zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - September 18, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - September 18, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Russian Propaganda Reportedly Behind Fake Hit-and-Run News About VP Kamala Harris
  • CISA and FBI Release Secure by Design Alert on Eliminating Cross-Site Scripting Vulnerabilities
  • New CISA Plan Aligns Federal Agencies in Cyber Defense

Russian Propaganda Reportedly Behind Fake Hit-and-Run News About VP Kamala Harris

Source: https://www.reuters.com/world/us/fake-kamala-hit-and-run-story-is-work-russian-propaganda-group-microsoft-says-2024-09-17/

What happened: Cybersecurity researchers have associated Russia with a disinformation operation falsely claiming that Vice President and Democratic Presidential candidate Kamala Harris left a child paralyzed in a hit-and-run incident in San Francisco in 2011. Russian group Storm-1516 reportedly created a video featuring an actor posing as the alleged victim. This video spread through a fake news website, "KBSF-TV," and was shared widely on social media, gaining millions of views.

Why it matters: State-sponsored disinformation campaigns, especially the ones targeting the Presidential candidates, aim to sow division, create mistrust among the electorate, and exacerbate existing political divides. By fabricating stories and using actors to impersonate victims, such tactics can effectively manipulate public opinion, making it difficult for individuals to discern truth from misinformation. Besides, Russia has intensified its effort to interfere in the U.S. elections, which will play a crucial role in shaping the geopolitical landscape of the near future. As an adversarial state, Russia is likely attempting to influence voter opinions, and thereby manipulate election results to favor its stance in the West. The most recent disinformation operation also aligns with broader Russian strategies to undermine U.S. support for Ukraine and exploit political divisions.

CISA and FBI Release Secure by Design Alert on Eliminating Cross-Site Scripting Vulnerabilities

Source: https://www.cisa.gov/news-events/alerts/2024/09/17/cisa-and-fbi-release-secure-design-alert-eliminating-cross-site-scripting-vulnerabilities

What happened: CISA and FBI recently released a secure by design fact sheet addressing cross-site scripting vulnerabilities. Vulnerabilities like cross-site scripting (XSS) continue to appear in software, enabling threat actors to exploit them. However, cross-site scripting vulnerabilities are preventable and should not be present in software products. CISA and FBI urge CEOs and other business leaders at technology manufacturers to direct their technical leaders and teams to review past instances of these defects and create a strategic plan to prevent them in the future.

Why it matters: Products that are secure by design reasonably protect against malicious cyber actors exploiting the most common and dangerous classes of product defects. Incorporating security at the outset—beginning in the design phase and continuing throughout development, release, and updates—reduces the burden on customers and risk to the public. Cross-site scripting vulnerabilities arise when manufacturers fail to properly validate, sanitize, or escape inputs. These failures allow threat actors to inject malicious scripts into web applications, exploiting them to manipulate, steal, or misuse data across different contexts. Although some developers employ input sanitization techniques to prevent XSS vulnerabilities, this approach is not infallible and should be reinforced with additional security measures. CISA and FBI encourage manufacturers to learn how to protect their products from falling victim to cross-site scripting exploits and other preventable malicious activity by taking ownership of customer security outcomes, embracing radical transparency and accountability, and building organizational structure and leadership to achieve these goals.

New CISA Plan Aligns Federal Agencies in Cyber Defense

Source: https://www.cisa.gov/news-events/alerts/2024/09/16/new-cisa-plan-aligns-federal-agencies-cyber-defense

What happened: CISA along with FCEB agencies developed the FCEB operational cybersecurity alignment (focal) plan to provide standard, essential components of enterprise operational cybersecurity and align the collective operational defense capabilities across the federal enterprise. The plan recommends actions that substantively advance operational cybersecurity improvements and alignment goals.

Why it matters: The Federal Civilian Executive Branch (FCEB) is comprised of agencies driven by different missions. All have independently established networks and system architectures to advance their critical work. Agencies vary widely in how effective they are at managing cyber risk, which, according to the authoring agencies, means there is no cohesive or consistent baseline security posture across all FCEB agencies. These diverse approaches were not designed to collectively address the dynamic nature of the current cyber threat environment, the complexity of the digital ecosystem, and the pace of technology modernization. As a result, despite concerted efforts to adapt and protect against cyberattacks, the FCEB remains vulnerable. Collective operational defense is required to adequately reduce risk posed to more than 100 FCEB agencies and to address dynamic cyber threats to government services and data. CISA’s FOCAL Plan outlines how agencies can work toward this by adopting proven practices along the spectrum—from prevention to incident detection and response—and identifying collective goals for security across the federal enterprise.

DEEP AND DARK WEB INTELLIGENCE

BreachForums user ZeroSevenGroup: The threat actor "ZeroSevenGroup" claimed to have hacked seven Israeli targets using their own virus. They allege to have accessed data from governmental, companies, and closed networks. They offer to sell the data to seven entities, including Hamas, Hezbollah, and Iran, for 200,000 XMR (Monero) each, while third parties must pay USD 400 million in XMR.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2024-38812: Broadcom has addressed a critical (CVSS score: 9.8) security flaw in VMware vCenter Server that could allow attackers to execute remote code on vulnerable servers by sending a network packet.

Affected products: VMware Cloud Foundation and VMware vCenter Server

Tags: DIB, tlp:green