zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - April 16, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - April 16, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • ZeroFox Intelligence Flash Report - Geopolitical and Cyber Risks of Iranian Attack on Israel
  • Cisco Duo's Multifactor Authentication Service Breached
  • Hackers Hide Malicious Codes in Images to Target 320 Organizations Globally

ZeroFox Intelligence Flash Report - Geopolitical and Cyber Risks of Iranian Attack on Israel

On April 13, Iran launched a massive, yet calibrated, attack on Israel in retaliation for an earlier Israeli strike on an Iranian consulate in Syria. Negative economic, geopolitical, and supply chain effects have been muted because markets already factored in the strike, which came with a two-week warning and deliberately avoided mass casualties. An immediate Israeli response that would widen the Israel-Hamas war is unlikely, but limited strikes against military positions belonging to Iranian allies across the Middle East are well within the realm of possibility. Ahead of the retaliation, ZeroFox identified cyber threat actors forming alliances with both Israel and Iran, which could escalate to cyberattacks on organizations on each side of the conflict. An Israeli-backed cyberattack on Iran is less likely, as Israel has historically focused its targeting on threats to its physical security.

Cisco Duo's Multifactor Authentication Service Breached

Cisco alerted its customers about a social engineering cyberattack in a third-party telephony provider for its Duo multi factor authentication (MFA) service. The company has warned its customers to watch for follow-up phishing attempts. Threat actors allegedly exploited compromised employee credentials to access the provider's systems and downloaded SMS logs for specific users within a certain period. Cisco has advised impacted users to stay vigilant against further phishing attacks.

Hackers Hide Malicious Codes in Images to Target 320 Organizations Globally

Researchers have observed threat actor TA558 using images infected with malicious code to deploy malware tools on targeted systems in over 320 organizations globally. The campaign initiates with emails containing seemingly harmless attachments that exploit a seven-year-old patched remote control execution (RCE) vulnerability in Microsoft Office. The attachments comprise a Visual Basic Script (VBS) that fetches an image file (JPG). The image comes with PowerShell code that downloads the final payload, delivering a diverse range of malware families. One way to fortify against this malware-delivery campaign is to update Microsoft Office to the latest versions.

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

VULNERABILITIES

  • CVE-2024-25629: c-ares is a C library for asynchronous DNS requests. ares__read_line() is used to parse local configuration files such as /etc/resolv.conf, /etc/nsswitch.conf, the HOSTALIASES file, and if using a c-ares version prior to 1.27.0, the /etc/hosts file.
  • CVE-2023-6814: Insertion of Sensitive Information into Log File vulnerability in Hitachi Cosminexus Component Container allows local users to gain sensitive information.

EXPLOITS

  • CVE-2020-5849: Unraid 6.8.0 allows authentication bypass.
  • CVE-2020-6857: CarbonFTP v1.4 uses insecure proprietary password encryption with a hard-coded weak encryption key. The key for local FTP server passwords is hard-coded in the binary.

BREACHES

Tags: DIB, tlp:green