zerofox logo
Advisories

Threat Intelligence Bulletin: 06/23/2023 - 06/29/2023

|by Alpha Team

banner image

ZeroFox Weekly Threat Bulletin: 06/23/2023 - 06/29/2023


ZeroFox Daily Intelligence:


ZeroFox Daily Intelligence Brief - June 29, 2023

Brief Highlights

  • ZeroFox Intelligence Assessment: Key Personnel Security Risks of Fitness Trackers
  • Auth-Bypass Vulnerability Discovered in Arcserve UDP
  • U.S. Patent and Trademark Office Discloses Years-Long Data Leak
  • Vulnerabilities: CVE-2023-2235 and CVE-2023-34652
  • Exploits: CVE-2001-1013 and CVE-2019-0841
  • Breaches: BreachForums/XSS: InstaForex Data Breach and Credit Card Data Breach: 2023-6-27

Report: https://zerofox.com/advisories/21032


ZeroFox Daily Intelligence Brief - June 28, 2023

Brief Highlights

  • EncroChat Takedown: Global Arrests and Exposure of Crime Networks
  • Researchers Find Technique to Unveil Secret Keys Through LED Power Analysis
  • Hacker Breaches Phone-Tracking App LetMeSpy
  • Vulnerabilities: CVE-2020-18414 and CVE-2023-3436
  • Exploits: CVE-2016-0099 and CVE-2015-2797
  • Breaches: Telegram: SunCloudPubl_max[.]7z Botnet Breach and BreachForums/XSS: Bendercraft Data Breach

Report: https://zerofox.com/advisories/21022


ZeroFox Daily Intelligence Brief - June 27, 2023

Brief Highlights

  • 19,000 Documents Exposed in Cyberattack on NYC DOE
  • Spike in Credential Stealing Attacks by Russian State-Affiliated Hackers
  • Anatsa Android Trojan Stealing Banking Information in Europe and America
  • Vulnerabilities: CVE-2023-3420, CVE-2023-34463, and CVE-2023-34924
  • Exploits: CVE-2019-9194, CVE-2010-3275, and CVE-2009-3843
  • Breaches: BreachForums/XSS: RuneScape Data Breach and BreachForums/XSS: Cannabis.com Data Breach

Report: https://zerofox.com/advisories/21010


ZeroFox Daily Intelligence Brief - June 26, 2023

Brief Highlights

  • American Airlines and Southwest Airlines Disclose Breach of Employee Data
  • Trojanized Super Mario Game Used to Install Windows Malware
  • Muddled Libra Targets BPO Sector with Advanced Social Engineering
  • Vulnerabilities: CVE-2023-27476 and CVE-2023-36663
  • Exploits: CVE-2006-4868, CVE-2018-13784 and CVE-2010-3275
  • Breaches: Credit Card Data Breach: 2023-6-24 (516422 | 3014) and BreachForums/XSS: Wealth Start Business Data Breach (205,785 Records)

Report: https://zerofox.com/advisories/20990


ZeroFox Daily Intelligence Brief - June 23, 2023

Brief Highlights

  • ZeroFox Cyber Threat Advisory: Ransomware & Digital Extortion Incidents Surging In Q2 2023
  • NSA Publishes BlackLotus Mitigation Guide
  • Mirai Botnet Targets 22 Flaws in D-Link, Zyxel, and Netgear Devices
  • Vulnerabilities: CVE-2023-33933 and CVE-2023-36192
  • Exploits: CVE-2010-3972 and CVE-2004-0937
  • Breaches: Credit Card Data Breach: 2023-6-21 (bc7301 | 2815) and BreachForums/XSS: Canva Data Breach (15,556 Records)

Report: https://zerofox.com/advisories/20973


Breach Disclosures:


Breach Disclosure: WonderPolls.com

An alleged data breach at WonderPolls.com – a U.S.-based community platform to hold polls and share opinions – exposed 72,367 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21012


Breach Disclosure: BleachAnime.org

An alleged data breach at BleachAnime.org – a U.S.-based anime role-playing and general discussion forum – exposed 107,714 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21011


Breach Disclosure: SpellForce

An alleged data breach at SpellForce – a Germany-based real-time strategy and role-playing series – exposed 110,119 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21009


