zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - July 10, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - July 10, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Justice Department Disrupts Covert Russian Government-Operated Social Media Bot Farm
  • New Blast-RADIUS Attack Bypasses Widely-Used RADIUS Authentication
  • Threat Actors with Political Motivations Target NATO amid Ongoing Summit

Justice Department Disrupts Covert Russian Government-Operated Social Media Bot Farm

Source: https://www.justice.gov/opa/pr/justice-department-leads-efforts-among-federal-international-and-private-sector-partners

What happened: A sophisticated disinformation campaign orchestrated by Russia, involving the use of artificial intelligence (AI), created and managed fake social media profiles. The U.S. The Justice Department announced the seizure of two domain names and investigated more than 900 social media accounts tied to the operation. These AI-generated profiles, often posing as American individuals, were used to promote messages that supported Russian government objectives, using technology to influence public opinion on a global scale.

Why it matters: The U.S. government's disruption of a Russian government-backed, AI-enabled propaganda campaign stopped a potentially significant threat posed by global disinformation campaigns. These operations undermine trust and security on widely used social media platforms, leading to potential financial losses and the widespread dissemination of false information. The infiltration of social media by AI-generated profiles can erode public confidence in the information they consume, which can destabilize trust in key systems.

New Blast-RADIUS Attack Bypasses Widely-Used RADIUS Authentication

Source: https://www.bleepingcomputer.com/news/security/new-blast-radius-attack-bypasses-widely-used-radius-authentication/

What happened: Blast-RADIUS, an authentication bypass exploit in the widely adopted RADIUS/UDP protocol, allows threat actors to compromise networks and devices using man-in-the-middle MD5 collision attacks. This vulnerability affects numerous networked devices in enterprise and telecommunication networks, where RADIUS is crucial for authentication across various services including DSL, FTTH, Wi-Fi, cellular roaming, and VPNs.

Why it matters: RADIUS (Remote Authentication Dial-In User Service) is integral to numerous critical functions such as network device authentication, DSL/FTTH (Fiber to the Home) connectivity, Wi-Fi security (802.1X), and mobile network roaming (2G/3G/5G). Exploitation of these critical functions poses severe security risks, potentially compromising tens of thousands of networked devices within a single enterprise or telecom network. Blast-RADIUS exploits a new protocol vulnerability (CVE-2024-3596) and an MD5 collision attack. This allows attackers to manipulate RADIUS traffic to gain administrative privileges without the need for brute-force attacks or credential theft, leveraging weaknesses in the MD5 hashing used in RADIUS protocol transactions.

Threat Actors with Political Motivations Target NATO amid Ongoing Summit

Source: https://cloud.zerofox.com/intelligence/advanced_dark_web/66914

What happened: ZeroFox intelligence has observed threat actor SeigedSec claiming to have breached the NATO Consultation, Command, and Control (C3) portal. Additionally, several other adversaries have been observed forming alliances to target NATO amid the 2024 Washington summit, which began on July 9 and will go on till July 11.

Why it matters: Most of the actors, including hacktivists, targeting NATO are politically motivated. SeigedSec has stated its support for the Palestinian cause to be the motivation behind its attack. In a Telegram post, the group states it was apparently able to access “tens of thousands documents.” The current geopolitical landscape, dotted with wars, is likely to incite more threat actor activity aimed toward disrupting international events and summits. NoName (057), a pro-Russian hacktivist group infamously known for targeting government entities with DDoS attacks, is actively recruiting other adversaries while claiming to continue DDoS attacks on NATO websites. However, since these are hacktivist groups, the attacks are likely to be short-lived and harmless.

DEEP AND DARK WEB INTELLIGENCE

Telegram user SN_Blackmeta: Threat group “SN_Blackmeta” claimed to have conducted a distributed denial of service (DDoS) attack against The Washington Times, a U.S.-based newspaper. According to the post, the attack lasted for four to five hours. The post can be found on the group's official Telegram channel "hXXps://t[.]me/SN_Darkmeta."

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2024-6409: This bug present in select OpenSSH versions, distinct from the earlier CVE-2024-6387 (RegreSSHion), poses a significant RCE risk due to a race condition in signal handling within the privsep child process.

Affected products: OpenSSH versions 8.7p1 and 8.8p1.

CVE-2024-34123: An attacker could exploit this vulnerability by inserting a malicious file into the search path, which the application might execute instead of the legitimate file. This could occur when the application uses a search path to locate executables or libraries. Exploitation of this issue requires user interaction, attack complexity is high.

Affected products: Adobe Premiere Pro versions 24.4.1 and earlier and 23.6.5 and earlier (Windows and macOS).

Tags: DIB, tlp:green