ZeroFox Cyber Intelligence Daily Brief - December 30, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - December 30, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Final Rule Issued to Address Threats Posed by Foreign Adversary Access to Americans’ Data
- AT&T, Verizon Mitigating Salt Typhoon Cyberespionage Incident; Small User Base Affected
- Data Breach Exposes Personal and Geo-Location Information of 800,000 Vehicles
Final Rule Issued to Address Threats Posed by Foreign Adversary Access to Americans’ Data
What happened: The Justice Department has issued a comprehensive final rule carrying out Executive Order (E.O.) 14117 “Preventing Access to Americans’ Bulk Sensitive Personal Data and United States Government-Related Data by Countries of Concern.”
Why it matters: The E.O. charged the Justice Department with establishing and implementing a new regulatory program to address the urgent and extraordinary national security threat posed by the continuing efforts of countries of concern (and covered persons that they can leverage) to access and exploit Americans’ bulk sensitive personal data and U.S. Government-related data. Countries of concern are likely to use artificial intelligence (AI) in conjunction with multiple unrelated data sets, for example, to identify U.S. persons whose links to the federal government would be otherwise obscured in a single dataset and who can then be targeted in espionage or blackmail.
AT&T, Verizon Mitigating Salt Typhoon Cyberespionage Incident; Small User Base Affected
What happened: In the Salt Typhoon cyberespionage incident, the threat actors reportedly targeted a small user base of major U.S. telecom companies, including AT&T and Verizon. While the networks are now secure, hackers gained full access to record calls and steal call data, prompting CISA to urge encrypted communication for high-profile figures.
Why it matters: AT&T and Verizon are mitigating this breach, however, threat actors have reportedly targeted a few individuals of “foreign intelligence interest.” Although a small number of users have been targeted, such breaches can likely enable nation-state actors to geolocate individuals, intercept sensitive communications, and compromise national security. Even with mitigations in place, the risks of undetected persistence or future attacks likely remain a threat.
Data Breach Exposes Personal and Geo-Location Information of 800,000 Vehicles
What happened: Volkswagen's automotive software company, Cariad, exposed data from approximately 800,000 electric vehicles due to improper configuration of two IT applications. The data, stored on a widely used cloud platform, included sensitive personal information, including precise geo-location details that could pinpoint vehicle locations down to a few centimeters.
Why it matters: This data breach exposed vulnerable customer information from major Volkswagen brands like VW, Audi, Seat, and Skoda, with far-reaching consequences that can compromise customer privacy and threaten security. The leaked information can allow malicious actors to track the real-time movements of individuals, including private citizens and law enforcement personnel, using precise location data, enabling them to steal sensitive information or even plan targeted attacks. Additionally, the breach involved terabytes of sensitive data likely linked to customers’ names, further increasing the risks of identity theft and targeted attacks.
DEEP AND DARK WEB INTELLIGENCE
Exploit user Devil.God: Untested threat actor "Devil.God" advertised an auction for AnyDesk access with local administrator rights to an unnamed U.S.-based transportation company on predominantly Russian language dark web forum Exploit.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2024-12856: The Four-Faith router models F3x24 and F3x36 are affected by an operating system (OS) command injection vulnerability. At least firmware version 2.0 allows authenticated and remote attackers to execute arbitrary OS commands over HTTP when modifying the system time via apply[.]cgi. Additionally, this firmware version has default credentials which, if not changed, would effectively change this vulnerability into an unauthenticated and remote OS command execution issue.
Affected products: Four-Faith router models F3x24 and F3x36
Tags: DIB, tlp:green