zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - September 29, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - September 29, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Threat Actors Continue to Exploit OT/ICS Through Unsophisticated Means
  • ZeroFox Intelligence Flash Report - Dark Web Actors Seek to Avoid Russian Military Conscription
  • Dell Suffers a Third Breach

Threat Actors Continue to Exploit OT/ICS Through Unsophisticated Means

Source: https://www.cisa.gov/news-events/alerts/2024/09/25/threat-actors-continue-exploit-otics-through-unsophisticated-means

What happened: CISA has released an alert about ongoing cyberattacks targeting internet-accessible operational technology (OT) and industrial control systems (ICS) devices, including those in the Water and Wastewater Systems (WWS) Sector.

Why it matters: CISA reports there is ongoing active exploitation of internet-accessible OT ICS devices. As a part of the U.S. critical infrastructure, water treatment facilities are lucrative targets for financially motivated and state-aligned actors. Exposed and vulnerable OT/ICS systems may allow cyber threat actors to use default credentials, conduct brute force attacks, or use other unsophisticated methods to access these devices and cause harm. OT and ICS operators in critical infrastructure sectors are to apply the recommendations listed in a CISA fact sheet that provides information and mitigations associated with cyber operations conducted by pro-Russia hacktivists.

ZeroFox Intelligence Flash Report - Dark Web Actors Seek to Avoid Russian Military Conscription

Source: https://www.zerofox.com/advisories/26417/

What happened: ZeroFox intelligence has observed a dark web community post from well-regarded actor “Monashka,” about the launch of a government web portal designed to overhaul the method by which military draft notices are served to Russian citizens. The post prompted discussion from several other actors centered around potential deep and dark web (DDW) services offering different methods of avoiding conscription in Russia.

Why it matters: Reportedly, under the new digital system, a summon would be officially considered “served” once it appears on the government portal, which both kick-starts a 20-day countdown within which the recipient must report to an enlistment office and enables border authorities to prevent served individuals from leaving Russia. Since the February 2022 Russian invasion of Ukraine, ZeroFox has observed numerous discussions in DDW forums involving actors seeking ways to avoid being drafted. As the war continues and eligibility requirements widen, it is likely that an array of DDW services will emerge to meet the growing demand from those seeking to avoid military service.

Dell Suffers a Third Breach Data breach

Source: https://hackread.com/dell-data-leak-in-week-amid-grep-cyberattacks/

What happened: More of Dell’s data has been released in a third wave of attack. ZeroFox observed the threat actor “grep” claim that they had already exfiltrated additional data in the event that the company would have fixed the issue to leak at a later date. Threat actors, who had released data allegedly associated with Dell last week, have released another set of Dell records on a dark web forum amid Dell’s investigation into claims of the previous breach. While the previous breach involved information reportedly belonging to over 10,000 employees, the actors claim that the latest breach targets data from third-party vendors catering to Dell.

Why it matters: The recent breach involved 500 MB of PDFs, images, videos, models, and MFA data, along with access vectors, including Chinese infrastructure. The second data breach involved confidential data, including database tables, schema migrations, and employee details, like employee ID, full name, and employee internal ID. If verified, the breach is likely to subject Dell to further cybersecurity threats by exposing critical system configurations and security vulnerabilities. Moreover, threat actors are very likely to engage Dell employees with personally identifiable information exposed in targeted malicious attacks, such as spear-phishing, extortion, and blackmail.

DEEP AND DARK WEB INTELLIGENCE

BreachForums user Sorb: a threat actor known as "sorb" claimed a breach of 1.4 million Americans' data, allegedly exposed via an attack on a Pakistani company that develops CRM software, on the predominantly English-language dark web forum BreachForums.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2024-40846: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Apple macOS. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the AppleIntelKBLGraphicsMTLDriver. Crafted texture data can trigger a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.

Affected products: AppleIntelKBLGraphicsMTLDriver

Tags: DIB, tlp:green