zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - July 11, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - July 11, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • CISA and FBI Release Secure by Design Alert on Eliminating OS Command Injection Vulnerabilities
  • Japan Warns of Attacks Linked to North Korean Kimsuky Hackers
  • Hackers Call It Quits After Releasing Data Allegedly Associated with the Heritage Foundation

CISA and FBI Release Secure by Design Alert on Eliminating OS Command Injection Vulnerabilities

Source: https://www.cisa.gov/news-events/alerts/2024/07/10/cisa-and-fbi-release-secure-design-alert-eliminating-os-command-injection-vulnerabilities

What happened: CISA and FBI have recently released their newest Secure by Design Alert in the series, “Eliminating OS Command Injection Vulnerabilities,” in response to recent well-publicized threat actor campaigns that exploited OS command injection defects in network edge devices (CVE-2024-20399, CVE-2024-3400, CVE-2024-21887) to target and compromise users.

Why it matters: These vulnerabilities could allow unauthenticated malicious actors to remotely execute code on network edge devices. Operating system (OS) command injection vulnerabilities have long been preventable by clearly separating user input from the contents of a command. Despite known prevention methods, these vulnerabilities persist due to inadequate input validation and sanitization practices during command construction. CISA and FBI have urged technical leaders to enforce secure command generation practices, conduct rigorous code reviews, and employ adversarial testing to safeguard against these vulnerabilities.

Japan Warns of Attacks Linked to North Korean Kimsuky Hackers

Source: https://www.bleepingcomputer.com/news/security/japan-warns-of-attacks-linked-to-north-korean-kimsuky-hackers/

What happened: Japan's Computer Emergency Response Team Coordination Center (JPCERT/CC) is warning about targeted attacks by the North Korean “Kimsuky” threat actors against Japanese organizations. JPCERT/CC emphasizes the importance of vigilance against CHM files, which can contain executable scripts designed to deliver malware, to mitigate these threats and protect organizational security.

Why it matters: Kimsuky, a North Korean advanced persistent threat (APT) group, conducts attacks across the globe to gather intelligence on topics of interest to the North Korean government. The group is known for using social engineering and phishing techniques to gain initial access to networks. They then deploy custom malware to steal data and retain persistence on networks. These attacks typically begin with phishing emails that impersonate security and diplomatic organizations, containing a malicious ZIP attachment. The ZIP file includes an executable disguised as a document file by using many spaces to hide the ".exe" extension, along with two decoy documents. Once executed, the malware can lead to the exfiltration of sensitive data, such as credentials, which can enable further infiltration into the organization's systems and applications.

Hackers Call It Quits After Releasing Data Allegedly Associated with the Heritage Foundation

Source: https://www.rollingstone.com/culture/culture-news/heritage-foundation-gay-furry-hackers-texts-1235057421/

What happened: SiegedSec, a hacktivist collective, released 2 GB of data supposedly associated with the American conservative think tank, Heritage Foundation. Soon after announcing the leak, the group stated its plans for disbandment on its Telegram channel, stating the group is trying to “avoid the eye” of law enforcement.

Why it matters: SiegedSec has been in the cybercrime limelight for attacks on NATO and Idaho National Laboratory (INL), a major nuclear lab in the United States. The adversary has cited Project 2025— an initiative from the Heritage Foundation comprising a collection of conservative policy proposals— as the reason for targeting the think tank. The motivation and the nature of the attack showcase the increasing role of politically motivated hacktivism, where hackers target organizations to purportedly promote social and political agendas, in this case, trans rights and opposition to anti-abortion laws. The group declared its plan to disband seemingly after an online altercation between the admins and the executive director of Heritage Foundation. However, whether the group will disband is currently difficult to affirm. Additionally, the exposure of sensitive personal data, including names, emails, and passwords can incite more politically-motivated cyberattacks targeting the owners of the data.

DEEP AND DARK WEB INTELLIGENCE

BreachForums user “Cvsp”: Threat actor "Cvsp" claimed to be selling a zero-day Windows Local Privilege Elevation (LPE) exploit on the predominantly English-language dark web forum BreachForums. The threat actor is offering the alleged zero-day exploit for USD 150,000.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2024-38080 and CVE-2024-38112: Microsoft has released patches for 143 security flaws, of which five are critical. Microsoft also fixed two zero-day vulnerabilities CVE-2024-38080 and CVE-2024-38112. CVE-2024-38080, affects Microsoft Windows Hyper-V virtualization technology, enabling an attacker with local access to gain system-level privileges. CVE-2024-38112 allows attackers to send victims specially crafted Internet Shortcut files (also known as URL files). When these files are clicked, they force Internet Explorer to open a URL controlled by the attacker, even if it is not the default browser.

Affected products: The affected products for CVE-2024-38080 and CVE-2024-38112 have been listed by Microsoft in the attached security updates.

CVE-2023-27532: It is a vulnerability in the Veeam Backup & Replication component that allows encrypted credentials stored in the configuration database to be obtained. This may lead to gaining access to the backup infrastructure hosts.

Affected products: Affects all Veeam Backup & Replication versions.

Tags: DIB, tlp:green