zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - March 26, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - March 26, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • ZeroFox Intelligence Flash Report: UK Confirms Chinese State-Sponsored Cyber Attacks
  • CISA and FBI Release Secure by Design Alert to Urge Manufacturers to Eliminate SQL Injection Vulnerabilities
  • United States Sanctions Crypto Exchanges Used by Russian Darknet Market, Banks

ZeroFox Intelligence Flash Report: UK Confirms Chinese State-Sponsored Cyber Attacks

On March 25, the UK government warned the public about Chinese State-sponsored entities targeting, while two U.S. government agencies sanctioned alleged Chinese hackers linked to APT31. The UK government is wary of growing threats from Chinese State-sponsored entities targeting and undermining the country’s democratic processes. The announcement attributed two cyber attacks against UK political entities to Chinese State-sponsored actors. The U.S. Justice Department and the FBI unsealed an indictment against seven alleged Chinese hackers associated with APT31 involved in targeting United States-based critics, businesses, and political officials over approximately 14 years.

CISA and FBI Release Secure by Design Alert to Urge Manufacturers to Eliminate SQL Injection Vulnerabilities

CISA and the FBI have jointly released an alert crafted in response to the recent, well-publicized exploitation of SQL injection (SQLi) defects in a managed file transfer application that impacted thousands of organizations. Additionally, the alert highlights the prevalence of this class of vulnerability. CISA and the FBI urge senior executives at technology manufacturing companies to mount a formal review of their code to determine its susceptibility to SQLi compromises. If found vulnerable, senior executives should ensure their organizations’ software developers begin immediate implementation of mitigations to eliminate this entire class of defect from all current and future software products.

U.S. Sanctions Crypto Exchanges Used by Russian Darknet Market, Banks

The U.S. Treasury Department's Office of Foreign Assets Control (OFAC) has sanctioned several entities, including three cryptocurrency exchanges, for working with Russian dark web markets and other sanctioned entities. Following these sanctions, all assets and interests in the United States connected to the designated individuals and entities have been frozen. Moreover, transactions involving the blocked entities’ assets have been prohibited unless authorized by OFAC. Financial institutions engaged with these sanctioned entities will be at risk of exposure to sanctions or enforcement actions.

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

VULNERABILITIES

  • CVE-2024-29057: Microsoft Edge (Chromium-based) Spoofing Vulnerability
  • CVE-2024-26247: Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability

BREACHES

Tags: DIB, tlp:green