ZeroFox Cyber Intelligence Daily Brief - October 26, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - October 26, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Russian Disinformation Targets Harris-Walz Campaign with Deepfakes Ahead of Election
- Electric Vehicle Charging Stations at Risk From Hack Attacks
- CISA Releases Four Industrial Control Systems Advisories
Russian Disinformation Targets Harris-Walz Campaign with Deepfakes Ahead of Election
Source: https://www.theregister.com/2024/10/25/russia_china_iran_election_disinfo/
What happened: Russian disinformation groups released several AI-generated deepfake videos, including one showing Kamala Harris joking about Trump’s assassination and another falsely accusing her of killing an endangered rhinoceros. On October 16, another video falsely accused Tim Walz of sexual assault.
Why it matters: Russian disinformation groups have ramped up efforts against the Harris-Walz campaign ahead of the U.S. elections to sway public opinion through fabricated stories, potentially influencing voter behavior. AI-generated media almost certainly poses a larger threat to the upcoming election than any previous one. ZeroFox notes that the increasing presence of AI-generated content in disinformation campaigns demonstrates how synthetic media alongside a statement can evoke emotion to garner support for and ridicule a political candidate.
Electric Vehicle Charging Stations at Risk From Hack Attacks
What happened: Researchers have discovered significant cybersecurity vulnerabilities in multiple brands of EV charging stations, primarily due to unsecured SSH and HTTP ports. These vulnerabilities can lead to expanded attack surfaces and potential threats to the power grid.
Why it matters: As demand for electric vehicles increases, so does the need for secure charging infrastructure. Unaddressed vulnerabilities can compromise not only individual users but also critical energy systems, allowing malicious actors to intercept communications between vehicles and charging stations, potentially leading to unauthorized access to sensitive data. Additionally, compromised charging stations could be manipulated to disrupt services or launch attacks on the broader electrical grid.
CISA Releases Four Industrial Control Systems Advisories
What happened: The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has released four Industrial Control Systems (ICS) advisories to provide timely information to network defenders amidst increasing attacks on critical infrastructure. The advisories relate to bugs in VIMESA VHF/FM Transmitter Blue Plus, iniNet Solutions SpiderControl SCADA PC HMI Editor, Deep Sea Electronics DSE855, and OMNTEC Proteus Tank Monitoring (Update A).
Why it matters: The vulnerabilities in the ICS products could lead to denial of service, remote control of devices, exfiltration of stored credentials, and unauthorized administrative actions. Such vulnerabilities pose a critical risk to the country’s infrastructure, especially with reports of foreign actors (both state-backed APTs and ideological hacktivists) relentlessly targeting various utilities. The U.S. Department of State recently offered up to USD 10 million for information leading to the arrests of a group of Iranian hackers responsible for cyberattacks on U.S. critical infrastructure.
DEEP AND DARK WEB INTELLIGENCE
BreachForums user IntelBroker: Threat actor IntelBroker has claimed to have leaked a database associated with Elife, a U.S.-based company offering airport shuttles, bus rental, limo rental, and pet transportation services on predominantly English-language dark web forum BreachForums.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2024-5947: Deep Sea Electronics DSE855 is vulnerable to a configuration disclosure when direct object reference is made to the Backup.bin file using an HTTP GET request. Successful exploitation of this vulnerability could allow an attacker to access stored credentials.
Affected products: Deep Sea Electronics DSE855: Version 1.0.26
Tags: DIB, tlp:green