zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - November 12, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - November 12, 2024

ZeroFox intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • 57 Million People Notified of Hot Topic Data Breach
  • Telegram’s Recent Policy Shift Leads Threat Actors to Platform Exodus, Abandonment, and Backup Channels
  • Halliburton Suffers USD 35 Million in Losses Due to August Ransomware Attack

57 Million People Notified of Hot Topic Data Breach

Source: https://www.bleepingcomputer.com/news/security/hibp-notifies-57-million-people-of-hot-topic-data-breach/

What happened: The personal information of over 54 million Hot Topic, Box Lunch, and Torrid customers was allegedly exposed in a data breach. The data include names, emails, birthdays, phone numbers, addresses, purchase histories, and encrypted credit card numbers. The data set, which includes sensitive financial details even if partially encrypted, raises serious privacy and financial security concerns.

Why it matters: This breach is significant as it exposes a vast amount of personal data that could be exploited in multiple ways, from identity theft to targeted phishing scams. The breach, reportedly likely from an information stealer malware infection, is being sold online, making it important for customers to be cautious of phishing and monitor their accounts. The breach may also lead to credential-stuffing attacks, especially if users reused passwords across accounts.

Telegram’s Recent Policy Shift Leads Threat Actors to Platform Exodus, Abandonment, and Backup Channels

Source: https://cloud.zerofox.com/intelligence/advanced_dark_web/74962

What happened: Telegram's recent policy changes have driven threat actors to modify their communication strategies. Under the new rules, users can report illegal activity for takedown, and Telegram can provide users’ phone numbers and IP addresses if ordered by a court. ZeroFox has observed that threat actor groups, in response, have begun decentralizing their operations, moving to X (formerly, Twitter) and Discord while deleting Telegram channels, removing invite links, and reorganizing.

Why it matters: Some groups, such as Anonymous Collective, Dark Storm Team, and Mysterious Team Bangladesh, are also creating backup Telegram channels to continue maintaining their presence on X. These groups are observed to quickly adapt by decentralizing to other platforms like X and Discord. This can likely complicate monitoring efforts for law enforcement making it harder to trace networks, detect threats in real-time, and investigate cybercrime.

Halliburton Suffers USD 35 Million in Losses Due to August Ransomware Attack

Source: https://www.darkreading.com/cybersecurity-operations/halliburton-optimistic-35m-data-breach-losses

What happened: Halliburton has revealed that the company suffered a loss of almost USD 35 million because of a ransomware attack in August. It experienced a USD 0.02 per share impact on its adjusted earnings from lost or delayed revenue due to the ransomware attack and storms in the Gulf of Mexico.

Why it matters: The company has yet to confirm the technical scope of the breach and the impacted data amid ongoing investigations into the ransomware attack. It is likely that the company will incur more losses in legal fees, given that the threat actors were able to exfiltrate some data in the attack. Additionally, the threat actors are likely to leak or sell the exfiltrated data to other threat actors or competitors of Halliburton despite ransom negotiations.

DEEP AND DARK WEB INTELLIGENCE

  • XSS user hinkim: Negative reputation threat actor "hinkim" has advertised access with administrator rights to a web portal of the Malaysian Department of Occupational Safety and Health on predominantly Russian language Dark Web forum XSS.

VULNERABILITY AND EXPLOIT INTELLIGENCE

  • CVE-2024-47295: This bug allows attackers to gain unauthorized control over Epson devices with blank admin passwords via the Web Config interface, risking data breaches, unauthorized access, and broader network exploitation if left unaddressed.

  • Affected product: Epson has listed the affected products in this advisory.

Tags: DIB, tlp:green