zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - October 23, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - October 23, 2024

ZeroFox intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • SEC Charges Companies for Misleading Cybersecurity Disclosures
  • Exposed United Nations Database Left Sensitive Information Accessible Online
  • Hackers Registered over 1,000 New Malicious Domains Targeting U.S. Elections

SEC Charges Companies for Misleading Cybersecurity Disclosures

Source: https://www.sec.gov/newsroom/press-releases/2024-174

What happened: The U.S. Securities and Exchange Commission (SEC) has charged a few U.S.-based companies with misleading disclosures about cybersecurity incidents. They have collectively agreed to pay over USD 7 million in fines without admitting wrongdoing.

Why it matters: Per the SEC, the charged firms minimized or framed breaches in hypothetical or vague terms, despite knowing the attacks had already occurred. Misleading cybersecurity disclosures can harm investors by hiding the real impact of breaches, leading to disruptions in mitigation efforts and likely affecting customers. For example, one of the companies failed to disclose two major intrusions, while another understated the extent of compromised files. These errors will likely impact customers and other entities dependent on the two firms.

Exposed United Nations Database Left Sensitive Information Accessible Online

Source: https://www.wired.com/story/un-women-database-exposure/

What happened: A United Nations Trust Fund to End Violence Against Women database was left unsecured, exposing 115,000 files online related to organizations that receive funding or partner with UN Women. A security researcher discovered the database, which lacked password protection, and reported it to the UN, leading to a swift resolution.

Why it matters: The exposed data contained sensitive data about vulnerable groups such as women, children, and LGBTQ communities in hostile environments. Reportedly such incidents are not uncommon and the exposure of such confidential data pertaining to already at-risk people, in this case, is likely to endanger their privacy and security. Financial audits, including bank account details, could be misused in scams, especially since the UN is a highly trusted organization. The data reportedly includes detailed insights into the funding, operations, and staff of civil society organizations, which could be leveraged by malicious actors or authoritarian governments to target these groups and the vulnerable people they serve. Such information could potentially jeopardize the safety and activities of organizations working in hostile regions.

Hackers Registered over 1,000 New Malicious Domains Targeting U.S. Elections

Source: https://cybersecuritynews.com/1000-new-malicious-domains-registered/

What happened: Cybersecurity researchers have discovered over 1,000 newly registered malicious domains exploiting public interest in the upcoming election. Meanwhile, a hacker known as “TAINTU” is reportedly attempting to sell 1.45 TB of classified United States Space Force (USSF) military technology archives for USD 15,000 in cryptocurrency. The leaked data includes sensitive information on advanced military technologies, space-based weapon systems, and strategic simulations.

Why it matters: The use of familiar phrases related to the presidential race makes these websites especially risky, potentially leading to phishing attacks and disinformation campaigns that can distort voter confidence and influence election outcomes. Additionally, the sale of 1.45 TB of classified USSF military technology archives raises significant national security concerns and the potential risks of sensitive information being accessed by malicious actors. If authentic, this sensitive information is likely to give adversaries valuable insights into U.S. defense capabilities and future military developments, affecting global security dynamics.

DEEP AND DARK WEB INTELLIGENCE

  • Pro-India hacktivist groups plan cyberattack on Canada: Hacktivist groups "Indian Cyber Force" and "Indian Cyber Army" announced that they are making preparations for a cyberattack on Canada, with the aim of disrupting its cyber infrastructure while India and Canada are experiencing increasing geo-political tensions.

VULNERABILITY AND EXPLOIT INTELLIGENCE

  • CVE-2024-38812: VMware has released new patches for CVE-2024-38812, a critical vCenter Server RCE vulnerability initially mispatched in September 2024. The flaw, exploited during China’s Matrix Cup, affects multiple vCenter versions and has no workaround.

  • Affected product: vCenter versions 7.0.3, 8.0.2, and 8.0.3

  • CVE-2024-44068: This is a use-after-free high-severity zero-day bug in the mobile processor of affected Samsung mobiles, which leads to privilege escalation. Researchers have also discovered an exploit for the big in the wild.

  • Affected products: M2m Scaler Driver in Samsung Mobile Processor and Wearable Processor Exynos 9820, 9825, 980, 990, 850, and W920

Tags: DIB, tlp:green