ZeroFox Cyber Intelligence Daily Brief - September 3, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - September 3, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Transport for London Notifies Customers of Cyberattack
- Threat Actor Threatens to Leak Data Allegedly Stolen from NOAA
- Business Services Giant CBIZ Discloses Customer Data Breach
Transport for London Notifies Customers of Cyberattack
What happened: Transport for London (TfL), responsible for running most of London’s transport network, is currently investigating a cyberattack. They have found no evidence that customer information has been compromised so far. TfL has notified customers about the cyberattack via email and a public statement.
Why it matters: At the time of reporting, the organization stated that there was no evidence of any customer data being compromised and that TfL services had not been impacted. Given that Transport for London (TfL) oversees much of London’s transport network, such a cyberattack could potentially disrupt transportation services, ticketing systems, and access to essential travel information, impacting daily commutes and travel plans for many. TfL's proactive steps in notifying customers and collaborating with government agencies are crucial for mitigating risks associated with the cyberattack.
Threat Actor Threatens to Leak Data Allegedly Stolen from NOAA
Source: https://cloud.zerofox.com/intelligence/advanced_dark_web/69604
What happened: Threat actor group CyberVolk has claimed to have breached the National Oceanic and Atmospheric Administration (NOAA) and is asking for a ransom in exchange for not releasing the data. The group has announced the release of five percent of the allegedly stolen data, while threatening to release the rest if the ransom is not paid.
Why it matters: The NOAA is considered part of the critical infrastructure of the United States and is involved in disaster preparedness and response, environmental monitoring, and scientific research. It is a lucrative target for financially motivated actors because of the sensitive and classified information it holds, which is crucial to national security. Even though the nature of the allegedly exfiltrated data is unknown at the time of reporting, it is likely to contain sensitive weather forecasts, climate models, and environmental monitoring data. If compromised, this information could disrupt weather predictions and hinder disaster response efforts. Besides, such a data breach can indirectly affect sectors like aviation, agriculture, and maritime operations, which depend on NOAA for accurate and timely information.
Business Services Giant CBIZ Discloses Customer Data Breach
What happened: CBIZ Benefits & Insurance Services (CBIZ) disclosed a data breach involving unauthorized access to client information in specific databases between June 2 and June 21. The breach was reportedly caused by an exploited vulnerability on one of CBIZ's web pages, allowing an unauthorized party to acquire sensitive data. The company is yet to determine or find if data has been misused.
Why it matters: CBIZ is a consulting company that provides financial and insurance services to organizations and individuals. This breach is responsible for the potential exposure of close to 36,000 individuals data including name, contact details, Social Security number, date of birth/death, retiree health information, and welfare plan information. Although the company has not confirmed that the data is being misused in any way, it is worth noting that, on July 17, 2024, ZeroFox observed an update on the Meow Ransomware leak site about the addition of a new victim—CBIZ. The ransomware group claimed to have for sale “confidential SQL databases,” which allegedly also includes the company’s transaction records. The group claims that this data may be valuable to other bad actors, among other reasons, for gaining valuable insights into the company’s business dealings. Threat actors can possibly leverage such data to use as blackmail, identity theft, fraud and phishing, and more.
DEEP AND DARK WEB INTELLIGENCE
Telegram user Dark Storm Team: Pro-Palestine threat actor group Dark Storm Team has indicated its intention to carry out a cyberattack against UAE, Israel, and France in the future. According to the group, the UAE needs to stop its support for Israel and stand with Palestine.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2024-45623: D-Link DAP-2310 Hardware A Firmware 1.16RC028 allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the ATP binary that handles PHP HTTP GET requests for the Apache HTTP Server (httpd). NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Affected products: D-Link DAP-2310 Hardware Revision A, Firmware v 1.16RC028
Tags: DIB, tlp:green