ZeroFox Daily Intelligence Brief - June 29, 2023
|by Alpha Team

ZeroFox Daily Intelligence Brief - June 29, 2023
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- ZeroFox Intelligence Assessment: Key Personnel Security Risks of Fitness Trackers
- Auth-Bypass Vulnerability Discovered in Arcserve UDP
- U.S. Patent and Trademark Office Discloses Years-Long Data Leak
- Vulnerabilities: CVE-2023-2235 and CVE-2023-34652
- Exploits: CVE-2001-1013 and CVE-2019-0841
- Breaches: BreachForums/XSS: InstaForex Data Breach and Credit Card Data Breach: 2023-6-27
ZeroFox Intelligence Assessment: Key Personnel Security Risks of Fitness Trackers
Recent reports of exposure risks in fitness trackers (including in Strava’s heat map feature) serve as a reminder of the potential safety and security hazards these trackers can pose. In this brief, ZeroFox reviews the recent concerns and analyzes the overall potential risks for key personnel. While it is unlikely that key personnel will discontinue the use of fitness apps altogether, ZeroFox provides some recommendations to manage their exposure and limit the risks.
Auth-Bypass Vulnerability Discovered in Arcserve UDP
Data-protection vendor Arcserve fixed a high-severity security flaw (CVE-2023-26258) in its Unified Data Protection (UDP) backup software that allowed attackers to bypass authentication and gain admin privileges. The flaw, present in UDP versions 7.0 to 9.0, enabled attackers on the local network to access the admin interface and potentially destroy data through ransomware attacks. Arcserve released UDP 9.1 on June 27, 2023 to fix the problem.
U.S. Patent and Trademark Office Discloses Years-Long Data Leak
The U.S. patent and Trademark Office (USPTO) inadvertently exposed approximately 61,000 filers' private addresses in a data spill lasting several years. The agency notified affected applicants that their private domicile addresses were mistakenly included in public records from February 2020 to March 2023. USPTO temporarily blocked access to non-critical APIs and removed affected bulk data products until a permanent solution was implemented. The agency believes that the data has not been misused.
VULNERABILITIES
- CVE-2023-2235 - A use-after-free vulnerability in the Linux Kernel Performance Events system can be exploited to achieve local privilege escalation.
- CVE-2023-34652 - PHPgurukl Hostel Management System v.1.0 is vulnerable to Cross Site Scripting (XSS) via Add New Course.
EXPLOITS
- CVE-2001-1013 - RedHat Linux 7.0 Apache - Remote Username Enumeration
- CVE-2019-0841 - AppXSvc Hard Link Privilege Escalation
BREACHES
- BreachForums/XSS: InstaForex Data Breach - (263,576 Records) | Email address and password
- Credit Card Data Breach: 2023-6-27 - (c01d79 | 3522) | Credit card
Tags: DIB, tlp:green