zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - September 23, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - September 23, 2024

ZeroFox intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Ukrainian Government Restricts Telegram Use amid Russian Spy Fears
  • Dell Suffers a Second Breach Amid Investigations of Previous Breach
  • Hacktivist Group Twelve Targets Russian Entities with Destructive Cyber Attacks

Ukrainian Government Restricts Telegram Use amid Russian Spy Fears

Source: https://www.reuters.com/technology/cybersecurity/ukraine-bans-official-use-telegram-app-over-fears-russian-spying-2024-09-20/

What happened: Ukraine has prohibited the use of the Telegram messaging app on official devices for government officials, military personnel, and critical workers, citing concerns that Russian intelligence can monitor communications and access user data.

Why it matters: This decision reflects ongoing security concerns during the war, as Telegram has become a vital communication tool amid the conflict. Protecting sensitive information is crucial for national security, especially given the reported capability of Russian special services to access private data on the platform and disseminate disinformation. The head of the security council's center clarified that the restrictions apply only to official devices, allowing personal use while emphasizing the need to safeguard official communications.

Dell Suffers a Second Breach amid Investigations of Previous Breach

Source: https://hackread.com/dell-hit-by-second-security-breach-in-week/

What happened: Threat actors, who had released data allegedly associated with Dell last week, have released another set of Dell records on a dark web forum amid Dell’s investigation into claims of the previous breach. While the previous breach involved information reportedly belonging to over 10,000 employees, the actors claim that the latest breach targets data from third-party vendors catering to Dell.

Why it matters: The alleged leaked information consists of confidential data, including database tables, schema migrations, and employee details, like employee ID, full name, and employee internal ID. If verified, the breach is likely to subject Dell to further cybersecurity threats by exposing critical system configurations and security vulnerabilities. Moreover, threat actors are very likely to engage Dell employees with personally identifiable information exposed in targeted malicious attacks, such as spear-phishing, extortion, and blackmail.

Hacktivist Group Twelve Targets Russian Entities with Destructive Cyberattacks

Source: https://thehackernews.com/2024/09/hacktivist-group-twelve-targets-russian.html

What happened: The hacktivist group Twelve has been carrying out cyberattacks against Russian targets using publicly available tools. Instead of demanding ransom, they reportedly encrypt victims' data and then deploy a wiper to destroy the targeted infrastructure. This attack ensures the data is irrecoverable, which likely shows that their focus is on the attack itself rather than financial profit.

Why it matters: The threat group is likely primarily motivated by political ideologies rather than financial gain, as they have not demanded ransom payments and instead destroy the data they compromise. Their actions may be aimed at crippling Russian infrastructure to hinder its military progress in the war, potentially sending a message to other entities that support Russia. Additionally, the group’s reliance on publicly available malware tools indicates a preference for traditional techniques over proprietary techniques like many threat groups employ to evade detection. This tactic may increase their vulnerability to detection by law enforcement and is likely indicative of the group’s focus on solely attacking their targets rather than developing exploits as a threat group.

DEEP AND DARK WEB INTELLIGENCE

  • BreachForums user SoftDeveloper: Threat actor "SoftDeveloper" claimed to have leaked a database associated with Menora Mivtachim, an Israel-based insurance company, on the predominantly English-language dark web forum BreachForums. The leaked database contains full name, identity card number, date of birth, address, and more.

VULNERABILITY AND EXPLOIT INTELLIGENCE

  • CVE-2024-45229: Versa Networks has released an advisory for this vulnerability affecting Versa Director. A cyber threat actor could exploit this vulnerability to exercise unauthorized REST APIs.

  • Affected products: Versa has listed all the affected products in this advisory.

  • CVE-2024-20017: In wlan service, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. A proof-of-concept (PoC) exploit is available for this bug.

  • Affected products:

    • SDK version 7.4.0.1 and before (for MT7622 and MT7915)
    • SDK version 7.6.7.0 and before (for MT7916, MT7981 and MT7986)
    • OpenWrt 19.07, 21.02 (for MT6890)

Tags: DIB, tlp:green