ZeroFox Cyber Intelligence Daily Brief - May 11, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - May 11, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- ASD’s ACSC, CISA, and Partners Release Secure by Design Guidance on Choosing Secure and Verifiable Technologies
- Widely Used Telit Cinterion Modems Open to SMS Takeover Attacks
- Google Releases Patches for The Fifth Chrome Zero-Day Vulnerability This Year
ASD’s ACSC, CISA, and Partners Release Secure by Design Guidance on Choosing Secure and Verifiable Technologies
What happened: Secure by Design Choosing Secure and Verifiable Technologies is a guidance to provide organizations with secure by design considerations when procuring digital products and services.
Why it matters: The guidance contains a range of internal and external considerations and offers sample questions to leverage at each stage of the procurement process. Additionally, the guidance informs manufacturers on steps they should be taking to align their development processes to secure by design principles and practices.
Widely Used Telit Cinterion Modems Open to SMS Takeover Attacks
What happened: Security flaws (CVE-2023-47610 through CVE-2023-47616) in Telit Cinterion cellular modems can allow threat actors to execute arbitrary code remotely through SMS. Higher severity bug CVE-2023-47610 allows “heap overflow problems that could affect the modem’s User Plane Location (SUPL) message handlers.”
Why it matters: All modems feature an SMS messaging interface, accessible with knowledge of the target modem's subscriber number within the cellular network. Operator restrictions may hinder binary SMS transmission, but circumvention via a fake base station is feasible. Exploiting CVE-2023-47610 enables arbitrary code execution via SMS, granting attackers deep-level access to the modem's operating system.
Google Releases Patches for The Fifth Chrome Zero-Day Vulnerability This Year
Source: https://chromereleases.googleblog.com/2024/05/stable-channel-update-for-desktop_9.html
What happened: Google has released security updates patching a zero-day vulnerability, CVE-2024-4671, in Chrome that threat actors are exploiting in the wild. CVE-2024-4671 is a “user after free” vulnerability in the Visuals component, crucial for content display.
Why it matters: After-free flaws occur when a program accesses memory that has been freed. Threat actors can exploit such flaws for data leaks, code execution, or crashes. With a 3.5 million user base, threat actors are likely to leverage zero days in Chrome to target several organizations, including critical infrastructure. For instance, nation state-actors exploited two zero-day vulnerabilities to breach MITRE in April.
DEEP AND DARK WEB INTELLIGENCE
- Dark Strom Team: On May 10, a threat actor group Dark Strom Team claimed to have carried out a cyber attack against Flickr, a U.S.-based photo-sharing platform.
VULNERABILITIES
CVE-2023-35743: D-Link DAP-2622 DDP Configuration Restore Auth Password Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-2622 routers. Authentication is not required to exploit this vulnerability.
CVE-2023-38097: NETGEAR ProSAFE Network Management System BkreProcessThread Exposed Dangerous Function Remote Code Execution Vulnerability.
Tags: DIB, tlp:green