ZeroFox Cyber Intelligence Daily Brief - July 15, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - July 15, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Rite Aid Confirms Data Breach After June Ransomware Attack
- IDF Computer Chief: 3 Billion Cyberattacks Against Israel Since Beginning of War
- Massive AT&T Data Breach Exposes Sensitive Customer Records
Rite Aid Confirms Data Breach After June Ransomware Attack
What happened: Rite Aid is conducting an investigation into a recent cyberattack, which was claimed by the RansomHub ransomware group. The company confirms that no “Social Security numbers, financial information, or patient information” were affected by the cyberattack.
Why it matters: A dark web post by the RansomHub group claims they stole 10 gigabytes of data from Rite Aid, including customer ID numbers and rewards numbers. RansomHub appears to focus on data-theft-based extortion rather than encrypting files to demand ransom payments. The company reportedly ended negotiations with the threat group, prompting them to threaten to leak the data in two weeks
IDF Computer Chief: 3 Billion Cyberattacks Against Israel Since Beginning of War
What happened: The Israel Defense Forces’ (IDF) cloud computing network experienced over three billion cyberattacks following the outbreak of war between Israel and Hamas on October 7, 2023, but all of the attacks were successfully intercepted and reportedly did not result in significant damage. The attacks targeted the operational cloud computing used by various systems serving troops on the ground, aiming to disrupt information sharing and the location of forces.
Why it matters: This event is significant because it highlights the increasing prevalence of cyber warfare in conflicts. The fact that the IDF's cloud computing network successfully fended off over three billion cyberattacks shows the critical importance of cybersecurity in military operations. It also demonstrates the evolving nature of warfare, where adversaries seek to target and disrupt digital infrastructure. The successful defense of the military's remote servers by Mamram, the IDF’s central computing system unit, underscores the vital role played by cybersecurity measures in safeguarding sensitive military information and maintaining operational continuity during times of conflict.
Massive AT&T Data Breach Exposes Sensitive Customer Records
Source: https://www.att.com/support/article/my-account/000102979
What happened: AT&T has alerted its customers and partners of a data breach, where adversaries illegally accessed customer data from its workspace and downloaded it on a third-party cloud platform. Investigations revealed that the breached data included phone call and text message records of “nearly all” AT&T cellular customers from May 2022 to October 2022 and January 2023.
Why it matters: An AT&T spokesperson has reportedly attributed the breach to Snowflake’s cloud services. Snowflake has grappled with a significant cyberattack that compromised sensitive customer data since early June. This impactful interconnected chain of attacks has led to cascading effects of compromised credentials, where access to one system can be leveraged to breach others. The volume of data exposed and the nature of the same, including sensitive personal and financial information, pose significant risks for individuals and organizations alike, with potential consequences ranging from identity theft to financial fraud, and more. Besides, the array of lucrative targets and the lure of high ransom payments may provide threat actors with a blueprint for developing more sophisticated digital extortion tactics to target third-party cloud services.
DEEP AND DARK WEB INTELLIGENCE
- BreachForums user infamous: On July 10, 2024, threat actor "infamous" claimed to have leaked a database associated with VNPT Ha Nam, a Vietnam-based telecommunications service provider, for USD 2,000 on the predominantly English-language dark web forum BreachForums.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2022-21587: Successful attacks of this critical vulnerability can result in takeover of Oracle Web Applications Desktop Integrator. It was highlighted in a recent CISA advisory for being used by threat actors to install Python remote access tool (RAT).
Affected products: Oracle E-Business Suite versions 12.2.3-12.2.11
Tags: DIB, tlp:green