ZeroFox Cyber Intelligence Daily Brief - March 13, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - March 13, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- ZeroFox Intelligence Brief - Social Engineering Series: MFA Bypass via Phishing
- Microsoft Patches Approximately 60 Vulnerabilities in the Latest Patch Tuesday
- Data of 27,000 People at Stanford Stolen in September Ransomware Attack
ZeroFox Intelligence Brief - Social Engineering Series: MFA Bypass via Phishing
MFA uptake has been on a consistent upward trajectory since its inception, and today its use is widely expected, considered best practice, and a part of basic cybersecurity hygiene. Despite improving security, some MFA protocols are still susceptible to bypass or circumvention by threat actors seeking to gain illicit network access. This type of activity is almost certainly on an upward trajectory as of 2024, as threat actors continuously evolve their techniques, tactics, and procedures (TTPs).
Microsoft Patches Approximately 60 Vulnerabilities in the Latest Patch Tuesday
In its latest edition of Patch Tuesday, Microsoft has released fixes for at least 60 vulnerabilities, of which the company has noted six as “more likely to be exploited.” CVE-2024-21390, an elevation of privilege flaw in Microsoft Authenticator, allows an attacker to access multi-factor authentication codes for the victim's accounts, as well as modify or delete accounts in the authenticator app. Microsoft has marked two HyperV vulnerabilities— CVE-2024-21407 and CVE-2024-21408— as critical and has urged customers to deploy patches for them urgently.
Data of 27,000 People at Stanford Stolen in September Ransomware Attack
Stanford University has disclosed details of a ransomware attack impacting its Department of Public Safety (SUDPS) network that compromised the personally identifiable information (PII) belonging to 27,000 individuals. The university revealed that the attackers did not gain access to systems outside the Department of Public Safety’s network. The exposed data varies per person and includes information such as date of birth, Social Security number, government ID, passport number, driver's license number, and other information the Department of Public Safety may have collected in its operations. The Akira ransomware gang has claimed the attack and has published the stolen data on their dark web leak site for download via BitTorrent.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- BreachForums user aaron_bushnell: Actor Claims Cyber Attack Against NATO Military Infrastructures
- Telegram user Anonymous Collective: Actor Claims Cyber Attack Against Liverpool Airport
VULNERABILITIES
- CVE-2024-22099: NULL Pointer Dereference vulnerability in Linux Linux kernel kernel on Linux, x86, ARM (net, bluetooth modules) allows Overflow Buffers. This vulnerability is associated with program files /net/bluetooth/rfcomm/core.C. This issue affects Linux kernel: v2.6.12-rc2.
- CVE-2024-23121: A maliciously crafted MODEL file in libodxdll.dll when parsed through Autodesk AutoCAD can force an Out-of-Bound Write. A malicious actor can leverage this vulnerability to cause a crash, write sensitive data, or execute arbitrary code in the context of the current process.
BREACHES
- Combolist: 'emailsp.txt' (248,034 Records): Email Address, Password
- Combolist: 'custom e hits betfair RAW.txt' (198,123 Records): Email Address, Password
Tags: DIB, tlp:green