ZeroFox Cyber Intelligence Daily Brief - September 26, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - September 26, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Threat Actors Continue to Exploit OT/ICS through Unsophisticated Means
- RansomHub Targets Delaware Libraries
- Critical Automated Tank Gauge Bugs Threaten Gas Infrastructure
Threat Actors Continue to Exploit OT/ICS through Unsophisticated Means
What happened: CISA has released an alert about ongoing cyberattacks targeting internet-accessible operational technology (OT) and industrial control systems (ICS) devices, including those in the Water and Wastewater Systems (WWS) Sector.
Why it matters: CISA reports there is ongoing active exploitation of internet-accessible OT ICS devices. As a part of the U.S. critical infrastructure, water treatment facilities are lucrative targets for financially motivated and state-aligned actors. Exposed and vulnerable OT/ICS systems may allow cyber threat actors to use default credentials, conduct brute force attacks, or use other unsophisticated methods to access these devices and cause harm. OT and ICS operators in critical infrastructure sectors are to apply the recommendations listed in a CISA fact sheet that provides information and mitigations associated with cyber operations conducted by pro-Russia hacktivists.
RansomHub Targets Delaware Libraries
Source: https://cloud.zerofox.com/intelligence/advanced_dark_web/71023
What happened: The RansomHub ransomware group has claimed to have stolen 56 GB of data, including financial documents, in a ransomware attack targeting Delaware Libraries. The organization confirmed it was experiencing an extended system/internet outage, affecting library services at some public libraries, with a few libraries closed at the time of reporting. However, the Delaware Library Catalog and eMedia services are still functioning.
Why it matters: The attack disrupted internet, printing, phone, and computer services, causing multiple libraries to shut down critical services and affecting 35 sites across the state. RansomHub has set a ransom payment deadline of September 30, but the organization has decided to rebuild its system instead of paying the ransom. Public libraries play a vital role in providing essential services, yet they are susceptible due to resource constraints and, to that end, often face financial difficulties while recuperating from cyberattacks. Besides, any exposed private user data can subject individuals to risks of further targeted triple extortion attacks.
Critical Automated Tank Gauge Bugs Threaten Gas Infrastructure
What happened: Researchers have uncovered 11 vulnerabilities, including critical ones, in Automatic Tank Gauge (ATG) systems. These flaws leave the systems vulnerable to exploitation, potentially endangering operational security at critical facilities and management systems.
Why it matters: ATGs are essential for monitoring fuel levels and ensuring proper storage at critical infrastructure facilities like gas stations, airports, and industrial sites. The discovered vulnerabilities, which also include unpatched ones, could allow attackers to gain full administrative control over these systems. Attackers could manipulate ATG systems to disrupt fuel distribution, cause fuel shortages, or even lead to physical damage and environmental harm, such as fuel leaks or spills. If these vulnerabilities are left unpatched, the consequences of an attack could escalate, affecting fuel availability and even causing widespread environmental issues.
DEEP AND DARK WEB INTELLIGENCE
BreachForums user grep: Threat actor “grep” claimed to have leaked a database associated with 911 Interpreters, a U.S.-based company that provides complete language solutions, on the predominantly English-language dark web forum BreachForums. The actor alleged that 911 Interpreters suffered a data breach in September 2024, exposing 12,000 Twilio call records, voicemails with record URLs, customers, interpreters, business details, and other internal data.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2024-45817: An issue has been identified that affects both XenServer 8 and Citrix Hypervisor 8.2 CU1 LTSR. It allows a malicious administrator of a guest VM to cause the host to crash or become unresponsive.
Affected products: XenServer 8 and Citrix Hypervisor 8.2 CU1 LTSR
Tags: DIB, tlp:green