ZeroFox Cyber Intelligence Daily Brief - October 22, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - October 22, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- DOJ Issues Proposed Rule Addressing National Security Risks Posed to U.S. Sensitive Data
- Hackers Exploit Roundcube Webmail Flaw
- China’s Spamouflage Escalates Campaign Against U.S. Senator as Election Day Looms
DOJ Issues Proposed Rule Addressing National Security Risks Posed to U.S. Sensitive Data
What happened: The Justice Department (DOJ) has issued a Notice of Proposed Rulemaking (NPRM) to implement President Biden’s Executive Order 14117 (the E.O.) of February 28, 2024, “Preventing Access to Americans’ Bulk Sensitive Personal Data and United States Government-Related Data by Countries of Concern.”
Why it matters: The E.O. addresses national security and foreign-policy threats from countries of concern and covers persons accessing bulk U.S. sensitive personal data or government-related data likely to be implicated by the categories of restricted transactions. The proposed rule would require vendor agreements, employment agreements, and investment agreements that qualify as restricted transactions to comply with the separately proposed security requirements developed by the Department of Homeland Security’s Cybersecurity and Infrastructure Agency (CISA) in coordination with the Justice Department.
Hackers Exploit Roundcube Webmail Flaw
What happened: Threat actors have been exploiting a stored XSS vulnerability (CVE-2024-37383) in the Roundcube Webmail client to target government organizations in the Commonwealth of Independent States (CIS) region. CIS emerged as an alternative to the crumbling Soviet Union in 1991, and includes Russia, Ukraine, and Belarus. The vulnerability allows attackers to execute malicious JavaScript code on the Roundcube page when a user opens a specially crafted email.
Why it matters: Roundcube Webmail is reportedly used by government and commercial organizations, making it a high-value target for threat actors to exfiltrate sensitive data. Vulnerabilities like CVE-2024-37383 could allow attackers to execute malicious code, potentially leading to data breaches or the compromise of sensitive information. In 2023, groups like Winter Vivern and APT28 used Roundcube flaws to target think tanks in Europe and Ukrainian government servers. Unpatched systems in high-profile organizations can become likely targets in geopolitical conflicts, further increasing the urgency for timely security updates to prevent espionage and data theft. System administrators still using affected versions (Roundcube versions earlier than 1.5.6 and versions 1.6 to 1.6.6) are urged to update as soon as possible.
China’s Spamouflage Escalates Campaign Against U.S. Senator as Election Day Looms
Source: https://www.theregister.com/2024/10/21/china_spamouflage_trolls_marc_rubio/
What happened: China's Spamouflage disinformation crew has targeted a prominent U.S. lawmaker with fake news campaigns, trolling his official X account and spreading negative stories about him on platforms like Reddit and Medium. This group, also known as Dragonbridge, has escalated its tactics by using deepfake technology to create phony videos aimed at influencing the upcoming presidential election.
Why it matters: The disinformation campaigns from this Chinese group pose a significant risk to U.S. democracy, especially with the 2024 election approaching. Platforms like Reddit have a wide reach, allowing false narratives to spread quickly and influence public opinion. As disinformation circulates, it can shape perceptions of political figures and issues, potentially swaying voter behavior and contributing to a divisive political landscape. The use of advanced techniques like deepfakes further complicates efforts to discern truth from falsehood, making it crucial for the public to remain vigilant about the information they consume.
DEEP AND DARK WEB INTELLIGENCE
Telegram user Mysterious Team Bangladesh: The threat actor group Mysterious Team Bangladesh announced an alliance with the pro-Russian group Cyber Army of Russia. The group claims to have conducted major operations against NATO countries and Israel.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2024-9537: ScienceLogic SL1 (previously known as EM7) has an unspecified vulnerability related to a third-party component included with SL1. This issue has been addressed in SL1 versions 12.1.3+, 12.2.3+, and 12.3+. Additionally, CISA has added this vulnerability to its Known Exploited Vulnerabilities (KEV) list.
Affected products: The affected products and versions have been listed in this security update.
Tags: DIB, tlp:green