ZeroFox Daily Intelligence Brief - July 7, 2023
|by Alpha Team

ZeroFox Daily Intelligence Brief - July 7, 2023
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- CISA and Partners Release Joint Cybersecurity Advisory on Newly Identified Truebot Malware Variants
- Critical Vulnerabilities Leave SolarView Devices in Solar Farms Exposed to Exploits
- JumpCloud Notifies Customers of Incident: Admin API Keys Invalidated as Security Measure
- INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS: ShadowHacker Leaks and BreachForum user TIA
- Vulnerabilities: CVE-2023-3439 and CVE-2023-21518
- Exploits: CVE-2004-2687
- Breaches: BreachForums/XSS: EDA Board Data Breach and BreachForums/XSS: Forbes Data Breach
CISA and Partners Release Joint Cybersecurity Advisory on Newly Identified Truebot Malware Variants
Cybersecurity officials from the United States and Canada have published a joint advisory highlighting the threat posed by the Truebot botnet (Silence Downloader), which threat actors use to collect and exfiltrate information from target victims. New variants of the malware allow criminals to gain initial access by exploiting a remote code execution bug (CVE-2022-31199) in the Netwrix Auditor application. The advisory recommends hunting and mitigation measures to deal with this threat.
Critical Vulnerabilities Leave SolarView Devices in Solar Farms Exposed to Exploits
Hundreds of SolarView devices in solar farms remain unpatched against two critical vulnerabilities. One of the bugs (CVE-2022-29303) enables remote execution of commands and has been actively exploited by the Mirai botnet. While the other vulnerability (CVE-2023-23333) is not known to be actively exploited, exploit code for it has been publicly available since February 2023.
JumpCloud Notifies Customers of Incident: Admin API Keys Invalidated as Security Measure
JumpCloud, a U.S.-based enterprise software firm that serves over 180,000 organizations, is notifying customers about an ongoing incident. As a precautionary measure, the company has invalidated existing admin API keys to protect clients. Affected organizations will need to generate new keys. The company is currently investigating the incident, and further details regarding the nature, scope, and impact are awaited.
INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- ShadowHacker Leaks: Telegram channel posts “freshest” data from Vietnam Airlines
- BreachForum user TIA Selling 27 million records from U.S.-based healthcare operator HCA Healthcare
VULNERABILITIES
- CVE-2023-3439 - A flaw was found in the MCTP protocol in the Linux kernel.
- CVE-2023-21518 - Improper access control vulnerability in SearchWidget prior to version 3.3 in China models allows untrusted applications to start arbitrary activity.
EXPLOITS
- CVE-2004-2687 - DistCC Daemon Command Execution
BREACHES
- BreachForums/XSS: EDA Board Data Breach (354,146 Records) Email address and password
- BreachForums/XSS: Forbes Data Breach (270,690 Records) Email address and password
Tags: DIB, tlp:green