zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - April 29, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - April 29, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Hackers Claim to Have Infiltrated Belarus’ Main Security Service
  • Ukraine Targeted in Cyberattack Exploiting 7-Year-Old Microsoft Office Flaw
  • Cybersecurity Incident Shuts Down London Drugs Stores Across Western Canada

Hackers Claim to Have Infiltrated Belarus’ Main Security Service

The Belarusian hacker activist group Cyber-Partisans claims to have breached the network of the country's main KGB security agency, accessing personnel files of over 8,000 employees. The attack is reportedly in retaliation for the KGB chief accusing the group of plotting attacks on critical infrastructure, including a nuclear power plant. According to a spokesperson for Cyber-Partisans, the group had been attempting to infiltrate the KGB's network for several years before successfully gaining access to its website and database.

Ukraine Targeted in Cyberattack Exploiting 7-Year-Old Microsoft Office Flaw

Cybersecurity researchers have uncovered a targeted operation aimed at Ukraine, utilizing a nearly seven-year-old vulnerability in Microsoft Office to distribute Cobalt Strike on compromised systems. The attack begins with a PowerPoint slideshow file named signal-2023-12-20-160512.ppsx, which researchers suggest may have been shared via the Signal instant messaging app. This file is reported to be an old U.S. Army instruction manual for mine clearing blades (MCB) for tanks. This vulnerability, with a CVSS score of 7.8, enables attackers to execute arbitrary actions by tricking victims into opening a malicious file.

Cybersecurity Incident Shuts Down London Drugs Stores Across Western Canada

London Drugs recently shut down 79 pharmacies across Western Canada after discovering a cybersecurity incident. The shut down of pharmacies was announced on social media, citing an "operational issue." The company has taken immediate steps to secure its network and data and has been working with leading third-party cybersecurity experts to assist with forensic investigation, containment, and remediation. For any urgent needs, London Drugs has its pharmacists on standby and has urged customers to contact their local store’s pharmacy for assistance.

VULNERABILITIES

  • CVE-2023-4692: An out-of-bounds write flaw was found in grub2's NTFS filesystem driver. This issue may allow an attacker to present a specially crafted NTFS filesystem image, leading to grub's heap metadata corruption. In some circumstances, the attack may also corrupt the UEFI firmware heap metadata. As a result, arbitrary code execution and secure boot protection bypass may be achieved.
  • CVE-2023-4693: An out-of-bounds read flaw was found on grub2's NTFS filesystem driver. This issue may allow a physically present attacker to present a specially crafted NTFS file system image to read arbitrary memory locations. A successful attack allows sensitive data cached in memory or EFI variable values to be leaked, presenting a high Confidentiality risk.

BREACHES

Tags: DIB, tlp:green