ZeroFox Cyber Intelligence Daily Brief - October 1, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - October 1, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Media Giant AFP Faces Cyberattack Disrupting News Delivery Services
- Ransomware Attack Forces Major Texas Hospital to Divert Ambulances
- North Korea Hackers Linked to Breach of German Missile Manufacturer
Media Giant AFP Faces Cyberattack Disrupting News Delivery Services
What happened: Agence France-Presse (AFP) recently experienced a cyberattack that affected its IT systems and client services, although news coverage remains unaffected. The organization is collaborating with France's cybersecurity agency to address the situation.
Why it matters: The cyberattack on AFP raises concerns about the security of information systems within the media sector, as disruptions can hinder the timely delivery of news. For AFP, this incident may potentially lead to a temporary loss of revenue from affected client services like custom news packages and content archives. While the core news coverage remains unaffected, the compromised client services may hinder the ability of partners to access or receive timely updates and data, thereby impacting their operational efficiency.
Ransomware Attack Forces Major Texas Hospital to Divert Ambulances
Source: https://www.theregister.com/2024/09/30/texan_hospital_ransomware/
What happened: A ransomware attack forced a major hospital in Lubbock, Texas, which provides critical emergency care, to divert ambulances and limit services. The hospital disconnected affected systems after detecting unusual network activity. At the time of writing, emergency operations remain disrupted while a third party investigates the incident.
Why it matters: The target hospital is crucial for the Texas town populace because it is the only level-one trauma center within a 400-mile radius. A cyberattack shutting down emergency operations for such a hospital poses a direct risk to the safety and even the lives of those who need urgent critical care. Hospitals—with repositories of sensitive information and the need to resolve network disruptions as soon as possible—are lucrative targets for financially motivated actors like ransomware groups. ZeroFox has detected more than 430 ransomware and digital extortion victims in the healthcare sector in the past year, close to 70 percent of which are in North America.
North Korea Hackers Linked to Breach of German Missile Manufacturer
Source: https://www.securityweek.com/north-korea-hackers-linked-to-breach-of-german-missile-manufacturer/
What happened: Kimsuky APT, linked to the North Korean government, breached a German defense company that manufactures Iris-T air defense systems. They employed a phishing campaign featuring fake job offers and sophisticated social engineering techniques to break into the company’s systems.
Why it matters: Such an attack on the German defense company, particularly one involved in the manufacturing of critical systems like the Iris-T air defense and other missile and ammunitions, presents significant risks to global security. Such breaches can result in the theft of sensitive military technologies, weakening not only the company but also the defense capabilities of connected nations that rely on these systems. North Korean threat actors could potentially sell secrets, compromising defense capabilities and likely undermining future weapon development and deployment. Additionally, the attack could lead to the proliferation of military technologies to other nations, destabilizing regional security and civilian lives.
DEEP AND DARK WEB INTELLIGENCE
Threat actor pryx leaks Govt. of Barbados data: The threat actor "pryx" claimed to have leaked a data package associated with the government of Barbados on their data leak site. The actor alleged that the dump contains driver's licenses, social identification, legal documents, as well as a database with names, email addresses, phone numbers, passports, national ID numbers, and more. The threat actor did not disclose the ultimate source of the data breach or how it was exploited.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2023-25280: OS Command injection vulnerability in D-Link DIR820LA1_FW105B03 allows attackers to escalate privileges to root via a crafted payload with the ping_addr parameter to ping.ccp. CISA added three other vulnerabilities and CVE-2023-25280 to its KEV catalog.
Affected product: D-Link DIR820LA1_FW105B03
Tags: DIB, tlp:green