Breach Disclosure: Canva

An alleged data breach at Canva – an Australia-based graphic design platform – exposed 15,556 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21008


Breach Disclosure: CEX.IO

An alleged data breach at CEX.IO – a U.K.-based media cryptocurrency exchange site – exposed 95,971 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21007


Breach Disclosure: Learn French by Podcast

An alleged data breach at Learn French by Podcast – a multilevel income generating site – exposed 120,739 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21006


Breach Disclosure: 500px

An alleged data breach at 500px – a Canada-based online photo-sharing platform – exposed 193,108 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21005


Breach Disclosure: Frostland

An alleged data breach at Frostland – a Russia-based online retail site – exposed 192,627 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21004


Breach Disclosure: Liancaijing

An alleged data breach at Liancaijing – a China-based blockchain news site – exposed 214,615 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21003


Breach Disclosure: Mycube

An alleged data breach at Mycube – a Russia-based virtual art gallery – exposed 207,150 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21002


Breach Disclosure: MarketDownload

An alleged data breach at MarketDownload – a U.S.-based media analytics site – exposed 104,368 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21001


Breach Disclosure: Linux Mint Forums

An alleged data breach at Linux Mint Forums – a U.S.-based bulletin board that discusses Linux Mint – exposed 69,707 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/20989


Breach Disclosure: ReWaSD_Additional Dataset

An alleged data breach at ReWASD – a U.S.-based mapping software used to reassign the keyboard, mouse keys, and controller buttons – exposed 103,254 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/20988


Breach Disclosure: Windhanenergy

An alleged data breach at Windhanenergy – a South Korea-based online baccarat (card gaming) site – exposed 57,310 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/20986


Breaking News:


Gas Stations Impacted by Cyberattack on Canadian Energy Giant Suncor

Some services at Petro-Canada gas stations have been disrupted following a cyberattack on parent company Suncor, one of the largest energy companies in North America. The company said it brought in third-party experts to aid investigation and response efforts, and noted that authorities have been notified.

See the full report here: https://www.securityweek.com/gas-stations-impacted-by-cyberattack-on-canadian-energy-giant-suncor/


NPM ecosystem at risk from “Manifest Confusion” attacks

The NPM (Node Package Manager) registry suffers from a security lapse called "manifest confusion," which undermines the trustworthiness of packages and makes it possible for attackers to hide malware in dependencies or perform malicious script execution during installation.

See the full report here: https://www.bleepingcomputer.com/news/security/npm-ecosystem-at-risk-from-manifest-confusion-attacks/


Linux version of Akira ransomware targets VMware ESXi servers

The Akira ransomware operation has been observed using a Linux encryptor to encrypt VMware ESXi virtual machines in double-extortion attacks against companies worldwide.

See the full report here: https://www.bleepingcomputer.com/news/security/linux-version-of-akira-ransomware-targets-vmware-esxi-servers/


Exploit released for new Arcserve UDP auth bypass vulnerability

Data protection vendor Arcserve has addressed a high-severity security flaw (tracked as CVE-2023-26258) in its Unified Data Protection (UDP) backup software that can let attackers bypass authentication and gain admin privileges.

See the full report here: https://www.bleepingcomputer.com/news/security/exploit-released-for-new-arcserve-udp-auth-bypass-vulnerability/


8Base Ransomware Spikes in Activity, Threatens U.S. and Brazilian Businesses

A ransomware threat called 8Base that has been operating under the radar for over a year has been attributed to a "massive spike in activity" in May and June 2023. The group utilizes encryption paired with 'name-and-shame' techniques to compel their victims to pay their ransoms.

See the full report here: https://thehackernews.com/2023/06/8base-ransomware-spikes-in-activity.html


CryptosLabs Scam Ring Targets French-Speaking Investors, Rakes in EUR 480 Million

Cybersecurity researchers have exposed the workings of a scam ring called CryptosLabs that is estimated to have made EUR 480 million in illegal profits by targeting users in French-speaking individuals in France, Belgium, and Luxembourg since April 2018.

See the full report here: https://thehackernews.com/2023/06/cryptoslabs-scam-ring-targets-french.html


New Electromagnetic Attacks on Drones Could Let Attackers Take Control

Drones that don't have any known security weaknesses could be the target of electromagnetic fault injection (EMFI) attacks, potentially enabling a threat actor to achieve arbitrary code execution and compromise their functionality and safety. Researchers found that it is possible to compromise the targeted device by injecting a specific EM glitch at the right time during a firmware update.

