zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - September 24, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - September 24, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Biden Administration Proposes to Ban Russia and China-Made Vehicle Technology
  • Background Check Company Data Exposed—Over 100 Million PII Revealed
  • China Urges Vigilance Against Taiwanese Cyberattacks

Biden Administration Proposes to Ban Russia and China-Made Vehicle Technology

Source: https://www.whitehouse.gov/briefing-room/statements-releases/2024/09/23/fact-sheet-protecting-america-from-connected-vehicle-technology-from-countries-of-concern/#:~:text=The%20Department%20of%20Commerce%20is,specifically%20the%20People%27s%20Republic%20of

What happened: The Biden-Harris administration has proposed prohibiting the sale or import of connected vehicles that incorporate certain technology and the import of particular components, specifically from the People’s Republic of China (PRC) and Russia. The proposal is the next step in investigating Chinese smart cars, which began in February.

Why it matters: The proposal addresses security risks from adversarial nations, like China and Russia, which will likely abuse connected vehicle technologies to gain a strategic upper hand through sabotage or surveillance operations. Vehicle technologies control vehicle movement, gather sensitive data, and use sensors to record infrastructure details, posing potential threats to U.S. national security. The rule targets "vehicle connectivity systems" (like Bluetooth, Wi-Fi) and "automated driving systems" that could subject U.S. citizens to potential threats from malicious state-sponsored or politically motivated actors through susceptible supply chains.

Background Check Company Data Exposed—Over 100 Million PII Revealed

Source: https://cybernews.com/security/us-mc2-background-check-data-leak/

What happened: A data breach at MC2 Data exposed sensitive information of over 100 million U.S. citizens due to an unsecured 2.2 TB database. The leak revealed private data, including names, birthdates, encrypted passwords, legal records, and partial payment information. Additionally, over 2.3 million MC2 subscribers had their personal details compromised.

Why it matters: The exposure of personal and sensitive information makes millions of individuals vulnerable to identity theft, phishing, and fraud, with criminals able to exploit this data. The leaked data could enable more effective and misuse by cybercriminals, such as background-check abuse and targeted attacks on individuals like employers, landlords, and law enforcement. This increases the chances of fraud, blackmail, and exploitation, threatening both personal and institutional security, and incurring reputational damages.

China Urges Vigilance Against Taiwanese Cyberattacks

Source: https://www.reuters.com/technology/cybersecurity/china-urges-netizens-be-vigilant-against-taiwanese-cyberattacks-2024-09-23/

What happened: China’s national security ministry has accused a Taiwan-based hacking group, Anonymous 64, of carrying out cyberattacks and engaging in "anti-propaganda sabotage" against Chinese targets. Taiwan's defense ministry refuted these claims, asserting that China is the true aggressor with its own cyberattacks and military actions.

Why it matters: China’s National Security Ministry alleged that Anonymous 64, linked to Taiwan’s cyber warfare wing, sought to spread misinformation about China through fake websites and social media posts. This included claims about President Xi Jinping and references to protests against COVID-19 restrictions and the Tiananmen Square crackdown. China said it had found that many of the websites Anonymous 64 claimed to have access to were fake and warned citizens should be vigilant against misinformation and report cyberattacks or cases of propaganda. This incident reflects the growing tensions between China and Taiwan, as both sides are increasingly using digital tactics to assert their narratives, raising concerns about regional stability and conflict.

DEEP AND DARK WEB INTELLIGENCE

Telegram users Hunt3r Kill3rs, Moroccan Cyber Force, UserSec, and more: In September 2024, ZeroFox observed several alliances between threat actors, with a highlight being pro-Russia groups' growing collaboration with pro-Palestine groups.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2024-7490: Improper Input Validation vulnerability in Microchip Technology Advanced Software Framework example DHCP server can cause remote code execution through a buffer overflow. This vulnerability is associated with program files tinydhcpserver[.]C and program routines lwip_dhcp_find_option. ASF is no longer being supported.

Affected products: Advanced Software Framework versions through 3.52.0.2574

Tags: DIB, tlp:green