ZeroFox Cyber Intelligence Daily Brief - July 4, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - July 4, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- ZeroFox Intelligence Flash Report - New Extended Validation Code Signing Service Advertised
- F1 Governing Body Discloses Data Breach Following Email Compromise
- South Africa National Healthcare Lab Still Reeling from Ransomware Attack
ZeroFox Intelligence Flash Report - New Extended Validation Code Signing Service Advertised
Source: https://www.zerofox.com/advisories/24155/
What happened: Untested actor “enryu” advertised a new extended validation (EV) code signing service on the primarily Russian-speaking dark web forum Exploit. According to the advertisement, illicit validation certificates can be purchased, which allow malicious webpages to bypass security protocols such as SmartScreen, Windows User Account Control, and Windows Defender, as well as some antivirus (AV) software provided by third parties.
Why it matters: Illicit validation certificates offer cyber threat actors the ability to augment a wide array of malicious activities, such as the deploying of disruptive malware to target networks, enhanced social engineering attacks, or data theft resulting in operational disruption, extortion or fraud. Given the versatility offered by initial network access, services such as these are very likely to appeal to a wide range of threat actors with varying intents and motivations, leading to their continued development, competitiveness, and innovation.
F1 Governing Body Discloses Data Breach Following Email Compromise
Source: https://www.fia.com/news/fia-statement-regarding-recent-data-incident
What happened: FIA (Fédération Internationale de l'Automobile), the governing body for Formula 1 (F1), reported that personal data was accessed by attackers who compromised multiple FIA email accounts through a phishing attack.
Why it matters: The breach at FIA not only compromised the privacy of individuals associated with the organization but also highlights the pervasive threat of phishing attacks in the digital age. With access to personal data from FIA email accounts, threat actors can potentially engage in identity theft, phishing campaigns targeting individuals associated with F1, and even attempt to exploit vulnerabilities within F1's digital infrastructure. This breach could further lead to compromised confidentiality of strategic information, sponsor relationships, and sensitive operational details. Prompt action by the FIA to mitigate unauthorized access demonstrates a proactive approach to data security, while notifying relevant data protection regulators ensures transparency and compliance with legal obligations.
South Africa National Healthcare Lab Still Reeling from Ransomware Attack
What happened: South Africa's National Health Laboratory Service (NHLS) is still recuperating from a ransomware attack that disrupted systems and deleted backups in late June 2024. The cyberattack blocked laboratories' information systems communicating with other medical databases resulting in delays in lab testing across public health facilities.
Why it matters: The ransomware disruption in South Africa could potentially worsen the existing stress on its healthcare systems, especially amid an mpox outbreak that has reportedly caused three deaths since May. Public hospitals and clinics are now facing increased pressure on their testing capabilities, as systems need to be shut down to recover from the ransomware attack. This will further delay the processing of lab tests in public health facilities, compounding the challenges faced by the healthcare sector during this critical time.
DEEP AND DARK WEB INTELLIGENCE
BreachForums user "injectioninferno": Threat actor "injectioninferno" claimed to have leaked a database associated with Banco Falabella, Chile on the predominantly English-language dark web forum, BreachForums. The threat actor allegedly leaked a sample package containing usernames.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2024-39309: Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. A vulnerability in versions prior to 6.5.7 and 7.1.0 allows SQL injection when Parse Server is configured to use the PostgreSQL database. The algorithm to detect SQL injection has been improved in versions 6.5.7 and 7.1.0. No known workarounds are available.
Affected products: Parse Server versions prior to 6.5.7 and 7.1.0
Tags: DIB, tlp:green