zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - September 12, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - September 12, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Scammers Target Former President Trump Digital Trading Cards in Phishing Scheme
  • Air-Gapped Networks Vulnerable to Acoustic Attack via LCD Screens
  • Adobe Fixes Acrobat Reader Zero-Day with Public PoC Exploit

Scammers Target Former President Trump Digital Trading Cards in Phishing Scheme

Source: https://hackread.com/fake-domains-trump-supporters-trading-card-scam/

What happened: Scammers are targeting collectors of former President Donald Trump‘s digital trading cards through fake websites, domain typosquatting, email phishing, and social engineering to exfiltrate sensitive information or install malware. The counterfeit sites mimic the official URL of the trading card website with subtle variations, tricking users into falling for fraudulent schemes.

Why it matters: In this operation, scammers lure and mislead victims with fake URLs such as trumpdigitaltradingcards[.]xyz and collecttrunpcards[.]com by mimicking legitimate sites with subtle spelling differences. With the rise of digital assets, scams targeting high-profile projects, especially those tied to political figures, have significant consequences. As the U.S. elections approach, cybercriminals will leverage the heightened political intensity and voter interests in presidential candidates—including former President Trump—in financially motivated scams. Such attacks can not only compromise sensitive personal data, but can also erode public trust in digital platforms, especially those involved directly or indirectly in electoral processes, such as campaigning or fundraising. Besides, eroding public confidence in legitimate platforms will likely motivate other similar malicious actors to conduct further attacks targeting electoral campaigns.

Air-Gapped Networks Vulnerable to Acoustic Attack via LCD Screens

Source: https://www.darkreading.com/ics-ot-security/air-gapped-networks-vulnerable-to-acoustic-attack-via-lcd-screens

What happened: PIXHELL, a new form of acoustic attack, reportedly leaks data from air-gapped systems via LCD monitors. The attack sequence involves a type of malware being used to manipulate screen pixels to produce sound waves that can transmit encoded data across an air gap.

Why it matters: PIXHELL poses a severe security threat by enabling data theft from isolated systems without traditional audio connections. Air gaps are used in critical military, government, and industrial sites to prevent internet-based cyber threats and protect sensitive networks. PIXHELL compromises the security of these air-gapped networks by using LCD screens to transmit encoded acoustic signals, potentially leaking sensitive information to a receiver up to two and a half meters away. Although the attack requires control of devices on both sides of the air gap (which could occur through supply chain breaches or insider threats), it exposes vulnerabilities in systems that are designed to be secure through isolation.

Adobe Fixes Acrobat Reader Zero-Day with Public PoC Exploit

Source: https://helpx.adobe.com/security/products/acrobat/apsb24-70.html

What happened: CVE-2024-41869 is a critical "use after free" vulnerability in Adobe Acrobat Reader, which If exploited allows attackers to execute malicious code by tricking victims into opening a malicious PDF document and eventually gaining full control of the targeted system. The flaw is now fixed. Users are strongly urged to upgrade to the latest versions of Acrobat Reader and Adobe Acrobat at the earliest to protect against potential attacks.

Why it matters: CVE-2024-41869 presents a critical security risk to millions of Adobe Acrobat Reader users globally. The vulnerability allows attackers to remotely execute code on a targeted system, potentially leading to data theft, espionage, or system compromise. Although the current proof of concept (PoC) reportedly does not contain malicious payloads, it can be used to successfully exploit the vulnerability. Since the PoC has already been shared publicly, it increases the risk of rapid exploitation before users can update their software, making it essential for users to apply patches immediately.

DEEP AND DARK WEB INTELLIGENCE

Telegram user Sylhet Gang: Pro-Palestine hacktivist group Sylhet Gang has claimed to have conducted DDoS attacks against multiple UAE entities, including a university, a bank, and a postal service organization.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2024-8355: This vulnerability allows physically present attackers to execute arbitrary code on affected installations of the Visteon Infotainment system. Authentication is not required to exploit this vulnerability. The specific flaw exists within the DeviceManager. When parsing the iAP Serial number, the process does not properly validate a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to execute code in the context of root.

Affected products: DeviceManager, Visteon Infotainment system

Tags: DIB, tlp:green