zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - February 24, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - February 24, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Russian-Linked Operation Texonto Engages PsyOps and Phishing in Cyberwar Tactics
  • Researchers Detail Apple's Recent Zero-Click Shortcuts Vulnerability
  • UnitedHealth Says Change Healthcare Hacked by Nation State, as Pharmacy Outages Drag On

Russian-Linked Operation Texonto Engages PsyOps and Phishing in Cyberwar Tactics

Russian-linked threat actors executed Operation Texonto, a multi-wave campaign from October to December 2023, using psychological operations (PsyOps) and spear-phishing to spread misinformation in Ukraine and steal Microsoft 365 credentials in Europe. The campaign deviates from typical malicious activity, utilizing a shared network infrastructure. It signifies another layer in the cyberwar between Russia-aligned actors and Ukraine. Cybersecurity researchers uncovered two distinct waves involving a spear-phishing attack on a Ukrainian defense company and an EU agency, followed by a disinformation campaign on topics like heating, drug, and food shortages.

Researchers Detail Apple's Recent Zero-Click Shortcuts Vulnerability

A significant security vulnerability, identified as CVE-2024-23204 with a CVSS score of 7.5, has been discovered in Apple's Shortcuts app. This flaw, now patched in the latest updates released on January 22, 2024 (iOS 17.3, iPadOS 17.3, macOS Sonoma 14.3, and watchOS 10.3), allowed shortcuts to access sensitive device information without user consent. The issue stemmed from the app's failure to prompt users for permission when certain actions involving sensitive data were executed. Apple Shortcuts, a scripting tool enabling users to create customized workflows for specific tasks, comes pre-installed on iOS, iPadOS, macOS, and watchOS platforms.

UnitedHealth Says Change Healthcare Hacked by Nation State, as Pharmacy Outages Drag On

UnitedHealth Group (UHG), a major U.S. health insurance giant, has confirmed that its subsidiary Change Healthcare suffered a cyberattack, likely by government-backed hackers. Change Healthcare is responsible for processing billions of healthcare transactions annually and claims to handle roughly one-in-three U.S. patient records, which equates to around a hundred million Americans. The exact nature of the attack is yet to be revealed. As a result of the outage, pharmacies across the country are unable to fulfill prescriptions through patients’ insurance, as Change Healthcare handles much of the billing process. Moreover, several people in the healthcare sector have reported to experience downtime due to the ongoing cyberattack.

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

VULNERABILITIES

  • CVE-2024-22243: Applications that use UriComponentsBuilder to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the host of the parsed URL may be vulnerable to a open redirect. https://cwe[.]mitre[.]org/data/definitions/601[.]html attack or to a SSRF attack if the URL is used after passing validation checks.
  • CVE-2024-26151: The mjml PyPI package, found at the "FelixSchwarz/mjml[-]python" GitHub repo, is an unofficial Python port of MJML, a markup language created by Mailjet.

EXPLOITS

  • CVE-2021-40870: Aviatrix Controller versions 6.x prior to 6.5-1804.1922 shell upload exploit that leverages a directory traversal vulnerability.
  • CVE-2021-33045: Various Dahua products suffers from multiple authentication bypass vulnerabilities.

BREACHES

Tags: DIB, tlp:green