ZeroFox Cyber Intelligence Daily Brief - March 30, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - March 30, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Decade-old Linux “Wall” Bug Helps Make Fake SUDO Prompts, Steal Passwords
- Personal Data of 2.7 Million Pakistanis Stolen from Government Records
- PyPI Halts Sign-Ups Amid Surge of Malicious Package Uploads Targeting Developers
Decade-old Linux “Wall” Bug Helps Make Fake SUDO Prompts, Steal Passwords
A security flaw dubbed WallEscape (CVE-2024-28085) can allow an unprivileged attacker to trick Linux users into typing their administrator password—via fake SUDO prompts on the victim’s machine. A successful exploit would need the "mesg" utility to be active and the “wall” command (of the util-linux package, part of the Linux OS) to have setgid permissions. The bug has been patched in linux-utils v2.40.
Personal Data of 2.7 Million Pakistanis Stolen from Government Records
An investigation has revealed that the personal information of more than 2.7 million Pakistanis has been stolen from the records of the National Database and Registration Authority (Nadra) office. A team was formed to probe the data leak from Nadra. According to sources, the probe team has found Nadra offices in Karachi, Multan, and Peshawar allegedly involved in the data leak. The stolen data was reportedly sent to Dubai and later sold in Argentina and Romania. The probe team has recommended an upgrade of technology, as well as departmental and criminal proceedings against those found responsible for the data breach.
PyPI Halts Sign-Ups Amid Surge of Malicious Package Uploads Targeting Developers
PyPI temporarily suspended new user sign-ups due to a surge in malicious projects uploaded as part of a typosquatting campaign. The pause in user sign-ups aimed to address a malware upload campaign, with services resuming after 10 hours on March 28. A software security firm, disclosed that threat actors targeted developers with typosquatted versions of popular packages. These malicious payloads aimed at stealing crypto wallets, browser data, and credentials, with a persistence mechanism to survive reboots. Another cybersecurity company confirmed over 100 malicious packages, particularly targeting machine learning libraries like Pytorch, Matplotlib, and Selenium.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- BreachForums user Cyber_589: Actor Claims to Leak Data From Turkey Karabuk University
- XSS user Ddarknotevil: Data breach impacting U.S.-based St. Jude Laboratories
VULNERABILITIES
- CVE-2024-2411: The MasterStudy LMS plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.3.0 via the 'modal' parameter.
- CVE-2024-2409: The MasterStudy LMS plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.3.1. This is due to insufficient validation checks within the _register_user() function called by the 'wp_ajax_nopriv_stm_lms_register' AJAX action.
BREACHES
- Combolist: 'emailsp.txt' (237,737 Records): Email Address, Password
- Combolist: '336K.txt' (333,508 Records): Email Address, Password
Tags: DIB, tlp:green