable due to poor cybersecurity hygiene. A lack of multifactor authentication in place and regular password rotation has been attributed as the main factor in these breaches.

Apple Addresses Bluetooth Vulnerability in AirPods Security Patch

Source: https://support.apple.com/en-us/HT214111

What happened: Apple has released a firmware update for its AirPods, addressing a vulnerability (CVE-2024-27867) that could allow attackers to spoof paired devices and eavesdrop on conversations.

Why it matters: The flaw impacts several models, including AirPods (2nd generation and later), AirPods Pro, AirPods Max, Powerbeats Pro, and Beats Fit Pro. By exploiting this flaw, an attacker could intercept Bluetooth signals and gain access to the headphones, compromising the privacy and confidentiality of conversations. It arises during the connection process when the headphones seek to connect to a previously paired device, which grants unauthorized access to the headphones, potentially allowing the attacker to eavesdrop on private conversations. The impact extends beyond mere inconvenience, as unauthorized access to personal audio devices could lead to privacy breaches and potential leakage of sensitive information. Users are advised to apply the update immediately to safeguard their devices against potential exploitation.

Tags: DIB, tlp:green