zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - January 22, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - January 22, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • CISA Issues Emergency Directive (ED) 24-01 on Ivanti Vulnerabilities
  • LockBit Ransomware Gang Claims Attack on the Sandwich Chain Subway
  • Microsoft Actions Following Attack by Nation State Actor Midnight Blizzard

CISA Issues Emergency Directive (ED) 24-01 on Ivanti Vulnerabilities

In its first emergency directive of 2024 (ED 24-01), CISA has directed all Federal Civilian Executive Branch (FCEB) agencies to immediately mitigate two actively exploited flaws in Ivanti Connect Secure and Ivanti Policy Secure (CVE-2023-46805 and CVE-2024-21887). As reported in ZeroFox’s Cyber Intelligence Daily Brief of January 14, these bugs are being widely exploited by several threat actors, including Chinese state-linked hackers. CISA advises FCEB agencies to apply the updates to the products within 48 hours of Ivanti releasing the updates and implement the mitigations as detailed in the ED.

LockBit Ransomware Gang Claims Attack on the Sandwich Chain Subway

The Lockbit ransomware group has targeted Subway and added the company to its list of victims on its Tor data leak site, threatening to leak the stolen data. Lockbit claims to have exfiltrated hundreds of gigabytes of sensitive data from Subway's internal system. The stolen information includes employee salaries, franchise royalty payments, master franchise commission payments, restaurant turnovers, and more. The hackers are giving Subway a limited time to secure the data; otherwise, they threaten to sell it to competitors.

Microsoft Actions Following Attack by Nation State Actor Midnight Blizzard

Microsoft has issued a warning about a security breach in some of its corporate email accounts by a Russian state-sponsored hacking group known as Midnight Blizzard, also known as Nobelium or APT29. The hackers, having gained access to the test account, proceeded to infiltrate a small percentage of Microsoft's corporate email accounts for over a month. The breached accounts included members of Microsoft's leadership team, cybersecurity, and legal departments, resulting in the theft of emails and attachments.

VULNERABILITIES

  • CVE-2024-23770: darkhttpd through 1.15 allows local users to discover credentials (for --auth) by listing processes and their arguments.
  • CVE-2024-23771: darkhttpd before 1.15 uses strcmp (which is not constant time) to verify authentication, which makes it easier for remote attackers to bypass authentication via a timing side channel.

BREACHES

Tags: DIB, tlp:green