zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - September 30, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - September 30, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • U.S. Charges Three Individuals in Hack-and-Leak Operation Targeting Electoral Campaigns
  • Ireland Fines Meta EUR 91 Million for Storing Passwords in Plaintext
  • Actor Claims DDoS Attacks on Countries Supporting Palestine

U.S. Charges Three Individuals in Hack-and-Leak Operation Targeting Electoral Campaigns

Source: https://www.justice.gov/opa/pr/three-irgc-cyber-actors-indicted-hack-and-leak-operation-designed-influence-2024-us

What happened: The U.S. Department of Justice (DoJ) has unsealed charges against three individuals, allegedly linked to the Islamic Revolutionary Guard Corps (IRGC), accused of hacking into accounts of current and former U.S. officials to steal campaign material to influence the 2024 election. The announcement comes days after U.S. authorities accused Iranian actors of hacking into former President Donald Trump’s campaign and attempting to share exfiltrated information to President Joe Biden’s campaign.

Why it matters: The charges are an ongoing effort from the U.S. government to tackle foreign cyber-interference in the upcoming elections. Foreign efforts to influence voter opinions, erode public trust in the electoral process, and impact the outcomes have begun and will very likely continue in the run-up to the elections. Additionally, with Iran being a key player in the ongoing conflicts in the Middle East, IRGC hackers will likely contribute to the efforts of disrupting the U.S. elections or threatening electoral operations by disseminating incendiary disinformation or misinformation. Iran’s actions aim to support the IRGC’s broader agenda, including avenging the killing of its former commander, Qasem Soleimani.

Ireland Fines Meta EUR 91 Million for Storing Passwords in Plaintext

Source: https://www.bleepingcomputer.com/news/legal/ireland-fines-meta-91-million-for-storing-passwords-in-plaintext/

What happened: Ireland's Data Protection Commission (DPC) has decided to fine Meta EUR 91 million (approx. USD 101 million) for storing passwords of hundreds of millions of users in plaintext, a violation of data protection standards. The issue was discovered in 2019, and while Meta reported it publicly and found no evidence of abuse, it involved the data of millions of Facebook and Instagram users.

Why it matters: Storing user account passwords without proper protections, such as encryption and access control, poses serious security risks. Plaintext passwords are vulnerable to theft, allowing attackers to gain unauthorized access to user accounts and potentially leading to identity theft, data breaches, and fraud. Without encryption, even internal personnel or external attackers who access the system could easily access sensitive information, compromising user privacy. This incident involving Meta is a violation of multiple provisions under the General Data Protection Regulation (GDPR), particularly those concerning data security and privacy.

Actor Claims DDoS Attacks on Countries Supporting Palestine

Source: https://cloud.zerofox.com/intelligence/advanced_dark_web/71186

What happened: AnonSec Kerala has announced a new wave of cyberattacks aimed at countries supporting Palestine, marking a resurgence of their operations following a period of technical issues that had previously hindered their activities. Their initial focus will be on launching DDoS attacks, with plans to escalate to “hacking” military.

Why it matters: The activities of AnonSec Kerala are significant due to the group's history of previous cyber operations, including DDoS attacks and data leaks targeting government institutions. Cybersecurity experts warn that the resurgence of this group could necessitate enhanced security measures worldwide, particularly in countries supporting Palestine. As their operations unfold, nations should closely monitor the potential impact on global cybersecurity. Notably, AnonSec Kerala has clarified that Russia will not be a target of these attacks, distinguishing it from other countries providing financial and military aid to Palestine.

DEEP AND DARK WEB INTELLIGENCE

Hacker Alliances and Collective Hacktivism: ZeroFox has observed a rise in hacker alliances and collective hacktivism. Hacker groups have come together to expand their impact beyond individual pursuits, where cyber threats transcend national boundaries and come together for shared objectives.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2024-0132: This critical vulnerability affects the NVIDIA Container Toolkit, posing a risk to all AI applications that utilize it for GPU access in cloud or on-premise settings. This vulnerability has a severity score of 9.0 and enables attackers to perform container escape attacks, giving them complete access to the host system. This access could lead to command execution and sensitive data exfiltration.

Affected products: NVIDIA Container Toolkit versions 1.16.1 and earlier, and GPU Operator versions 24.6.1 and earlier

Tags: DIB, tlp:green