ZeroFox Daily Intelligence Brief - June 1, 2023
|by Alpha Team

ZeroFox Daily Intelligence Brief - June 1, 2023
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- ZeroFox Intelligence Flash Report: EDR Bypass Claims Spark Mixed Reactions
- Enzo Biochem Discloses Ransomware Attack Affecting Clinical Data of 2.5 Million Individuals
- Abandoned Salesforce Sites Pose Data-Security Risks
- Vulnerabilities: CVE-2023-2942, CVE-2023-2944, and CVE-2023-32964
- Exploits: CVE-2016-9793, CVE-2017-17562, and CVE-2010-1870
- Breaches: Credit Card Data Breach: 2023-5-30 and Credit Card Data Breach: 2023-5-31
ZeroFox Intelligence Flash Report: EDR Bypass Claims Spark Mixed Reactions
A threat actor known as "spyboy" on the Russian underground forum RAMP claims to be selling a software tool capable of evading and disabling prominent antivirus (AV) and endpoint detection and response (EDR) software. Reactions from underground actors regarding the claims have been mixed, with some actors defending spyboy's assertions while others raise doubts about their validity.
Enzo Biochem Discloses Ransomware Attack Affecting Clinical Data of 2.5 Million Individuals
Enzo Biochem, a New York-based bioscience and diagnostics firm, disclosed that an April 2023 ransomware attack compromised test information and personal data of around 2.5 million individuals. The threat actors accessed, and in certain instances exfiltrated, patients’ names, test information, and roughly 600,000 Social Security numbers from its IT systems.
Abandoned Salesforce Sites Pose Data-Security Risks
Salesforce customers have been observed to leave Community sites unmaintained after use, without proper deactivation—risking the exposure of sensitive corporate, vendor, and user data. These sites often contain valuable business and personal information, including personally identifiable information (PII), that can be accessed by threat actors if administrators are not diligently implementing requisite security procedures.
VULNERABILITIES
- CVE-2023-2942 - Improper Input Validation in GitHub repository openemr/openemr prior to 7.0.1
- CVE-2023-2944 - Improper Access Control in GitHub repository openemr/openemr prior to 7.0.1.
- CVE-2023-32964 - Cross-Site Request Forgery (CSRF) vulnerability in Made with Fuel Better Notifications for WP plugin <= 1.9.2 versions
EXPLOITS
- CVE-2016-9793 - Linux Kernel SO_SNDBUFFORCE / SO_RCVBUFFORCE Local Privilege Escalation
- CVE-2017-17562 - GoAhead Web Server LD_PRELOAD Arbitrary Module Load
- CVE-2010-1870 - Apache Struts < 2.2.0 Remote Command Execution
BREACHES
- Credit Card Data Breach: 2023-5-30 - (c09f82 | 2877) Credit card
- Credit Card Data Breach: 2023-5-31 - (d46a4d | 2279) Credit card
Tags: DIB, tlp:green