Threat Intelligence Bulletin: 06/30/2023 - 07/06/2023
|by Alpha Team

ZeroFox Weekly Threat Bulletin: 06/30/2023 - 07/06/2023
ZeroFox Daily Intelligence:
ZeroFox Daily Intelligence Brief - July 6, 2023
Brief Highlights
- Suspected Key Figure of Notorious Cybercrime Group OPERA1ER Arrested
- Teams Exploit Tool Released by Member of U.S. Navy's Red Team
- Japanese Port of Nagoya’s Operations Affected by Ransomware Attack
- Data broker / initial-access broker / hacktivist group: Türk Hack Team and Solntsepek
- Vulnerabilities: CVE-2023-2156 and CVE-2022-41854
- Exploits: CVE-2007-3898 and CVE-2018-19246
- Breaches: Credit Card Data Breach: Credit Card Data Breach: 2023-7-4 and BreachForums/XSS: Coinmama Data Breach
Report: https://zerofox.com/advisories/21121
ZeroFox Daily Intelligence Brief - July 5, 2023
Brief Highlights
- Sweden Warns Companies Against Google Analytics Use
- AIIMS Ransomware Attack Prompts Indian Government to Formulate National Cybersecurity Response Framework (NCRF)
- Mexican Cybercriminal Neo_Net Behind Global Android Malware Campaign Targeting Banks
- Vulnerabilities: CVE-2022-4297 and CVE-2023-24078
- Exploits: CVE-2019-1405
- Breaches: BreachForums/XSS: xkcd Data Breach and Coachella Data Breach
Report: https://zerofox.com/advisories/21098
ZeroFox Daily Intelligence Brief - July 4, 2023
Brief Highlights
- ZeroFox Event Assessment: 2023 NATO Summit
- Microsoft Denies 30 Million Account Breach Claimed by Anonymous Sudan
- CISA Warns Users of Vulnerabilities in Samsung Devices and D-Link Router
- Vulnerabilities: CVE-2023-32439 and CVE-2023-36664
- Exploits: CVE-2017-5123 and CVE-2004-0940
- Breaches: BreachForums: Rail Coach Factory Data Breach and Credit Card Data Breach: 2023-7-3
Report: https://zerofox.com/advisories/21083
ZeroFox Daily Intelligence Brief - July 3, 2023
Brief Highlights
- CISA Alert: DoS and DDoS Attacks Against Multiple Sectors
- Pay and Employee Benefit Data Of 2,000 Dublin Airport Staff Compromised
- Iranian Hackers Employ POWERSTAR Backdoor in Espionage Campaign
- Vulnerabilities: CVE-2023-36191 and CVE-2023-3420
- Exploits: CVE-2013-4212 and CVE-2017-6098
- Breach: Credit Card Data Breach: 2023-7-2 (bbff33 | 2692)
Report: https://zerofox.com/advisories/21061
ZeroFox Daily Intelligence Brief - June 30, 2023
Brief Highlights
- Best Practices to Secure Cloud Continuous Integration / Continuous Delivery (CI/CD) Environments
- MITRE Publishes List of Top 25 Software Weaknesses for 2023
- Clop's MOVEit Campaign Affects Over 15 Million Individuals in Nearly 150 Orgs
- Vulnerabilities: CVE-2023-36607 and CVE-2023-3465
- Exploits: CVE-2018-1133 and CVE-2013-4011
- Breaches: BreachForums/Amunet: American Academy of Psychiatry and the Law Data Breach and Credit Card Data Breach: 2023-6-28
Report: https://zerofox.com/advisories/21043
Breach Disclosures:
Breach Disclosure: Cannabis.com
An alleged data breach at Cannabis.com – a U.S.-based cannabis selling site – exposed 194,308 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21122
Breach Disclosure: RGB HiFi & Video Data
An alleged data breach at RGB HiFi & Video Data – a U.K.-based consumer electronic and computer retailer– exposed 156,504 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21120
Breach Disclosure: Novolux Lighting
An alleged data breach at Novolux Lighting – a Spain-based manufacturer of lighting application – exposed 6,978 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21119
Breach Disclosure: Tibia.net.pl
An alleged data breach at Tibia.net.pl – a Poland-based forum involved in discussions related to opentibia – exposed 138,946 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21118
Breach Disclosure: Sumotorrent
An alleged data breach at Sumotorrent – a U.S.-based general torrent site with content – exposed 249,985 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21117
Breach Disclosure: Redbox
An alleged data breach at Redbox – a U.S.-based movie and video game rental company – exposed 250,450 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21116
Breach Disclosure: Coachella
An alleged data breach at Coachella – a U.S.-based organization that hosts music and arts festival – exposed 227,805 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21115
Breach Disclosure: Acne
