ZeroFox Cyber Intelligence Daily Brief - October 11, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - October 11, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- NSA Issues Updated Guidance on Russian SVR Cyber Operations
- OpenAI Says Chinese Gang Tried to Phish Its Staff
- Akira and Fog Ransomware Exploit Critical Veeam RCE Flaw
NSA Issues Updated Guidance on Russian SVR Cyber Operations
What happened: The National Security Agency (NSA), along with international partners, issued a joint Cybersecurity Advisory titled “Update on SVR Cyber Operations and Vulnerability Exploitation,” warning about ongoing cyber threats from Russia's Foreign Intelligence Service (SVR). The advisory highlights the SVR's exploitation of specific software vulnerabilities and its intent to target additional ones. It provides a list of currently exploited vulnerabilities and recommends mitigation strategies to enhance cybersecurity in response to SVR cyber activities.
Why it matters: The ongoing cyber threats from the SVR involve sophisticated tactics, techniques, and procedures (TTPs) that enable attackers to gain access, escalate privileges, and move laterally within networks, ultimately leading to data exfiltration. Their use of methods such as spear phishing, password spraying, and cloud exploitation makes it challenging for organizations to defend against these intrusions. The recommendation to establish a baseline for authorized devices and scrutinize non-compliant systems is crucial, as it can help organizations detect and mitigate these threats more effectively, thereby enhancing their overall cybersecurity posture and protecting sensitive information from potential breaches.
OpenAI Says Chinese Gang Tried to Phish Its Staff
Source: https://www.theregister.com/2024/10/10/china_phish_openai/
What happened: OpenAI reported that it disrupted a spear-phishing campaign launched by a China-based group known as SweetSpecter, which targeted its employees via both personal and corporate email addresses. The campaign involved phishing emails containing a malicious attachment intended to deploy the SugarGh0st RAT malware, granting the hackers control over compromised machines.
Why it matters: The successful deployment of such malware could have led to significant data breaches and unauthorized access to sensitive information within OpenAI, potentially compromising proprietary data and damaging the company’s reputation. Additionally, the alleged use of OpenAI’s services—such as reconnaissance, vulnerability research, and scripting support—for offensive cyber operations raises concerns about the ethical implications and security risks associated with the exploitation of AI technologies for malicious purposes. In a separate development, OpenAI revealed that it has thwarted over 20 operations and deceptive networks globally that sought to exploit its platform for malicious activities since the start of the year.
Akira and Fog Ransomware Exploit Critical Veeam RCE Flaw
What happened: The Akira and Fog ransomware campaigns exploited a critical flaw (CVE-2024-40711) in Veeam Backup & Replication (VBR) servers, allowing them to gain remote code execution (RCE). Attackers leveraged this vulnerability using compromised VPN credentials without multifactor authentication (MFA). Veeam released patches in early September while publishing the proof-of-concept code later to accommodate time for patch application.
Why it matters: Veeam’s VBR software is widely used across several industrial sectors for backup and disaster recovery. Attackers have previously exploited bugs in the software in ransomware attacks against Latin American IT companies and critical infrastructure in the United States, making patch applications extremely crucial. By targeting systems vulnerable to CVE-2024-40711, attackers can potentially disrupt business operations and compromise sensitive data.
DEEP AND DARK WEB INTELLIGENCE
Threat actor leaks Israeli ambassador's emails: Threat group Handala Hack claimed to have leaked 50,000 secret emails belonging to a high-ranking member of Israel's diplomatic service, who supposedly served as an ambassador to critical allies and also worked in the country's external intelligence agency.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2024-9680: The vulnerability involves a use-after-free issue in Animation timelines, allowing attackers to execute arbitrary code. By exploiting this flaw, an attacker was able to achieve code execution within the content process. There have been reports of this vulnerability being actively exploited in the wild.
Affected products: Firefox, Firefox ESR
CVE-2024-9441: An unpatched vulnerability in Nice Linear eMerge E3 access controller systems could allow arbitrary OS commands to be executed. The flaw affects various versions of Nortek Linear eMerge E3 Access Control and has not been patched.
Affected products: Several versions of Nortek Linear eMerge E3 Access Control
Tags: DIB, tlp:green