ZeroFox Cyber Intelligence Daily Brief - October 27, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - October 27, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- SEC Charges Companies for Misleading Cybersecurity Disclosures
- Hackers Exploit Roundcube Webmail Flaw
- Security Company Denies Being Hacked by Pro-Palestinian Threat Actors
SEC Charges Companies for Misleading Cybersecurity Disclosures
Source: https://www.sec.gov/newsroom/press-releases/2024-174
What happened: The U.S. Securities and Exchange Commission (SEC) has charged a few U.S.-based companies with misleading disclosures about cybersecurity incidents. They have collectively agreed to pay over USD 7 million in fines without admitting wrongdoing.
Why it matters: Per the SEC, the charged firms minimized or framed breaches in hypothetical or vague terms, despite knowing the attacks had already occurred. Misleading cybersecurity disclosures can harm investors by hiding the real impact of breaches, leading to disruptions in mitigation efforts and likely affecting customers. For example, one of the companies failed to disclose two major intrusions, while another understated the extent of compromised files. These errors will likely impact customers and other entities dependent on the two firms.
Hackers Exploit Roundcube Webmail Flaw
What happened: Threat actors have been exploiting a stored XSS vulnerability (CVE-2024-37383) in the Roundcube Webmail client to target government organizations in the Commonwealth of Independent States (CIS) region. CIS emerged as an alternative to the crumbling Soviet Union in 1991, and includes Russia, Ukraine, and Belarus. The vulnerability allows attackers to execute malicious JavaScript code on the Roundcube page when a user opens a specially crafted email.
Why it matters: Roundcube Webmail is reportedly used by government and commercial organizations, making it a high-value target for threat actors to exfiltrate sensitive data. Vulnerabilities like CVE-2024-37383 could allow attackers to execute malicious code, potentially leading to data breaches or the compromise of sensitive information. In 2023, groups like Winter Vivern and APT28 used Roundcube flaws to target think tanks in Europe and Ukrainian government servers. Unpatched systems in high-profile organizations can become likely targets in geopolitical conflicts, further increasing the urgency for timely security updates to prevent espionage and data theft. System administrators still using affected versions (Roundcube versions earlier than 1.5.6 and versions 1.6 to 1.6.6) are urged to update as soon as possible.
Security Company Denies Being Hacked by Pro-Palestinian Threat Actors
Source: https://www.darkreading.com/cyberattacks-data-breaches/eset-wiper-attack-targets-israel
What happened: Security firm ESET denied reports that hackers compromised its systems to target Israeli customers with wiper malware, confirming that only its partner, Comsecure, was affected. A malicious email campaign, blocked within ten minutes, impersonated ESET with a fake security warning and malware-laced ZIP attachment.
Why it matters: Even though the hackers could not breach the ESET platform, they leveraged its partner network, abused anti-spoofing defenses, and mimicked official channels to distribute malware. The malware distributed resembles tactics used by politically motivated Handala group, known for attacking Israeli organizations following the Israel-Hamas conflict. The campaign’s sophistication, bypassing email authentication protocols, reveals security gaps in vendor relationships that hackers will likely target to further their agenda during geopolitical crises.
Tags: DIB, tlp:green