zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - December 28, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - December 28, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Palo Alto Releases Patch for PAN-OS DoS Flaw — Update Immediately
  • Threat Actor Claims to Target Turkey’s Ministry of National Defense
  • Finnish Authorities Board Ship Suspected of Damaging Undersea Power and Internet Lines

Palo Alto Releases Patch for PAN-OS DoS Flaw — Update Immediately

Source: https://thehackernews.com/2024/12/palo-alto-releases-patch-for-pan-os-dos.html

What happened: Palo Alto Networks disclosed a high-severity vulnerability, CVE-2024-3393, in PAN-OS software, affecting versions 10.X, 11.X, and Prisma Access. The flaw, linked to the Domain Name System (DNS) Security feature, allows an unauthenticated attacker to trigger a denial-of-service (DoS) condition by sending a malicious packet that reboots the firewall. Repeated attacks can cause the firewall to enter maintenance mode.

Why it matters: This vulnerability enables unauthenticated attackers to exploit a weakness in the DNS Security feature, potentially disrupting network security infrastructure, leading to service outages, compromising firewall availability, and leaving affected systems vulnerable to further attacks. The flaw can further allow an unauthenticated attacker to repeatedly trigger DoS conditions, causing widespread service disruptions and downtime. The vulnerability has been patched and users are urged to update to the patched versions to prevent potential attacks.

Threat Actor Claims to Target Turkey’s Ministry of National Defense

Source: https://cloud.zerofox.com/intelligence/advanced_dark_web/78249

What happened: ZeroFox observed that threat actor "Rey" (aka Hikki-Chan), an administrator of the HELLCAT ransomware group, claimed on BreachForums to have access to Turkey's Ministry of National Defense servers. In subsequent chat, Rey hinted at potentially leaking the Turkish citizens' database.

Why it matters: The potential compromise of Turkey's Ministry of National Defense servers poses a significant risk of exposing sensitive government and military information. If the claim proves accurate, it can lead to severe national security threats, particularly if classified materials or details of military operations are accessed. Additionally, the threat of leaking the Turkish citizens' database further escalates the situation, potentially resulting in a large-scale privacy breach and putting millions of individuals at risk of identity theft, fraud, and other malicious activities.

Finnish Authorities Board Ship Suspected of Damaging Undersea Power and Internet Lines

Source: https://www.reuters.com/world/europe/finland-police-investigate-role-foreign-ship-after-power-cable-outage-2024-12-26/

What happened: Finnish authorities have seized the Eagle S, a ship suspected of damaging an undersea power cable connecting Finland and Estonia and breaking or damaging four internet cables. The vessel, linked to Russia’s shadow fleet, was boarded by the Finnish coast guard, and its cargo was confiscated amid investigations that its anchor possibly sabotaged the cables.

Why it matters: Undersea cables play a critical role in electricity transmission and internet connectivity, thereby lending substantial support to modern infrastructure and cross-border communications. Damage to these cables not only strains energy and internet supply—directly impacting civilian life and national security—but the repair processes are also likely to take up more resources, given the winter weather conditions.

DEEP AND DARK WEB INTELLIGENCE

XSS user professorx2: Untested threat actor "professorx2" advertised loader malware dubbed "BlackHunter" on predominantly Russian language dark web forum XSS.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2023-35082: An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted functionality or resources of the application without proper authentication.

Affected products: Ivanti EPMM versions 11.10 and earlier.

Tags: DIB, tlp:green