zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - September 25, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - September 25, 2024

ZeroFox intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • ZeroFox Intelligence Flash Report - Dark Web Actors Seek to Avoid Russian Military Conscription
  • Suspected Cyberattack Forces Kansas Water Plant to Manual Operations
  • U.S. Government Agency CMS Says Data Breach Impacted 3.1 Million People

ZeroFox Intelligence Flash Report - Dark Web Actors Seek to Avoid Russian Military Conscription

Source: https://www.zerofox.com/advisories/26417/

What happened: ZeroFox intelligence has observed a dark web community post from well-regarded actor “Monashka,” about the launch of a government web portal designed to overhaul the method by which military draft notices are served to Russian citizens. The post prompted discussion from several other actors centered around potential deep and dark web (DDW) services offering different methods of avoiding conscription in Russia

Why it matters: Reportedly, under the new digital system, a summon would be officially considered “served” once it appears on the government portal, which both kick-starts a 20-day countdown within which the recipient must report to an enlistment office and enables border authorities to prevent served individuals from leaving Russia. Since the February 2022 Russian invasion of Ukraine, ZeroFox has observed numerous discussions in DDW forums involving actors seeking ways to avoid being drafted. As the war continues and eligibility requirements widen, it is likely that an array of DDW services will emerge to meet the growing demand from those seeking to avoid military service.

Suspected Cyberattack Forces Kansas Water Plant to Manual Operations

Source: https://www.securityweek.com/kansas-water-facility-switches-to-manual-operations-following-cyberattack/

What happened: A suspected cyberattack has forced a Kansas water treatment facility to switch to manual operations. The water supply was unaffected, and there was no disruption to service, according to officials, who reassured residents that the drinking water remained safe.

Why it matters: The incident mirrors a similar case in Texas—where Russia-linked actors caused a Texas town’s water system to overflow. In November 2023, threat actors were actively exploiting Unitronics programmable logic controllers (PLCs) used in the Water and Wastewater Systems (WWS) Sector. These are examples of how cyberattacks can have repercussions in the physical world. Besides, as a part of the U.S. critical infrastructure, water treatment facilities are lucrative targets for both financially motivated and ideological state-aligned actors. Moreover, U.S. water facilities have been frequent targets of cyberattacks, with Russian GRU-affiliated hackers engaging in espionage and sabotage operations since at least 2020.

U.S. Government Agency CMS Says Data Breach Impacted 3.1 Million People

Source: https://www.bleepingcomputer.com/news/healthcare/us-govt-agency-cms-says-data-breach-impacted-31-million-people/

What happened: The Centers for Medicare & Medicaid Services (CMS) announced that the personal information of over three million health plan beneficiaries was compromised in the 2023 MOVEit ransomware attacks by the Clop ransomware group. The breach occurred after hackers infiltrated the Wisconsin Physicians Service (WPS), which provides Medicare administrative services, exposing sensitive data.

Why it matters: This breach exposes sensitive data, including Social Security numbers, personal and medical information, which can lead to identity theft and fraud. The scale of the exposure affects a significant number of individuals, raising concerns about data security in the healthcare sector. These stolen data can be readily shared or sold on the dark web, increasing the likelihood of further attacks and leaving affected individuals vulnerable to identity theft and fraud. Impacted individuals are being offered 12 months of free credit monitoring to help mitigate the risks associated with the exposure.

DEEP AND DARK WEB INTELLIGENCE

  • BreachForums user 888: On September 24, 2024, threat actor 888 claimed to have leaked a database associated with Oracle, a U.S.-based cloud technology company that provides computing infrastructure and software services.

VULNERABILITY AND EXPLOIT INTELLIGENCE

  • CVE-2024-7593: It is an authentication bypass vulnerability (CVSS score of 9.8) stemming from a flawed implementation of an authentication algorithm. This issue allows remote unauthenticated attackers to bypass authentication on Internet-exposed vTM admin panels. CISA has included this Ivanti vTM vulnerability in its Known Exploited Vulnerabilities (KEV) catalog, noting that it is actively being exploited.

  • Affected products: Ivanti Virtual Traffic Manager versions 22.2, 22.3, 22.3R2 , 22.5R1, 22.6R1, and 22.7R1

Tags: DIB, tlp:green