zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - September 16, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - September 16, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • ZeroFox Intelligence Flash Report - New Exploitation of Existing Vulnerability Announced for Sale
  • CISA Releases Analysis of FY23 Risk and Vulnerability Assessments
  • Threat Actor Allegedly Leaks RobbinHood Ransomware C2C Tools, Exposing Sensitive Data

ZeroFox Intelligence Flash Report - New Exploitation of Existing Vulnerability Announced for Sale

Source: https://www.zerofox.com/advisories/26120/

What happened: On September 6, 2024, an actor known as “skng” posted in the dark web forum xss advertising a new malicious script that is allegedly designed to target Fortinet software solutions. The product allegedly enables the exploitation of an existing critical vulnerability known as CVE-2022-40684, which was discovered in early October 2022.

Why it matters: If successfully exploited, CVE-2022-40684 can allow the attacker to gain access to privileged administrative interfaces without being in possession of legitimate credentials. Shortly after the vulnerability’s discovery, mitigating software patches were released alongside customer advisory notices. The vast majority of network exploitation leverages old or existing vulnerabilities that have since been remedied by software manufacturers. Threat actors are able to both capitalize on the users that have not conducted the appropriate software updates and leverage malicious Deep and Dark Web services that specialize in uncovering and monetizing new methods of exploiting existing and patched vulnerabilities, such as the script offered by skng.

CISA Releases Analysis of FY23 Risk and Vulnerability Assessments

Source: https://www.cisa.gov/news-events/alerts/2024/09/13/cisa-releases-analysis-fy23-risk-and-vulnerability-assessments

What happened: CISA has published an analysis detailing the findings from the 143 risk and vulnerability assessments (RVAs) conducted across multiple critical infrastructure sectors in fiscal year 2023 (FY23). The analysis details a sample attack path including tactics and steps a cyber threat actor could follow to compromise an organization with weaknesses representative of those CISA observed in FY23 RVAs.

Why it matters: After conducting trend analysis on the networks and network defenses of the entities in the 143 RVAs, CISA and the the United States Coast Guard (USCG) made high-level observations that would improve the ability of critical infrastructure (CI) organizations to secure and protect their networks. Throughout the assessment lifecycle, Valid Accounts was the most prominent technique used across multiple tactics. Although CISA and the USCG teams do not directly emulate an adversary, they locate any conditions present in the environment, or use opportunistic techniques. In previous years, assessors primarily used Valid Accounts to gain initial access into the network. However, in FY23, they found opportunities to use Valid Accounts to move laterally through the network, evade defenses, and escalate privileges, although in many cases, the same accounts can be used in several stages of the ATT&CK framework. Therefore, a threat actor can do a lot with a small number of credentials accessed early on, especially when Microsoft Active Directory database is extracted using a domain account.

Threat Actor Allegedly Leaks RobbinHood Ransomware C2C Tools, Exposing Sensitive Data

Source: https://dailydarkweb.net/threat-actor-allegedly-leaks-robbinhood-ransomware-c2c-tools-exposing-sensitive-data/

What happened: A threat actor has unveiled the release of critical C2C tools used by the RobbinHood ransomware group, updated to version 2.0 in 2020. The actor reportedly discovered this data during an attack on a government target, where RobbinHood operators failed to erase their shadow files. The leaked information includes sensitive details such as victim data, the group’s Monero (XMR) and Bitcoin (BTC) addresses, operational tools, fake file hosters, and domain information.

Why it matters: The release of critical C2C tools and 7z file containing 130 MB of uncompressed sensitive data by a threat actor is significant, as it may encourage other threat actors or groups to also release similar tools and data, resulting in widespread exposure of sensitive information, increasing risks for organizations and individuals. Such leaks can enable malicious actors to exploit or replicate the disclosed techniques, exacerbating the threat landscape. For law enforcement and security researchers, the data provides crucial insights into the ransomware group's operations, aiding in threat identification and mitigation, but also poses challenges due to the volume and potential for misinformation. Additionally, the leaked IDS/IPS logs and operational details could help attackers refine their methods to avoid detection, while the exposed cryptocurrency addresses and hosting domains might be used to trace financial transactions or disrupt the group's infrastructure.

DEEP AND DARK WEB INTELLIGENCE

BreachForums user IntelBroker: Established threat actor IntelBroker claimed to be selling a database associated with the Department of Motor Vehicles and Insurance Auto Auctions in the United States, on the predominantly English-language dark web forum, BreachForums. IntelBroker alleged that the breach was facilitated by a threat actor known as "EnergyWeaponUser" on September 12, 2024.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2024-8190: An OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and earlier allows a remote authenticated attacker with admin privileges to achieve remote code execution. Since Ivanti CSA 4.6 is End-of-Life and no longer receives updates or patches for its OS or third-party libraries, this vulnerability remains unaddressed.

Affected products: CSA version 4.6 (All versions before Patch 519)

Tags: DIB, tlp:green