ZeroFox Cyber Intelligence Daily Brief - November 17, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - November 17, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- People's Republic of China Actors Target Commercial Telecommunications Infrastructure
- CISA, NSA, and Partners Issue Report on Last Year’s Top Exploited Vulnerabilities
- Law Enforcement Encounters New Hurdles in iPhone Data Access with iOS 18
People's Republic of China Actors Target Commercial Telecommunications Infrastructure
What happened: The FBI and CISA have released a joint statement addressing a broad and significant cyber espionage campaign orchestrated by actors affiliated with the People’s Republic of China (PRC), targeting multiple telecommunication companies. Through the campaign, the actors accessed customer call records data, data from law enforcement (LE) requests, and private communications of a few individuals, primarily involved in government or political activity.
Why it matters: The campaign targets, including telecommunication networks, LE databases, and government-associated individuals, likely indicate that the PRC actors were gathering intelligence on the U.S. government and political figures. Such breaches risk exposing classified operations, compromising individual safety, and damaging trust in essential communication infrastructures. Besides, with a new government soon to be formed in the United States, adversarial state-affiliated actors are likely to turn their attention towards government intelligence to give their states a political edge.
CISA, NSA, and Partners Issue Report on Last Year’s Top Exploited Vulnerabilities
What happened: In 2023, malicious cyber actors exploited more zero-day vulnerabilities to compromise enterprise networks compared to 2022, allowing them to conduct cyber operations against higher-priority targets. In 2023, the majority of the most frequently exploited vulnerabilities were initially exploited as a zero-day. The advisory addresses the top 15 vulnerabilities and several mitigations.
Why it matters: Malicious cyber actors continue to have the most success exploiting vulnerabilities within two years after public disclosure of the vulnerability. The utility of these vulnerabilities declines over time as more systems are patched or replaced. Malicious cyber actors find less utility from zero-day exploits when international cybersecurity efforts reduce the lifespan of zero-day vulnerabilities. The authoring agencies strongly encourage vendors, designers, developers, and end-user organizations to implement the recommendations provided to reduce the risk of compromise by malicious cyber actors.
Law Enforcement Encounters New Hurdles in iPhone Data Access with iOS 18
Source: https://www.wired.com/story/mysterious-iphone-reboot-ios-18-police/
What happened: Some iPhones in police custody have been rebooting automatically, complicating forensic investigations. These reboots, linked to Apple’s iOS 18, switch devices from an easily accessible After First Unlock (AFU) state to a more secure Before First Unlock (BFU) state, making it harder for police to extract data.
Why it matters: Apple has developed the “inactivity reboot” feature in iOS 18, which forces locked iPhones to restart after four days, as a potential anti-theft measure. Even though the feature is likely to help secure lost or stolen devices, it has caused disruptions in law enforcement (LE) efforts to access locked phones. Threat actors will likely try to leverage this feature by triggering automatic reboots on devices they cannot fully access to delay investigations—which would buy them time to erase or remotely tamper data and hinder LE from gathering crucial evidence.
Tags: DIB, tlp:green