ZeroFox Daily Intelligence Brief - June 23, 2023
|by Alpha Team

ZeroFox Daily Intelligence Brief - June 23, 2023
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- ZeroFox Cyber Threat Advisory: Ransomware & Digital Extortion Incidents Surging In Q2 2023
- NSA Publishes BlackLotus Mitigation Guide
- Mirai Botnet Targets 22 Flaws in D-Link, Zyxel, and Netgear Devices
- Vulnerabilities: CVE-2023-33933 and CVE-2023-36192
- Exploits: CVE-2010-3972 and CVE-2004-0937
- Breaches: Credit Card Data Breach: 2023-6-21 (bc7301 | 2815) and BreachForums/XSS: Canva Data Breach (15,556 Records)
ZeroFox Cyber Threat Advisory: Ransomware & Digital Extortion Incidents Surging In Q2 2023
ZeroFox Intelligence reports that the number of ransomware and digital extortion incidents recorded so far this quarter is almost 40% higher than in Q1 2023, with the number increasing as Clop ransomware group continues to name victims after its exploitation of a MOVEit Transfer bug. Recent successes have very likely emboldened threat actors, with attacks leveraging vulnerabilities in third-party service software having considerable downstream impact. 8Base is the most prolific new strain, with 72 attacks in June to date—predominantly on small and midsize businesses.
NSA Publishes BlackLotus Mitigation Guide
The U.S. National Security Agency (NSA) has released guidance against the BlackLotus malware, which evades detection, resists removal, and neutralizes Windows security features. While Microsoft released updates to address the vulnerability used in BlackLotus attacks, the fix is disabled by default and does not remove the attack vector. The NSA advises admins to manually secure devices by implementing additional hardening, applying security updates, configuring endpoint security software, and customizing UEFI Secure Boot.
Mirai Botnet Targets 22 Flaws in D-Link, Zyxel, and Netgear Devices
A Mirai botnet variant is targeting security vulnerabilities to hijack devices such as routers, WiFi dongles, thermal monitoring systems, access control systems, and solar power monitors from D-Link, Arris, Zyxel, TP-Link, Tenda, Netgear, and MediaTek, for use in distributed denial-of-service (DDoS) attacks. Signs of infection include overheating, configuration changes, frequent disconnections, and performance degradation. Users are advised to update firmware, use strong access credentials, and disable remote admin panels if unnecessary.
VULNERABILITIES
- CVE-2023-33933 - Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache Traffic Server.
- CVE-2023-36192 - Sngrep v1.6.0 was discovered to contain a heap buffer overflow via the function capture_ws_check_packet at /src/capture.c.
EXPLOITS
- CVE-2010-3972 - Microsoft IIS 7.5 (Windows 7) - FTPSVC Unauthorized Remote Denial of Service (PoC)
- CVE-2004-0937 - Multiple AntiVirus - “.zip” Detection Bypass
BREACHES
- Credit Card Data Breach: 2023-6-21 (bc7301 | 2815) - Credit card
- BreachForums/XSS: Canva Data Breach - (15,556 Records) | Email address and password
Tags: DIB, tlp:green