zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - January 1, 2025

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - January 1, 2025

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • U.S. Imposes Sanctions on Entities in Iran, Russia over Election Interference
  • Healthcare Services Have Patient Data Breached
  • Harley-Davidson Data Breach Exposes Personal Details of over 66,000 Customers

U.S. Imposes Sanctions on Entities in Iran, Russia over Election Interference

Source: https://www.reuters.com/world/us-issues-fresh-iran-russia-sanctions-over-election-interference-treasury-dept-2024-12-31/

What happened: The U.S. imposed sanctions on Iranian and Russian entities accused of attempting to interfere in the 2024 U.S. election. Linked to Iran's Revolutionary Guard Corps (IRGC) and Russia's military intelligence agency (GRU), these entities have been carrying out disinformation campaigns designed to influence U.S. voters and stir socio-political unrest.

Why it matters: Russian and Iranian state-backed actors intensified their cyber efforts ahead of the 2024 U.S. elections, employing tactics such as disinformation campaigns, AI-generated deepfakes, and bomb threats targeting polling locations. Multiple sources including ZeroFox’s advisory have highlighted the adversary’s activities, including the launch of fake news disguised as credible sources, deepfakes involving Vice President Kamala Harris, and the monetization of the election on the deep and dark web (DDW). Federal agencies, such as the FBI, CISA, and Office of the Director of National Intelligence (ODNI) have also observed a rise in foreign influence campaigns from Russia aimed at undermining public confidence in the integrity of U.S. elections. The sanctions imposed are a significant response to this ongoing foreign interference.

Healthcare Services Have Patient Data Breached

Source: https://www.hipaajournal.com/email-accounts-breaches-dap-health-access-telecare-northwest-asthma-allergy/

What happened: Several healthcare services disclosed data breaches involving unauthorized access to email accounts containing sensitive patient data, including medical records and personally identifiable information (PII). Investigations revealed varying extents of exposed data and while regulatory impact and the total number of affected individuals remain unclear, at the time of writing.

Why it matters: The breaches involving sensitive patient data can likely lead to identity theft, financial fraud, and privacy violations, putting affected individuals at significant risk. Additionally, stolen healthcare information can be used to obtain unauthorized medical services or prescriptions in the patient’s name, potentially impacting their medical records and insurance coverage.

Harley-Davidson Data Breach Exposes Personal Details of over 66,000 Customers

Source: https://cloud.zerofox.com/intelligence/advanced_dark_web/78459

What happened: Harley-Davidson, a well-known American motorcycle manufacturer, has fallen victim to a data breach allegedly conducted by the cybercriminal group "888." The group claims to have leaked a database containing sensitive personal information of over 66,700 Harley-Davidson customers.

Why it matters: This breach exposes a wide range of personal data, including full names, addresses, email addresses, and phone numbers, all of which can be exploited for identity theft and other forms of cybercrime. At the time of writing, Harley-Davidson has yet to officially confirm the breach.

DEEP AND DARK WEB INTELLIGENCE

XSS user netcut: Negative reputation threat actor "netcut" advertised network access to a server of an unnamed Software-as-a-Service (SaaS) company based in Singapore on predominantly Russian language dark web forum XSS.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2024-56116: A cross-site request forgery vulnerability in Amiro.CMS before 7.8.4 allows remote attackers to create an administrator account.

Affected products: Amiro.CMS versions before 7.8.4

Tags: DIB, tlp:green