zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - July 19, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - July 19, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Potential CrowdStrike-Related Outage Cause Global Chaos
  • WazirX Cryptocurrency Exchange Loses USD 230 Million in Major Security Breach
  • ZeroFox Intelligence Flash Report - U.S. Led Trade Restrictions Likely to Increase Espionage Threat

Potential CrowdStrike-Related Outage Cause Global Chaos

Source: https://www.bbc.com/news/live/cnk4jdwp49et

What happened: Microsoft is taking mitigation actions after users reported getting “Blue Screen of Death” error messages, possibly resulting from an issue with a recent CrowdStrike update. In an alert posted for customers, Crowdstrike says it is aware of “reports of crashes,” and its engineering team has identified a content deployment related to this issue and reverted those changes.

Why it matters: Windows has a large and global user base, which is why the outage has affected organizations and entities worldwide, including banks, news sites, healthcare institutions, and telecommunication companies. The impact has extended to key airports, including Narita, Delhi, Edinburgh, and Sydney, with airlines calling for a “global ground stop” and issuing notices of potential disruptions. At the time of reporting, Microsoft is actively mitigating the issue. It has released a statement on X, “Multiple services are continuing to see improvements in availability.”

WazirX Cryptocurrency Exchange Loses USD 230 Million in Major Security Breach

Source: https://thehackernews.com/2024/07/wazirx-cryptocurrency-exchange-loses.html

What happened: WazirX, one of India’s leading cryptocurrency exchanges (owned by Binance), experienced a security breach involving one of its multisig (Multi-Signature) wallets. This breach led to the temporary suspension of both Indian Rupee and cryptocurrency withdrawals. Approximately USD 230 million worth of assets in SHIB, ETH, MATIC, PEPE, USDT, FLOKI, and more were transferred suspiciously from the affected wallet.

Why it matters: Cryptocurrency regulations in India are still evolving, and security incidents like this could attract increased regulatory scrutiny. Regulators may impose new requirements on exchanges to enhance security measures, potentially impacting how exchanges operate and users engage with cryptocurrencies. As one of India's largest crypto exchanges, disruptions at WazirX can potentially impact market stability and investor sentiment. Despite utilizing features like multisig (technology designed to require multiple keys or signatures to authorize transactions) for security, threat actors could conduct an attack on one of its wallets. The threat actors might have compromised one of the signing keys through phishing attacks or social engineering, gaining enough control to authorize transactions. Initial investigations suggest the incident may be linked to North Korean threat actors, which adds a geopolitical dimension to the cyberattack.

ZeroFox Intelligence Flash Report - U.S. Led Trade Restrictions Likely to Increase Espionage Threat

Source: https://www.zerofox.com/advisories/24558/

What happened: Some of the world’s largest technology companies and global stock markets plummeted in value on July 18, likely because the United States is seeking to enforce a rarely-used rule allowing it to prohibit sales of any foreign-made product with at least some U.S.-made materials to China.

Why it matters: Restricting access to advanced technologies will likely put China at a competitive disadvantage when it comes to producing emerging technologies vital to its trade-based economy, as well as weapons systems needed for national security. China is very likely to retaliate with its own trade restrictions against companies and states that comply with the U.S. restrictions. Chinese-backed cyber threat actors are very likely to increase cyber espionage against entities that produce the withheld technology with the goal of creating its own endogenous industries.

DEEP AND DARK WEB INTELLIGENCE

BreachForums user “st0jke”: Threat actor st0jke claimed to be selling 2 million phone stalkerware users database on the predominantly English-language dark web forum BreachForums. Allegedly, the actor advertised an authentication bypass vulnerability on a phone stalkerware website which enables access to sensitive information and login to any account. The leaked users data allegedly includes pictures, videos, messages, calls, and contracts.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2024-37381: An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2024 flat allows an authenticated attacker within the same network to execute arbitrary code.

Affected product: Endpoint Manager (EPM) 2024 flat

Tags: DIB, tlp:green