See the full report here: https://thehackernews.com/2023/06/alert-new-electromagnetic-attacks-on.html


US Patent and Trademark Office notifies filers of years-long data leak

The U.S. Patent and Trademark Office (USPTO) said in a notice sent to affected trademark applicants that it inadvertently exposed about 61,000 filers’ private addresses in a years-long data spill of public records between February 2020 and March 2023.

See the full report here: https://techcrunch.com/2023/06/28/uspto-trademark-data-api-leak/


Newly Uncovered ThirdEye Windows-Based Malware Steals Sensitive Data

A previously undocumented Windows-based information stealer called ThirdEye has been discovered in the wild with capabilities to harvest sensitive data from infected hosts. The researchers who made the discovery, said they found the malware in an executable that masqueraded as a PDF file with a Russian name "CMK Правила оформления больничных листов.pdf.exe," which translates to "CMK Rules for issuing sick leaves.pdf.exe."

See the full report here: https://thehackernews.com/2023/06/newly-uncovered-thirdeye-windows-based.html


Around USD 14,0000 in Singaporean Currency stolen in fake Singtel SMS phishing scams since June 2023

At least SGD 20,000 (USD 14,000) has been lost by victims of a phishing scam variant since June 2023, as stated by the Singapore Police Force (SPF). There have been at least 12 victims of this phishing scam variant, which involves a fake SMS purportedly sent by Singtel and embedded with a fraudulent URL link.

See the full report here: https://www.channelnewsasia.com/singapore/fake-singtel-sms-phishing-scams-20000-lost-3591696


LetMeSpy, a phone tracking app spying on thousands, says it was hacked

Hackers have stolen the messages, call logs and locations intercepted by a widely used phone monitoring app called LetMeSpy, according to the company that makes the spyware. The phone monitoring app, which is used to spy on thousands of people using Android phones around the world, said in a notice on its login page that on June 21 2023, “a security incident occurred involving obtaining unauthorized access to the data of website users​​.”

See the full report here: https://techcrunch.com/2023/06/27/letmespy-hacked-spyware-thousands/


New Ongoing Campaign Targets npm Ecosystem with Unique Execution Chain

Cybersecurity researchers have discovered a new ongoing campaign aimed at the npm ecosystem that leverages a unique execution chain to deliver an unknown payload to targeted systems. The campaign was first discovered on June 11, 2023.

See the full report here: https://thehackernews.com/2023/06/new-ongoing-campaign-targets-npm.html


Critical SQL Injection Flaws Expose Gentoo Soko to Remote Code Execution

Multiple SQL injection vulnerabilities have been disclosed in Gentoo Soko that could lead to remote code execution (RCE) on vulnerable systems. These SQL injections happened despite the use of an Object-Relational Mapping (ORM) library and prepared statements, The two issues, which were discovered in the search feature of Soko, have been collectively tracked as CVE-2023-28424 (CVSS score: 9.1). They were addressed within 24 hours of responsible disclosure on March 17, 2023.

See the full report here: https://thehackernews.com/2023/06/critical-sql-injection-flaws-expose.html


EncroChat takedown led to 6,500 arrests and USD 979 million seized

Europol announced that the takedown of the EncroChat encrypted mobile communications platform has led to the arrest of over 6,600 people and the seizure of USD 979 million in illicit funds. EncroChat phones ran a special, hardened version of Android that promised users unbreakable encryption, anonymity, and no traceability. These features were valued by criminals who wanted to communicate securely, so tens of thousands paid EUR 1,500 (USD 1,635) for a six-month subscription with global coverage and 24/7 support.

See the full report here: https://www.bleepingcomputer.com/news/security/encrochat-takedown-led-to-6-500-arrests-and-979-million-seized/


New Mockingjay process injection technique evades EDR detection

A new process injection technique named "Mockingjay" could allow threat actors to bypass EDR (Endpoint Detection and Response) and other security products to stealthily execute malicious code on compromised systems.

