zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - August 12, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - August 12, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Donald Trump’s Campaign Says Its Emails Were Hacked
  • Fake X Content Warnings on Earthquakes and War Lure Users to Scam Sites
  • GPS Spoofers Target Commercial Airlines

Donald Trump’s Campaign Says Its Emails Were Hacked

Source: https://www.securityweek.com/donald-trumps-campaign-says-its-emails-were-hacked/

What happened: Former President Donald Trump's campaign reported a hack and suggested that Iranian actors were behind the theft and distribution of sensitive internal documents. This announcement followed a report detailing attempts by foreign agents to interfere in the 2024 U.S. presidential campaign, including an Iranian military intelligence unit targeting a high-ranking campaign official with a spear-phishing email.

Why it matters: As the U.S. presidential elections approach, cyberattackers are intensifying their efforts to disrupt the process, with foreign interference via hacking, mis/disinformation campaigns, and targeted spear-phishing attacks being a major threat. Recently, a political media outlet reported receiving internal documents from Donald Trump's campaign via an anonymous AOL account named "Robert." The Trump campaign attributed the hack to "foreign sources hostile to the United States," suggesting Iranian involvement, which Iran has denied. Additionally, a recent threat intel report revealed that in June, Iranian government-linked hackers attempted to breach the account of a high-ranking U.S. presidential campaign official, following a prior breach of a county-level U.S. official's account. This election is already facing threats from hacking, leaks, and violent plots, signaling an increased risk of further cyberattacks and disruptions as Election Day approaches.

Fake X Content Warnings on Earthquakes and War Lure Users to Scam Sites

Source: https://www.bleepingcomputer.com/news/security/fake-x-content-warnings-on-ukraine-war-earthquakes-used-as-clickbait/

What happened: Through fake content warnings on X posts, seemingly regarding the Ukraine war and earthquake warnings in Japan, scammers are luring users into clicking their way to scam adult sites, malicious browser extensions, and shady affiliate sites.

Why it matters: The fake content warnings on posts with sensational information are images with malicious links. By exploiting users' trust in urgent, seemingly credible information, like news about the Ukraine war or Japanese earthquake warnings, these tricks, though not new, can cause serious harm. By luring people into clicking fake content warnings, scammers can redirect them to malicious sites that could steal personal information, install harmful software, or trick them into buying counterfeit services. The implications likely include financial loss, privacy breaches, or device exposure to other malicious adversaries. Additionally, users will likely lose trust in genuine content warnings on social media, making it harder to discern real threats from scams.

GPS Spoofers Target Commercial Airlines

Source: https://www.reuters.com/technology/cybersecurity/gps-spoofers-hack-time-commercial-airlines-researchers-say-2024-08-10/

What happened: A recent surge in GPS spoofing has raised significant concerns about flight safety. Research indicates a 400 percent increase in GPS spoofing incidents affecting commercial airliners in recent months. Many of these incidents reportedly involve illicit ground-based GPS systems, particularly around conflict zones, where they broadcast incorrect positions to the surrounding airspace in an attempt to confuse incoming drones or missiles.

Why it matters: GPS spoofing allows threat actors to trick people by manipulating (in this case aviation) an aircraft’s location effectively misdirecting navigation systems and other connected systems. As spoofing incidents become more frequent and complex, flight crews need to stay cautious and manage unpredictable situations while maintaining safety in increasingly challenging conditions.

DEEP AND DARK WEB INTELLIGENCE

BreachForums user "Sorb" | The threat actor Sorb claimed to have leaked a database associated with Brazil's Finance FGTS, the severance indemnity fund for employees which is managed by the Caixa Econômica Federal, on the dark web forum BreachForums. The data, priced at $1,400 USD, includes sensitive information such as full names, phone numbers, document numbers, dates of birth, and addresses.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2024-38200: Microsoft has warned about an unpatched zero-day vulnerability in Office that could allow attackers to access sensitive information if exploited. In a web-based attack scenario, an attacker could create or use a compromised website that hosts a specially crafted file designed to exploit this vulnerability. If a user interacts with the file, it could lead to unauthorized disclosure of confidential data.

Affected products:

  • Microsoft Office 2016 (64-bit edition)
  • Microsoft Office 2016 (32-bit edition)
  • Microsoft Office LTSC 2021 for 32-bit editions
  • Microsoft Office LTSC 2021 for 64-bit editions
  • Microsoft 365 Apps for Enterprise for 64-bit Systems
  • Microsoft 365 Apps for Enterprise for 32-bit Systems
  • Microsoft Office 2019 for 64-bit editions
  • Microsoft Office 2019 for 32-bit editions

Tags: DIB, tlp:green