zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - December 9, 2023

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - December 9, 2023

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Russian APT28 Military Hackers Target 14 Countries by Exploiting Microsoft Outlook Zero-Day
  • Atlassian Patches Critical RCE Vulnerabilities—Patch Now
  • CISA Releases Joint Guide for Software Manufacturers: The Case for Memory Safe Roadmaps

Russian APT28 Military Hackers Target 14 Countries by Exploiting Microsoft Outlook Zero-Day

Cyber researchers have observed APT28, tracked as Fighting Ursa / Fancy Bear / STRONTIUM and linked to Russia's Main Intelligence Directorate (GRU), leveraging a Microsoft Outlook zero-day exploit (CVE-2023-23397) in three separate campaigns to target member countries of the North Atlantic Treaty Organization (NATO), Ukraine, Jordan, the United Arab Emirates, and one NATO Rapid Deployable Corps. Despite Microsoft releasing a patch for CVE-2023-23397 earlier this year, the threat group continues to exploit the vulnerability to infiltrate compromised networks. These campaigns have allowed APT28 to zero in on crucial infrastructure entities including energy production, pipeline operations, and air transportation.

Atlassian Patches Critical RCE Vulnerabilities—Patch Now

Atlassian has disclosed details of four critical vulnerabilities (CVE-2023-22524, CVE-2023-22523, CVE-2023-22522, and CVE-2022-1471) that can allow an attacker to perform remote code execution (RCE). The bugs affect multiple products, including Confluence Data Center and Server, Assets Discovery app, and Companion app for MacOS. Admins are urged to deploy the available patches as soon as they can. Atlassian has also provided a temporary workaround for those who are unable to deploy the patches right now.

CISA Releases Joint Guide for Software Manufacturers: The Case for Memory Safe Roadmaps

CISA, in collaboration with several international security agencies, has published an advisory encouraging the implementation of memory safe roadmaps to eliminate memory safety vulnerabilities from software products. These roadmaps will be evidence of how manufacturers are owning security outcomes, embracing radical transparency, and taking a top-down approach to developing secure products. The advisory has been released as a part of the Secure by Design campaign and details how software manufacturers can transition to memory safe programming languages (MSLs).

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

VULNERABILITIES

  • CVE-2023-42568: Improper access control vulnerability in SmartManagerCN prior to SMR Dec-2023 Release 1 allows local attackers to access arbitrary files with system privilege.
  • CVE-2023-26158: All versions of the package mockjs are vulnerable to Prototype Pollution via the Util.extend function due to missing check if the attribute resolves to the object prototype.

BREACHES

Tags: DIB, tlp:green