See the full report here: https://www.bleepingcomputer.com/news/security/new-mockingjay-process-injection-technique-evades-edr-detection/


Hundreds of devices found violating new CISA federal agency directive

Researchers have discovered hundreds of Internet-exposed devices on the networks of U.S. federal agencies that have to be secured according to a recently issued CISA Binding Operational Directive. An analysis of the attack surfaces of more than 50 Federal Civilian Executive Branch (FCEB) organizations led to the discovery of more than 13,000 individual hosts exposed to Internet access, distributed across over 100 systems linked to FCEB agencies.

See the full report here: https://www.bleepingcomputer.com/news/security/hundreds-of-devices-found-violating-new-cisa-federal-agency-directive/


Siemens Energy confirms data breach after MOVEit data-theft attack

Siemens Energy has confirmed that some of its data was stolen during the recent Clop ransomware data-theft camapign relies on a zero-day vulnerability in the MOVEit Transfer platform.

See the full report here: https://www.bleepingcomputer.com/news/security/siemens-energy-confirms-data-breach-after-moveit-data-theft-attack/


Microsoft Warns of Widescale Credential Stealing Attacks by Russian Hackers

Researchers detected a spike in credential-stealing attacks conducted by the Russian state-affiliated hacker group known as Midnight Blizzard. The intrusions, which made use of residential proxy services to obfuscate the source IP address of the attacks, target governments, IT service providers, NGOs, defense, and critical manufacturing sectors, the tech giant's threat intelligence team said. Midnight Blizzard, formerly known as Nobelium, is also tracked under the monikers APT29, Cozy Bear, Iron Hemlock, and The Dukes.

See the full report here: https://thehackernews.com/2023/06/microsoft-warns-of-widescale-credential.html


Japanese Cryptocurrency Exchange Falls Victim to JokerSpy macOS Backdoor Attack

An unknown cryptocurrency exchange located in Japan was the target of a new attack to deploy an Apple macOS backdoor called JokerSpy.

See the full report here: https://thehackernews.com/2023/06/japanese-cryptocurrency-exchange-falls.html


Researchers Find Way to Recover Cryptographic Keys by Analyzing LED Flickers

A group of academics discovered that it's possible to recover secret keys from a device by analyzing video footage of its power LED. Cryptographic computations performed by the CPU change the power consumption of the device which affects the brightness of the device's power LED.

See the full report here: https://thehackernews.com/2023/06/researchers-find-way-to-recover.html


New Fortinet's FortiNAC Vulnerability Exposes Networks to Code Execution Attacks

Fortinet has rolled out updates to address a critical security vulnerability impacting its FortiNAC network access control solution that could lead to the execution of arbitrary code. Tracked as CVE-2023-33299, the flaw is rated 9.6 out of 10 for severity on the CVSS scoring system. It has been described as a case of Java untrusted object deserialization.

See the full report here: https://thehackernews.com/2023/06/new-fortinets-fortinac-vulnerability.html


Suncor Energy cyberattack impacts Petro-Canada gas stations

Petro-Canada gas stations across Canada are impacted by technical problems preventing customers from paying with credit card or rewards points as its parent company, Suncor Energy, discloses they suffered a cyberattack. It expects transactions with customers and suppliers to be negatively impacted until the incident is resolved.

See the full report here: https://www.bleepingcomputer.com/news/security/suncor-energy-cyberattack-impacts-petro-canada-gas-stations/


Man charged in US for running "Monopoly" darknet drug market

A 33-year-old man from Serbia has been extradited from Austria to the United States to face charges of running a criminal darknet narcotics marketplace called "Monopoly Market." According to a U.S. Department of Justice announcement, the suspect has been charged with facilitating USD 18 million in illegal drug transactions through his website. The suspect was arrested in Austria in November 2022 and indicted on July 26, 2022, with the Department of Justice announcing the charges in June 2023.

See the full report here: https://www.bleepingcomputer.com/news/security/man-charged-in-us-for-running-monopoly-darknet-drug-market/


Hackers steal data of 45,000 New York City students in MOVEit breach

The New York City Department of Education (NYC DOE) says hackers stole documents containing the sensitive personal information of up to 45,000 students from its MOVEit Transfer server. The managed file transfer (MFT) software was used by NYC DOE to securely transfer data and documents internally and externally to various vendors, including special education service providers. NYC DOE patched the servers as soon as the developer disclosed info on the exploited vulnerability (CVE-2023-34362); however, the attackers were already abusing the bug in large-scale attacks as a zero-day before security updates were available.

