ZeroFox Cyber Intelligence Daily Brief - April 30, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - April 30, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- CISA Issues Guidelines To Mitigate Risks from AI to U.S. Critical Infrastructure
- Collection Agency FBCS Warns Data Breach Impacts 1.9 Million People
- Muddling Meerkat Hackers Manipulate DNS Using China’s Great Firewall
CISA Issues Guidelines To Mitigate Risks from AI to U.S. Critical Infrastructure
What happened: CISA has released new guidelines, including a four-part mitigation strategy, to fortify U.S. critical infrastructure against three significant types of risks from artificial intelligence (AI): failures within AI design and implementation, use of AI in attacks on infrastructure, and targeted assaults on AI systems themselves.
Why it matters: Cyberattacks against U.S. critical infrastructure have increased in the past few months, with threat actors targeting government contractors and departments. Reports have also warned about the use of AI to target critical infrastructure in the months leading to the U.S. elections.
Collection Agency FBCS Warns Data Breach Impacts 1.9 Million People
What happened: Financial Business and Consumer Solutions (FBCS) has suffered a data breach that impacted over 1.9 million individuals in the United States. Unauthorized access was detected in specific systems within the agency’s network, potentially exposing sensitive information such as full names, Social Security Numbers (SSN), dates of birth, account details, and driver’s license numbers or ID cards.
Why it matters: The data breach poses increased risks of phishing, fraud, and social engineering attacks for the affected individuals. While FBCS has implemented additional security measures to prevent future breaches, recipients of the data breach notifications are advised to stay vigilant against unsolicited communications and monitor their accounts and credit reports for any suspicious activity.
Muddling Meerkat Hackers Manipulate DNS Using China’s Great Firewall
What happened: Threat actor dubbed Muddling Meerkat has been manipulating domain name systems (DNS) to probe global networks. The threat actor is suspected to be a Chinese nation-state hacker whose techniques involve injecting fake responses through China's Great Firewall (GFW) after manipulating mail exchange (MX).
Why it matters: The threat actor’s ability to bypass China’s GFW and manipulate DNS has implications to the nation’s internet censorship system using sophisticated capabilities. However, a report suggests that the threat actor does not aim for disruption but for testing other networks to plan for future attacks instead.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- Space Bears user Space Bears: Cortex Chiroprati
- Space Bears user Space Bears: New Ransomware Group Emerges
VULNERABILITIES
- CVE-2024-1371: The LeadConnector plugin for WordPress is vulnerable to unauthorized modification & loss of data due to a missing capability check on the lc_public_api_proxy() function in all versions up to, and including, 1.7. This makes it possible for unauthenticated attackers to delete arbitrary posts.
- CVE-2024-4226: It was identified that in certain versions of Octopus Server, that a user created with no permissions could view all users, user roles and permissions. This functionality was removed in versions of Octopus Server after the fixed versions listed.
EXPLOITS
- CVE-2021-44077: Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remote code execution. This is related to /RestAPI URLs in a servlet, and ImportTechnicians in the Struts configuration.
- CVE-2021-34484: Windows User Profile Service Elevation of Privilege Vulnerability
BREACHES
- Combolist: '50K COD.txt' (55,993 Records): Email Address, Password
- Combolist: '20 K VALORANT COMBO BY FLESYX.txt' (16,865 Records): Email Address, Password
Tags: DIB, tlp:green