zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - June 12, 2023

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - June 12, 2023

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Strava’s Heatmap Feature Could Expose Users' Home Addresses
  • Fortinet Releases Critical SSL VPN Patch to Address Remote Code Execution Vulnerability
  • Brand-New Security Bugs Addressed in MOVEit Transfer
  • Vulnerabilities: CVE-2023-35036, CVE-2020-36732, and CVE-2023-29753
  • Breaches: Credit Card Data Breach: 2023-6-10 and Telegram: 'ZEBRA CLOUD FREE.rar' Botnet Breach

Strava’s Heatmap Feature Could Expose Users' Home Addresses

Security researchers have uncovered a privacy risk in fitness app Strava’s heatmap feature, which aggregates activity data to help users find exercise spots. The researchers were able to achieve a 37.5% accuracy rate in predicting users’ home locations using publicly available data. The researchers have suggested mitigation measures such as setting privacy zones, opting out of the feature, or keeping profiles private for added privacy.

Fortinet Releases Critical SSL VPN Patch to Address Remote Code Execution Vulnerability

Fortinet has issued firmware updates for Fortigate devices, addressing an undisclosed critical pre-authentication remote code execution (RCE) flaw in its SSL VPN. The security fixes were included in the recently released FortiOS firmware versions 6.0.17, 6.2.15, 6.4.13, 7.0.12, and 7.2.5. Administrators are urged to apply the patches because of the likelihood of threat actors attempting to exploit the flaw.

Brand-New Security Bugs Addressed in MOVEit Transfer

All MOVEit Transfer customers have been advised to apply a new patch released on June 9, 2023, to address several critical SQL injection vulnerabilities. The bugs could allow an unauthenticated attacker to gain unauthorized access to the MOVEit Transfer database and modify or steal data from users’ databases. The bugs were revealed during an investigation of a different vulnerability (CVE-2023-34362) that was reportedly exploited by the Clop ransomware group.

VULNERABILITIES

  • CVE-2023-35036 - In MOVEit Transfer before 2021.0.7 (13.0.7), 2021.1.5 (13.1.5), 2022.0.5 (14.0.5), 2022.1.6 (14.1.6), and 2023.0.2 (15.0.2), SQL injection vulnerabilities have been found that could allow an unauthenticated attacker to gain unauthorized access to MOVEit Transfer's database.
  • CVE-2020-36732 - The crypto-js package before 3.2.1 for Node.js generates random numbers by concatenating the string "0." with an integer, which makes the output more predictable than necessary.
  • CVE-2023-29753 - An issue found in Facemoji Emoji Keyboard v.2.9.1.2 for Android allows a local attacker to cause a denial of service via the SharedPreference files.

BREACHES

Tags: DIB, tlp:green