ZeroFox Daily Intelligence Brief - June 9, 2023
|by Alpha Team

ZeroFox Daily Intelligence Brief - June 9, 2023
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Asylum Ambuscade Combines Cyber Espionage and Cybercrime in Recent Attacks
- CISA Releases Two Industrial Control Systems Advisories
- Google Switches Email Authentication Standards Because of Spoofing Vulnerability
- Vulnerabilities: CVE-2023-29536, CVE-2023-29533, and CVE-2023-29535
- Exploits: CVE-2011-2371, CVE-2014-3704, and CVE-2021-38294
- Breaches: BreachForums: UniverseGamers Gunz Data Breach and Credit Card Data Breach: 2023-6-7
Asylum Ambuscade Combines Cyber Espionage and Cybercrime in Recent Attacks
The Asylum Ambuscade group has been observed carrying out cyberattacks on small to medium-sized businesses (SMBs) worldwide, combining cyber espionage with cybercrime. The threat group was initially identified in March 2022, as part of research focused on phishing campaigns targeting entities assisting Ukrainian refugees. Asylum Ambuscade’s targets encompass banks, cryptocurrency traders, government entities, and SMBs across North America, Europe, and Central Asia.
CISA Releases Two Industrial Control Systems Advisories
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has released two industrial control systems (ICS) advisories highlighting vulnerabilities in Atlas Copco Power Focus 6000 (CVSS v3 6.5) and Sensormatic Electronics Illustra Pro Gen 4 (CVSS v3 8.3). The advisories provide technical details of the bugs and recommend mitigation measures.
Google Switches Email Authentication Standards Because of Spoofing Vulnerability
Google claims to have resolved a vulnerability that allowed scammers to impersonate certain service providers on Gmail. The issue originated from a flaw in the email authentication program, Brand Indicators for Message Identification (BIMI), which safeguards users against brand-spoofing and phishing attacks. Google initially used SPF but switched to DKIM after discovering a bug in SPF which allowed non-authenticated emails to appear authentic, compromising user safety.
VULNERABILITIES
- CVE-2023-29536 - An attacker could cause the memory manager to incorrectly free a pointer that addresses attacker-controlled memory, resulting in an assertion, memory corruption, or a potentially exploitable crash.
- CVE-2023-29533 - A website could have obscured the fullscreen notification by using a combination of window.open, fullscreen requests, window.name assignments, and setInterval calls.
- CVE-2023-29535 - Following a Garbage Collector compaction, weak maps may have been accessed before they were correctly traced.
EXPLOITS
- CVE-2011-2371 - Mozilla Firefox Array.reduceRight() Integer Overflow
- CVE-2014-3704 - Drupal HTTP Parameter Key/Value SQL Injection
- CVE-2021-38294 - Apache Storm Nimbus 2.2.0 Command Execution
BREACHES
- BreachForums: UniverseGamers Gunz Data Breach - (955,350 Records) | Email address, username, password, security questions, and user activity
- Credit Card Data Breach: 2023-6-7 - (ac961a | 2547) | Credit card
Tags: DIB, tlp:green