ZeroFox Daily Intelligence Brief - May 23, 2023
|by Alpha Team

ZeroFox Daily Intelligence Brief - May 23, 2023
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- ZeroFox Intelligence Brief: An Overview of 5G and Potential Vulnerabilities: A ZeroFox Intelligence Brief
- Indonesian Cybercriminals Exploit AWS for Crypto Mining Operations
- CVE-2023-2844
- CVE-2023-28409
- CVE-2023-28413
- Credit Card Data Breach: 2023-5-22
An Overview of 5G and Potential Vulnerabilities: A ZeroFox Intelligence Brief
While 5G promises significant upgrades in speed, bandwidth, and energy efficiency, its implementation has been largely restricted to North America, East Asia, and Western Europe. A range of factors—from cost and supply chain challenges to the absence of a distributed user base and infrastructure limitations—have hindered its global proliferation. ZeroFox Intelligence has analyzed the potential threats to this technology, such as a growing digital attack surface, potential network slicing and edge computing misconfigurations, and supply chain vulnerabilities. The report also touches on the challenges with legacy infrastructure and inherited vulnerabilities and provides some recommendations for the way ahead.
Indonesian Cybercriminals Exploit AWS for Crypto Mining Operations
A financially motivated threat actor is abusing Amazon Web Services’ (AWS) Elastic Compute Cloud (EC2) instances for crypto mining. The group, known as GUI-vil, leverages Graphical User Interface (GUI) tools like S3 Browser for initial operations. It exploits AWS keys in exposed source code repositories or vulnerable GitLab instances for entry. GUI-vil's activities trace back to Indonesian IP addresses, and its main goal is to mine cryptocurrency at the expense of victim organizations.
VULNERABILITIES
- CVE-2023-2844 - GitHub repository cloudexplorer-dev/cloudexplorer-lite prior to v1.1.0 is missing an authorization.
- CVE-2023-28409 - Unrestricted upload of file with dangerous type exists in MW WP Form versions v4.4.2 and earlier, which may allow a remote unauthenticated attacker to upload an arbitrary file.
- CVE-2023-28413 - Directory traversal vulnerability in Snow Monkey Forms versions v5.0.6 and earlier allows a remote unauthenticated attacker to obtain sensitive information, alter the website, or cause a denial-of-service (DoS) condition.
BREACHES
- Credit Card Data Breach: 2023-5-22 (fc50be | 3031) Credit Card
Tags: DIB, tlp:green