zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - October 30, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - October 30, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Six Charged in Scheme to Defraud the U.S. Federal Government
  • China's “Evasive Panda” APT Debuts High-End Cloud Hijacking
  • Massive PSAUX Ransomware Attack Targets 22,000 CyberPanel Instances

Six Charged in Scheme to Defraud the U.S. Federal Government

Source: https://www.justice.gov/opa/pr/six-charged-scheme-defraud-federal-government

What happened: Six individuals have been charged for their roles in schemes to rig bids, defraud the government and pay bribes and kickbacks in connection with the sale of IT products and services to federal government purchasers. These are the first charges in the Justice Department’s ongoing investigation into IT manufacturers, distributors and resellers who sell products and services to government purchasers, including to the intelligence community.

Why it matters: The defendants’ actions reportedly resulted in overcharges of millions of dollars to the U.S. government, including the Department of Defense (DOD). As alleged in the indictment, the co-conspirators used their positions of trust to learn sensitive, confidential procurement information, including procurement budgets for large U.S. government IT contracts. The co-conspirators used that inside information to craft bids at artificially determined, non-competitive and non-independent prices, ensuring the accused would win the procurement.

China's “Evasive Panda” APT Debuts High-End Cloud Hijacking

Source: https://www.darkreading.com/cloud-security/china-evasive-panda-apt-cloud-hijacking

What happened: China-sponsored hacking group Evasive Panda has launched CloudScout, a sophisticated post-compromise toolset that exploits stolen Web session cookies to access various cloud services. This tool works in conjunction with their proprietary malware framework, MgBot, enabling it to target popular cloud storage and email platforms.

Why it matters: CloudScout allows attackers to bypass security measures through authenticated session hijacking, posing a serious threat to cloud security. CloudScout's ability to infiltrate at least 10 different cloud applications reveals the rising risks associated with these services. As organizations increasingly rely on cloud solutions, this capability can enable attackers to gain unauthorized access to sensitive data, leading to breaches that compromise personal information and corporate secrets. Such widespread access heightens the potential for financial loss and reputational damage, while also facilitating further malicious activities like identity theft and espionage.

Massive PSAUX Ransomware Attack Targets 22,000 CyberPanel Instances

Source: https://www.bleepingcomputer.com/news/security/massive-psaux-ransomware-attack-targets-22-000-cyberpanel-instances/

What happened: Over 22,000 CyberPanel instances were targeted in a PSAUX ransomware attack via critical remote code execution (RCE) vulnerabilities, leading to widespread service disruptions. Attackers exploited these flaws to gain unauthorized access, impacting numerous services.

Why it matters: The mass exposure of these vulnerabilities highlights the importance of timely software updates and security practices. A threat intel search engine platform revealed that close to 22,000 vulnerable CyberPanel instances were visible online, with a significant number of affected instances located in the United States. It increases the likelihood of cyberattacks, particularly ransomware incidents, as attackers are drawn to easily exploitable targets. This widespread vulnerability can lead to substantial operational disruptions for businesses relying on affected instances, potentially resulting in downtime and revenue loss. Moreover, unauthorized access could lead to data breaches, raising serious privacy concerns and regulatory compliance issues.

DEEP AND DARK WEB INTELLIGENCE

BreachForums user HikkI-Chan: Threat actor HikkI-Chan was allegedly selling a database associated with Sistema de Atendimento Integral ao Cidadão (SAIC) in Brazil, on predominantly English-language dark web forum BreachForums. The breach reportedly consists of 160,000 citizen information.

VULNERABILITY AND EXPLOIT INTELLIGENCE

Apple Security Updates: Apple has released security updates for iOS and macOS to address over 70 vulnerabilities across various products. The updates enhance security through improved authentication, better checks and logic, enhanced input validation, and refined handling of content and memory. Additionally, they include measures for private data redaction, state management, and file handling.

Affected products: The affected products and versions have been listed in this security update.

CVE-2024-50388: An OS command injection vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If exploited, the vulnerability could allow remote attackers to execute arbitrary commands.

Affected products: HBS 3 Hybrid Backup Sync 25.1.x

Tags: DIB, tlp:green