ZeroFox Cyber Intelligence Daily Brief - March 6, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - March 6, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Apple Blunts Zero-Day Attacks With iOS 17.4 Update
- NSA Issues Zero-Trust Guidance to Limit Adversaries on the Network
- Treasury Sanctions Members of the Intellexa Commercial Spyware Consortium
Apple Blunts Zero-Day Attacks With iOS 17.4 Update
Apple has recently rolled out urgent software updates iOS 17.4, iPadOS 17.4, and iOS 16.7.6, to fix multiple security flaws including two exploited vulnerabilities, Kernel (CVE-2024-23225) and RTKit (CVE-2024-23296). These flaws could potentially allow attackers to bypass kernel memory protections. Additionally, Apple has also patched a privacy flaw in the Accessibility feature and a Safari Private Browsing bug. The company has confirmed evidence of zero-day exploits in the wild and plans to add more fixes as additional vulnerabilities are yet to be documented.
NSA Issues Zero-Trust Guidance to Limit Adversaries on the Network
The Zero Trust network and environment pillar curtails adversarial lateral movement by employing controls and capabilities to logically and physically segment, isolate, and control access (on-premises and off-premises) through granular policy restrictions. The concepts introduced in the advisory guide on enhancing existing network security controls to limit the potential impact of a compromise through data flow mapping, macro and micro-segmentation, and software-defined networking. These capabilities enable host isolation, network segmentation, enforcement of encryption, and enterprise visibility.
Treasury Sanctions Members of the Intellexa Commercial Spyware Consortium
The Department of the Treasury’s Office of Foreign Assets Control (OFAC) identified members and entities of Intellexa Consortium connected with developing and distributing commercial spyware technology to target Americans, including U.S. government officials, journalists, and policy experts. Reportedly, Intellexa Consortium has been responsible for the global proliferation of commercial spyware and tools called Predator that can help malicious entities in information stealing and can help carry out other surveillance capabilities like geolocation tracking.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- Telegram user The Dark Cyber Team: Actors Launch Cyber Attacks Targeting India
VULNERABILITIES
- CVE-2024-1938: Type Confusion in V8 in Google Chrome prior to 122.0.6261.94 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)
- CVE-2024-1939: Type Confusion in V8 in Google Chrome prior to 122.0.6261.94 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
BREACHES
- Combolist: 'auth.coyote.com (2).txt' (649 Records): Email Address, Password
- Combolist: '5k_lines_by__mailpassraul.txt' (5,441 Records): Email Address, Password
Tags: DIB, tlp:green