ZeroFox Cyber Intelligence Daily Brief - April 25, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - April 25, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Cisco Releases Security Updates Addressing ArcaneDoor, Vulnerabilities in Cisco Firewall Platforms
- U.S. Charges Samourai Cryptomixer Founders for Laundering USD 100 Million
- Leicester Streetlights in Disarray After Cyberattack
Cisco Releases Security Updates Addressing ArcaneDoor, Vulnerabilities in Cisco Firewall Platforms
Cisco has released security updates to address ArcaneDoor—exploitation of Cisco Adaptive Security Appliances (ASA) devices and Cisco Firepower Threat Defense (FTD) software. A cyber threat actor could exploit vulnerabilities (CVE-2024-20353, CVE-2024-20359, CVE-2024-20358) to take control of an affected system. Cisco has reported active exploitation of CVE 2024-20353 and CVE-2024-20359 and CISA has added these vulnerabilities to its Known Exploited Vulnerabilities Catalog. CISA strongly encourages users and administrators to apply the necessary updates, hunt for any malicious activity, and report positive findings to CISA.
U.S. Charges Samourai Cryptomixer Founders for Laundering USD 100 Million
The founders of Samourai have been charged by the U.S. Department of Justice for laundering over USD 100 million from criminal enterprises. The accused used Samourai's Whirlpool crypto mixer to process over USD 2 billion in illicit funds. Samourai's "Ricochet" service used intermediate transactions to prevent tracking of cryptocurrency funds from criminal activity. The founders allegedly earned around USD 4.5 million in fees for Whirlpool and Ricochet transactions. Samourai's Wallet mobile application was seized by Icelandic law enforcement, along with their domains and web servers. The Google Play Store has removed the Android mobile app after being served a seizure warrant.
Leicester Streetlights in Disarray After Cyberattack
A cyberattack on Leicester left the city’s streetlights blazing continually driving electricity costs up. The attack forced the city to shut down its IT systems making it difficult for the city to effectively respond to infrastructural issues. On April 4, 2024, ZeroFox observed an update on the INC Ransomware leak site targeting Leicester City Council. The threat actor claimed to have stolen 3TB of private information. Authorities confirm that the cyberattack affected Leicester’s central management system and that this issue may be resolved by the “first week of May.”
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- BreachForums user Ynnian: Actor Claims to Leak Data From Lekpharm
- BreachForums user sedapmalam: Actor Claims to Leak Data From Tunas Toyota
EXPLOITS
- CVE-2024-22836: An OS command injection vulnerability exists in Akaunting v3.1.3 and earlier. An attacker can manipulate the company locale when installing an app to execute system commands on the hosting server.
- CVE-2024-21887: A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the appliance.
BREACHES
- BreachForums: urcuqui.gob.ec Breach (28 Records): Password, Email Address, Name, Username
- Combolist: '350K Gmail Access Combo.txt' (363,919 Records): Email Address, Password
Tags: DIB, tlp:green