ZeroFox Cyber Intelligence Daily Brief - June 15, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - June 15, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- North Korea’s Moonstone Sleet Expands its Targets to the Software Supply Chain
- NATO to Crack Down on Russian Spies in Response to Sabotage
- ZKTeco Biometric System Found Vulnerable to 24 Critical Security Flaws
North Korea’s Moonstone Sleet Expands its Targets to the Software Supply Chain
What happened: A North Korean APT called Moonstone Sleet, which was identified last month, has expanded its distribution of malicious node package manager (npm) code to public repositories, posing a threat to the software supply chain by poisoning open-source code repositories.
Why it matters: As reported in ZeroFox’s Cyber Daily Intelligence Brief of May 30, researchers discovered Moonstone Sleet conducting financially motivated attacks and cyberespionage campaigns. While its quick expansion of techniques warrants attention, Moonstone Sleet's targeting of the software supply chain is also indicative of the growing risk to the open-source ecosystem, as demonstrated by the large-scale impact of previous supply chain attacks. Supply chain attacks affect all users of the compromised software and can have widespread consequences for government, critical infrastructure, and private sector software customers. With China’s persisting geopolitical tensions with other nations, other Chinese state-sponsored actors will likely follow Moonstone Sleet’s suit to conduct supply chain attacks.
ZKTeco Biometric System Found Vulnerable to 24 Critical Security Flaws
Source: https://thehackernews.com/2024/06/zkteco-biometric-system-found.html
What happened: Researchers have detected 24 vulnerabilities in a hybrid biometric access system from Chinese manufacturing company ZKTeco. The flaws include SQL injections, stack-based buffer overflows, and command injections.
Why it matters: These vulnerabilities could allow attackers to defeat authentication, steal biometric data, and deploy malicious backdoors. Exploiting them can lead to significant risks since attackers can sell biometric data on the dark web, allowing actors to potentially create deepfakes and conduct sophisticated social engineering attacks.
NATO to Crack Down on Russian Spies in Response to Sabotage
What happened: NATO has decided to undertake “tougher action” against Russia in light of recent acts of sabotage and cyberattacks, including disinformation, against NATO allies.
Why it matters: The military alliance also plans to prioritize protecting its maritime and cyber infrastructure while tightening restrictions on Russian intelligence personnel. The added security measures may be instrumental in safeguarding member states to better protect themselves from recent Russia-led cyberattacks where a Russian-backed cybercampaign targeted government bodies, "critical infrastructure operators" and other entities in Lithuania, Poland, Slovakia and Sweden.
DEEP AND DARK WEB INTELLIGENCE
Telegram user SN_Blackmeta: Threat actor "SN_Blackmeta" announced an attack against Yahoo. The group has claimed it will continue attacking Microsoft in support of the Palestinian cause.
Tags: DIB, tlp:green