zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - March 23, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - March 23, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • German Authorities Shut Down Darknet Marketplace for Drugs, Data and Cybercrime Services
  • Unsaflok Flaw Can Let Hackers Unlock Millions of Hotel Doors
  • Ivanti Discloses Two More Critical Vulnerabilities

German Authorities Shut Down Darknet Marketplace for Drugs, Data and Cybercrime Services

German authorities announced the takedown of Nemesis Market, a major darknet hub for drugs, stolen data, and cybercrime services like ransomware and DDoS attacks. They seized servers in Germany and Lithuania besides approximately USD 102,000 in cryptocurrency. The FBI, the Drug Enforcement Administration (DEA), and the Internal Revenue Service (IRS) collaborated in investigating the darknet platform, which boasted 150,000 user accounts and 1,100 seller accounts worldwide. This operation is expected to fuel ongoing probes targeting users and sellers involved in illicit activities facilitated by Nemesis Market.

Unsaflok Flaw Can Let Hackers Unlock Millions of Hotel Doors

Cybersecurity researchers have discovered "Unsaflok," a series of vulnerabilities affecting 3 million Saflok electronic RFID locks used in 13,000 hotels and homes in 131 countries. These flaws allow attackers to forge keycards and easily unlock any door, impacting various Saflok models, including the Saflok MT, the Quantum Series, the RT Series, the Saffire Series, and the Confidant Series. The manufacturer, Dormakaba, has been working to mitigate the flaw, but as of March 2024, 64% of the locks remain vulnerable to attacks. It has been further noted that malicious keycards can override the deadbolt, so security measures aren't enough to prevent unauthorized entry. Guests can determine if the locks on their rooms are vulnerable by using the NFC Taginfo app (Android, iOS) to check their keycard type from their phone.

Ivanti Discloses Two More Critical Vulnerabilities

Ivanti has disclosed two new critical vulnerabilities affecting its products and has released patches for them. Dubbed CVE-2023-46808, with a CVSS score of 9.8, this bug affects Ivanti Neurons for ITSM. It can let an authenticated remote attacker write or upload files to the ITSM server and execute arbitrary code. Ivanti has patched the bug in all supported versions of Ivanti Neurons for ITSM (2023.3, 2023.2, and 2023.1) and all Ivanti Neurons for ITSM Cloud landscapes. CVE-2023-41724, with a CVSS score of 9.6, allows an unauthenticated threat actor to execute arbitrary commands on the underlying operating system of the appliance within the same physical or logical network. The patch for the bug is available in versions 9.17.1, 9.18.1, and 9.19.1 of Ivanti Standalone Sentry.

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

VULNERABILITIES

  • CVE-2024-2816: A vulnerability classified as problematic was found in Tenda AC15 15.03.05.18. The manipulation leads to cross-site request forgery. The attack can be launched remotely.
  • CVE-2024-2817: A vulnerability, which was classified as problematic, has been found in Tenda AC15 15.03.05.18. The manipulation leads to cross-site request forgery. The attack may be launched remotely.

EXPLOITS

  • CVE-2020-29669: In the Macally WIFISD2-2A82 Media and Travel Router 2.000.010, the Guest user is able to reset its own password.

BREACHES

Tags: DIB, tlp:green