ZeroFox Weekly Intelligence Brief – January 22, 2024
|by Alpha Team

ZeroFox Weekly Intelligence Brief – January 22, 2024
TLP:GREEN
ZeroFox’s Weekly Intelligence Briefing highlights the major developments and trends across the cyber threat landscape. ZeroFox Intelligence is derived from a variety of sources, including—but not limited to—curated open-source accesses, vetted social media, proprietary data sources, and direct access to threat actors and groups through covert communication channels. Information relied upon to complete any report cannot always be independently verified. As such, ZeroFox applies rigorous analytic standards and tradecraft in accordance with best practices and includes caveat language and source citations to clearly identify the veracity of our Intelligence reporting and substantiate our assessments and recommendations. All sources used in this particular Intelligence product were identified prior to 12:00 PM (EDT) on January 19, 2024; per cyber hygiene best practices, caution is advised when clicking on any third-party links.
Read the Brief
View the full report here.
Chrome Addresses Four Vulnerabilities Including an Actively Exploited Zero-Day
What happened: Google Chrome recently addressed four vulnerabilities, including an actively exploited zero-day flaw observed in the wild through now published updates. CVE-2024-0519 is a high-severity vulnerability that allows threat actors to exploit its out-of-bounds memory access in the V8 JavaScript and WebAssembly engine to trigger a crash.
’MyFlaw’ Zero-Day RCE Vulnerability Uncovered in Opera Browser
What happened: On January 15, Guardio Labs disclosed that it discovered a critical zero-day Remote Code Execution (RCE) vulnerability in Opera web browser for Microsoft Windows and Apple macOS that would allow for the execution of malicious files on the operating systems. The now patched vulnerability, dubbed ‘MyFlaw’ due to its exploitation of Opera’s browser-to-mobile file and message-sharing extension My Flow, granted potential threat actors the ability to bypass the browser’s sandbox and subsequently create a fraudulent extension that imitated a mobile device to pair with the target computer. Once the fraudulent extension is downloaded, an encrypted payload could be sent via a JavaScript file and executed once the user clicks on the screen. Evidence to suggest active exploitation of this vulnerability in the wild has not yet been found. Additionally, while ZeroFox has not yet observed any dark web chatter from threat actors regarding this vulnerability, it will continue to monitor for such.
Actor KernelMode Advertised Malware for Sale Designed to Kill Most AV and EDR Products
What happened: On January 17, 2024, the actor KernelMode advertised a malware for sale that can kill most antivirus and EDR products on the Exploit forum. The actor claimed the malware was successfully tested on Microsoft Windows 7-11 operating systems to terminate processes for several AV and EDR products. The malware was priced at USD 5000 a month with a limit of five clients.
Tags: tlp:green