ZeroFox Cyber Intelligence Daily Brief - August 28, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - August 28, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Pro-Russian Threat Actor Targets Indian Entities
- Park’N Fly Notifies 1 Million Customers of Data Breach
- AT&T Outage Hits Some Wireless Customers as Company Addresses “Software issue”
Pro-Russian Threat Actor Targets Indian Entities
Source: https://cloud.zerofox.com/intelligence/advanced_dark_web/69231
What happened: Pro-Russia threat actor group Server Killers has taken responsibility for alleged distributed denial-of-service (DDoS) attacks targeting various entities in India, including Bank of India, e-Hospital India, and the Indian Police.
Why it matters: In DDoS attacks against a bank, customers will likely lose access to their accounts, face difficulties completing transactions, and experience delays in payroll deposits or bill payments. A hospital can face interruption in its operations, leading to delays in accessing patient records and disturbance in medical services, potentially compromising patient care. Meanwhile, DDoS can disrupt police systems by overwhelming their servers, causing outages that hinder communication, access to critical data, and emergency response coordination, potentially jeopardizing public safety. Besides, the pro-Russian stance of the group indicates a political motivation behind the attack. State-aligned cybercriminals often use cyberattacks as a form of digital protest or retaliation. In this case, for instance, the attack was likely a response to the Indian Prime Minister visiting Ukraine six weeks after he visited Moscow. India and Russia have been longtime defense and economic partners. However, Prime Minister Narendra Modi's visit to Russia drew sharp condemnation from both Ukraine and the West. His visit to Ukraine is likely to be seen as a move to maintain India’s neutral stance in the Russia-Ukraine war, which could motivate Russia or Ukraine-aligned actors to target India to coerce it into aligning with the political stance of their respective states.
AT&T Outage Hits Some Wireless Customers as Company Addresses “Software issue”
Source: https://edition.cnn.com/2024/08/27/business/att-outage-software-issue-tuesday/index.html
What happened: Many AT&T customers across the United States reported outages that left them in SOS mode for several hours and unable to make or receive calls or send texts. The company confirmed this outage while stating that they are currently working on fixing a “software issue.”
Why it matters: The outage is estimated to have affected thousands of users across major cities like Tennessee, Florida, Los Angeles and Arkansas, among other cities. Tennessee authorities announced that the outage may affect wireless 911 connectivity and directed people toward non-emergency communication lines. Other cities—Arkansas and Seminole County—reported difficulties in connecting to 911 services. San Jose police also confirmed that the AT&T outage affected people’s ability to call 911 but services were reportedly restored about three hours later. Tampa in Florida reported that 911 services were not affected but non-emergency and district phone lines were. AT&T has experienced several outages this year, leaving people in the United States unable to place calls, text or access the internet for several hours. Such outages are likely to have devastating consequences for people, especially those trying to access emergency services.
Park’N Fly Notifies 1 Million Customers of Data Breach
What happened: Park'N Fly, a major Canadian off-airport parking provider, suffered a data breach in mid-July that exposed the personal and account information of approximately one million customers. The breach occurred through stolen VPN credentials. The company has reportedly confirmed that no financial or payment card information was affected.
Why it matters: This breach impacts a substantial number of customers by exposing their full names, email addresses, physical addresses, Aeroplan numbers, and CAA numbers, which significantly increases the risk of identity theft and fraud. The exposed personal information can facilitate targeted phishing and scam attempts, while the compromised Aeroplan and CAA numbers may lead to account hijacking and fraudulent activity within loyalty and membership programs. Additionally, this incident also raises broader concerns about the security of customer data and the need for companies to minimize data retention to mitigate such risks. Park'N Fly has advised impacted customers to stay vigilant for phishing attempts from malicious actors posing as legitimate contacts, whether via email or phone calls.
DEEP AND DARK WEB INTELLIGENCE
BreachForums user “X0Frankenstein” | Threat actor X0Frankenstein claimed to have leaked a database associated with the University of Toronto on the predominantly English-language dark web forum BreachForums. The threat actor alleges that they compromised 6,000 lines of sensitive data, including email addresses, divisions, last names, first names, telephone numbers, and more. They also noted that the data breach occurred in 2024. The threat actor did not disclose the source of the breach or how it was exploited.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2024-7971: This bug is a type confusion in V8 in Google Chrome, which allows a remote attacker to exploit heap corruption via a crafted HTML page. CISA added this to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation.
Affected products: Google Chrome versions prior to 128.0.6613.84
Tags: DIB, tlp:green