zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - November 16, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - November 16, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • PL/Perl Flaw in PostgreSQL Enables Arbitrary Code Execution
  • “Hostile” Foreign Hackers Infiltrate Hungary's Defense Procurement Agency
  • U.S. Individual Sentenced to 5 Years over Laundering Crypto Stolen from Bitfinex Hack

PL/Perl Flaw in PostgreSQL Enables Arbitrary Code Execution

Source: https://www.darkreading.com/vulnerabilities-threats/varonis-warns-bug-discovered-postgresql-pl-perl

What happened: Cybersecurity researchers have discovered a critical vulnerability (CVE-2024-10979) in the PL/Perl language extension of PostgreSQL. It enables threat actors to modify environment variables in PostgreSQL session processes, execute arbitrary code, and run queries to access sensitive information.

Why it matters: CVE-2024-1097 affects several versions of PL/Perl language extension, including PostgreSQL 17.0 and earlier, with updates available to mitigate the issue. The vulnerability poses significant risks for organizations relying on PostgreSQL, especially where privileged access could lead to data breaches or server compromises. Attackers will likely exploit this bug to tamper with database environments and extract sensitive machine data.

“Hostile” Foreign Hackers Infiltrate Hungary's Defense Procurement Agency

Source: https://www.euronews.com/my-europe/2024/11/14/hostile-foreign-hackers-infiltrate-hungarys-defence-procurement-agency

What happened: Hungary's Defence Procurement Agency suffered a ransomware attack by the INC group, which encrypted data and demanded USD 5 million. At the time of writing, Hungary does not confirm any national security compromise. However, ZeroFox observed an update on the INC ransomware leak site containing screenshots shared by the attackers likely involving sensitive data.

Why it matters: The breach of Hungary's Defence Procurement Agency has significant risks, as it exposes critical systems to potential misuse by cybercriminals. The encryption and ransom demands could disrupt operations, delay important procurements, and hinder security initiatives. Additionally, the leaked sensitive data, including procurement details, can likely lead to further exploitation or compromise the integrity of national defense strategies.

U.S. Man Sentenced to 5 Years over Laundering Crypto Stolen from Bitfinex Hack

Source: https://www.reuters.com/technology/us-man-sentenced-5-years-over-laundering-crypto-stolen-bitfinex-hack-2024-11-14/

What happened: A tech entrepreneur from New York was sentenced to five years in prison after pleading guilty to laundering 120,000 stolen bitcoin from Bitfinex, a major cryptocurrency exchange, which occurred in 2016. The stolen bitcoin, originally worth USD 71 million, grew to over USD 4.5 billion by the time of their arrest.

Why it matters: This case shows the growing risks and challenges within the cryptocurrency space, where cybercriminals are increasingly using advanced techniques to steal and launder digital assets. The massive surge in the value of the stolen bitcoin demonstrates how criminal activities in the crypto space can have long-lasting financial implications. With cryptocurrency’s value skyrocketing, this case shows how illicit activities can escalate in tandem.

DEEP AND DARK WEB INTELLIGENCE

BreachForums user miyako: Moderately credible threat actor "miyako" advertised network access with root rights to an unnamed U.S.-based state university on predominantly English language Dark Web forum BreachForums.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2024-52301: This vulnerability allows unauthorized access and data tampering via manipulated URLs, affecting multiple versions; developers must update immediately and strengthen PHP configurations to mitigate risks. The vulnerability has a CVSS score of 8.7 Affected products: The affected products are on this advisory.

Tags: DIB, tlp:green