zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - October 18, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - October 18, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Alabama Man Arrested for Role in Securities and Exchange Commission X Account Hack
  • CISA and FBI Release Joint Guidance on Product Security Bad Practices for Public Comment
  • North Korean Hackers Disguised as IT Workers to Infiltrate Western Firms

Individual Arrested for Role in Securities and Exchange Commission X Account Hack

Source: https://www.justice.gov/opa/pr/alabama-man-arrested-role-securities-and-exchange-commission-x-account-hack

What happened: The FBI arrested an individual on charges related to the January hack of the Securities and Exchange Commission (SEC)’s social media account on X (formerly, Twitter) to prematurely announce the approval of bitcoin Exchange Traded Funds (ETF). The indictment alleges that the individual accessed the SEC’s account on X by using the stolen identity of a person who had access to the account to take over their cellphone number.

Why it matters: This crackdown is significant because it addresses serious market manipulation risks stemming from breaches of social media accounts, particularly for influential organizations like the SEC. The false announcement led to substantial price volatility in Bitcoin, with its value briefly rising over USD 1,000 before plummeting by more than USD 2,000 after the SEC reasserted its authority. Such incidents not only disrupt financial markets but also erode trust in regulatory bodies responsible for such communications, posing risks for investors and overall market stability.

CISA and FBI Release Joint Guidance on Product Security Bad Practices for Public Comment

Source: https://www.cisa.gov/news-events/alerts/2024/10/16/cisa-and-fbi-release-joint-guidance-product-security-bad-practices-public-comment

What happened: CISA and the FBI have released joint guidance on Product Security Bad Practices, a part of CISA’s Secure by Design initiative. This joint guidance supplies an overview of exceptionally risky product security bad practices for software manufacturers who produce software in support of critical infrastructure or national critical functions.

Why it matters: The bad practices presented in this guidance are organized into three categories: product properties, security features, and organizational processes and policies. This guidance contains brief information about specific bad practices, recommended actions, and additional resources. While this guidance is intended for software manufacturers who develop software products and services in support of critical infrastructure, all software manufacturers are strongly encouraged to avoid these product security bad practices.

North Korean Hackers Disguised as IT Workers to Infiltrate Western Firms

Source: https://hackread.com/fake-north-korean-it-workers-west-firms-demand-ransom/

What happened: Hackers from North Korean threat group Nickel Tapestry are infiltrating companies in the United States, United Kingdom, and Australia disguised as IT workers to steal sensitive data and demand ransom. Using fake identities, the hackers manipulate human resources processes, bypass company security through personal devices, and conceal their real locations with VPNs and residential proxies.

Why it matters: Even though the tactic Nickel Tapestry uses is not new, it exposes companies to considerable risks. A fake worker breached a company's network, stole sensitive data, and demanded a ransom after poor performance, escalating the financial damage. Moreover, the hackers use fake references and shared tasks, evading detection and maintaining persistent access. The campaign not only exfiltrates data for monetary gain but also very likely leverages Western company resources for funding the North Korean weapon program.

DEEP AND DARK WEB INTELLIGENCE

XSS user Croatoan: Untested threat actor "Croatoan" advertised remote desktop access to three unnamed companies based in the United States, Austria, and the Czech Republic respectively on predominantly Russian-language dark web forum XSS.

VULNERABILITY AND EXPLOIT INTELLIGENCE

Oracle October Patch Update: Oracle released its quarterly Critical Patch Update Advisory for October 2024 to address vulnerabilities in multiple products. A cyber threat actor could exploit some of these vulnerabilities to take control of an affected system.

Affected products: Oracle has listed the affected products in the October Critical Patch Update advisory.

CVE-2024-44133: This vulnerability allows threat actors to bypass the operating system’s Transparency, Consent, and Control (TCC) technology and gain unauthorized access to a user’s data, browsed pages, device camera, microphone, and location.

Affected products: macOS versions less than 15; it is now fixed in macOS Sequoia 15

Tags: DIB, tlp:green