zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - March 14, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - March 14, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Notable CPU Manufacturers and Software Vendors Targeted in New GhostRace Attack
  • Nissan Oceania Warns 100,000 Individuals of Their Data Being Exposed in a December 2023 Breach
  • Fortinet Warns of Severe SQLi Vulnerability in FortiClientEMS Software

Notable CPU Manufacturers and Software Vendors Targeted in New GhostRace Attack

Cybersecurity researchers have disclosed the details of a new type of data leakage attack named GhostRace, targeting major CPU manufacturers and some popular software. GhostRace leverages speculative race conditions (SRCs) to extract sensitive data from memory, like passwords and encryption keys and requires physical or privileged access. This exploit bypasses common synchronization measures, posing threats of code execution and data theft. The attack method, Inter-Process Interrupt Storming, involves flooding the targeted process’ CPU core to induce kernel memory leaks. Linux developers have added a feature that limits the Inter-Process Interrupts (IPIs) rate, but they are not taking further steps because of performance concerns. CVE identifiers have been assigned for GhostRace and Inter-Process Interrupt Storming.

Nissan Oceania Warns 100,000 Individuals of Their Data Being Exposed in a December 2023 Breach

Nissan Oceania has provided an update on the December 2023 data breach, stating it has impacted approximately 100,000 individuals. The list of the affected individuals includes some of Nissan's customers, dealers, and a few current and former employees. Ten percent of the list had at least one form of government ID stolen. The remaining 90 percent lost other forms of personal information, such as copies of loan-related transaction statements, employment and salary information, and more general information like dates of birth. Nissan has provided mitigation measures, including access to Australia and New Zealand’s national identity and cyber support community service, free credit monitoring, and reimbursement where government ID replacement is recommended by the relevant issuing authority.

Fortinet Warns of Severe SQLi Vulnerability in FortiClientEMS Software

Fortinet has issued a warning about a critical security vulnerability affecting its FortiClientEMS software, potentially allowing attackers to undertake code execution on affected systems. The flaw (CVE-2023-48788) has a CVSS rating of 9.3 out of 10 and impacts several versions of FortiClientEMS.The vulnerability in FortiClientEMS involves an SQL injection flaw, which is categorized under CWE-89. This type of vulnerability allows attackers to execute unauthorized code or commands by exploiting special elements within SQL commands. This vulnerability can be exploited by unauthenticated attackers via carefully crafted requests. While there is no evidence of active exploitation of these vulnerabilities yet, users are still strongly advised to promptly apply the updates to safeguard their systems.

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

VULNERABILITIES

  • CVE-2024-2400: Use after free in Performance Manager in Google Chrome prior to 122.0.6261.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
  • CVE-2024-28388: SQL injection vulnerability in SunnyToo stproductcomments module for PrestaShop v.1.0.5 and before, allows a remote attacker to escalate privileges and obtain sensitive information via the StProductCommentClass::getListcomments method.

BREACHES

Tags: DIB, tlp:green