ZeroFox Cyber Intelligence Daily Brief - August 22, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - August 22, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- ZeroFox Intelligence Flash Report - RansomHub Extortion Activity on Sharp Upward Trajectory
- Pakistan Police Arrests Individual Over Suspicions of Spreading Disinformation on Southport Attack
- Cyberattack Disrupts Microchip Technology Manufacturing Facilities
ZeroFox Intelligence Flash Report - RansomHub Extortion Activity on Sharp Upward Trajectory
Source: https://www.zerofox.com/advisories/25431/
What happened: The ransomware-as-a-service (RaaS) operation “RansomHub” has almost certainly significantly increased its operational tempo in recent weeks, having conducted more attacks so far in Q3 2024 than in Q1 and Q2 2024 combined. RansomHub was first observed in approximately February 2024 and exhibited a higher tempo of attacks during those initial weeks than is usually observed from new ransomware operations.
Why it matters: RansomHub’s activity as a proportion of all ransomware activity observed by ZeroFox is also on a sharp upward trajectory, with the group accounting for approximately 2 percent of all attacks in Q1, 5.1 percent in Q2, and 14.2 percent so far in Q3. There is a likely chance that RansomHub will remain the most prominent ransomware collective for the coming months and continue to attract affiliates. The collective will almost certainly continue to target a highly diverse array of sectors, and the proportion of attacks targeting organizations located in North America will very likely increase.
Pakistan Police Arrests Individual Over Suspicions of Spreading Disinformation on Southport Attack
Source: https://www.nytimes.com/2024/08/21/world/asia/pakistan-arrest-southport-riots.html
What happened: Pakistani authorities have arrested an individual on charges of cyber terrorism for spreading disinformation that aided in inciting violent riots in the United Kingdom after a fatal stabbing attack that claimed the lives of three children last month.
Why it matters: The arrested individual, a freelance web developer, worked for a news aggregation website that botched the identity of the Southport stabber with incorrect and sensational claims. The disinformation played a crucial role in fuelling the violent racist and anti-immigration riots that followed. Disinformation can lead to real-world consequences by spreading false or misleading information that influences public opinion, incites violence, or disrupts social harmony. For example, the infamous "Pizzagate" incident where a man fired shots inside a pizzeria in Washington, D.C., was due to disinformation claiming the pizzeria was connected to a child trafficking ring.
Cyberattack Disrupts Microchip Technology Manufacturing Facilities
Source: https://www.securityweek.com/cyberattack-disrupts-microchip-technology-manufacturing-facilities/
What happened: A cyberattack on a U.S.-based semi-conductor supplier, Microchip Technology, affected some of its manufacturing facilities’ operations. The company confirmed that the attack disrupted servers and business operations, causing it to isolate affected systems while shutting certain systems down.
Why it matters: Threat actors have not claimed this attack but researchers suspect this could be a ransomware attack. Other chip manufacturing companies have been targeted in the past where threat groups Dark Angels and LockBit have claimed responsibility for the attack. The attack on Microchip Technologies could also have led to the theft of data which could potentially endanger confidential information that can be leveraged by foreign entities seeking to dominate the global chip market. Attacks on industries that are closely linked to critical infrastructure poses a significant threat to a country’s security. Such an attack could potentially lay the foundations of future operations.
DEEP AND DARK WEB INTELLIGENCE
- Telegram user SN_Blackmeta: Threat actor group SN_Blackmeta has claimed to have conducted a cyberattack against Arab National Bank in Saudi Arabia. Allegedly, the cyberattack impacts the entire infrastructure of the bank, including their online banking services, secure login access, account management, transaction history, payments and transfers, and other online banking features.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2024-6800:This critical (CVSS score: 9.5) could allow an attacker to bypass authentication and gain administrator access to the system. The problem is related to an XML signature wrapping flaw that arises when using the Security Assertion Markup Language (SAML) authentication standard with specific identity providers. It was fixed in GitHub Enterprise Server versions 3.13.3, 3.12.8, 3.11.14, and 3.10.16.
Affected products: GitHub Enterprise Server prior to 3.14
Tags: DIB, tlp:green