zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - November 11, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - November 11, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Law Enforcement Encounters New Hurdles in iPhone Data Access with iOS 18
  • Unknown Hackers Target Texas Oilfield Supplier in Ransomware Attack
  • Scammers Target UK Senior Citizens with Winter Fuel Payment Texts

Law Enforcement Encounters New Hurdles in iPhone Data Access with iOS 18

Source: https://www.wired.com/story/mysterious-iphone-reboot-ios-18-police/

What happened: Some iPhones in police custody have been rebooting automatically, complicating forensic investigations. These reboots, linked to Apple’s iOS 18, switch devices from an easily accessible After First Unlock (AFU) state to a more secure Before First Unlock (BFU) state, making it harder for police to extract data.

Why it matters: Apple has developed the “inactivity reboot” feature in iOS 18, which forces locked iPhones to restart after four days, as a potential anti-theft measure. Even though the feature is likely to help secure lost or stolen devices, it has caused disruptions in law enforcement (LE) efforts to access locked phones. Threat actors will likely try to leverage this feature by triggering automatic reboots on devices they cannot fully access to delay investigations—which would buy them time to erase or remotely tamper data and hinder LE from gathering crucial evidence.

Unknown Hackers Target Texas Oilfield Supplier in Ransomware Attack

Source: https://www.darkreading.com/cyberattacks-data-breaches/mystery-hackers-texas-oilfield-supplier-ransomware-attack

What happened: Newpark Resources, a Texas-based oil drilling services provider, was hit by a ransomware attack, causing disruptions to some of its information and business systems. The company reported limitations in access to key operational and corporate functions, including financial reporting. Following the breach, Newpark activated its security response plan and restricted access to affected systems.

Why it matters: A ransomware attack on critical infrastructure, like that on Newpark Resources, poses significant risks. Such disruptions can halt essential operations, potentially endangering public safety and causing economic fallout due to downtime. Compromised systems may expose sensitive operational data, opening pathways for further attacks or espionage. Additionally, critical infrastructure often serves interconnected industries, where disruptions can impact supply chains and other sectors reliant on continuous operation.

Scammers Target UK Senior Citizens with Winter Fuel Payment Texts

Source: https://www.bleepingcomputer.com/news/security/scammers-target-uk-senior-citizens-with-winter-fuel-payment-texts/

What happened: Scammers have been sending fraudulent text messages to British senior citizens, claiming to offer “winter heating allowances” and “cost of living support.” The texts contain links to fake websites that mimic official government pages, aiming to steal personal and financial details from recipients.

Why it matters: This scam preys on the uncertainty caused by recent cuts to winter fuel payments, targeting vulnerable pensioners who may be more susceptible to such fraudulent offers. The phishing campaign is widespread, involving over 500 different domains, and is designed to exploit people's fear of missing out on vital financial assistance. Authorities are warning seniors to be cautious and avoid clicking on suspicious links to protect their sensitive data from being stolen.

DEEP AND DARK WEB INTELLIGENCE

Scattered Spider and BlackCat Resurface: Two prominent criminal groups, Scattered Spider and BlackCat/ALPHV, seemingly vanished after a series of high-profile cyber heists last year, followed by arrests and website seizures. However, in the past few months, both groups have resurfaced, with new reported attacks and potential rebranding.

VULNERABILITY AND EXPLOIT INTELLIGENCE

Six vulnerabilities in Mazda cars: Six vulnerabilities (CVE-2024-8355 to CVE-2024-8360) have been discovered in Mazda car infotainment systems due to insufficient sanitization of user input. A physically present attacker could exploit these flaws by connecting a specially crafted USB device to the system, enabling arbitrary code execution with root privileges. These vulnerabilities are reportedly unpatched.

Affected products: Connectivity Master Unit (CMU) software version 74.00.324A, and other early 70.x versions.

Tags: DIB, tlp:green