zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - March 25, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - March 25, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • ZeroFox Intelligence Brief - Search Engine Optimization Poisoning
  • Elite Russian Hackers Targeting German Politicians
  • Details of Millions of United Kingdom Voters Accessed by Chinese State

ZeroFox Intelligence Brief - Search Engine Optimization Poisoning

While a legitimate practice, search engine optimization (SEO) is also used for malicious purposes. This is referred to as SEO poisoning, or “black hat SEO,” and like legitimate SEO, it usually relies upon the premise that users of search engines find the top SERP results in the most credible and appropriate to their search, increasing the likelihood they will be visited. SEO Poisoning is leveraged by a wide array of threat actors, such as financially-motivated cybercriminals, politically-motivated state actors, ideologically-motivated hacktivists, and organizations seeking a competitive advantage. The threat from SEO poisoning to organizations and individuals will almost certainly increase in 2024 as threat actors continually develop new social engineering methods to entice victims and deploy malicious payloads.

Elite Russian Hackers Targeting German Politicians

APT29, a hacking group associated with Russian intelligence, targeted multiple members of German political parties intending to infiltrate their networks and steal data. The hackers attempted to phish key German political figures by sending email invitations to a fictitious dinner event hosted by Christian Democratic Union (CDU), Germany’s center-right political party. The CDU acknowledged the ongoing threat of digital attacks from both domestic and foreign sources and confirmed receiving prompt information about the attack, clarifying that the March 1 dinner event was fabricated.

Details of Millions of United Kingdom Voters Accessed by Chinese State

A China-linked cyberattack on the Electoral Commission has compromised the personal details of millions of voters. The UK government is reportedly planning to confirm the identities of 43 prominent people (including members of parliament and peers) who have been targeted by China-backed attacks. Ministers, along with the deputy prime minister are expected to reveal details to the parliament about Beijing being behind the wave of cyberattacks on Monday. According to sources, sanctions against individuals thought to be connected with the alleged activity are under strong consideration. A small group of politicians have been called to a briefing by parliament’s director of security, about the activity. Reforms of UK spying laws, including the Investigatory Powers (Amendment) Bill, are also on the agenda for Monday’s Common session.

VULNERABILITIES

  • CVE-2023-5685: A flaw was found in XNIO. The XNIO NotifierState that can cause a Stack Overflow Exception when the chain of notifier states becomes problematically large can lead to uncontrolled resource management and a possible denial of service (DoS).
  • CVE-2024-2826: A vulnerability classified as problematic was found in lakernote EasyAdmin up to 20240315. This vulnerability affects unknown code of the file /ureport/designer/saveReportFile. The manipulation leads to xml external entity reference. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-257716.

BREACHES

Tags: DIB, tlp:green