ZeroFox Cyber Intelligence Daily Brief - September 28, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - September 28, 2024
ZeroFox intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- ASD’s ACSC, CISA, and Partners Release Guidance on Active Directory Compromises
- Public Wi-Fi Operator Investigating Cyberattack at UK's Busiest Train Stations
- Chinese Hackers Breach U.S. ISPs, Raising Stakes for Critical Infrastructure Security
ASD’s ACSC, CISA, and Partners Release Guidance on Active Directory Compromises
What happened: The Australian Signals Directorate Australian Cyber Security Centre (ASD ACSC), the Cybersecurity and Infrastructure Security Agency (CISA), and other U.S. and international partners released the joint guide Detecting and Mitigating Active Directory Compromises. This guide informs organizations of recommended strategies to mitigate common techniques used by malicious actors to compromise Active Directory.
Why it matters: Active Directory is the most widely used authentication and authorization solution in enterprise information technology (IT) networks worldwide. Malicious actors frequently target it to escalate privileges and access sensitive user information. Responding to and recovering from attacks on active Directory can be costly and disruptive. CISA urges organizations to review its guidance and implement recommended measures to enhance Active Directory security.
Public Wi-Fi Operator Investigating Cyberattack at UK's Busiest Train Stations
Source: https://www.theregister.com/2024/09/26/public_wifi_operator_investigating_cyberattack/
What happened: One of the United Kingdom’s busiest train stations is investigating a cyber incident where those connecting to the public WI-Fi were directed to a compromised landing page, which showed an “unsavory” message. The message refers to the 2017 Manchester Arena bombings and is reportedly Islamophobic.
Why it matters: The consequences of the lack of encryption and security around public Wi-Fi networks is especially dangerous in incidents like this where critical infrastructure is involved. Better security surrounding such essential components of daily city operations can limit dangers to civilian lives and resources in the future. Such attacks have the potential to disrupt transportation services, ticketing systems, and access to essential travel information, impacting daily commutes and travel plans for many.
Chinese Hackers Breach U.S. ISPs, Raising Stakes for Critical Infrastructure Security
Source: https://www.darkreading.com/cyberattacks-data-breaches/chinas-salt-typhoon-cyberattacks-us-isps
What happened: Newly identified Chinese state-backed APT group "Salt Typhoon" has breached several U.S. Internet Service Providers, aiming to steal sensitive data and potentially prepare for future disruptive attacks. Salt Typhoon has reportedly targeted a small number of broadband and cable networks, focusing on gaining long-term access.
Why it matters: Threat actors are likely to leverage their control over ISP networks to collect valuable intelligence on high-value individuals, such as federal employees, law enforcement, and military personnel. They can also access location data, services accessed, and communication patterns. This access also poses a strategic risk: it enables capabilities to disrupt critical U.S. infrastructure. Given ongoing tensions with China, such footholds could be leveraged to hinder U.S. responses to geopolitical events, such as military conflicts in the Pacific region.
DEEP AND DARK WEB INTELLIGENCE
- LeakBase user Phobia: Threat actor "Phobia" claimed to have leaked a database of Federal Firearms Licenses (FFL), United States on the deep web forum LeakBase.
VULNERABILITY AND EXPLOIT INTELLIGENCE
Cisco IOS and IOS XE Software Security Advisories: Cisco has published its semiannual Bundled Publication of Cisco IOS and IOS XE Software Security Advisories, which details 11 vulnerabilities affecting these software platforms. The release includes corresponding software updates to address these issues.
Affected products: The affected products and versions have been listed by Cisco in the respective security advisories.
Tags: DIB, tlp:green