zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - October 16, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - October 16, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Framing Software Component Transparency: Establishing a Common Software Bill of Materials
  • Finland Seizes Servers of “Sipultie” Dark Web Drugs Market
  • Reports Suggest Uptick in Russia, China, and Iran-Linked Attacks Against Adversaries

Framing Software Component Transparency: Establishing a Common Software Bill of Materials

Source: https://www.cisa.gov/news-events/alerts/2024/10/15/guidance-framing-software-component-transparency-establishing-common-software-bill-materials-sbom

What happened: CISA has published the "Framing Software Component Transparency," created by the Software Bill of Materials (SBOM) Tooling & Implementation Working Group, which is one of the five SBOM community-driven workstreams facilitated by CISA.

Why it matters: This resource provides a detailed foundation for SBOM, defining key concepts and terms while outlining how software components should be represented. It serves as a guide for SBOM creation processes and clarifies SBOM Attributes from the “2021 Framing Software Component Transparency document,” detailing minimum expectations, recommended practices, and aspirational goals for each Attribute. This work reflects extensive discussions within the SBOM Tooling and Implementation Working Group and incorporates feedback from the broader software community.

Finland Seizes Servers of “Sipultie” Dark Web Drugs Market

Source: https://www.bleepingcomputer.com/news/legal/finland-seizes-servers-of-sipultie-dark-web-drugs-market/

What happened: Finnish Customs, in collaboration with Europol and other international authorities, took down the darknet marketplace “Sipulitie,” which was used to anonymously sell illegal narcotics. The operation also seized the site's servers and took offline a related chat-based platform, Tsätti. Authorities have identified the operator, moderators, and users of the marketplaces, with arrests very likely to follow.

Why it matters: This takedown is significant because it disrupts a major network for illegal narcotics sales, which had operated anonymously and amassed over EUR 1.3 million (USD 1.42 million) in revenue. Identifying the operators and users of these platforms also opens the door for further arrests, potentially dismantling broader criminal networks involved in drug trafficking. The operation undermines the infrastructure that criminals rely on, likely making it more difficult for similar marketplaces to emerge or regain traction. This crackdown is likely to disrupt a critical supply chain for drug traffickers, curbing the distribution of narcotics across Europe and stemming the revival of similar marketplaces in the future.

Reports Suggest Uptick in Russia, China, and Iran-Linked Attacks Against Adversaries

Source: https://www.securityweek.com/cybercriminals-are-increasingly-helping-russia-and-china-target-the-us-and-allies-microsoft-says/

What happened: A cybersecurity report suggests that the governments of Russia, China, and Iran increasingly rely on hackers to conduct cyber espionage, intelligence gathering, and disinformation campaigns targeting the United States and its allies. Hackers linked to Iran compromised an Israeli dating site for profit and political gain, while a Russian criminal network infiltrated Ukrainian military devices to support the invasion.

Why it matters: The growing alliance between authoritarian governments and criminal hackers offers mutual benefits, with states cost-effectively enhancing their cyber operations and criminals receiving protection and profits for their state-aligned activities. Furthermore, such alliances, with increased focus on the United States, also spell danger for the upcoming U.S. elections, which will play a crucial role in determining the geopolitical landscape of the next few years. ZeroFox has also noted a very likely uptick in espionage-focused operations in the pre-election period as the opposing states seek to understand the implications of potential outcomes.

DEEP AND DARK WEB INTELLIGENCE

BreachForums user ayla: ZeroFox has observed a new cybercrime group named "ICA Group" on the predominantly English-language dark web forum BreachForums. Threat actor "ayla" posted that ICA Group is in the process of hiring “smart" individuals, hackers, and cyber terrorists.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2024-9487: An improper verification of cryptographic signature vulnerability was identified in GitHub Enterprise Server that allowed SAML SSO authentication to be bypassed resulting in unauthorized provisioning of users and access to the instance. Exploitation required the encrypted assertions feature to be enabled, and the attacker would require direct network access as well as a signed SAML response or metadata document. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.15 and was fixed in versions 3.11.16, 3.12.10, 3.13.5, and 3.14.2.

Affected products: All versions of GitHub Enterprise Server prior to 3.15 were affected and this vulnerability was fixed in versions 3.11.16, 3.12.10, 3.13.5, and 3.14.2.

Tags: DIB, tlp:green