zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - June 5, 2023

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - June 5, 2023

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Magecart Campaign Infects Legitimate Sites to Host Credit Card Stealer Scripts
  • Hackers Spoof Popular Brands in “Picture in Picture” Attack
  • Burton Snowboards Confirms Data Breach
  • Vulnerabilities: CVE-2023-34411, CVE-2023-34410, and CVE-2023-34408
  • Exploits: CVE-2005-0581 and CVE-2015-3306
  • Breach: Credit Card Data Breach: 2023-6-3

Magecart Campaign Infects Legitimate Sites to Host Credit Card Stealer Scripts

A new Magecart campaign steals credit cards by hijacking legitimate websites as makeshift command and control servers. Researchers have observed this campaign compromising organizations in the United States, United Kingdom, Australia, Brazil, Peru, and Estonia. Victims often remain unaware of the breach for over a month, highlighting the attacks' stealthiness. The stolen data is sent to the attacker's server through an obfuscated IMG tag.

Hackers Spoof Popular Brands in “Picture in Picture” Attack

Hackers are using obfuscation tactics with glossy advertising photos to trick users into visiting credential-harvesting sites and giving up personal information. This trend of updating old phishing tactics with new tools, like AI, makes the attacks more convincing. The approach, called "picture in picture," links marketing photos to malicious URLs. It bypasses URL filters and targets users with social engineering.

Burton Snowboards Confirms Data Breach

Leading snowboard manufacturer Burton Snowboards has confirmed a data breach, notifying customers that their sensitive information may have been accessed or stolen during a "cyber incident" in February 2023. The attack caused a system outage and forced the company to cancel online orders. Affected customers have been informed that their names, Social Security numbers, and financial account information may have been compromised.

VULNERABILITIES

  • CVE-2023-34411 - The xml-rs crate before 0.8.14 for Rust and Crab allows a denial of service (panic) via an invalid <! token (such as <!DOCTYPEs/%<!A nesting) in an XML document.
  • CVE-2023-34410 - An issue was discovered in Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.2.
  • CVE-2023-34408 - DokuWiki before 2023-04-04a allows XSS via RSS titles.

EXPLOITS

  • CVE-2005-0581 - CA BrightStor ARCserve License Service - 'GCR NETWORK' Remote Buffer Overflow (Metasploit)
  • CVE-2015-3306 - ProFTPD 1.3.5 Mod_Copy Command Execution

BREACHES

Tags: DIB, tlp:green