zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - April 13, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - April 13, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • CVE-2024-3400 PAN-OS: OS Command Injection Vulnerability in GlobalProtect Gateway
  • Sneaky Credit Card Skimmer Disguised as Harmless Facebook Tracker
  • ZeroFox Intelligence Brief - Social Engineering Series: Business Email Compromise

CVE-2024-3400 PAN-OS: OS Command Injection Vulnerability in GlobalProtect Gateway

Palo Alto Networks has disclosed a critical command injection vulnerability (CVE-2024-3400; CVSS score: 10) in the PAN-OS software with GlobalProtect feature configuration and device telemetry enabled in the firewall. According to the company’s advisory, patches for affected versions—PAN-OS 10.2, PAN-OS 11.0, and PAN-OS 11.1—will be available by April 14, 2024. This vulnerability can allow a threat actor to execute arbitrary code with root privileges on the firewall by first making distinct feature configurations.

Sneaky Credit Card Skimmer Disguised as Harmless Facebook Tracker

Cybersecurity researchers have discovered a credit card skimming malware hidden within a fake Meta Pixel tracker script, aimed at evading detection. The malware is injected into websites through custom code tools like WordPress plugins and Magento admin panels, which appear legitimate but contain additional JavaScript code redirecting to a compromised domain. To mitigate the potential risks posed by such malware, defenders should keep websites updated, review admin accounts, and update passwords frequently.

ZeroFox Intelligence Brief - Social Engineering Series: Business Email Compromise

BEC is a high-effort phishing technique in which a threat actor targets the legitimate email addresses of organizations and individuals, tricking users into providing sensitive information, which can lead to monetary theft or enable further malicious activity. Reporting suggests that BEC attacks are on a sharp upward trajectory, which is very likely due in part to their relatively high success rates and payoff in comparison to other methods of cyberattack. BEC will certainly remain a pertinent threat to organizations across industries this year, as threat actors continue to capitalize upon established techniques, high success rates, and constantly increasing financial payoffs.

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

VULNERABILITIES

  • CVE-2024-21463: Memory corruption while processing Codec2 during v13k decoder pitch synthesis.
  • CVE-2024-21454: Transient DOS while decoding the ToBeSignedMessage in Automotive Telematics.

EXPLOITS

  • CVE-2020-10915: This vulnerability allows remote attackers to execute arbitrary code on affected installations of VEEAM One Agent 9.5.4.4587.
  • CVE-2020-7351: An OS Command Injection vulnerability in the endpoint_devicemap.php component of Fonality Trixbox Community Edition allows an attacker to execute commands on the underlying operating system as the "asterisk" user.

BREACHES

Tags: DIB, tlp:green