zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - April 28, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - April 28, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Cisco Releases Security Updates Addressing ArcaneDoor, Vulnerabilities in Cisco Firewall Platforms
  • APT28 Exploited Windows Print Spooler Flaw to Steal Credentials
  • U.S. Government Issues New Guidance on Fortifying Election Infrastructure

Cisco Releases Security Updates Addressing ArcaneDoor, Vulnerabilities in Cisco Firewall Platforms

Cisco has released security updates to address ArcaneDoor—exploitation of Cisco Adaptive Security Appliances (ASA) devices and Cisco Firepower Threat Defense (FTD) software. A cyber threat actor could exploit vulnerabilities (CVE-2024-20353, CVE-2024-20359, CVE-2024-20358) to take control of an affected system. Cisco has reported active exploitation of CVE 2024-20353 and CVE-2024-20359 and CISA has added these vulnerabilities to its Known Exploited Vulnerabilities Catalog. CISA strongly encourages users and administrators to apply the necessary updates, hunt for any malicious activity, and report positive findings to CISA.

APT28 Exploited Windows Print Spooler Flaw to Steal Credentials

Security researchers have observed Russian GRU-linked APT28 (Forest Blizzard / STRONTIUM / Sednit / Fancy Bear) abusing a bug (CVE-2022-38028) in Windows Print Spooler to elevate privileges and steal credentials. The attacks—which target European and North American governments, non-governmental, education, and transportation entities—have continued from around April 2019. Patches for the bug were issued in October 2022; users should apply the patches at the earliest possible to guard their networks against such attacks.

U.S. Government Issues New Guidance on Fortifying Election Infrastructure

The U.S. government has released guidance to help election infrastructure stakeholders prepare for and respond to efforts by foreign adversaries to undermine the U.S. election process. The People’s Republic of China (PRC), the Russian Federation, and the Islamic Republic of Iran remain the primary nation-state actors involved in hostile efforts by or on behalf of foreign governments to shape U.S. policies, decisions, and discourse. The guidance suggests early communication, promoting transparency, and securing public-facing content to help mitigate the impacts on election operations and maintain public confidence in the security and integrity of the American democratic process.

Tags: DIB, tlp:green