ZeroFox Cyber Intelligence Daily Brief - October 6, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - October 6, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Several Flaws in Business Routers Expose Networks to Major Attacks
- FIN7 Hackers Launch Deepfake Nude “Generator” Sites to Spread Malware
- Ireland Fines Meta EUR 91 Million for Storing Passwords in Plaintext
Several Flaws in Business Routers Expose Networks to Major Attacks
Source: https://www.theregister.com/2024/10/02/draytek_routers_bugs/
What happened: Cybersecurity researchers have found fourteen vulnerabilities in DrayTek Vigor routers, with one flaw rated a critical 10 in severity, exposing more than 700,000 devices to the public internet. The flaws can allow attackers to gain root access, deploy ransomware, exfiltrate data, conduct denial-of-service attacks, or create botnets.
Why it matters: Reportedly, most vulnerable routers are embedded in business networks and open to exploitation through their exposed web interfaces. With the routers functioning like small servers, attackers can use them to launch massive attacks, conceal their origins, and compromise connected devices, posing a serious risk to business operations and security. Chinese APTs have previously used DrayTek bugs to employ vulnerable devices in a botnet setup for a cover data transfer operation.
FIN7 Hackers Launch Deepfake Nude “Generator” Sites to Spread Malware
What happened: The APT group FIN7 has launched a network of fake AI-powered “deepnude generator” sites designed to infect visitors with infostealer malware. These sites entice users interested in generating non-consensual explicit images by offering free trials or free downloads, but instead, they distribute information stealing malware Lumma Stealer.
Why it matters: The rise of deepfake technology, particularly through AI-powered deepnude generators, poses serious ethical and legal challenges. These tools can create non-consensual explicit images, causing emotional distress and reputational harm for the individuals involved, while undermining personal autonomy and privacy. Additionally, groups like FIN7 exploit this technology to distribute malware, increasing risks to personal security. Cybercriminals prey on curiosity around deepfake generators, with malware like Lumma Stealer compromising sensitive data, including login credentials and financial information, leading to identity theft, financial loss, and more.
Ireland Fines Meta EUR 91 Million for Storing Passwords in Plaintext
What happened: Ireland's Data Protection Commission (DPC) has decided to fine Meta EUR 91 million (approx. USD 101 million) for storing passwords of hundreds of millions of users in plaintext, a violation of data protection standards. The issue was discovered in 2019, and while Meta reported it publicly and found no evidence of abuse, it involved the data of millions of Facebook and Instagram users.
Why it matters: Storing user account passwords without proper protections, such as encryption and access control, poses serious security risks. Plaintext passwords are vulnerable to theft, allowing attackers to gain unauthorized access to user accounts and potentially leading to identity theft, data breaches, and fraud. Without encryption, even internal personnel or external attackers who access the system could easily access sensitive information, compromising user privacy. This incident involving Meta is a violation of multiple provisions under the General Data Protection Regulation (GDPR), particularly those concerning data security and privacy.
Tags: DIB, tlp:green