ZeroFox Cyber Intelligence Daily Brief - October 12, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - October 12, 2024
ZeroFox intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Fidelity Notifies 77,000 Customers About an August Breach
- Pro-Palestine Cyber Groups Continue Targeting Israeli Orgs
- Best Practices to Configure BIG-IP LTM Systems to Encrypt HTTP Persistence Cookies
Fidelity Notifies 77,000 Customers About an August Breach
Source: https://www.darkreading.com/cyberattacks-data-breaches/fidelity-notifies-77k-customers-data-breach
What happened: An August data breach targeting Fidelity Investments compromised the personal information of over 77,000 individuals. An unauthorized third party accessed two customer accounts, prompting an investigation after Fidelity detected the breach on August 19. The compromised data did not involve Fidelity accounts but impacted a small subset of customers.
Why it matters: The latest breach marks the second breach affecting Fidelity this year, following another breach in March involving a service provider. Despite assurances that the attackers accessed no accounts, the leak of personal information exposes affected customers to the risk of identity theft or fraud. The breach also highlights potential weaknesses in customer data management, which could encourage further attacks and breaches.
Pro-Palestine Cyber Groups Continue Targeting Israeli Orgs
Source: https://cloud.zerofox.com/intelligence/advanced_dark_web/72036
What happened: Pro-Palestine groups have continued cyberattacks on Israel, often targeting critical infrastructure and trying to disrupt services. Pro-Palestine threat group Anonymous Syria claimed to have leaked sensitive data on 7,000 Israeli citizens, while threat group Handala Hack claimed to have leaked 50,000 secret emails from a high-ranking Israeli diplomat (who supposedly worked with key allies and was also involved in the country’s external intelligence agency).
Why it matters: In the past year, ZeroFox has observed a series of cyber campaigns by pro-Palestine threat actors targeting Israel and its allies. The exposure of sensitive information about 7,000 Israeli citizens raises concerns about personal security and privacy, with potential risks of identity theft and harassment. Additionally, the leak of 50,000 secret emails from a high-ranking diplomat could jeopardize Israel's diplomatic relations and intelligence operations, providing adversaries with strategic insights. Notably, the group Handala has emerged as a key player, claiming 65 attacks across dark web forums like BreachForums and RAMP since the conflict began.
Best Practices to Configure BIG-IP LTM Systems to Encrypt HTTP Persistence Cookies
What happened: CISA has warned of threat actors using unencrypted persistent cookies from the F5 BIG-IP Local Traffic Manager (LTM) module to enumerate other non-internet facing devices on the network.
Why it matters: A malicious cyber actor could leverage the information gathered from unencrypted persistence cookies to infer or identify additional network resources and potentially exploit vulnerabilities found in other devices present on the network. CISA has urged organizations to encrypt persistent cookies employed in F5 BIG-IP devices. Additionally, F5 has developed an iHealth heuristic to detect and alert customers when cookie persistence profiles do not have encryption enabled.
DEEP AND DARK WEB INTELLIGENCE
- BreachForums user EagleStrike: On October 11, 2024, threat actor EagleStrike claimed to have leaked a database associated with the Asia Pacific Energy Research Centre on the predominantly English-language dark web forum BreachForums.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2024-9164: GitLab has released security updates to address eight vulnerabilities, including a critical flaw, CVE-2024-9164, that allows unauthorized execution of CI/CD pipelines on arbitrary branches. Organizations using affected versions are advised to update to patched versions promptly to safeguard their CI/CD processes and sensitive data.
Affected product: GitLab EE versions from 12.5 prior to 17.2.9, from 17.3 prior to 17.3.5, and from 17.4 prior to 17.4.2.
Tags: DIB, tlp:green