zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - July 16, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - July 16, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Data of Millions of mSpy Customers Leaked Online
  • Threat Actor Leaks Disney’s Internal Communication on Dark Web Forum
  • Hacker Claims to Leak Data Associated with BMW

Data of Millions of mSpy Customers Leaked Online

Source: https://www.securityweek.com/data-of-millions-of-mspy-customers-leaked-online/

What happened: Hacktivists have reportedly stolen and leaked more than 300 GB of data from spyware maker mSpy. The breached data includes 142 GB of user data and support tickets, 176 GB of attachments, 2.4 million unique email addresses, and more. The data leak reportedly occurred as a result of a breach in a specific account linked to a customer-support system.

Why it matters: mSpy is a “parental control application” which allows users to monitor and log the activity of specific device users. The recent data leak exposed a decade's worth of data that showed the application's notorious use in surveillanceware by actors to monitor individuals secretly in real time without their consent or knowledge. The leaked data exposed data linked to civilians, “senior-ranking U.S. military personnel, a serving U.S. federal appeals court judge, a U.S. government department’s watchdog, and an Arkansas county sheriff’s office seeking a free license to trial the app.” Sensitive data leaked at this scale places vulnerable entities like children and other individuals exposed to stalkers, which endangers them to kidnappings and further monitoring. With the collected data, threat actors can conduct targeted surveillance, monitor communications, and track physical movements, posing significant risks to privacy and security.

Threat Actor Leaks Disney’s Internal Communication on Dark Web Forum

Source: https://cloud.zerofox.com/intelligence/advanced_dark_web/67116

What happened: Threat actor “NullBulge” claimed to have leaked a database associated with Disney on dark web forum BreachForums. The threat actor allegedly gained access to Disney's internal Slack, which exposed 1.1 TB of data, including almost 10,000 channels, messages and files, unreleased projects, raw images and code, some logins, links to internal APIs/web pages, and more.

Why it matters: The leaked database poses significant risks to Disney as it includes unreleased projects, internal communications, and sensitive information like logins and API access. This breach could lead to intellectual property theft, compromising Disney's competitive advantage and potentially harming its brand reputation. Threat actors could further exploit the leaked data to launch targeted phishing attacks against employees or users, manipulate stock prices with insider information, or sell proprietary content on illicit platforms. Moreover, access to internal APIs and web pages could facilitate further infiltration into Disney's systems, enabling more extensive cyberattacks or data breaches.

Hacker Claims to Leak Data Associated with BMW

Source: https://cloud.zerofox.com/intelligence/advanced_dark_web/67125

What happened: ZeroFox intelligence has observed threat actor 888 claiming to have leaked a database allegedly associated with BMW customers located in Hong Kong on BreachForums. The leaked data supposedly includes salutations, surnames, first names, mobile numbers, and opt-out SMS preferences.

Why it matters: The threat actor has claimed that the database has been sourced from a data breach BMW suffered this year, which exposed nearly 14,000 rows of customer data. In February, researchers discovered a misconfigured cloud storage server belonging to BMW that exposed sensitive information, reportedly including private keys for BMW’s cloud services in China, Europe, and the United States. At the time of reporting, it is not evident if the recent breach resulted from the misconfigured server. Impacted individuals of the alleged breach may face targeted phishing attacks, an influx of spam messages, blackmail, extortion scams, and potential identity theft. Additionally, the breach can lead to unauthorized changes in SMS preferences, causing users to miss important communications. The exposure of such details erodes privacy and trust, and makes individuals vulnerable to further exploitation.

DEEP AND DARK WEB INTELLIGENCE

  • XSS user Str0ng: Untested threat actor "Str0ng" advertised a data breach impacting Federal Government Advisors, United States, on the predominantly Russian language dark web forum "XSS." According to Str0ng, the 5 GB breached data contains an exfiltrated award contracts table. The actor charged USD 350 for the breach package.

VULNERABILITY AND EXPLOIT INTELLIGENCE

  • CVE-2024-36401: CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog (KEV), based on evidence of active exploitation. These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise.

  • Affected products: GeoServer prior to versions 2.23.6, 2.24.4, and 2.25

Tags: DIB, tlp:green