zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - October 15, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - October 15, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Thousands of Fortinet Instances Vulnerable
  • Pokémon Game Developer Confirms Data Breach
  • Italy's Intesa Said It Alerted Authorities on Security Breach After Checks

Thousands of Fortinet Instances Vulnerable

Source: https://www.theregister.com/2024/10/14/fortinet_vulnerability/

What happened: Over 86,000 Fortinet instances reportedly remain vulnerable to a critical flaw that attackers began exploiting last week. The vulnerability affects FortiOS, FortiPAM, FortiProxy, and FortiWeb, with the majority of impacted devices located in Asia, North America, and Europe. Administrators are urged to update to unaffected versions.

Why it matters: Fortinet appliances are widely used in critical sectors like government, finance, and enterprise IT, making them valuable targets for attackers. With over 86,000 instances still exposed, cybercriminals could exploit this flaw to gain unauthorized access, potentially leading to data breaches, network disruption, or further malicious activity. The spread of vulnerable devices across Asia, North America, and Europe likely increases the risk of widespread impact. Unpatched systems may lead to more sophisticated cyberattacks, threatening organizational security.

Pokémon Game Developer Confirms Data Breach

Source: https://www.bleepingcomputer.com/news/security/pokemon-dev-game-freak-confirms-breach-after-stolen-data-leaks-online/

What happened: The developer behind the Pokémon game series, Game Freak, confirmed that a cyberattack in August 2024 compromised personal information belonging to employees, contractors, and retirees, including names and email addresses. However, the company has yet to address the circulation of alleged leaked source code and development builds for upcoming Pokémon games, which surfaced on social media platforms and leak sites over the weekend.

Why it matters: The compromised personal information can expose the impacted individuals to targeted phishing attacks, extortion attempts, and financial scams. There is also a roughly even chance of malicious actors doxing these individuals on social media. Meanwhile, posts on X have drawn significant attention by leaking alleged development materials, including potential official artwork, game plans, and storylines for future games. This surge of interest creates an opportunity for malicious actors to distribute harmful links disguised as leaked game content, posing risks to fans eager to access the stolen files.

Italy's Intesa Said It Alerted Authorities on Security Breach After Checks

Source: https://www.reuters.com/technology/cybersecurity/italys-intesa-said-it-alerted-authorities-security-breach-after-checks-2024-10-14/

What happened: Intesa Sanpaolo, a leading banking group in Europe, reported a data breach involving one of its employees, affecting thousands of account holders, including Prime Minister Giorgia Meloni. The bank alerted the country's data protection authority after conducting thorough checks.

Why it matters: The involvement of a bank employee in this data breach makes the situation particularly concerning, as it affects thousands of account holders, including Prime Minister Giorgia Meloni. This breach not only puts the personal information of many individuals at risk but also casts doubt on the bank's internal security practices. The fact that a high-profile figure is impacted intensifies the scrutiny on Intesa Sanpaolo, emphasizing the need for stringent data protection protocols to safeguard sensitive information in an increasingly digital landscape.

DEEP AND DARK WEB INTELLIGENCE

BreachForums user X0Frankenstein | Threat actor named X0Frankenstein claimed to have leaked a database associated with the Belarusian Chamber of Commerce and Industry on the predominantly English-language dark web forum BreachForums. The threat actor alleged that the Belarusian Chamber of Commerce and Industry suffered a data breach in 2024. The leaked database contains applications for health insurance, passport scans, timesheets, and more.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2024-8963: A suspected nation-state adversary has been observed exploiting three security vulnerabilities in the Ivanti Cloud Service Appliance (CSA). CVE-2024-8963 is a critical path traversal vulnerability found in Ivanti CSA versions prior to patch 4.6 Patch 519, which allows remote, unauthenticated attackers to gain access to restricted functionalities.

Affected products: CSA 4.6 (All versions before Patch 519)

Tags: DIB, tlp:green