An alleged data breach at Acne – a U.S.-based site that reviews information about acne and its treatments – exposed 237,987 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21114
Breach Disclosure: xkcd
An alleged data breach at xkcd – a U.S.-based bulletin board – exposed 202,321 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21113
Breach Disclosure: Playforceone
An alleged data breach at Playforceone – a U.S.-based gaming venue platform – exposed 211,259 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21112
Breach Disclosure: 1Mil_Comcast Combolist
A combolist breach package titled “1Mil_Comcast Combolist" exposed 999,855 email addresses and plain-text passwords, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21111
Breach Disclosure: Coinmama
An alleged data breach at Coinmama – a U.S.-based cryptocurrency exchange platform – exposed 212,170 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21110
Breach Disclosure: Whitepages
An alleged data breach at Whitepages – a U.S.-based company that provides online directory services, fraud screening, and identity verification – exposed 142,191 email addresses and plain-text passwords, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21109
Breach Disclosure: Rail Coach Factory
An alleged data breach at Rail Coach Factory – a India-based rail coach manufacturer – exposed 7,579 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21108
Breach Disclosure: Go 4 Ngineeringjobs
An alleged data breach at Go 4 Ngineeringjobs – an online platform for job seekers – exposed 171,959 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21107
Breach Disclosure: RuneScape
An alleged data breach at RuneScape – a U.K.-based site that sells merchandise, T-shirts, and hoodies – exposed 78,749 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21106
Breach Disclosure: Bendercraft
An alleged data breach at Bendercraft – a Russia-based Minecraft discussion site – exposed 158,181 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21105
Breach Disclosure: MyMiniGames
An alleged data breach at MyMiniGames – a U.S.-based online gaming portal – exposed 44,787 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21104
Breach Disclosure: Facepunch
An alleged data breach at Facepunch – aa U.K.-based video game developer and publisher – exposed 280,317 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21090
Breach Disclosure: Ias100
An alleged data breach at Ias100– an India-based coaching institute – exposed 152,378 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21089
Breach Disclosure: Seochat
An alleged data breach at Seochat – a U.S.-based platform for learning and sharing knowledge – exposed 252,566 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21088
Breach Disclosure: InstaForex
An alleged data breach at InstaForex – a Russia-based developer of forex trading platform – exposed 263,576 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21087
Breach Disclosure: Bizbilla
An alleged data breach at Bizbilla – an India-based B2B e-commerce marketplace – exposed 174,332 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21086
Breach Disclosure: HMPS & Associates
An alleged data breach at HMPS & Associates – an India-based chartered accountant firm – exposed 125,999 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21085
Breach Disclosure: Wanadoo
An alleged data breach at Wanadoo – a U.S.-based email service provider – exposed 176,449 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21084
Breach Disclosure: Game Ogre
An alleged data breach at Game Ogre – a U.S.-based a free online game community with a forum and blog – exposed 58,796 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21082
Breach Disclosure: Epic Games
An alleged data breach at Epic Games – a U.S.-based company that provides the manufacturing and retailing of video games and software for multiple devices and platforms – exposed 83,063 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21081
Breach Disclosure: Zacks Investment Research
An alleged data breach at Zacks Investment Research – a U.S.-based company that produces independent research and investment content – exposed 8,874,860 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21080
Breach Disclosure: Gfycat
