ZeroFox Cyber Intelligence Daily Brief - May 3, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - May 3, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- CISA Urges Software Devs to Weed Out Path Traversal Vulnerabilities
- North Korean Actors Exploit Weak DMARC Security Policies to Mask Spearphishing Efforts
- Operation Pandora Shut Down 12 Scam Call Center; 21 Arrested
CISA Urges Software Devs to Weed Out Path Traversal Vulnerabilities
What Happened: CISA and the FBI have jointly issued an advisory urging software companies to address path traversal vulnerabilities in their products before deployment. Path traversal exploits can enable attackers to manipulate files crucial for code execution or authentication, posing significant security risks.
Why It Matters: This joint alert underscores the urgency of mitigating path traversal vulnerabilities impacting critical infrastructure sectors, as it can be exploited by attackers to manipulate critical files, potentially compromising system security and exposing sensitive data. By promptly addressing these flaws, software companies can enhance the resilience of their products and safeguard against potential cyber threats, ultimately bolstering overall cybersecurity.
North Korean Actors Exploit Weak DMARC Security Policies to Mask Spearphishing Efforts
Source: https://www.ic3.gov/Media/News/2024/240502.pdf
What happened: According to the Federal Bureau of Investigation’s (FBI) advisory, in collaboration with other U.S. agencies, North Korean threat actors Kimsuky APT exploit DNS Domain-based Message Authentication, Reporting and Conformance (DMARC) to carry out social engineering attempts. The threat group has conducted spearphishing campaigns by posing as legitimate journalists, academics, and other experts.
What it means: Well configured DMARC protects emails from spoofed emails and threat actors using an illegitimate domain’s email exchange. North Korea utilizes spear-phishing campaigns as a means to gather intelligence on geopolitical events, adversary foreign policy strategies, and any information that may impact North Korean interests. Through these campaigns, North Korean actors gain unauthorized access to the documents, research, and communications of their targets, allowing them to gather data and strategic information.
Operation Pandora Shut Down 12 Scam Call Center; 21 Arrested
What happened: German, Albanian, Bosnian-Herzegovinian, Kosovo, and Lebanese law enforcement has shut down the operations of 12 call centers responsible for thousands of daily scam calls, investment fraud, and romance scams and arrested 21 individuals.
Why it matters: The scam network had already managed to claim thousands of victims through manipulation tactics, shocking and cheating them out of their savings. Operation Pandora managed to curb over eighty percent of these indicted crimes and prevented potential financial damage of almost EUR 10 million.
DEEP AND DARK WEB INTELLIGENCE
- Threat Actor 303: On May 2, threat actor 303 leaked a database from The Central Bank of the Argentine Republic on the predominantly English-language dark web forum, “BreachForums."
VULNERABILITIES
- Critical Aruba Networks Buffer Overflow Bugs: Threat actors could exploit CVE-2024-26304, CVE-2024-26305, CVE-2024-33511, and CVE-2024-33512 to execute unauthenticated remote code by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of these vulnerabiliies result in the ability to execute arbitrary code as a privileged user on the underlying operating system.
Affected products: ArubaOS 10.5.1.0 and below, ArubaOS 10.4.1.0 and below, ArubaOS 8.11.2.1 and below, and ArubaOS 8.10.0.10 and below.
Tags: DIB, tlp:green