ZeroFox Cyber Intelligence Daily Brief - February 6, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - February 6, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Hong Kong Company Loses USD 25 Million to Deep Fake Scam Targeting an Employee
- Announcement of a Visa Restriction Policy to Promote Accountability for the Misuse of Commercial Spyware
- Mitsubishi Electric Factory Automation Flaws Expose Engineering Workstations
Hong Kong Company Loses USD 25 Million to Deep Fake Scam Targeting an Employee
The Hong Kong branch of a multi-national company suffered a loss of USD 25 million after scammers used deepfake technology to trick one of its employees. The targeted finance department employee reportedly received a message from an individual claiming to be the company's UK-based chief financial officer. They then attended a video conference with deepfake versions of the company's CFO and other company employees. After this, the employee, acting on instructions received on the call, supposedly transferred USD 25.6 million to various Hong Kong bank accounts across 15 transactions.
The U.S. Restricts Visa for those Involved in Misuse of Commercial Spyware
The U.S. government has announced visa restrictions on those involved with the misuse of commercial spyware. This policy is essential for the United States to limit “repression, restrict the free flow of information, and enable human rights abuses.” The policy allows the imposition of visa restrictions on actors that can potentially misuse human rights, as well as financially benefit from such exploits and develop and operationally control companies that provide commercial spyware to governments.
Mitsubishi Electric Factory Automation Flaws Expose Engineering Workstations
Mitsubishi Electric reported two vulnerabilities — a high-severity authentication bypass and a critical remote code execution vulnerability — that have affected several factory automation products. The implications of these vulnerabilities can mean that potential threat actors can gain high-privileged access to an engineering workstation, allowing them to reprogram PLCs. According to sources, no patch has been issued yet for these vulnerabilities, but the company urges users to employ cybersecurity measures to limit chances of exposure.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- Telegram user Stormous: Actor Claims no Affiliation With Knight Ransomware
- BreachForums user emo: Actor Claims to Leak Data From Gaming Underground Network
VULNERABILITIES
- CVE-2024-24808: pyLoad is an open-source Download Manager written in pure Python.
- CVE-2024-20828: Improper authorization verification vulnerability in Samsung Internet prior to version 24.0 allows physical attackers to access files downloaded in SecretMode without proper authentication.
EXPLOITS
- CVE-2021-37589: Virtua Cobranca before 12R allows SQL Injection on the login page.
- CVE-2022-31325: There is a SQL Injection vulnerability in ChurchCRM 4.4.5 via the 'PersonID' field in /churchcrm/WhyCameEditor.php.
BREACHES
- Combolist: 'facebook%20by%20%40anonnymee.txt%20600%20account.txt' (715 Records): Email Address, Password
- Combolist: '58K_Gaming_Europa.txt' (58,142 Records): Email Address, Password
Tags: DIB, tlp:green