zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - August 19, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - August 19, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Pentagon Leaker Arraigned on Military Charges Ahead of March Trial
  • National Public Data Confirms Breach Exposing Social Security Numbers
  • OpenAI Disrupts Covert Iranian Influence Operation Leveraging ChatGPTto Target U.S. Elections

Pentagon Leaker Arraigned on Military Charges Ahead of March Trial

Source: https://www.reuters.com/world/us/pentagon-leaker-teixeira-arraigned-military-charges-ahead-march-trial-2024-08-16/

What happened: A member of the Massachusetts Air National Guard was arraigned on charges of violating military laws related to the leaking of classified U.S. national security documents. The accused, who was arrested in April 2023, deferred entering a plea until his court-martial trial starts in March 2024. The Air Force accuses him of obstructing justice and ignoring orders related to classified information.

Why it matters: Despite his rank, the accused had top-secret clearance and access to hundreds of classified documents on topics like Russia's invasion of Ukraine and sensitive geopolitical issues. The Air Force prosecutors stated that the accused ignored an order to stop accessing unrelated classified information and obstructed justice by disposing of an iPad, hard drive, and iPhone after the leaks were discovered, while also instructing someone to delete his online messages. The leaks, which were shared on Discord, a messaging app, indicates there may be others involved or aware of the leak, potentially broadening the scope of the breach. This breach could expose strategic details, compromise intelligence sources, and potentially endanger lives, highlighting the severe impact of mishandling and leaking classified information.

National Public Data Confirms Breach Exposing Social Security Numbers

Source: https://www.bleepingcomputer.com/news/security/national-public-data-confirms-breach-exposing-social-security-numbers/

What happened: National Public Data (NPD) confirmed that the recent data breach it suffered included contact information like phone numbers and addresses, Social Security numbers (SSN), and email addresses. Threat actor “SXUL” reportedly took credit for breaching NPD back in April 2024 and priced the sale of the stolen database for USD 2 million.

Why it matters: The National Public Data breach poses severe, long-term risks, such as fraudulent credit accounts, loans, and tax returns and has the potential to lead to significant financial losses and legal battles for both the victims and Jerico Pictures. Jerico Pictures has recently been served a class action lawsuit for the failure to properly secure people’s personally identifiable information (PII). Exposed SSNs pose significant risks to people’s information security since they are important identifiers in financial and governmental transactions and can be a target for identity scammers. Threat actors can also abuse exposed contact details like email addresses to target people in phishing campaigns to gain further information to conduct other fraudulent activities.

OpenAI Disrupts Covert Iranian Influence Operation Leveraging ChatGPTto Target U.S. Elections

Source: https://thehackernews.com/2024/08/openai-blocks-iranian-influence.html

What happened: OpenAI has taken down a set of ChatGPT accounts generating content to cater to a covert Iranian influence operation, dubbed Storm-2035, targeting the upcoming U.S. elections. The action, OpenAI states, is part of its ongoing efforts to detect and stop covert influence operations (IO).

Why it matters: OpenAI’s investigation revealed that the campaign used ChatGPT to generate long-form content and short social media comments. The generated content addressed various topics, including the conflict in Gaza and Israel’s presence at the Olympic Games—and to a lesser extent, Venezuelan politics, the rights of Latinx communities in the United States (both in Spanish and English), and Scottish independence. The campaign failed to achieve high user engagement. Notably, with the U.S. presidential elections on the horizon, the escalating tensions in the Middle East, and the ongoing Russia-Ukraine war, state-sponsored actors are increasingly weaponizing generative artificial intelligence (AI) to fuel influence campaigns. Such operations allow actors to further their agenda while hiding their true identity or intentions.

DEEP AND DARK WEB INTELLIGENCE

XSS user "CyberPudge" | The untested threat actor CyberPudge advertised web panel access with administrator rights to an undisclosed U.S.-based government agency on the predominantly Russian language Dark Web forum "XSS." According to CyberPudge, the server contains payment data, documents, and allows the upload of files. The actor charged USD 1,500 for the access.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2024-7909: A vulnerability has been found in TOTOLINK EX1200L 9.3.5u.6146_B20201023. This vulnerability affects the function setLanguageCfg of the file /www/cgi-bin/cstecgi[.]cgi. The manipulation of the argument langType leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

Affected product: Totolink EX1200L_Firmware V9.3.5u.6146_B20201023

Tags: DIB, tlp:green