zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - August 7, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - August 7, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • French Police Probes Ransomware Attack on Grand Palais Olympic Venue
  • Thousands of Devices Wiped by Breach Affecting Classroom Management Platform
  • CISA Releases Secure by Demand Guidance

French Police Probes Ransomware Attack on Grand Palais Olympic Venue

Source: https://presse.rmngp.fr/le-grandpalaisrmn-vise-par-une-cyberattaque/

What happened: French cybercrime police are probing a ransomware attack on the Grand Palais Réunion des musées nationaux (Rmn) in Paris, where Olympic events like fencing and Taekwondo are being held. The central computer system, which also oversees data for 40 smaller museums, was targeted but no disruption to the Olympic events occurred.

Why it matters: While the attack did not disrupt the ongoing events, it underscores the broader risk of cyber threats during major international gatherings. The cyber criminals demanded a ransom and threatened to leak financial data, raising concerns about data security and the potential for broader impacts on affiliated museums. The data leak could result in significant financial losses for the museums, damage their reputation, and expose individuals to identity theft and fraud. With Paris hosting the Olympics, threat actors see an opportunity to exploit the global attention for financial gain or to cause operational chaos. As the Olympics attract global scrutiny, maintaining operational integrity and safeguarding sensitive data becomes crucial for organizers and affiliated institutions. Just ahead of the Paris Olympics, many threat actors have been observed collaborating to intensify DDoS campaigns against France, leveraging their combined resources and expertise to disrupt the event.

Thousands of Devices Wiped by Breach Affecting Classroom Management Platform

Source: https://www.bleepingcomputer.com/news/security/hacker-wipes-13-000-devices-after-breaching-classroom-management-platform/

What happened: A data breach affecting Mobile Guardian, a globally used digital classroom management platform, has wiped data from over 13,000 students’ systems. The company has confirmed that a hacker gained unauthorized access to the platform, impacting its instances in North America, Europe, and Singapore.

Why it matters: In light of the incident, the Singaporean Ministry of Education has announced the removal of the Mobile Guardian Device Management Application from all iPads and Chromebooks in the country. Among the affected users are students from secondary schools. Although investigations are yet to reveal the type of information exposed, it is likely to include sensitive information such as student names, addresses, grades, and behavioral records. The personal data of the users, including minors, can be exploited for identity theft, cyberbullying, and phishing attacks.

CISA Releases Secure by Demand Guidance

Source: https://www.cisa.gov/news-events/alerts/2024/08/06/cisa-releases-secure-demand-guidance

What happened: CISA and the Federal Bureau of Investigation (FBI) have released a “secure by demand” guidance to help organizations drive a secure technology ecosystem by ensuring their software manufacturers prioritize secure technology from the start. This guidance is aimed at helping company’s ​​assess whether a given supplier has practices and policies in place to ensure that security is a core consideration from the earliest stages of the product development lifecycle.

Why it matters: According to the guidance, customers need to focus on how a manufacturer approaches product security. Enterprise security refers to practices to protect a company’s own infrastructure and operations, while product security refers to actions the software manufacturer takes to ensure the products they deliver are secure against attackers. There are many compliance standards that organizations use during procurement that focus on enterprise security; conversely, relatively few focus on product security. This guide bridges that gap by offering resources organizations can leverage to assess product security maturity and whether a manufacturer follows secure by design principles.

DEEP AND DARK WEB INTELLIGENCE

BreachForums user Fenice: On August 6, 2024, threat actor Fenice posted a link to download the dataset related to a breach affecting the National Public Data, a U.S.-based a public records data provider, on the predominantly English-language dark web forum BreachForums. Earlier on April 7, 2024, threat actor USDoD posted a sample associated with National Public Data breach on Breachforums. It was reported that actor USDoD was a middle man for the initial posting. Both actors, Fenice and USDoD, credited threat actor SXUL for the breach.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2024-7502: A crafted DPA file could force Delta Electronics DIAScreen to overflow a stack-based buffer, which could allow an attacker to execute arbitrary code.

Affected products: IAScreen versions prior to 1.4.2

CVE-2024-7565: This vulnerability allows remote attackers to execute arbitrary code on affected installations of SMARTBEAR SoapUI. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the unpackageAll function. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context of the current user.

Affected product: SoapUI

Tags: DIB, tlp:green