zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - September 7, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - September 7, 2024

ZeroFox intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • U.S. Government and Tech Giants Discuss on Expanding Anti-Censorship VPN Tools
  • Chinese “Tropic Trooper” APT Targets Mideast Governments
  • Apache Fixes High-Severity OFBiz Remote Code Execution Vulnerability

U.S. Government and Tech Giants Discuss on Expanding Anti-Censorship VPN Tools

Source: https://www.reuters.com/technology/us-calls-big-tech-help-evade-online-censors-russia-iran-2024-09-05/

What happened: The White House organized a meeting with major U.S. tech companies and civil society activists to address the rising demand for VPN services in countries with strict internet censorship, like Russia, Iran, and Myanmar. The U.S.-funded Open Technology Fund (OTF) sought to secure more digital bandwidth and lower costs for its anti-censorship VPN tools. OTF reported that the number of VPN users has surged from nine million to 46 million monthly.

Why it matters: The surge in VPN usage is a direct reflection of the growing need for internet access in heavily censored countries such as Russia, Iran, and Myanmar. Even though OTF-funded VPNs have become crucial tools in these regions, OTF faces challenges in scaling up its operations due to limited resources. The U.S. government has increased funding through the “Surge and Sustain Fund for Anti-Censorship Technology.” However, hosting the network traffic requires heavy financial resources. OTF plans to meet the expanding demand with discounted or subsidized server bandwidth plans designed by major tech companies.

Chinese “Tropic Trooper” APT Targets Mideast Governments

Source: https://www.darkreading.com/cyberattacks-data-breaches/chinese-tropic-trooper-apt-targets-mideast-governments

What happened: An investigation into the China-linked APT group Tropic Trooper has uncovered an espionage campaign targeting government entities in the Middle East, especially those publishing human-rights studies related to the Israel-Hamas war. Tropic Trooper, previously known for targeting other regions, has reportedly shifted its focus to exploit vulnerabilities in public-facing servers.

Why it matters: Tropic Trooper's current activity likely points towards a show of support for a specific geopolitical cause — a kind of activism underlined by strategic interests. It is likely that being China-linked, they may be acting in the best political interest of their sponsor by spying on publications in the Middle East to possibly disrupt such activities or harvest information. The group has been active for more than a decade during which time it has targeted critical infrastructure entities in Taiwan, the Philippines, and Hong Kong, and is probably politically motivated. This cyber espionage group has in the past accessed information. Researchers suspect that they lie in wait for the perfect opportunity to utilize this information. The same can be likely said for these recent attacks where researchers observed that the group did their best in evading detection when they found that they were being observed.

Apache Fixes High-Severity OFBiz Remote Code Execution Vulnerability

Source: https://thehackernews.com/2024/09/apache-ofbiz-update-fixes-high-severity.html

What happened: Apache has fixed a high-severity vulnerability in its open-source OFBiz software, which allowed attackers to execute arbitrary code on vulnerable operating system servers. A forced browsing weakness causes this flaw (tracked as CVE-2024-45195), which has a CVSS score of 7.5 out of 10.

Why it matters: Attackers could exploit this flaw to fully compromise business systems, like CRM and ERP applications, without authentication. CVE-2024-45195 poses a major threat as it can bypass previous patches and allow remote code execution. It could lead to unauthorized access, malicious code execution, or disruption in critical business functions, leading to serious operational and financial damage. For organizations, it could likely result in potential loss of sensitive information and significant financial and reputational harm. Apache has urged users to upgrade OFBiz to version 18.12.16, which patches CVE-2024-45195 by adding authorization checks.

DEEP AND DARK WEB INTELLIGENCE

VULNERABILITY AND EXPLOIT INTELLIGENCE

  • CVE-2024-44000: This is an account takeover vulnerability that was found in LiteSpeed Cache, used on over 6 million WordPress sites.

  • Affected products: LiteSpeed Cache

Tags: DIB, tlp:green