ZeroFox Cyber Intelligence Daily Brief - October 25, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - October 25, 2024
ZeroFox intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- CISA and Partners Release Joint Guidance to Assist Software Manufacturers with Safe Software Deployment Processes
- Insurance Admin Landmark Says Data Breach Impacts 800,000 People
- Pro-Russia and Pro-Palestine Hacktivist Groups Target Australia
CISA and Partners Release Joint Guidance to Assist Software Manufacturers with Safe Software Deployment Processes
What happened: Today, CISA—along with U.S. and international partners—released a joint guidance to aid software manufacturers in establishing secure software deployment processes to help ensure software is reliable and safe for customers. Additionally, it offers guidance on how to deploy in an efficient manner as part of the software development lifecycle (SDLC).
Why it matters: The guide is primarily intended for software or service manufacturers deploying software to many types of customer systems, including mobile devices and laptops, as well as for cloud-based services. While the guide is not specifically focused on internal IT teams deploying to internal systems, many of the same phases will apply—albeit in a modified form. Other domains may require phases that are balanced differently. For example, organizations will have to contemplate complexities in some deployment scenarios, such as OSS software deployments, and the tradeoffs between automatic versus manual updates. This guide will not cover all scenarios but can be a useful tool for organizations looking to mature their deployment processes.
Insurance Admin Landmark Says Data Breach Impacts 800,000 People
What happened: Landmark Admin, a third-party administrator for insurance companies, disclosed a data breach that compromised the personal information of over 800,000 individuals after suspicious activity was detected in May 2024. The company quickly shut down its IT systems and engaged cybersecurity experts to investigate the incident.
Why it matters: The breach exposed sensitive information, including Social Security numbers, personal data, and financial information, potentially putting affected individuals at risk for identity theft or financial fraud. The scale of the breach affects a large number of people, highlighting vulnerabilities in data security within the insurance industry and raising concerns about the protection of personal information. Given the sensitive nature of the stolen data, affected individuals are advised to closely monitor their credit reports and bank accounts for any unusual activity.
Pro-Russia and Pro-Palestine Hacktivist Groups Target Australia
Source: https://cloud.zerofox.com/intelligence/advanced_dark_web/72975
What happened: Pro-Palestine and pro-Russia hacktivist groups DXPLOIT and Cyber Army Russia Reborn claim to have launched distributed denial-of-distribution (DDoS) attacks targeting Australian entities under the #OpsAustralia campaign. The attackers allegedly disrupted the websites of Regional Express Airlines and Heritage Bank. Additionally, pro-Russian actors claimed responsibility for DDoS attacks targeting the websites of Australian Prime Ministers.
Why it matters: The current cyber landscape is dotted with politically aligned threat actors, especially hacktivists, where cyber warfare often reflects ongoing political and diplomatic conflicts. The threat actors have cited Australia’s support for Israel and Ukraine to be the motivation behind their alleged DDoS attacks. Targeting financial institutions, airlines, and political sites directly affects essential services and public trust. Besides, Australia’s position on international conflicts will likely expose it to greater cyber threats, including state-sponsored attacks, which can target its national security.
DEEP AND DARK WEB INTELLIGENCE
- XSS user Croatoan: Untested threat actor "Croatoan" advertised RDP access to three distinct U.S.-based and Canadian companies on predominantly Russian language Dark Web forum XSS.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2024-20481: A vulnerability in the Remote Access VPN (RAVPN) service of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) of the RAVPN service. This vulnerability has been patched.
Affected product: Vulnerable Cisco ASA or FTD Software with RAVPN enabled
AWS Vulnerability: A vulnerability in Amazon Web Services (AWS) Cloud Development Kit (CDK) can result in a target account’s takeover, potentially leading to data breaches and scams. The flaw is now fixed.
Affected products: Amazon Web Services (AWS) Cloud Development Kit (CDK)
Tags: DIB, tlp:green