zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - November 1, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - November 1, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Fortinet Updates Guidance and Indicators of Compromise following FortiManager Vulnerability Exploitation
  • Sophos Reveals Five-Year Battle with Chinese Hackers Attacking Network Devices
  • New Phishing Kit Xiū gǒu Targets Users Across Five Countries With 2,000 Fake Sites

Fortinet Updates Guidance and Indicators of Compromise following FortiManager Vulnerability Exploitation

Source: https://www.cisa.gov/news-events/alerts/2024/10/30/fortinet-updates-guidance-and-indicators-compromise-following-fortimanager-vulnerability

What happened: Fortinet has updated their security advisory addressing a critical FortiManager vulnerability (CVE-2024-47575) to include additional workarounds and indicators of compromise (IOCs). A remote, unauthenticated cyber threat actor could exploit this vulnerability to gain access to sensitive files or take control of an affected system. At this time, all patches have been released.

Why it matters: CISA previously added this vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation, as confirmed by Fortinet. CISA strongly encourages users and administrators to apply the necessary updates, hunt for any malicious activity, assess potential risk from service providers, and report positive findings to CISA.

Sophos Reveals Five-Year Battle with Chinese Hackers Attacking Network Devices

Source: https://www.bleepingcomputer.com/news/security/sophos-reveals-5-year-battle-with-chinese-hackers-attacking-network-devices/

What happened: Sophos recently published a series of reports dubbed "Pacific Rim," revealing their ongoing confrontations with Chinese threat actors targeting networking devices over the past five years. The reports reveal that these threat actors, including Volt Typhoon, APT31, and APT41/Winnti, exploit vulnerabilities to deploy custom malware for monitoring communications, stealing credentials or act as proxy servers for further attacks.

Why it matters: The revelations from Sophos regarding the ongoing threats posed by Chinese threat actors show the evolving risk to global cybersecurity. The deployment of custom malware by these actors jeopardizes not only individual organizations but also the broader digital ecosystem. Many zero-day vulnerabilities developed by Chinese researchers are reportedly shared with both vendors and the Chinese government, enabling state-sponsored actors to exploit these weaknesses for espionage and cyberattacks. The implications are severe, as organizations face potential financial losses, reputational harm, and operational disruptions, while geopolitical tensions rise due to the impact of state-sponsored cyber activities.

New Phishing Kit Xiū gǒu Targets Users Across Five Countries With 2,000 Fake Sites

Source: https://thehackernews.com/2024/11/new-phishing-kit-xiu-gou-targets-users.html

What happened: Two thousand websites associated with public sector, postal, digital services, and banking services in Australia, Japan, Spain, the United Kingdom, and the United States have been observed to carry the phishing kit called Kit Xiū gǒu. The campaign reportedly uses well-known and legitimate anti-bot and hosting obfuscation services to mask their operation.

Why it matters: The global presence of the Kit Xiū gǒu phishing kit on thousands of public sector and service websites highly likely poses a significant risk of phishing attacks that are harder to detect, targeting governments and critical infrastructure and putting sensitive user data at risk. By exploiting these websites, threat actors can gain greater exposure to individuals interacting with government, postal, banking, and digital services. This can lead to these individuals getting scammed, having their money stolen from their accounts, doxxed, and more.

DEEP AND DARK WEB INTELLIGENCE

Breachforums user kzoldyck | Threat actor "kzoldyck" claimed to have leaked a database associated with Interbank in Peru on predominantly English-language dark web forum BreachForums. The actor alleged that Interbank suffered a data breach on October 30, 2024, exposing information on approximately 3 million customers.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2024-8956: PTZOptics PT30X-SDI/NDI-xx before firmware 6.3.40 is vulnerable to an insufficient authentication issue. The camera does not properly enforce authentication to /cgi-bin/param.cgi when requests are sent without an HTTP Authorization header. The result is a remote and unauthenticated attacker can leak sensitive data such as usernames, password hashes, and configuration details. Additionally, the attacker can update individual configuration values or overwrite the whole file.

Affected products: PTZOptics PT30X-SDI/NDI-xx before firmware 6.3.40

Tags: DIB, tlp:green