ZeroFox Daily Intelligence Brief - June 6, 2023
|by Alpha Team

ZeroFox Daily Intelligence Brief - June 6, 2023
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- British Companies’ Staff Details Targeted in Russia-Linked Cyber Attack
- KeePassUpdate Addresses Critical Master Password Vulnerability
- Gigabyte Releases BIOS Updates to Bolster Security and Patch Backdoor Vulnerability
- Vulnerabilities: CVE-2018-25087, CVE-2023-2546, and CVE-2023-32699
- Exploit: CVE-2010-2743
- Breaches: BreachForums/XSS: Kraken Data Breach, Telegram: Night Sorted.zip Botnet Breach, and BreachForums/Leakbase: Moon Valley Nurseries Data Breach
British Companies’ Staff Details Targeted in Russia-Linked Cyberattack
Prominent U.K.-based companies, including British Airways (BA) and Boots, are investigating potential data breaches after payroll provider Zellis fell victim to an attack on the MOVEit tool by Russia-linked attackers. Names, addresses, national insurance numbers, and banking details of BA employees have been compromised in the attack. Security researchers attributed the attacks to a group called Lace Tempest, known for ransomware operations using the Clop strain.
KeePass Update Addresses Critical Master Password Vulnerability
Users of the 2.x branch of KeePass password manager should upgrade to version 2.54, which fixes a critical vulnerability (CVE-2023-32784) that allows retrieval of the master password from system memory dumps. As reported in the ZeroFox Daily Intelligence Brief last month, a proof-of-concept tool demonstrated the memory-analysis technique to retrieve the master password, with the exclusion of the first character.
Gigabyte Releases BIOS Updates to Bolster Security and Patch Backdoor Vulnerability
Hardware manufacturer Gigabyte has released BIOS updates for its personal computers (PCs) after an inadvertent system backdoor was discovered on hundreds of Gigabyte PC models. The updates implement stricter security measures during the boot process, including enhanced file validation and blocking downloads from servers without valid certificates.
VULNERABILITIES
- CVE-2018-25087 - A vulnerability classified as problematic was found in Arborator Server, which affects the function start of the file project.cgi.
- CVE-2023-2546 - The WP User Switch plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.0.2.
- CVE-2023-32699 - Version 2.9.1 and prior of MeterSphere, an open-source continuous-testing platform, are vulnerable to denial of service.
EXPLOITS
- CVE-2010-2743 - Win32k Keyboard Layout Vulnerability
BREACHES
- BreachForums/XSS: Kraken Data Breach - (14,379 Records) Email address and password
- Telegram: Night Sorted.zip Botnet Breach - ( 20,743 Records) Email address and password
- BreachForums/Leakbase: Moon Valley Nurseries Data Breach - (30,995 Records) Email address, name, phone number, physical address, company name, and website
Tags: DIB, tlp:green