ZeroFox Cyber Intelligence Daily Brief - October 10, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - October 10, 2024
ZeroFox intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Scammers Target Hurricane Victims with Phishing and Malware
- Internet Archive Hacked, Data Breach Impacts 31 Million Users
- Critical Fortinet Bug Actively Exploited in the Wild
Scammers Target Hurricane Victims with Phishing and Malware
Source: https://hackread.com/scammers-florida-hurricane-victim-fake-fema-malware/
What happened: Cybercriminals are targeting Hurricane Helene victims and relief organizations in Florida, abusing disaster recovery efforts. Researchers have identified three types of scams—fraudulent FEMA claims, phishing attacks using fake hurricane relief websites, and malware disguised as FEMA documents. The schemes aim to steal personal data and funds by posing as legitimate aid providers.
Why it matters: Scammers exploit the urgent need for immediate aid through fake relief websites and malicious files, which could subject individuals to identity theft, financial losses, and even blackmail and extortion. CISA has warned users to be vigilant about fraudulent emails and social media messages—often containing malicious links or attachments—common after major natural disasters. Such scams take advantage of the interests and tensions surrounding natural disasters and complicate disaster recovery, putting already vulnerable individuals at greater risk of financial harm. With another hurricane, Hurricane Milton, threatening the U.S. landscape, such scams will very likely continue to target unsuspecting users for the time being.
Internet Archive Hacked, Data Breach Impacts 31 Million Users
What happened: The Internet Archive's "Wayback Machine" experienced a data breach in which a hacker compromised the site and stole a user authentication database containing 31 million records.
Why it matters: This breach exposes sensitive authentication data for registered members, including email addresses, screen names, password change timestamps, hashed passwords, and other internal data, putting millions of users at risk of identity theft and account compromise. With the potential for further attacks from hacker groups, the integrity of the Internet Archive—an essential resource for historical web content—could be jeopardized, affecting countless users and researchers who rely on its services. Additionally, the Internet Archive suffered a DDoS attack, which has been claimed by the SN_BlackMeta hacktivist group, indicating that more disruptive actions may follow.
Critical Fortinet Bug Actively Exploited in the Wild
What happened: The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has revealed that a critical Fortinet FortiOS vulnerability (CVE-2024-23113) is being abused by threat actors in attacks. All Federal Civilian Executive Branch (FCEB) agencies are mandated to apply the relevant patches by October 30, 2024..
Why it matters: The bug, which was patched in February this year, can allow a remote unauthenticated attacker to execute arbitrary code via specially crafted requests because of an externally-controlled format string in affected Fortinet FortiOS versions. It affects various versions of FortiOS, FortiPAM 1.0, FortiProxy 7.0, and FortiWeb 7.4. While details of the public exploitation haven’t been disclosed, CISA has added the bug to its Known Exploited Vulnerabilities Catalog.
DEEP AND DARK WEB INTELLIGENCE
- Telegram user SN_Blackmeta: On October 9, 2024, hacktivist group SN_Blackmeta resurfaced, marking its return with a series of disruptive activities. It is known for their focus on DDoS attacks.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2024-9463: Palo Alto Networks has released patches for several critical vulnerabilities in its Expedition customer migration tool, cautioning that attackers could easily exploit these flaws to gain control of firewall administrator accounts. One significant flaw, identified as CVE-2024-9463, is an OS command injection vulnerability with a CVSS score of 9.9. This flaw enables an unauthenticated attacker to execute arbitrary OS commands as root, potentially exposing usernames, cleartext passwords, device configurations, and API keys from PAN-OS firewalls.
Affected product: The affected products and versions have been listed by Palo Alto Networks in this security update.
Tags: DIB, tlp:green