zerofox logo
Advisories

ZeroFox Weekly Intelligence Brief – February 19, 2024

|by Alpha Team

banner image

ZeroFox Weekly Intelligence Brief – February 19, 2024

ZeroFox’s Weekly Intelligence Briefing highlights the major developments and trends across the cyber threat landscape. ZeroFox Intelligence is derived from a variety of sources, including—but not limited to—curated open-source accesses, vetted social media, proprietary data sources, and direct access to threat actors and groups through covert communication channels. Information relied upon to complete any report cannot always be independently verified. As such, ZeroFox applies rigorous analytic standards and tradecraft in accordance with best practices and includes caveat language and source citations to clearly identify the veracity of our Intelligence reporting and substantiate our assessments and recommendations. All sources used in this particular Intelligence product were identified prior to 12:00 PM (EDT) on February 16, 2024; per cyber hygiene best practices, caution is advised when clicking on any third-party links.

Read the Brief

View the full report here

Authorities Release Rhysida Ransomware Decryptor

Cybersecurity experts, including some from the Korea Internet and Security Agency (KISA), have successfully uncovered an implementation vulnerability in Rhysida ransomware, marking the first-ever decryption of the 2023-born ransomware. The experts used an analysis exposing the ransomware's utilization of LibTomCrypt, intermittent encryption, and a predictable pseudo-random number generator. The decryption applies only to the Windows PE version of Rhysida; it does not apply to the ESXi or the PowerShell payload versions. KISA is distributing a Rhysida ransomware recovery tool free of charge to help victims of the ransomware.

New Fortinet RCE Bug is Actively Exploited, CISA Confirms

CISA has confirmed that the new Fortinet RCE bug is actively being exploited. An out-of-bounds write weakness found in the FortiOS operating system led to the vulnerability (CVE-2024-21762), which lets unauthenticated attackers remotely execute arbitrary code on a compromised device. CISA has asked the Federal Civilian Executive Branch (FCEB) agencies to fix this vulnerability by February 16.

Patch Tuesday: Microsoft Confirms Windows Exploits Bypassing Security Features

Microsoft’s February 2024 Patch Tuesday updates focused on fixes for 73 vulnerabilities, including five critical vulnerabilities. Among the updates were also fixes of two actively-exploited zero-day vulnerabilities (CVE-2024-21351 and CVE-2024-21412, marked moderate and important respectively) and a critical remote code execution (RCE) bug in Microsoft Office (CVE-2024-21413). Microsoft also warned that at least three vulnerabilities are being exploited in live malware attacks and has urged users to install the fixes immediately.

Tags: tlp:green