zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - January 14, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - January 14, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Chinese Nation-State Hackers Found To Be Actively Exploiting Ivanti Zero-Days
  • NIST Warns of Security and Privacy Risks from Rapid AI System Deployment
  • New macOS Backdoor via North Korean Hackers

Chinese Nation-State Hackers Found To Be Actively Exploiting Ivanti Zero-Days

Researchers have reported that hackers purportedly linked to the Chinese state are actively exploiting a couple of remote zero-day vulnerabilities in Ivanti Connect Secure (ICS) VPN devices. Threat actors take advantage of the two vulnerabilities (CVE-2023-46805 and CVE-2024-21887) to gain unauthorized access to compromised systems. They can then steal data, configure files, or execute commands remotely. It is also possible that the Chinese government-backed hackers have exfiltrated some credentials of the VPN service users.

NIST Warns of Security and Privacy Risks from Rapid AI System Deployment

The U.S. National Institute of Standards and Technology (NIST) highlights privacy and security challenges linked to the increased deployment of artificial intelligence (AI) systems. NIST outlines potential threats, including adversarial manipulation of training data, exploitation of model vulnerabilities, and malicious interaction to extract sensitive information. As generative AI systems like OpenAI ChatGPT and Google Bard become integral to online services, AI models face risks such as corrupted training data, software vulnerabilities, data model poisoning, and privacy breaches due to prompt injection attacks.

New macOS Backdoor via North Korean Hackers

Cybersecurity researchers have identified a new macOS backdoor named SpectralBlur, linked to a North Korean malware family, KANDYKORN. SpectralBlur, a moderately capable backdoor, shares similarities with KANDYKORN, known for its remote access trojan capabilities. Lazarus-connected BlueNoroff has previously been associated with KANDYKORN. Recent observations indicate a combination of elements from KANDYKORN and RustBucket in the threat actor's campaigns. The findings suggest North Korean threat actors are increasingly targeting macOS, particularly in industries like cryptocurrency and blockchain. SpectralBlur attempts to hinder analysis and evade detection, showcasing the growing trend of macOS-focused malware threats.

Tags: DIB, tlp:green