ZeroFox Daily Intelligence Brief - May 25, 2023
|by Alpha Team

ZeroFox Daily Intelligence Brief - May 25, 2023
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- China State-Sponsored Cyber Actor Evades Detection with Stealth Techniques
- Barracuda Discloses Zero-Day Bug in Email Security Gateway Appliance
- GitLab Strongly Recommends Patching Max Severity Flaw
- CVE-2022-30256
- CVE-2023-2732
- CVE-2023-31861
- CVE-2012-0391
- CVE-2023-2732
- CVE-2009-0658
- Credit Card Data Breach: 2023-5-24
China State-Sponsored Cyber Actor Evades Detection with Stealth Techniques
A joint Five Eyes advisory has provided hunting guidance and associated best practices to detect malicious activities of Chinese state-sponsored cyber actor Volt Typhoon. The group has been targeting organizations in government, maritime, communications, manufacturing, and other critical sectors across the United States since 2021. The attacks begin by exploiting an unknown zero-day vulnerability in internet-exposed Fortinet FortiGuard devices and use living-off-the-land techniques to evade detection.
Barracuda Discloses Zero-Day Bug in Email Security Gateway Appliance
Security-solutions provider Barracuda identified a zero-day vulnerability (CVE-2023-2868) in its Email Security Gateway (ESG) appliance on May 19, 2023, and applied a global security patch within a day to eliminate the bug. Only ESG appliances were affected; other Barracuda products and SaaS email security services remained unaffected. A second patch was applied on May 21, 2023, and affected users were notified through the ESG interface. Barracuda announced that it would monitor the situation, send updates through its status page, and provide direct outreach to impacted customers.
GitLab Strongly Recommends Patching Max Severity Flaw
Web-based Git repository GitLab has released an emergency security update to address a maximum severity path traversal flaw (CVE-2023-2825) impacting GitLab Community Edition (CE) and Enterprise Edition (EE) version 16.0; earlier versions are not affected by the bug. The flaw, which has been patched in version 16.0.1 of CE and EE, allows an unauthenticated attacker to read arbitrary files on the server when an attachment exists in a public project nested within at least five groups. Successful exploitation of the bug can expose sensitive data, proprietary software code, user credentials, tokens, files, and other private information.
VULNERABILITIES
- CVE-2022-30256 - An issue was discovered in MaraDNS Deadwood through 3.5.0021 that allows variant V1 of unintended domain name resolution.
- CVE-2023-2732 - The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.2.
- CVE-2023-31861 ZLMediaKit 4.0 is vulnerable to Directory Traversal.
EXPLOITS
- CVE-2012-0391 - Apache Struts 2.2.1.1 Remote Command Execution
- CVE-2009-1043 - Core Security Technologies Advisory 2009.0420
- CVE-2009-0658 - Adobe - JBIG2Decode Memory Corruption (Metasploit)
BREACHES
- Credit Card Data Breach: 2023-5-24 (bf9ac6 | 2053) Credit card
Tags: DIB, tlp:green