ZeroFox Cyber Intelligence Daily Brief - October 5, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - October 5, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Hackers Exploit Critical CosmicSting Flaw, Targeting Thousands of Online Merchants
- Handala Targets Several Israeli National Entities
- Dutch Police: “State Actor” Likely Behind Recent Data Breach
Hackers Exploit Critical CosmicSting Flaw, Targeting Thousands of Online Merchants
Source: https://www.theregister.com/2024/10/04/cisco_ray_ban_whirpool_cosmicsting_hack/
What happened: At least seven threat actors have exploited a critical vulnerability (CVE-2024-34102), dubbed CosmicSting, in Adobe's Commerce and Magento software, targeting over 4,275 online merchants, including notable brands like Ray-Ban and Whirlpool.
Why it matters: CosmicSting enables cybercriminals to alter website pages and secretly steal sensitive customer data, particularly payment information. It threatens customer login credentials and other personal information, posing a severe risk for online shoppers. The bug affects software products widely popular among online shopping sites, thereby attracting several financially motivated threat actors. Besides, in the highly competitive ransomware landscape, such vulnerabilities leave organizations susceptible to large-scale breaches that can severely impact networks and operations.
Handala Targets Several Israeli National Entities
Source: https://cloud.zerofox.com/intelligence/advanced_dark_web/71579
What happened: ZeroFox recently observed an update on the Handala Hack Team’s leak site, where the group claims to have targeted Israel's internal security agency (Shin Bet), a former Prime Minister’s emails, and the Soreq Nuclear Research Center. The threat actor alleges that they breached the security systems of phones belonging to Shin Bet officers, leaking over 7 TB of sensitive data that is allegedly connected to more than 30,000 officers. They also claim to have leaked over 11,000 emails from former Israeli Prime Minister Ehud Barak.
Why it matters: Ideologically and geopolitically motivated hacktivist groups such as Handala—which has explicitly declared its support to the Palestinian cause—attack entities that stand against their cause by compromising sensitive information. Their campaigns can not only pose immediate risks to national security of the target country but also likely lead to escalations in regional tensions and compromised intelligence operations. Such attacks not only pose immediate risks to national security but also likely lead to escalations in regional tensions and compromised intelligence operations. The hacked emails for Israel’s former Prime Minister may have been intended to weaken public trust. The leak of “secret emails” can provide proponents of Palestine with leverage against Israel in the Israel-Palestine war. ZeroFox has detected close to 300 ransomware and digital extortion victims in the Middle East-Africa region in the past year, of which over 25 percent were targeted by the Handala Hack Team.
Dutch Police: “State Actor” Likely Behind Recent Data Breach
What happened: The national Dutch police (Politie) revealed that a state actor was likely responsible for the data breach detected last week. The breach compromised sensitive information, including the contact details, names, and email addresses of police officers.
Why it matters: The investigation into the breach is ongoing, with authorities opting not to disclose the identity of the responsible party or the specifics of how the attack was executed until all details have been thoroughly analyzed. The attack compromised sensitive information, including contact details and private data of multiple officers, which could be exploited for malicious purposes. As the police focus on assessing the nature and scope of the leak, they have also implemented enhanced security measures to protect sensitive data.
DEEP AND DARK WEB INTELLIGENCE
BreachForums user selukas: Threat actor "selukas" claimed to have leaked a database associated with CrunchBase, a U.S.-based provider of private-company prospecting and research solutions, on the predominantly English-language dark web forum BreachForums.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2024-21894: A heap overflow vulnerability in IPSec component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure allows an unauthenticated malicious user to send specially crafted requests in-order-to crash the service thereby causing a DoS attack. In certain conditions this may lead to execution of arbitrary code.
Affected products: Ivanti Connect Secure (Version 9.x and 22.x) and Ivanti Policy Secure
Tags: DIB, tlp:green