ZeroFox Cyber Intelligence Daily Brief - September 14, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - September 14, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- False Claims of Hacked Voter Information Likely Intended to Sow Distrust of U.S. Elections
- GitLab Warns of Critical Pipeline Execution Vulnerability
- Cambodian Senator Sanctioned by U.S. over Alleged Forced Labor Cyber-Scam Camps
False Claims of Hacked Voter Information Likely Intended to Sow Distrust of U.S. Elections
What happened: The FBI and CISA have warned about attempts to undermine public confidence in the security of U.S. election infrastructure by spreading disinformation, falsely claiming that cyberattacks have compromised U.S. voter registration databases.
Why it matters: Malicious actors continue to spread false or misleading information, trying to manipulate public opinion and undermine confidence in U.S. democratic institutions. One of the most common tactics involves using obtained voter registration information as evidence to support false claims that a cyber operation compromised election infrastructure. Access registration data is not an independent indicator of a voter registration database compromise. Most U.S. voter information can be purchased or otherwise legitimately acquired through publicly available sources. In recent election cycles, when cyber actors have obtained voter registration information, the acquisition of this data did not impact the voting process or election results. Furthermore, the announcement states the FBI and CISA have no information suggesting that any cyberattack on U.S. election infrastructure has impacted electoral processes.
GitLab Warns of Critical Pipeline Execution Vulnerability
What happened: GitLab has issued critical updates to versions 17.3.2, 17.2.5, and 17.1.7 for both GitLab Community Edition (CE) and Enterprise Edition (EE). These updates address a total of 18 security issues, including a severe vulnerability (identified as CVE-2024-6678) that could allow attackers to trigger pipelines as arbitrary users under certain conditions.
Why it matters: CVE-2024-6678 has a CVSS score of 9.9, indicating its potential for significant damage. The flaw affects GitLab versions from 8.14 through 17.1.7, as well as versions from 17.2 before 17.2.5 and versions from 17.3 before 17.3.2. If not patched, attackers could exploit this vulnerability to execute environment stop actions with the permissions of the job owner, potentially compromising automated CI/CD workflows. This exploitation could allow threat actors to perform actions such as stopping pipelines or altering the build and deployment processes. Such actions could disrupt software development workflows, introduce malicious code or vulnerabilities, and compromise the integrity and security of the entire CI/CD pipeline. Ultimately, this could lead to data loss, system downtime, exposure of sensitive information, and broader security risks across the affected GitLab installations.
Cambodian Senator Sanctioned by U.S. over Alleged Forced Labor Cyber-Scam Camps
Source: https://www.theregister.com/2024/09/13/cambodian_senator_sanctioned_for_cyberscams/
What happened: The U.S. Department of the Treasury’s Office of Foreign Assets Control (OFAC) has issued sanctions against a Cambodian senator for serious human rights abuse related to the treatment of trafficked workers subjected to forced labor in online scam centers.
Why it matters: According to a report, ongoing corruption and official complicity in trafficking crimes remain widespread, resulting in selective and often politically motivated enforcement of laws, inhibiting effective law enforcement action against trafficking crimes, including forced labor in online scam operations. Traffickers reportedly force victims to work up to 15 hours a day and, in some cases, “resell” victims to other scam operations or subject them to sex trafficking. High-ranking individuals, such as the individual being sanctioned here, often evade law-enforcement action while continuing to conduct their operations—given the power they hold in their jurisdiction. An international law-enforcement action such as the one carried out by the U.S. OFAC is essential in limiting global human trafficking and cyber-scam operations and likely deterring other criminals from setting up such elaborate and organized criminal operations.
DEEP AND DARK WEB INTELLIGENCE
Exploit user sganarelle2 | Well-regarded threat actor "sganarelle2" advertised an auction for Citrix access with local administrator rights to an undisclosed U.S.-based company on the predominantly Russian language Dark Web forum Exploit. According to sganarelle2, the company generates more than USD 190 million in revenue. The starting bid for the access was USD 1,000, with a minimum bid of USD 200, and an instant purchase price of USD 2,000.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2024-7188: A critical vulnerability with a CVSS score of 9.8 has been discovered in Bylancer Quicklancer 2.4. This issue pertains to an unspecified handling of the listing file within the GET Parameter Handler component. By manipulating the range2 argument, an attacker can execute SQL injection. This vulnerability can be exploited remotely. It has been publicly disclosed and is identified as VDB-272609.
Affected product: Quicklancer version 2.4
Tags: DIB, tlp:green