See the full report here: https://www.bleepingcomputer.com/news/security/hackers-steal-data-of-45-000-new-york-city-students-in-moveit-breach/


New PindOS JavaScript dropper deploys Bumblebee, IcedID malware

Security researchers discovered a new malicious tool they named PindOS that delivers the Bumblebee and IcedID malware typically associated with ransomware attacks. PindOS is a simple JavaScript malware dropper that appears to be built specifically to fetch the next-stage payloads that deliver the attackers’ final payload.

See the full report here: https://www.bleepingcomputer.com/news/security/new-pindos-javascript-dropper-deploys-bumblebee-icedid-malware/


Anatsa Android trojan now steals banking info from users in US, UK

A new mobile malware campaign since March 2023 pushes the Android banking trojan "Anatsa" to online banking customers in the U.S., the U.K., Germany, Austria, and Switzerland. According to security researchers, who have been tracking the malicious activity, the attackers are distributing their malware via the Play Store, Android's official app store, and already have over 30,000 installations via this method alone.

See the full report here: https://www.bleepingcomputer.com/news/security/anatsa-android-trojan-now-steals-banking-info-from-users-in-us-uk/


Cybercrime Group 'Muddled Libra' Targets BPO Sector with Advanced Social Engineering

A threat actor known as Muddled Libra is targeting the business process outsourcing (BPO) industry with persistent attacks that leverage advanced social engineering ploys to gain initial access. The attack style defining Muddled Libra appeared on the cybersecurity radar in late 2022 with the release of the 0ktapus phishing kit, which offered a prebuilt hosting framework and bundled templates.

See the full report here: https://thehackernews.com/2023/06/cybercrime-group-muddled-libra-targets.html


Hackers targeted Fort Worth's cyber system over Texas' gender surgery stance, city officials say

The City of Fort Worth reportedly believes it was targeted by cybercriminals because of Texas' stance on sex reassignment surgery, officials stated. The city's Information Technology Solutions department learned about a post claiming that the city's website was hacked. They believe the hacker group SeigedSec, who allegedly posted about the incident on Telegram, was behind the attack.

See the full report here: https://www.foxnews.com/us/hackers-targeted-fort-worths-cyber-system-over-texas-gender-surgery-stance-city-officials-say


Commonwealth Bank outage leaves customers unable to access money, use CommBank online

The Commonwealth Bank has apologised to its customers after a major glitch left them unable to make purchases with their bank cards or access their accounts for hours. Customers received error messages when trying to use the NetBank online banking service and the CommBank mobile app.

See the full report here: https://www.abc.net.au/news/2023-06-26/commbank-commonwealth-bank-outage-under-investigation/102523142


Twitter Hacker Sentenced to 5 Years in Prison for USD 120,000 Crypto Scam

A U.K. citizen who took part in the massive July 2020 hack of Twitter has been sentenced to five years in prison in the U.S. The infamous Twitter breach allowed the defendant and his co-conspirators to obtain unauthorized access to backend tools used by Twitter, abusing them to hijack 130 popular accounts to perpetrate a crypto scam that netted them about USD 120,000 in illegal profits.

See the full report here: https://thehackernews.com/2023/06/twitter-hacker-sentenced-to-5-years-in.html


U.S. Cybersecurity Agency Adds 6 Flaws to Known Exploited Vulnerabilities Catalog

The U.S. Cybersecurity and Infrastructure Security Agency has added a batch of six flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. This comprises three vulnerabilities in Apple products (CVE-2023-32434, CVE-2023-32435, and CVE-2023-32439), two flaws in VMware (CVE-2023-20867 and CVE-2023-20887), and one shortcoming impacting Zyxel devices (CVE-2023-27992).

See the full report here: https://thehackernews.com/2023/06/us-cybersecurity-agency-adds-6-flaws-to.html


Chinese Hackers Using Never-Before-Seen Tactics for Critical Infrastructure Attacks

The newly discovered Chinese nation-state actor known as Volt Typhoon has been observed to be active in the wild since at least mid-2020, with the hacking crew linked to never-before-seen tradecraft to retain remote access to targets of interest. The group consistently employed ManageEngine Self-service Plus exploits to gain initial access, followed by custom web shells for persistent access, and living-off-the-land (LotL) techniques for lateral movement.

