zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - January 26, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - January 26, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • CISA Joins ACSC-led Guidance on How to Use AI Systems Securely
  • ZeroFox Intelligence Profile - IntelBroker
  • Hewlett Packard Enterprise Discloses Hack Conducted by Russian Threat Actors

CISA Joins ACSC-led Guidance on How to Use AI Systems Securely

The joint guidance released by CISA and led by ACSC provides organisations with steps on how to use AI systems securely. The paper summarises some important threats related to AI systems and prompts organisations to consider steps they can take to engage with AI while managing risk. It provides mitigations to assist both organisations that use self-hosted and third-party hosted AI systems. The guidance within this publication is focused on using AI systems securely rather than developing secure AI systems.

ZeroFox Intelligence Profile - IntelBroker

Well-regarded and established threat actor IntelBroker is a hacker and malware developer that has recently increased their targeting of U.S. government entities. Since the actor first became active in October 2022, IntelBroker has targeted approximately 150 victims with the majority being in the government, financial services, and technology sectors. IntelBroker mainly targets the United States and Canada, the APAC region, and European countries.

Hewlett Packard Enterprise Discloses Hack Conducted by Russian Threat Actors

American multinational IT company Hewlett Packard Enterprise (HPE) has disclosed that APT 29 (alias Midnight Blizzard, Cozy Bear, and Nobelium), a Russian state-sponsored threat actor, hacked its cloud email environment. On discovering the breach, the company immediately engaged its response process to investigate, contain, and remediate the incident. HPE has further confirmed it has expelled the threat actors from the targeted systems and that the incident did not materially impact the company.

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

  • Abyss: Micrometal
  • MyData: New Ransomware Group Emerges

VULNERABILITIES

  • CVE-2024-0809: Inappropriate implementation in Autofill in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to bypass Autofill restrictions via a crafted HTML page.
  • CVE-2024-0811: Inappropriate implementation in Extensions API in Google Chrome prior to 121.0.6167.85 allowed an attacker who convinced a user to install a malicious extension to leak cross-origin data via a crafted Chrome Extension. (Chromium security severity: Low)

EXPLOITS

  • CVE-2022-22630: A use after free issue was addressed with improved memory management.
  • CVE-2022-30004: Sourcecodester Online Market Place Site v1.0 suffers from an unauthenticated blind SQL Injection Vulnerability allowing remote attackers to dump the SQL database via time-based SQL injection..

BREACHES

Tags: DIB, tlp:green