ZeroFox Cyber Intelligence Daily Brief - March 17, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - March 17, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Japan Warns of a PyPI Supply Chain Attack Conducted by North Korean Hackers
- French Government Targeted in Denial-of-Service Attacks by Pro-Russian Hackers
- Fortinet Warns of Severe SQLi Vulnerability in FortiClientEMS Software
Japan Warns of a PyPI Supply Chain Attack Conducted by North Korean Hackers
Cybersecurity officials in Japan are warning developers that North Korean hacking group Lazarus has been targeting the PyPI software repository for Python apps in a supply chain attack. The threat actor has uploaded malicious packages with a similar name to a legitimate encryption toolkit for Python. These packages, once downloaded, inject Windows systems with a dangerous Trojan called Comebacker. Since PyPI is a centralized service used worldwide, experts have advised developers to be wary of Lazarus’ latest campaign and use software composition analysis (SCA) tools to evaluate dependencies and spot fake or compromised legitimate packages.
French Government Targeted in Denial-of-Service Attacks by Pro-Russian Hackers
On March 11, the French government said that a cyberattack of “unprecedented intensity” had targeted several of its services, prompting the activation of a special crisis center to restore online services. A statement from Prime Minister Gabriel Attal’s office further added that the attack had struck multiple ministries. By Monday afternoon, the attack’s impact had been reduced, restoring several impacted services and sites. ZeroFox has observed threat actor group Anonymous Sudan take responsibility for targeting the French government in denial-of-service attacks. The threat actor has particularly named the French Interministerial Directorate of Digital Affairs as its victim.
Fortinet Warns of Severe SQLi Vulnerability in FortiClientEMS Software
Fortinet has issued a warning about a critical security vulnerability affecting its FortiClientEMS software, potentially allowing attackers to undertake code execution on affected systems. The flaw (CVE-2023-48788) has a CVSS rating of 9.3 out of 10 and impacts several versions of FortiClientEMS. Fortinet has fixed two other critical bugs in FortiOS and FortiProxy (CVE-2023-42789 and CVE-2023-42790) that could permit attackers to execute arbitrary code or commands via specially crafted HTTP requests. While there is no evidence of active exploitation of these vulnerabilities yet, users are still strongly advised to promptly apply the updates to safeguard their systems.
Tags: DIB, tlp:green