See the full report here: https://thehackernews.com/2023/06/chinese-hackers-using-never-before-seen.html


American Airlines, Southwest Airlines disclose data breaches affecting pilots

American Airlines and Southwest Airlines, two of the largest airlines in the world, disclosed data breaches caused by the hack of Pilot Credentials, a third-party vendor that manages multiple airlines' pilot applications and recruitment portals. Both airlines were informed of the Pilot Credentials incident on May 3 2023, which was limited solely to the systems of the third-party vendor, with no compromise or impact on the airlines' own networks or systems.

See the full report here: https://www.bleepingcomputer.com/news/security/american-airlines-southwest-airlines-disclose-data-breaches-affecting-pilots/


Grafana warns of critical auth bypass due to Azure AD integration

Grafana has released security fixes for multiple versions of its application, addressing a vulnerability that enables attackers to bypass authentication and take over any Grafana account that uses Azure Active Directory for authentication.

See the full report here: https://www.bleepingcomputer.com/news/security/grafana-warns-of-critical-auth-bypass-due-to-azure-ad-integration/


Trojanized Super Mario game used to install Windows malware

A trojanized installer for the popular Super Mario 3: Mario Forever game for Windows has been infecting unsuspecting players with multiple malware infections.

See the full report here: https://www.bleepingcomputer.com/news/security/trojanized-super-mario-game-used-to-install-windows-malware/


VMware fixes vCenter Server bugs allowing code execution, auth bypass

VMware has addressed multiple high-severity security flaws in vCenter Server, which can let attackers gain code execution and bypass authentication on unpatched systems. vCenter Server is the control center for VMware's vSphere suite and a server management solution that helps admins manage and monitor virtualized infrastructure. The security bugs were found in the DCE/RPC protocol implementation used by vCenter Server.

See the full report here: https://www.bleepingcomputer.com/news/security/vmware-fixes-vcenter-server-bugs-allowing-code-execution-auth-bypass/


Mirai botnet targets 22 flaws in D-Link, Zyxel, Netgear devices

A Mirai botnet variant is targeting security vulnerabilities to hijack devices such as routers, WiFi dongles, thermal monitoring systems, access control systems, and solar power monitors from D-Link, Arris, Zyxel, TP-Link, Tenda, Netgear, and MediaTek, for use in distributed denial-of-service (DDoS) attacks. Signs of infection include overheating, configuration changes, frequent disconnections, and performance degradation. Users are advised to update firmware, use strong access credentials, and disable remote admin panels if unnecessary.

See the full report here: https://www.bleepingcomputer.com/news/security/mirai-botnet-targets-22-flaws-in-d-link-zyxel-netgear-devices/


CISA orders govt agencies to patch bugs exploited by Russian hackers

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added six more security flaws to its known exploited vulnerabilities (KEV) list. Three of them were exploited by Russian APT28 cyberspies to hack into Roundcube email servers belonging to Ukrainian government organizations. The cyber-espionage group (also tracked as BlueDelta, Fancy Bear) was previously linked to Russia's General Staff Main Intelligence Directorate (GRU), the country's military intelligence service.

See the full report here: https://www.bleepingcomputer.com/news/security/cisa-orders-govt-agencies-to-patch-bugs-exploited-by-russian-hackers/


NSA shares tips on blocking BlackLotus UEFI malware attacks

The U.S. National Security Agency (NSA) released guidance on how to defend against BlackLotus UEFI bootkit malware attacks. BlackLotus has been circulating on hacking forums since October 2022, marketed as malware capable of evading detection, withstanding removal efforts, and neutralizing multiple Windows security features such as Defender, HVCI, and BitLocker.

See the full report here: https://www.bleepingcomputer.com/news/security/nsa-shares-tips-on-blocking-blacklotus-uefi-malware-attacks/


Microsoft Teams bug allows malware delivery from external accounts

Security researchers have found a simple way to deliver malware to an organization with Microsoft Teams, despite restrictions in the application for files from external sources. The attack works with Microsoft Teams running the default configuration, which permits communication with Microsoft Teams accounts outside the company, typically referred to as "external tenants."

