zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - July 4, 2023

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - July 4, 2023

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • ZeroFox Event Assessment: 2023 NATO Summit
  • Microsoft Denies 30 Million Account Breach Claimed by Anonymous Sudan
  • CISA Warns Users of Vulnerabilities in Samsung Devices and D-Link Router
  • Vulnerabilities: CVE-2023-32439 and CVE-2023-36664
  • Exploits: CVE-2017-5123 and CVE-2004-0940
  • Breaches: BreachForums: Rail Coach Factory Data Breach and Credit Card Data Breach: 2023-7-3

ZeroFox Event Assessment: 2023 NATO Summit – Vilnius, Lithuania (July 11-12, 2023)

The upcoming NATO summit is garnering significant attention over strained diplomatic relations and the possibility of disruptive activity, considering the event’s location near Russia and Sweden’s application for membership. While the threat of terrorism to the summit is currently considered low, there is a moderate risk of cyberattack or hacking operations by threat actors linked to Russian intelligence agencies. Politically-motivated hacktivism is also expected in the lead up to and during the summit.

Microsoft Denies 30 Million Account Breach Claimed by Anonymous Sudan

Microsoft has denied claims by hacktivist group "Anonymous Sudan" that it breached the company's servers and stole credentials for 30 million customer accounts. The hacktivists are offering to sell for USD 50,000 a database they allegedly exfiltrated after breaching Microsoft’s servers. Microsoft, however, states there is no evidence of any breach or compromise of customer data. Microsoft previously disclosed that Anonymous Sudan caused disruptions via “layer 7” DDoS attacks on Azure, Outlook, and OneDrive.

CISA Warns Users of Vulnerabilities in Samsung Devices and D-Link Router

The Cybersecurity and Infrastructure Security Agency (CISA) has added eight new vulnerabilities to its known exploited vulnerabilities catalog. Among them, six were patched security flaws affecting Samsung mobile devices, while the other two were D-Link router and access-point vulnerabilities exploited by a Mirai botnet variant. All of these bugs have been patched for several years. However, these vulnerabilities may still persist in various government and enterprise systems.

VULNERABILITIES

  • CVE-2023-32439 - A type confusion issue was addressed in iOS 16.5.1 and iPadOS 16.5.1, Safari 16.5.1, macOS Ventura 13.4.1, iOS 15.7.7 and iPadOS 15.7.7.
  • CVE-2023-36664 - Artifex Ghostscript through 10.01.2 mishandles permission validation for pipe devices.

EXPLOITS

  • CVE-2017-5123 - Linux Kernel 4.13 (Ubuntu 17.10) - waitid() SMEP/SMAP Privilege Escalation Exploit
  • CVE-2004-0940 - Apache 1.3.x mod_include - Local Buffer Overflow

BREACHES

Tags: DIB, tlp:green