ZeroFox Cyber Intelligence Daily Brief - August 20, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - August 20, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- 240 GB of Data Stolen from Toyota Allegedly Leaked by Threat Actors
- FlightAware Configuration Error Leaked User Data for Years
- Pro-Russia Sites Disguise as Legitimate U.S. News Sites to Spread Incendiary Information
240 GB of Data Stolen from Toyota Allegedly Leaked by Threat Actors
Source: https://cloud.zerofox.com/intelligence/advanced_dark_web/68608
What happened: Threat actor group ZeroSevenGroup claimed to have conducted a cyberattack against Toyota’s U.S. branch. The breached data included details on Toyota employees, customers, contracts, and financial records. Toyota has confirmed a network breach following the release of 240 GB of stolen data on a hacking forum.
Why it matters: This breach exposes a wide range of sensitive information, including contact details, financial records, customer data, employee records, photos, databases, network infrastructure, and emails, potentially impacting numerous individuals and business operations. The attackers also claimed to use the ADRecon tool (extracts extensive information from Active Directory environments) to gather network infrastructure details and credentials, potentially gaining deep insight into Toyota's network and security. This could lead to increased risk of further attacks and misuse of the stolen credentials. Toyota has not yet disclosed when the breach was detected, how the attacker gained access, or the extent of data exposure.
FlightAware Configuration Error Leaked User Data for Years
What happened: Investigations reveal that a configuration error in the FlightAware’s systems could have exposed sensitive user data including Social Security numbers, IP addresses, and more. The company has fixed the configuration error and prompts users to reset their login passwords as a precautionary measure.
Why it matters: Flight data has reportedly been exposed for three years; however, there is no evidence that threat actors have abused this data. This exposed data has the potential for threat actors gaining unauthorized access to user accounts possibly via credential stuffing to hijack accounts. Resetting passwords is an essential step toward strengthening accounts that have had their login credentials exposed since threat actors can use this information to gain access to bank accounts and other sensitive repositories since most passwords are often reused.
Pro-Russia Sites Disguise as Legitimate U.S. News Sites to Spread Incendiary Information
What happened: Pro-Russia websites masquerading as U.S. news outlets are posting incendiary misleading disinformation, such as unsubstantiated claims of Democratic Party’s’ involvement in a plot to kill Former President Donald Trump, ahead of the high-stakes U.S. elections. Researchers have observed such sites proliferate over recent months, outnumbering U.S. newspaper sites.
Why it matters: The fake sites leverage easily accessible artificial intelligence (AI) tools to produce inflammatory content, intending to promote controversial or inaccurate narratives. The operation increases its reach by engaging audiences with the content re-told in various languages across several social media platforms and repeated by AI chatbots. Such AI-powered disinformation campaigns threaten the upcoming U.S. elections because they are designed to interfere with the elections, influence voter opinions, and reduce trust in reliable sources and information. Deepfakes associated with elections in Asia and the European Union have raised concerns and prompted social media companies to take preventive measures. Besides, state-sponsored disinformation campaigns have geopolitical angles, where the state aims to propagate its political agenda or sway the election results to favor its motives.
DEEP AND DARK WEB INTELLIGENCE
- Telegram user Dark Storm Team: Pro-Palestine threat actor group Dark Storm Team has claimed to have conducted a DDoS attack against the website of Capital Bank in the United States. The attack was carried out as part of its ongoing campaigns #OpIsrael and #OPNATO.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2024-23897: This critical Jenkins vulnerability can be exploited to gain remote code execution to its catalog of security bugs. On August 19, CISA added it to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation.
Affected products: Jenkins versions 2.441 and earlier; LTS versions 2.426.2 and earlier
CVE-2024-38193: An attacker who successfully exploited this privilege escalation bug could gain SYSTEM privileges. A patch for this bug, which has been exploited by threat actors, is now available.
Affected products: Windows Ancillary Function Driver (AFD.sys) for WinSock
Tags: DIB, tlp:green