See the full report here: https://www.bleepingcomputer.com/news/security/microsoft-teams-bug-allows-malware-delivery-from-external-accounts/


Critical Flaw Found in WordPress Plugin for WooCommerce Used by 30,000 Websites

A critical security flaw has been disclosed in the WordPress "Abandoned Cart Lite for WooCommerce" plugin that's installed on more than 30,000 websites. This vulnerability makes it possible for an attacker to gain access to the accounts of users who have abandoned their carts, who are typically customers but can extend to other high-level users when the right conditions are met. Tracked as CVE-2023-2986, the shortcoming has been rated 9.8 out of 10 for severity on the CVSS scoring system. It impacts all versions of the plugin, including and prior to versions 5.14.2.

See the full report here: https://thehackernews.com/2023/06/critical-flaw-found-in-wordpress-plugin.html


Alert: Million of GitHub Repositories Likely Vulnerable to RepoJacking Attack

Millions of software repositories on GitHub are likely vulnerable to an attack called RepoJacking, a new study has revealed. The supply chain vulnerability, also known as dependency repository hijacking, is a class of attacks that makes it possible to take over retired organization or user names and publish trojanized versions of repositories to run malicious code.

See the full report here: https://thehackernews.com/2023/06/alert-million-of-github-repositories.html


MULTI#STORM Campaign Targets India and U.S. with Remote Access Trojans

A new phishing campaign codenamed MULTI#STORM has set its sights on India and the U.S. by leveraging JavaScript files to deliver remote access trojans on compromised systems. The attack chain ends with the victim machine infected with multiple unique RAT (remote access trojan) malware instances, such as Warzone RAT and Quasar RAT.

See the full report here: https://thehackernews.com/2023/06/multistorm-campaign-targets-india-and.html


New Cryptocurrency Mining Campaign Targets Linux Systems and IoT Devices

Internet-facing Linux systems and Internet of Things (IoT) devices are being targeted as part of a new campaign designed to illicitly mine cryptocurrency. The threat actors behind the attack use a backdoor that deploys a wide array of tools and components such as rootkits and an IRC bot to steal device resources for mining operations. The backdoor also installs a patched version of OpenSSH on affected devices, allowing threat actors to hijack SSH credentials, move laterally within the network, and conceal malicious SSH connections.

See the full report here: https://thehackernews.com/2023/06/new-cryptocurrency-mining-campaign.html


LockBit Developing Ransomware for Apple M1 Chips, Embedded Systems

The LockBit gang is building ransomware for new architectures, forgoing Windows and potentially posing entirely new problems for their victims along the way. In a blog published on June 22 2023, cybersecurity researchers describe having "stumbled on" a .ZIP file with a trove of LockBit malware samples inside. The samples appear to have derived from LockBit's previous encryptor variations targeting VMWare ESXi hypervisors.

See the full report here: https://www.darkreading.com/vulnerabilities-threats/lockbit-ransomware-apple-m1-chips-embedded-systems


Azure AD "Log in With Microsoft" Authentication Bypass Affects Thousands

Organizations that have implemented the "Log in with Microsoft" feature in their Microsoft Azure Active Directory environments could potentially be vulnerable to an authentication bypass that opens the door to online and cloud account takeovers.

See the full report here: https://www.darkreading.com/cloud/azure-ad-log-in-with-microsoft-authentication-bypass-affects-thousands


USB Drives Spread Spyware as China's Mustang Panda APT Goes Global

Espionage malware that spreads by self-propagating through infected USB drives has re-surfaced recently in an incident at a European healthcare institution. The campaign is the work of the Chinese-state-sponsored APT that tracks as "Camaro Dragon," but which is probably better known as Mustang Panda (aka Luminous Moth and Bronze President).

See the full report here: https://www.darkreading.com/threat-intelligence/usb-drives-spyware-china-mustang-panda-apt-global


ZeroFox Intelligence Reports:


ZeroFox Intelligence Brief - Key Personnel Security Risks of Fitness Trackers

In this Intelligence Brief, ZeroFox researchers review the recent concerns around fitness trackers, as well as overall potential risks and recommendations for limiting risk and exposure for key personnel.

Report: https://zerofox.com/advisories/21031


Tags: tlp:clear,  all industries,  global