zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - April 1, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - April 1, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Reported Supply Chain Compromise Affecting XZ Utils Data Compression Library, CVE-2024-3094
  • AT&T Confirms Data Breach; 73 Million Customer Data Exposed
  • Pentagon Outlines Cybersecurity Strategy for Defense Industrial Base

Reported Supply Chain Compromise Affecting XZ Utils Data Compression Library, CVE-2024-3094

CISA and the open source community are responding to reports of malicious code being embedded in XZ Utils versions 5.6.0 and 5.6.1. This activity was assigned CVE-2024-3094. XZ Utils is data compression software and may be present in Linux distributions. The malicious code may allow unauthorized access to affected systems. CISA recommends developers and users to downgrade XZ Utils to an uncompromised version—such as XZ Utils 5.4.6 Stable—hunt for any malicious activity and report any positive findings to CISA.

AT&T Confirms Data Breach; 73 Million Customer Data Exposed

AT&T has released a statement confirming that a data set released on a dark web forum comprises AT&T data-specific fields and affects 7.6 million current and 65.4 million former customers. It has stated that a “robust investigation” is underway. Meanwhile, the company has begun communicating proactively with impacted customers and is offering free credit monitoring. This announcement comes after AT&T denied that the leaked data set was associated with it, as reported in ZeroFox’s Cyber Intelligence Daily Brief on March 18. ZeroFox has also observed threat actor MajorNelson claiming to leak a database associated with AT&T.

Pentagon Outlines Cybersecurity Strategy for Defense Industrial Base

The U.S. Department of Defense (DOD) has highlighted four goals in its cybersecurity strategy for the defense industrial base (DIB). The Pentagon is working with more than 100,000 DIB companies and their subcontractors to protect the sector from malicious cyber activities. The first goal is to strengthen the DOD governance structure for DIB cybersecurity through strengthening inter-agency collaboration and regulations development for DIB contractors and subcontractors. The second goal is to improve DIB's cybersecurity posture. The third goal is to preserve the resiliency of critical capabilities by protecting production and critical suppliers. The final goal is to improve collaboration with the DIB through enhanced threat awareness, improved communication, and the expansion of public-private cybersecurity collaboration.

VULNERABILITIES

  • CVE-2024-20043: In da, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
  • CVE-2024-20044: In da, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

BREACHES

Tags: DIB, tlp:green