zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - November 13, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - November 13, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • CISA, NSA, and Partners Issue Report on Last Year’s Top Exploited Vulnerabilities
  • Encrypted Networks Lure Minors into Organized Crime, Europol Warn
  • German Interior Minister Warns of Cyber Threat Ahead of Elections

CISA, NSA, and Partners Issue Report on Last Year’s Top Exploited Vulnerabilities

Source: https://media.defense.gov/2024/Nov/12/2003581596/-1/-1/0/CSA-2023-TOP-ROUTINELY-EXPLOITED-VULNERABILITIES.PDF

What happened: In 2023, malicious cyber actors exploited more zero-day vulnerabilities to compromise enterprise networks compared to 2022, allowing them to conduct cyber operations against higher-priority targets. In 2023, the majority of the most frequently exploited vulnerabilities were initially exploited as a zero-day. The advisory addresses the top 15 vulnerabilities and several mitigations.

Why it matters: Malicious cyber actors continue to have the most success exploiting vulnerabilities within two years after public disclosure of the vulnerability. The utility of these vulnerabilities declines over time as more systems are patched or replaced. Malicious cyber actors find less utility from zero-day exploits when international cybersecurity efforts reduce the lifespan of zero-day vulnerabilities. The authoring agencies strongly encourage vendors, designers, developers, and end-user organizations to implement the recommendations provided to reduce the risk of compromise by malicious cyber actors.

Encrypted Networks Lure Minors into Organized Crime, Europol Warns

Source: https://www.europol.europa.eu/media-press/newsroom/news/europol-warns-of-organised-crime-networks-recruiting-minors-for-criminal-acts

What happened: Europol has reported that criminal networks in Europe are now actively recruiting minors for serious crimes through social media and encrypted messaging. The organizations use gamified tactics, disguising criminal tasks as “challenges” to attract young people, while encryption conceals communications from law enforcement.

Why it matters: The cyber-driven recruitment strategy creates a potent challenge for law enforcement, as criminals leverage encrypted channels and social media to mask their activities and evade surveillance. Encryption and coded language minimize digital traces, disrupting efforts to monitor or intercept recruitment campaigns. This particular evolution in the criminal recruitment strategy is likely to accelerate the entry of minors into violent crime and complicate digital evidence-gathering.

German Interior Minister Warns of Cyber Threat Ahead of Elections

Source: https://www.reuters.com/technology/cybersecurity/german-interior-minister-warns-cyber-threat-ahead-elections-2024-11-12/

What happened: Germany’s interior minister, Nancy Faeser, warned that the country must enhance its cyber defenses against disinformation and cyberattacks, reportedly from Russia, as it prepares for early elections. The Federal Office for Information Security’s report stated no major incidents occurred during the recent EU and state elections, but monitoring will intensify for national elections.

Why it matters: Germany’s upcoming snap elections likely faces heightened risks from cyberattacks and disinformation campaigns, potentially undermining electoral integrity and public trust. Strengthening cybersecurity is essential not only to protect the integrity of election results but also to ensure that disinformation does not sway public opinion or destabilize social order, particularly in an environment of political and economic uncertainty where the Social Democrat Olaf Scholz's three-way coalition recently collapsed.

DEEP AND DARK WEB INTELLIGENCE

BreachForums user 888: Threat actor "888" claimed to have leaked a database associated with Tibber, a Norwegian-Swedish energy company that offers digital electricity supply services on predominantly English-language dark web forum BreachForums.

VULNERABILITY AND EXPLOIT INTELLIGENCE

Microsoft Patch Tuesday for November 2024: Microsoft's November 2024 Patch Tuesday addressed 91 vulnerabilities, including four zero-days (two actively exploited). Key fixes include critical remote code execution and privilege escalation flaws across Windows 10 and 11 updates. Affected products: Microsoft has listed all the vulnerabilities and their affected products in the Patch Tuesday release notes.

CVE-2023-4699: Arbitrary command execution vulnerability due to missing authentication for critical function exists in Mitsubishi Electric proprietary protocol communication used in the affected products. Successful exploitation of this vulnerability may allow a remote attacker to execute arbitrary commands by sending specific packets to the affected products.

Affected products: CISA has listed the affected products in the Industrial Control Systems (ICS) advisory addressing this bug.

Tags: DIB, tlp:green