zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - February 22, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - February 22, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • ZeroFox Intelligence Flash Report - iSoon Data Leak Provides a Glimpse of Chinese State Cyber Espionage Priorities, Tools, and Tradecraft
  • CISA, EPA, and FBI Release Top Cyber Actions for Securing Water Systems
  • DoT Advisory Addresses Vulnerabilities in Maritime Systems

ZeroFox Intelligence Flash Report - iSoon Data Leak Provides a Glimpse of Chinese State Cyber Espionage Priorities, Tools, and Tradecraft

The iSoon data disclosures reveal the priorities, tools, and tradecraft of ongoing cyber espionage and influence operations being perpetrated by China nation-state actors, shedding light on the relationship between government contractors and the breadth of cyber tools at the Chinese government’s disposal. On or about February 16, GitHub account “I-S00N” published what they claimed were files associated with China-based company iSoon (aka Anxun), an organization affiliated with China’s Ministry of Public Safety (MPS). The alleged leaker organized the data into eight sections, with the information dating between 2018 and 2022 on wide-ranging tools and programs. The materials included technical details about some automated offensive tools, like an all-in-one penetration testing software program that enabled the automation of brute forcing, network attacks, directory scanning, data collection, et cetera. There were also automated social engineering kits that could be utilized in phishing campaigns and social media account takeovers.

CISA, EPA, and FBI Release Top Cyber Actions for Securing Water Systems

CISA along with the FBI and the Environmental Protection Agency (EPA), addressed cyberattacks on water and wastewater systems and entities and released a fact sheet including mitigation measures. The fact sheet suggests to reduce exposure to the public-facing internet, conducting regular cybersecurity assessments, change default passwords immediately, conduct an Inventory of operational technology/information technology assets, develop and exercise cybersecurity incident response and recovery plans, backup OT/IT systems, reduce exposure to vulnerabilities, and conduct cybersecurity awareness training.

DoT Advisory Addresses Vulnerabilities in Maritime Systems

The U.S. Department of Transportation (DoT) has issued an advisory to maritime stakeholders regarding potential vulnerabilities in maritime port equipment, networks, operating systems, software, and infrastructure. The advisory highlights that foreign companies, particularly from the People’s Republic of China (PRC), play a significant role in manufacturing, installing, and maintaining port equipment, posing risks to global maritime infrastructure's information technology (IT) and operational technology (OT) systems. Cybersecurity researchers have identified risks associated with integrating and utilizing the PRC's state-supported National Public Information Platform for Transportation and Logistics (LOGINK), Nuctech scanners, and automated ship-to-shore cranes worldwide. To mitigate these risks, maritime industry stakeholders such as vessel owners/operators, shippers, and port operators are advised to implement cybersecurity best practices including access control (identity and access management), vulnerability mitigation, and configuration management.

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

VULNERABILITIES

  • CVE-2024-24577: libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Using well-crafted inputs to git_index_add can cause heap corruption that could be leveraged for arbitrary code execution. There is an issue in the has_dir_name function in src/libgit2/index.c, which frees an entry that should not be freed. The freed entry is later used and overwritten with potentially bad actor-controlled data leading to controlled heap corruption. Depending on the application that uses libgit2, this could lead to arbitrary code execution. This issue has been patched in version 1.6.5 and 1.7.2.
  • CVE-2024-24575: libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Using well-crafted inputs to git_revparse_single can cause the function to enter an infinite loop, potentially causing a Denial of Service attack in the calling application. The revparse function in src/libgit2/revparse.c uses a loop to parse the user-provided spec string. There is an edge-case during parsing that allows a bad actor to force the loop conditions to access arbitrary memory. Potentially, this could also leak memory if the extracted rev spec is reflected back to the attacker. As such, libgit2 versions before 1.4.0 are not affected. Users should upgrade to version 1.6.5 or 1.7.2.

BREACHES

Tags: DIB, tlp:green