zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - July 2, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - July 2, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Latest Intel CPUs Impacted by New Indirector Side-Channel Attack
  • “RegreSSHion” Bug Threatens Takeover of Millions of Linux Systems
  • Threat Actor Targets Multiple UAE Entities Citing Political Reasons for the Attacks

Latest Intel CPUs Impacted by New Indirector Side-Channel Attack

Source: https://www.bleepingcomputer.com/news/security/latest-intel-cpus-impacted-by-new-indirector-side-channel-attack/

What happened: Researchers have discovered a new type of high-precision Branch Target Injection (BTI) attack dubbed “Indirector” affecting modern Intel processors, including chips from the Raptor Lake and the Alder Lake generations. It exploits vulnerabilities in the Indirect Branch Predictor (IBP) and Branch Target Buffer (BTB), two hardware components in modern Intel CPUs to manipulate speculative execution and potentially steal sensitive data.

Why it matters: The discovery of the “Indirector” attack on modern Intel processors underscores significant vulnerabilities in speculative execution mechanisms, crucial for performance optimization in CPUs. By exploiting flaws in the IBP and BTB, attackers can manipulate these components to execute unauthorized code and potentially extract sensitive data from affected systems. This threat compromises the integrity of systems by bypassing security measures like Address Space Layout Randomization (ASLR), which are designed to prevent precisely such unauthorized access.

“RegreSSHion” Bug Threatens Takeover of Millions of Linux Systems

Source: https://www.darkreading.com/cloud-security/regresshion-bug-threatens-takeover-of-millions-of-linux-systems

What happened: A critical RCE bug has been found in the OpenSSH secure communications suite which has the potential to expose Linux systems to remote attackers who could cause a denial of service, and possibly execute arbitrary code. This vulnerability (CVE-2024-6387), dubbed as “RegreSSHion,” is a reappearance of the already fixed CVE-2006-5051 bug.

Why it matters: Although this vulnerability was patched several years ago, changes or updates have inadvertently introduced this vulnerability. “This incident highlights the crucial role of thorough regression testing to prevent the reintroduction of known vulnerabilities into the environment.” According to the advisory, exploiting CVE-2024-6387 can result in a full system compromise and takeover, allowing threat actors to execute arbitrary code with the highest privileges, bypass security mechanisms, steal data, and maintain persistent access to the system.

Threat Actor Targets Multiple UAE Entities Citing Political Reasons for the Attacks

Source: https://cloud.zerofox.com/intelligence/advanced_dark_web/66593

What happened: ZeroFox has observed threat actor SN_Blackmeta claiming to target prominent entities in the United Arab Emirates (UAE), including two banks, a news agency, and a news channel. The actor cites their support for Palestine as the motive for these cyberattacks.

Why it matters: SN-Blackmeta has allegedly disabled the critical infrastructure and disrupted incoming and outgoing transfers of one of the targeted banks. Geopolitical stances have often driven cyber warfare. Instances of this behavior are frequent nowadays, with a significant portion associated with the two major ongoing wars, the Russia-Ukraine war and the Israel-Hamas war. Several threat actors, like SN-Blackmeta, have announced their allegiances and are participating in attacks that reflect their support. It is important to note that irrespective of the motives behind such cyberattacks, the civilian population is almost always caught in the crossfire and is subjected to financial losses and psychological threats.

DEEP AND DARK WEB INTELLIGENCE

BreachForums user IntelBroker: Well-regarded and established threat actor IntelBroker has claimed to have leaked a database from Virginia Department of Elections on the predominantly English-language dark web forum, BreachForums. The leaked package contains 65,000 rows of candidate ID, candidate name, total votes, party, election name, election ID, office ID, and number of seats.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2024-2973: An authentication bypass using an alternate path or channel vulnerability in Juniper Networks Session Smart Router or Conductor running with a redundant peer allows a network based attacker to bypass authentication and take full control of the device.

Affected products: Session Smart Router & Conductor:

  • All versions before 5.6.15
  • From 6.0 before 6.1.9-lts
  • From 6.2 before 6.2.5-sts

WAN Assurance Router:

  • 6.0 versions before 6.1.9-lts
  • 6.2 versions before 6.2.5-sts

Tags: DIB, tlp:green