zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - March 11, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - March 11, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Japan Warns of a PyPI Supply Chain Attack Conducted by North Korean Hackers
  • Update on Microsoft Actions Following Attack by Nation State Actor Midnight Blizzard
  • QNAP Warns of Critical Auth Bypass Flaw in its NAS Devices

Japan Warns of a PyPI Supply Chain Attack Conducted by North Korean Hackers

Cybersecurity officials in Japan are warning developers that North Korean hacking group Lazarus has been targeting the PyPI software repository for Python apps in a supply chain attack. The threat actor has uploaded malicious packages with a similar name to a legitimate encryption toolkit for Python. These packages, once downloaded, inject Windows systems with a dangerous Trojan called Comebacker. Since PyPI is a centralized service used worldwide, experts have advised developers to be wary of Lazarus’ latest campaign and use software composition analysis (SCA) tools to evaluate dependencies and spot fake or compromised legitimate packages.

Update on Microsoft Actions Following Attack by Nation State Actor Midnight Blizzard

Microsoft issued an update on Midnight Blizzard’s attack on January 12. In the ongoing investigation, Microsoft observes that Midnight Blizzard has been using exfiltrated data to gain further access to source code repositories and internal systems. Microsoft reports that the group has increased certain techniques in the last month such as password sprays. At this time of writing, the group’s attacks have not impacted any customer-facing systems, but the threat actors did access some of Microsoft’s “secrets” which were then shared with customers via email. Microsoft is currently in talks with customers regarding mitigations.

QNAP Warns of Critical Auth Bypass Flaw in its NAS Devices

QNAP, network attached storage (NAS) can reportedly be exploited by threat actors to conduct authentication bypass, command injection, and SQL injection. The three vulnerabilities observed in QTS, QuTS hero, QuTScloud, and myQNAPcloud are CVE-2024-21899, CVE-2024-21900, and CVE-2024-21901. The advisory recommends users to follow mitigation procedures to protect their data like personal information, intellectual property, and business details.

VULNERABILITIES

  • CVE-2024-28816: Student Information Chatbot a0196ab allows SQL injection via the username to the login function in index.php.
  • CVE-2024-1048: A flaw was found in the grub2-set-bootflag utility of grub2. After the fix of CVE-2019-14865, grub2-set-bootflag will create a temporary file with the new grubenv content and rename it to the original grubenv file. If the program is killed before the rename operation, the temporary file will not be removed and may fill the filesystem when invoked multiple times, resulting in a filesystem out of free inodes or blocks.

BREACHES

Tags: DIB, tlp:green