zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - March 29, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - March 29, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Retail Chain Hot Topic Hit by New Credential-Stuffing Attacks
  • Cisco Warns of Password-Spraying Attacks Targeting VPN Services
  • Finland Blames Chinese Hacking Group APT31 for Parliament Cyber Attack

Retail Chain Hot Topic Hit by New Credential-Stuffing Attacks

Hot Topic, an American retailer, experienced two rounds of credential-stuffing attacks in November, which compromised the personal information and partial payment data of affected customers. The attackers targeted Hot Topic Rewards accounts using login details obtained from an unidentified source. The company confirmed that unauthorized parties launched automated attacks on their website and mobile app on November 18-19 and November 25, 2023. Investigations are ongoing to determine if any accounts were accessed as a result of these attacks.

Cisco Warns of Password-Spraying Attacks Targeting VPN Services

Cisco has warned customers about password-spray attacks on Remote Access VPN (RAVPN) services configured on Cisco Secure Firewall. The attacks—which target third-party VPN concentrators as well as Cisco products—can lead to accounts being locked, resulting in Denial of Service (DoS)-like conditions. To help defenders, Cisco has disclosed indicators of compromise and suggested mitigation measures, including enabling logging to a remote syslog server for improved correlation and auditing of network incidents, ensuring secure default remote access VPN profiles, using TCP shun, and using certificate-based authentication for RAVPN.

Finland Blames Chinese Hacking Group APT31 for Parliament Cyber Attack

The Finnish police has accused Chinese state-backed threat group APT31 for an attack on Finland’s Parliament between late 2020 and early 2021. U.S. and U.K. officials have also linked this group (also tracked as Altaire, Bronze Vinewood, Judgement Panda, and Violet Typhoon) to cyberespionage campaigns on businesses, government officials, dissidents, and politicians.

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

VULNERABILITIES

  • CVE-2024-27318: Versions of the package onnx before and including 1.15.0 are vulnerable to Directory Traversal as the external_data field of the tensor proto can have a path to the file which is outside the model current directory or user-provided directory. The vulnerability occurs as a bypass for the patch added for CVE-2022-25882.

  • CVE-2024-27319: Versions of the package onnx before and including 1.15.0 are vulnerable to Out-of-bounds Read as the ONNX_ASSERT and ONNX_ASSERTM functions have an off by one string copy.

EXPLOITS

  • CVE-2020-25790: Typesetter CMS 5.x through 5.1 allows admins to upload and execute arbitrary PHP code via a .php file inside a ZIP archive. NOTE: the vendor disputes the significance of this report because "admins are considered trustworthy"; however, the behavior "contradicts our security policy" and is being fixed for 5.2
  • CVE-2020-27387: An unrestricted file upload issue in HorizontCMS through 1.0.0-beta allows an authenticated remote attacker (with access to the FileManager) to upload and execute arbitrary PHP code by uploading a PHP payload, and then using the FileManager's rename function to provide the payload (which will receive a random name on the server) with the PHP extension, and finally executing the PHP file via an HTTP GET request to /storage/. NOTE: the vendor has patched this while leaving the version number at 1.0.0-beta.

BREACHES

Tags: DIB, tlp:green