ZeroFox Cyber Intelligence Daily Brief - February 14, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - February 14, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- ISC Releases Security Advisories for BIND 9
- Bumblebee Malware Strain Spotted in a New Campaign After a Four-Month Hiatus
- Patch Tuesday: Microsoft Confirms Windows Exploits Bypassing Security Features
ISC Releases Security Advisories for BIND 9
The Internet Systems Consortium (ISC) released security advisories to address eight vulnerabilities affecting multiple versions of ISC’s Berkeley Internet Name Domain (BIND) 9. Seven of these high severity vulnerabilities have a CVSS score of 7.5. According to CISA, a threat actor can exploit these to carry out a denial-of-service.
Bumblebee Malware Strain Spotted in a New Campaign After a Four-Month Hiatus
The Bumblebee malware strain has resurfaced, launching phishing attacks on U.S. organizations after a four-month hiatus. Initially discovered in April 2022, Bumblebee is linked to the Conti and Trickbot cybercrime syndicate and serves as a replacement for the BazarLoader backdoor. In the latest campaign, the malware strain disguises itself as fake voicemail notifications sent to thousands of organizations via emails. These emails contain a OneDrive URL leading to a Word document with a deceptive lure that eventually leads to the malware launching in the compromised system.
Patch Tuesday: Microsoft Confirms Windows Exploits Bypassing Security Features
In the February 2024 batch of Patch Tuesday updates, Microsoft issued over 70 security fixes. Among the updates were fixes of two actively exploited zero-day vulnerabilities (CVE-2024-21351 and CVE-2024-21412, marked moderate and important respectively) and a critical remote code execution (RCE) bug in Microsoft Office (CVE-2024-21413). This RCE bug could be exploited through the software’s Preview Pane, which can allow attackers to bypass the Office Protected View and open in editing mode rather than protected mode. Microsoft also warned that at least three vulnerabilities are being exploited in live malware attacks and has urged for immediate attention. The software maker warned its users against the risk of remote code execution, security feature bypass, information disclosure, and privilege escalation attacks.
Tags: DIB, tlp:green