ZeroFox Cyber Intelligence Daily Brief - April 22, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - April 22, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- U.S. Government Issues New Guidance on Fortifying Election Infrastructure
- MITRE Says State Hackers Breached Its Network via Ivanti Zero-Days
- CrushFTP Zero-Day Actively Exploited
U.S. Government Issues New Guidance on Fortifying Election Infrastructure
The U.S. government has released guidance to help election infrastructure stakeholders prepare for and respond to efforts by foreign adversaries to undermine the U.S. election process. The People’s Republic of China (PRC), the Russian Federation, and the Islamic Republic of Iran remain the primary nation-state actors involved in hostile efforts by or on behalf of foreign governments to shape U.S. policies, decisions, and discourse. The guidance suggests early communication, promoting transparency, and securing public-facing content to help mitigate the impacts on election operations and maintain public confidence in the security and integrity of the American democratic process.
MITRE Says State Hackers Breached Its Network via Ivanti Zero-Days
The MITRE Corporation suffered a data breach in January 2024 via two Ivanti zero-days (CVE-2023-46805 and CVE-2024-21887). A state-backed hacking group hacked one of MITRE's VPNs and bypassed multi-factor authentication (MFA) defenses using session hijacking. The breach was discovered on MITRE's Networked Experimentation, Research, and Virtualization Environment (NERVE) network. The company has contacted relevant authorities, notified affected parties, and is working on restoring the operational activities.
CrushFTP Zero-Day Actively Exploited
Multi-platform file transfer server CrushFTP has reportedly warned users to patch their systems against an actively exploited zero-day. Security researchers have observed attackers targeting CrushFTP servers in American organizations, potentially for politically motivated cyberespionage. The bug, which affects CrushFTP v11 versions below 11.1, has been patched in v11.1.0.
VULNERABILITIES
- CVE-2018-25101: A vulnerability, which was classified as problematic, has been found in l2c2technologies Koha up to 20180108. This issue affects some unknown processing of the file /cgi-bin/koha/opac-MARCdetail.pl. The manipulation of the argument biblionumber with the input 2">
leads to cross site scripting. The attack may be initiated remotely. The identifier of the patch is 950fc8e101886821879066b33e389a47fb0a9782. It is recommended to upgrade the affected component. The identifier VDB-261677 was assigned to this vulnerability. - CVE-2024-28722: Cross Site Scripting vulnerability in Innovaphone myPBX v.14r1, v.13r3, v.12r2 allows a remote attacker to execute arbitrary code via the query parameter to the /CMD0/xml_modes.xml endpoint
BREACHES
- Combolist: '370K gmail.com combolist.txt' (366,449 Records): Email Address, Password
- Combolist: '60%20CRUNCHYROLL.txt' (72 Records): Email Address, Password
Tags: DIB, tlp:green