zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - July 5, 2023

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - July 5, 2023

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Sweden Warns Companies Against Google Analytics Use
  • AIIMS Ransomware Attack Prompts Indian Government to Formulate National Cybersecurity Response Framework (NCRF)
  • Mexican Cybercriminal Neo_Net Behind Global Android Malware Campaign Targeting Banks
  • Vulnerabilities: CVE-2022-4297 and CVE-2023-24078
  • Exploits: CVE-2019-1405
  • Breaches: BreachForums/XSS: xkcd Data Breach and Coachella Data Breach

Sweden Warns Companies Against Google Analytics Use)

Swedish data-protection authorities have warned companies not to use Google Analytics, indicating that its use involved the transfer of personal data to the United States—breaching the European Union's General Data Protection Regulation (GDPR) conventions. The European Court of Justice (CJEU) had previously ruled that the United States did not have adequate level of protection for personal data at the time of the ruling.

AIIMS Ransomware Attack Prompts Indian Government to Formulate National Cybersecurity Response Framework (NCRF)

A November 2022 ransomware attack on India’s premier medical university and hospital, All India Institute of Medical Sciences, has catalyzed the creation of a national cybersecurity response framework. The attack exposed vulnerabilities in network architecture and prompted authorities to work towards enhancing infrastructure protection, properly addressing data breaches and gaps in response mechanisms, and improving inter-ministerial cooperation. The NCRF will be made public and implemented in critical infrastructure sectors, such as power and healthcare.

Mexican Cybercriminal Neo_Net Behind Global Android Malware Campaign Targeting Banks

A Mexico resident using the nom de plume “Neo_Net” has been linked to an Android mobile malware campaign targeting major Spanish and Chilean banks. The accused successfully stole over EUR 350,000 from bank accounts and compromised the personal information of numerous victims. The campaign leverages SMS phishing and rogue Android apps to capture credentials and two-factor authentication codes.

THREAT ACTIVITY: INITIAL-ACCESS & DATA BROKERS

  • Exploit user "GenesisStore": Reputable threat actor announces sale of Genesis market assets and infrastructure
  • Anonymous Sudan: Claims to have attacked video-game developer Riot Games; announces intent to attack Israel soon

VULNERABILITIES

  • CVE-2022-4297 - WordPress WP AutoComplete Search plugin versions 1.0.4 and below suffer from a remote SQL injection vulnerability.
  • CVE-2023-24078 - Real Time Logic FuguHub v8.1 and earlier contain a remote code execution vulnerability.

EXPLOITS

BREACHES

Tags: DIB, tlp:green