zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - June 8, 2023

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - June 8, 2023

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Researchers Link Lazarus to Atomic Wallet Attack
  • Honda API Exposed Customer Data and Internal Documents
  • Barracuda: Replace Hacked ESG Appliances
  • Vulnerabilities: CVE-2023-33326, CVE-2023-3068, and CVE-2023-33556
  • Exploits: CVE-2010-2227, CVE-2008-4696, and CVE-2009-3103
  • Breaches: BreachForums/XSS: EpicNPC Marketplace Data Breach and Credit Card Data Breach: 2023-6-6

Researchers Link Lazarus to Atomic Wallet Attack

Blockchain researchers have linked notorious North Korean cybercriminal group Lazarus to an attack on Atomic Wallet, a “non-custodial” cryptocurrency wallet. The same group was responsible for two prominent attacks last year (Axie Infinity hack in March 2022 and Harmony Horizon Bridge hack in June 2022), which resulted in a cumulative loss of USD 720 million. The incumbent North Korean regime is known to leverage cryptocurrency heists to fund its activities (including arms development) and evade sanctions.

Honda API Exposed Customer Data and Internal Documents

Honda's e-commerce platform for power equipment, marine, and lawn & garden products had an API vulnerability which potentially allowed anyone to reset passwords for any account. The bug, which exposed certain internal financial reports, orders, and even some customers’ personally identifiable information (PII), was discovered by a security researcher who had previously breached Toyota's supplier portal. Honda reportedly confirmed the resolution of the bug by April 3, 2023.

Barracuda: Replace Hacked ESG Appliances

Security company Barracuda urged customers to immediately replace hacked Email Security Gateway (ESG) appliances, regardless of the patch version. A critical remote command injection flaw (CVE-2023-2868) affecting Barracuda ESGs was patched on May 20 2023, and attackers' access to compromised appliances was cut off the next day. However, the vulnerability had been exploited since at least October 2022.

VULNERABILITIES

  • CVE-2023-33326 - An unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability has been found in EventPrime plugin <= 2.8.6 version.
  • CVE-2023-3068 - A critical vulnerability has been found in Campcodes Retro Cellphone Online Store 1.0.
  • CVE-2023-33556 - TOTOLink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the staticGw parameter at /setting/setWanIeCfg.

EXPLOITS

  • CVE-2010-2227 - Apache Tomcat Transfer-Encoding Information Disclosure and Denial of Service
  • CVE-2008-4696 - Opera History Search XSS
  • CVE-2009-3103 - Microsoft Windows - SMB2 Negotiate Protocol “0x72” Response Denial of Service

BREACHES

Tags: DIB, tlp:green