zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - March 9, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - March 9, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • ZeroFox Intelligence Assessment - How GenAI is Changing the Cyber Threat Landscape
  • CISA and NSA Release Cybersecurity Information Sheets on Cloud Security Best Practices
  • Medusa Ransomware Gang Claims Cyberattack on a U.S. Federal Credit Union

ZeroFox Intelligence Assessment - How GenAI is Changing the Cyber Threat Landscape

Generative Artificial Intelligence (GenAI) models offer vast potential in enabling mass automation, economic growth, scientific advances, and communication. However, there are also numerous security risks arising from its development and deployment, including ethical concerns, societal impacts, and use by nefarious cyber actors for malicious purposes. Adoption of GenAI-enabled technologies by corporate enterprises will also very likely introduce new vulnerabilities into organizations’ infrastructure and undermine secure-by-design principles. With emerging technologies and tools getting widespread and significant media and public attention, much of the discussion around the threat from GenAI is misleading, unclear, and unhelpful. At least in the short to medium term, GenAI will very likely serve as a force for both good and evil; the rapid development of new technologies will be added to the repository of tools used by threat actors to conduct their attacks as well as to the arsenals security personnel use to mitigate threats.

CISA and NSA Release Cybersecurity Information Sheets on Cloud Security Best Practices

The NSA and CISA have jointly issued five cybersecurity bulletins and five joint Cybersecurity Information Sheets (CSIs) to recommend best practices with mitigations to improve the security of their cloud environments. The guides cover identity and access management, secure key management, network segmentation, encryption, data security, and risk mitigation from managed service providers. They emphasize securing credentials, configuring multi-factor authentication, and encrypting data. The release follows instances like the Russian Nobelium threat actors targeting cloud services, prompting vigilance among cybersecurity professionals. CISA has also released “Untitled Goose Tool” that helps detect Azure cloud service attacks.

Medusa Ransomware Gang Claims Cyberattack on a U.S. Federal Credit Union

Medusa ransomware claims to have breached the systems of US 1364 Federal Credit Union, a non-profit financial organization. The threat actor has provided screenshots of sample data to support its claims. The sample data reportedly includes names, dates of birth, ID and passport numbers, driver's license details, business data, email addresses, and bank account numbers. In late February, the credit union suffered some technical difficulties, which might be connected to Medusa’s claimed attack. No official statement or ransom discussions have emerged as of now.

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

VULNERABILITIES

  • CVE-2024-23746: Miro Desktop 0.8.18 on macOS allows code injection via a complex series of steps that might be usable in some environments.
  • CVE-2024-23222: A type confusion issue was addressed with improved checks. This issue is fixed in iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, tvOS 17.3.

BREACHES

Tags: DIB, tlp:green