zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - January 23, 2025

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - January 23, 2025

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • CISA and FBI Release Advisory on How Threat Actors Chained Vulnerabilities in Ivanti CSA
  • Conduent Deals with Cybersecurity Incident that Caused Disruptions to Few States
  • Telegram Captcha Tricks User into Running Malicious PowerShell Scripts

CISA and FBI Release Advisory on How Threat Actors Chained Vulnerabilities in Ivanti CSA

Source: https://www.cisa.gov/news-events/alerts/2025/01/22/cisa-and-fbi-release-advisory-how-threat-actors-chained-vulnerabilities-ivanti-cloud-service

What happened: CISA, in partnership with the Federal Bureau of Investigation (FBI), released Threat Actors Chained Vulnerabilities in Ivanti Cloud Service Applications. This advisory was crafted in response to active exploitation of vulnerabilities—CVE-2024-8963, an administrative bypass vulnerability; CVE-2024-9379, a SQL injection vulnerability; and CVE-2024-8190 and CVE-2024-9380, remote code execution vulnerabilities—in Ivanti Cloud Service Appliances (CSA) in September 2024.

Why it matters: Threat actors chained the listed vulnerabilities to gain initial access, conduct remote code execution (RCE), obtain credentials, and implant webshells on victim networks. All four vulnerabilities affect Ivanti CSA version 4.6x versions before 519, and two of the vulnerabilities (CVE-2024-9379 and CVE-2024-9380) affect CSA versions 5.0.1 and below. CISA and FBI strongly encourage network administrators and defenders to upgrade to the latest supported version of Ivanti CSA and to hunt for malicious activity on their networks using the detection methods and indicators of compromise (IOCs) provided in the advisory.

Conduent Deals with Cybersecurity Incident that Caused Disruptions to Few States

Source: https://techcrunch.com/2025/01/22/conduent-confirms-outage-was-due-to-a-cybersecurity-incident/

What happened: A cybersecurity incident at U.S. government contractor Conduent caused service disruptions, leaving residents in several states without access to support payments. The issue has been contained, and all systems have been restored, according to the company.

Why it matters: Although services are being restored, disruptions in Conduent's services impacted vital support payments for vulnerable individuals. Government contractors managing essential public services are increasingly targeted by threat actors. These attackers likely target critical infrastructure companies since they are vulnerable due to the sensitive data they handle, the breach of which can cause real-world harm to individuals.

Telegram Captcha Tricks People into Running Malicious PowerShell Scripts

Source: https://www.bleepingcomputer.com/news/security/telegram-captcha-tricks-you-into-running-malicious-powershell-scripts/

What happened: Threat actors on X (Twitter) are exploiting news about Ross Ulbricht (founder of Silk Road) to lure users into a Telegram channel. Once there, they trick users into running PowerShell code that infects their devices with malware, using a new variant of the "ClickFix" tactic.

Why it matters: Threat actors are capitalizing on trending news to deceive users into executing malicious code, which, if run, can likely give attackers control of the victim’s system, steal sensitive data, or deploy additional malware, potentially resulting in financial loss or identity theft. Platforms like Telegram, have become a hotbed for cybercriminals, offering a relatively unregulated space to distribute malware, coordinate attacks, and target users. The use of ClickFix tactic has gained popularity among threat actors over the past year due to its effectiveness in distributing malware.

DEEP AND DARK WEB INTELLIGENCE

Cl0p Reveals 50 Undisclosed Victims: On January 22, 2025, ZeroFox observed that Cl0p ransomware group announced the disclosure of 50 additional unrevealed victims, which likely is a continuation of their exploitation of the Cleo vulnerability.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2024-32555: Incorrect privilege assignment vulnerability in Easy Real Estate allows privilege escalation via the social login.

Affected products: Easy Real Estate versions through 2.2.6.

Tags: DIB, tlp:green