ZeroFox Cyber Intelligence Daily Brief - June 27, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - June 27, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Chinese State-Linked Global Cyberattacks Blur Lines Between Espionage and Ransomware
- CISA and Partners Release Guidance for Exploring Memory Safety in Critical Open Source Projects
- Apple Addresses Bluetooth Vulnerability in AirPods Security Patch
Chinese State-Linked Global Cyberattacks Blur Lines Between Espionage and Ransomware
Source: https://thehackernews.com/2024/06/chinese-and-n-korean-hackers-target.html
What happened: Cybersecurity researchers have linked Chinese and North Korean state-sponsored actors to ransomware and data encryption attacks, conducted from 2021 to 2023, targeting global government and critical infrastructure sectors. These activities included notable attacks on the All India Institute of Medical Sciences (AIIMS) and the Presidency of Brazil.
Why it matters: Combining sophisticated tools— like Cobalt Strike and custom malware— with ransomware to extort ransom, sabotage, distract, misattribute, and eliminate evidence reflects the evolving techniques and skills of state-sponsored cyber espionage groups. The deployed malware allows the adversaries to evade detection, which in turn can let these adversaries remain in the infiltrated systems for a significant amount of time. During this time, the adversaries can destabilize the emergency services of targeted nations, strain international relations, spread misinformation or disinformation, and serve the broader strategic interests of adversarial states. Additionally, the blending of cybercrime and state-sponsored espionage tactics complicates attribution and allows states to claim plausible deniability by framing these attacks as the work of independent cybercriminals.
CISA and Partners Release Guidance for Exploring Memory Safety in Critical Open Source Projects
What happened: CISA has released Exploring Memory Safety in Critical Open Source Projects in partnership with the Federal Bureau of Investigation (FBI) and other agencies. This guidance aims to provide organizations with findings on the scale of memory safety risk in specific open source software (OSS).
Why it matters: Memory safety vulnerabilities are among the most prevalent classes of software vulnerability and reportedly generate substantial costs for both software manufacturers and consumers related to patching, incident response, and other efforts. This joint guidance provides a starting point for software manufacturers to create memory safe roadmaps, including plans to address memory safety in external dependencies which commonly include OSS.
Apple Addresses Bluetooth Vulnerability in AirPods Security Patch
Source: https://support.apple.com/en-us/HT214111
What happened: Apple has released a firmware update for its AirPods, addressing a vulnerability (CVE-2024-27867) that could allow attackers to spoof paired devices and eavesdrop on conversations.
Why it matters: The flaw impacts several models, including AirPods (2nd generation and later), AirPods Pro, AirPods Max, Powerbeats Pro, and Beats Fit Pro. By exploiting this flaw, an attacker could intercept Bluetooth signals and gain access to the headphones, compromising the privacy and confidentiality of conversations. It arises during the connection process when the headphones seek to connect to a previously paired device, which grants unauthorized access to the headphones, potentially allowing the attacker to eavesdrop on private conversations. The impact extends beyond mere inconvenience, as unauthorized access to personal audio devices could lead to privacy breaches and potential leakage of sensitive information. Users are advised to apply the update immediately to safeguard their devices against potential exploitation.
DEEP AND DARK WEB INTELLIGENCE
BreachForums user infamous: Threat actor "infamous" claimed to have leaked data associated with National Disaster Management Authority, India, priced at USD 1,000 on the predominantly English-language dark web forum, BreachForums. The actor claims that the leaked database contains the following information: name, gender, blood, date of birth, email, mobile number, and more. The threat actor did not disclose the ultimate source of the data breach or how it was exploited.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2024-5806: It is a critical authentication bypass vulnerability in Progress MOVEit Transfer, a managed file transfer (MFT) solution. It enables attackers to bypass authentication in the Secure File Transfer Protocol (SFTP) module, used for file transfers operation via SSH.
Affected products: MOVEit Transfer from 2023.0.0 before 2023.0.11, from 2023.1.0 before 2023.1.6, and from 2024.0.0 before 2024.0.2 versions.
CVE-2024-5276: Fortra FileCatalyst Workflow (web-based file exchange and sharing platform) has a critical SQL injection vulnerability (CVE-2024-5276) that allows remote unauthenticated attackers to create unauthorized admin accounts and manipulate data in the application database. FileCatalyst Workflow, utilized globally for large file transfers and private cloud collaboration, is impacted by this flaw.
Affected products: FileCatalyst Workflow 5.1.6 Build 135 and older versions.
Tags: DIB, tlp:green