ZeroFox Daily Intelligence Brief - May 22, 2023
|by Alpha Team

ZeroFox Daily Intelligence Brief - May 22, 2023
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Notorious Cyber Gang Returns for New Wave of Financially Motivated Attacks
- Luxottica Confirms 2021 Data Breach After Information of 70 Million Customers Leaks Online
- CISA: Samsung ASLR Bypass Bug Actively Exploited by Threat Actors
- CVE-2021-31239
- CVE-2023-2726
- CVE-2023-2721
- Credit Card Data Breach: 2023-5-21
Notorious Cyber Gang Returns for New Wave of Financially Motivated Attacks
Researchers have recently observed cybercrime group FIN7 deploying Clop ransomware in attacks, marking the group’s first ransomware campaign since late 2021. Fin7—now tracked as “Sangria Tempest” under the new taxonomy for threat actor groups—uses PowerShell script POWERTRASH to load the Lizar post-exploitation tool and gain access to a target network. It then uses OpenSSH and Impacket to move laterally and deploy Clop ransomware. Active since 2012, this financially motivated group has targeted a wide range of organizations, including software, consulting, and financial services.
Luxottica Confirms 2021 Data Breach After Information of 70 Million Customers Leaks Online
Luxottica, the world's largest eyewear company, has confirmed a 2021 data breach that exposed the personal information of 70 million customers, including email addresses, dates of birth, and mailing addresses. The leaked database, which was reportedly exfiltrated on May 16, 2021, was posted with free access in the last month on various hacking forums. Luxottica is currently investigating the incident and has stated that the compromised data does not include individuals’ financial information, Social Security numbers, or login passwords. Luxottica is the owner of popular brands like Ray-Ban, Oakley, Chanel, Prada Eyewear, Versace, Dolce & Gabbana, Burberry, Giorgio Armani, Michael Kors, and others.
CISA: Samsung ASLR Bypass Bug Actively Exploited by Threat Actors
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a security bug (CVE-2023-21492; CVSS score: 4.4) affecting Samsung mobile devices running Android 11, 12, and 13 to its Known Exploited Vulnerabilities Catalog. This vulnerability inserts sensitive information into log files and can allow a privileged, local attacker to conduct an address space layout randomization (ASLR) bypass. Samsung addressed this vulnerability as part of its May 2023 Security Maintenance Release (SMR) updates, and all U.S. Federal Civilian Executive Branch Agencies (FCEB) are mandated to patch the bug by June 9, 2023.
VULNERABILITIES
- CVE-2021-31239 - An issue found in SQLite SQLite3 v.3.35.4 allows a remote attacker to cause a denial of service via the appendvfs.c function.
- CVE-2023-2726 - Inappropriate implementation in WebApp Installs in Google Chrome prior to 113.0.5672.126 allowed an attacker who convinced a user to install a malicious web app to bypass install dialog via a crafted HTML page.
- CVE-2023-2721 - Use after free in Navigation in Google Chrome prior to 113.0.5672.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
BREACHES
- Credit Card Data Breach: 2023-5-21 (1a6256 | 2383) Credit Card
- Credit Card Data Breach: 2023-5-21 (d4a1b9 | 2840) Credit Card
- Credit Card Data Breach: 2023-5-19 (52dfb8 | 2922) Credit Card
Tags: DIB, tlp:green