ZeroFox Daily Intelligence Brief - July 3, 2023
|by Alpha Team

ZeroFox Daily Intelligence Brief - July 3, 2023
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- CISA Alert: DoS and DDoS Attacks Against Multiple Sectors
- Pay and Employee Benefit Data Of 2,000 Dublin Airport Staff Compromised
- Iranian Hackers Employ POWERSTAR Backdoor in Espionage Campaign
- Vulnerabilities: CVE-2023-36191 and CVE-2023-3420
- Exploits: CVE-2013-4212 and CVE-2017-6098
- Breach: Credit Card Data Breach: 2023-7-2 (bbff33 | 2692)
CISA Alert: DoS and DDoS Attacks Against Multiple Sectors
CISA has issued an alert relating to reports of targeted denial-of-service (DoS) and distributed denial-of-service (DDoS) attacks against various organizations. The alert recommended response, mitigation, and prevention measures and directed people towards detailed resources on understanding and dealing with such attacks. Last month, hacktivist group Anonymous Sudan was observed using “layer 7” (application layer) DDoS attacks in a widely reported campaign, in contrast to the more common DDoS attacks targeting layer 3 or 4 (network/transport).
Pay and Employee Benefit Data Of 2,000 Dublin Airport Staff Compromised
Dublin Airport Authority (DAA) has disclosed that the pay and benefit data of around 2,000 employees was compromised in a cyberattack on service provider Aon. DAA is one of about 100 companies affected by Clop ransomware group’s attack on file-transfer tool MOVEit. Ireland’s flag carrier Aer Lingus recently disclosed a data breach affecting nearly 5,000 current and former employees after payroll company Zellis reportedly suffered a similar attack.
Iranian Hackers Employ POWERSTAR Backdoor in Espionage Campaign
Charming Kitten, an Iranian state-backed group with ties to the Islamic Revolutionary Guard Corps (IRGC), has been linked to a spear-phishing campaign deploying an updated version of PowerShell backdoor POWERSTAR. Charming Kitten excels in social engineering and employs tailored fake personas on social-media platforms to build rapport before delivering malicious links. The group is also known as APT35, Cobalt Illusion, Mint Sandstorm, and Yellow Garuda, and has utilized other implants like PowerLess and BellaCiao.
VULNERABILITIES
- CVE-2023-36191: sqlite3 v3.40.1 was discovered to contain a segmentation violation at /sqlite3_aflpp/shell.c.
- CVE-2023-3420: Type Confusion in V8 in Google Chrome prior to 114.0.5735.198 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
EXPLOITS
- CVE-2013-4212 : Apache Roller - OGNL Injection
- CVE-2017-6098 : WordPress Plugin Mail Masta 1.0 - SQL Injection
BREACHES
- Credit Card Data Breach: 2023-7-2 (bbff33 | 2692) Credit card
Tags: DIB, tlp:green