ZeroFox Cyber Intelligence Daily Brief - December 11, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - December 11, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- U.S. Treasury Issues Sanctions Against PRC Firm for Hacking Firewalls and Attempted Ransomware Attacks
- Scottish Parliament TV Vulnerable to Deepfakes
- Cyber Resilience Act Introduces New Rules for Digital Products in the EU
U.S. Treasury Issues Sanctions Against PRC Firm for Hacking Firewalls and Attempted Ransomware Attacks
Source: https://home.treasury.gov/news/press-releases/jy2742
What happened: The Department of the Treasury’s Office of Foreign Assets Control (OFAC) has sanctioned cybersecurity company Sichuan Silence and one of its employees, both based in the People’s Republic of China (PRC) for compromising tens of thousands of firewalls worldwide in April 2020.
Why it matters: The sanctioned employee exploited a zero-day vulnerability in a firewall product to deploy malware on approximately 81,000 firewalls worldwide, stealing credentials and attempting to deploy the Ragnarok ransomware variant. Given that a considerable number of the compromised targets were associated with U.S. critical infrastructure, it had a potential to cause widespread damage and harm to human life. Meanwhile, Sichuan Silence supplied PRC intelligence and others with tools to exploit network routers, posing significant risks to U.S. national security, foreign policy, and the stability of critical infrastructure sectors.
Scottish Parliament TV Vulnerable to Deepfakes
What happened: Researchers warn that deepfakes pose cybersecurity risks to Scottish Parliamentary live streams and archived recordings, potentially undermining public trust. Threats include hijacking live streams, creating manipulated videos for social media, and using archives to train artificial intelligence (AI) for malicious purposes.
Why it matters: Deepfake threats to the Scottish Parliament can likely endanger democratic processes through the spread of manipulated content and misinformation, misleading the public and amplifying false narratives. Without safeguards, archives could be exploited to enhance AI tools for targeted malicious campaigns against Parliament members. The Scottish Parliament reportedly lacks measures to prevent such attacks, but solutions like authentication checks and reporting plans will likely better safeguard the individual identities and privacy.
Cyber Resilience Act Introduces New Rules for Digital Products in the EU
Source: https://digital-strategy.ec.europa.eu/en/policies/cyber-resilience-act
What happened: The Cyber Resilience Act (CRA) introduces mandatory cybersecurity requirements for manufacturers and retailers, governing the planning, design, development, and maintenance of such products. Manufacturers will be required to provide care during the lifecycle of their products, while some critical products of particular relevance for cybersecurity will need to undergo a third-party assessment by an authorized body before they are sold in the EU market.
Why it matters: The regulation applies to all products connected directly or indirectly to another device or network except for specified exclusions such as certain open-source software or services products already covered by existing rules, which is the case for medical devices, aviation and cars. The new rules will rebalance responsibility towards manufacturers, who must ensure their products with digital elements meet cybersecurity standards for the EU market. This will allow buyers to make more informed decisions, trusting the cybersecurity of products with the Conformité Européene (CE) mark, which is the mandatory conformity marking for regulating products sold in the EU.
DEEP AND DARK WEB INTELLIGENCE
Telegram user Holy League: On December 10, 2024, pro-Palestine and pro-Russia threat actor collective "Holy League" claimed to be in France and plans to initiate offensive operations against Germany starting on December 11, 2024.
VULNERABILITY AND EXPLOIT INTELLIGENCE
Microsoft December 2024 Patch Tuesday: In its December 2024 edition of Patch Tuesday release, Microsoft has released security updates for 71 flaws, including one actively exploited zero-day vulnerability. Affected products: Microsoft has listed all the vulnerabilities and their affected products in this advisory.
Tags: DIB, tlp:green