An alleged data breach at Gfycat – a U.S.-based user-generated short video hosting company – exposed 147,857 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21079
Breach Disclosure: American Academy of Psychiatry and the Law
An alleged data breach at American Academy of Psychiatry and the Law – a U.S.-based professional organization in the field of forensic psychiatry – exposed 3,001 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21077
Breach Disclosure: Eletroplus
An alleged data breach at Eletroplus– a Brazil-based information technology company – exposed 74,256 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21066
Breach Disclosure: Gameshot
An alleged data breach at Gameshot – a U.S.-based video games consoles and accessories retailer – exposed 300,089 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21065
Breach Disclosure: Wealth Start Business
An alleged data breach at Wealth Start Business – a multilevel income generating site – exposed 205,785 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21064
Breach Disclosure: Keybe
An alleged data breach at Keybe – a U.S.-based AI-powered sales platform – exposed 1,044,657 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21063
Breach Disclosure: HackGive
An alleged data breach at HackGive – a U.S.-based premium account generator – exposed 36,755 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21062
Breach Disclosure: ManaCube
An alleged data breach at ManaCube – a U.K.-based multiplayer network for Minecraft java edition – exposed 59,880 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21060
Breach Disclosure: Shotbow
An alleged data breach at Shotbow – U.S.-based a multiplayer server for Minecraft – exposed 57,612 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21059
Breach Disclosure: Clasificados Efectivos
An alleged data breach at Clasificados Efectivos – a Colombia-based classifieds site – exposed 48,820 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21058
Breach Disclosure: Aquatic Community
An alleged data breach at Aquatic Community – a U.S.-based meet and great community – exposed 51,014 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21057
Breach Disclosure: Dueling Network
An alleged data breach at Dueling Network – a U.S.-based online gaming site – exposed 99,979 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21042
Breaking News:
Japan’s largest port temporarily stopped operations after ransomware attack
The Port of Nagoya, the largest and busiest port in Japan, had been targeted in a ransomware attack that currently impacted its operations, resulting in a halt for 2 days. Since then, the port services have been restored.
See the full report here: https://www.bleepingcomputer.com/news/security/japans-largest-port-stops-operations-after-ransomware-attack/
Police arrest suspect linked to notorius OPERA1ER cybercrime gang
Law enforcement has detained a suspect believed to be a key member of the OPERA1ER cybercrime group, which has targeted mobile banking services and financial institutions in malware, phishing, and Business Email Compromise (BEC) campaigns.
See the full report here: https://www.bleepingcomputer.com/news/security/police-arrest-suspect-linked-to-notorius-opera1er-cybercrime-gang/
New tool exploits Microsoft Teams bug to send malware to users
A member of U.S. Navy's red team has published a tool called TeamsPhisher that leverages an unresolved security issue in Microsoft Teams to bypass restrictions for incoming files from users outside of a targeted organization, the so-called external tenants.
See the full report here: https://www.bleepingcomputer.com/news/security/new-tool-exploits-microsoft-teams-bug-to-send-malware-to-users/
RedEnergy Stealer-as-a-Ransomware Threat Targeting Energy and Telecom Sectors
A sophisticated stealer-as-a-ransomware threat dubbed RedEnergy has been spotted in the wild targeting energy utilities, oil, gas, telecom, and machinery sectors in Brazil and the Philippines through their LinkedIn pages.
See the full report here: https://thehackernews.com/2023/07/redenergy-stealer-as-ransomware-threat.html
Silentbob Campaign: Cloud-Native Environments Under Attack
Cybersecurity researchers have unearthed an attack infrastructure that's being used as part of a "potentially massive campaign" against cloud-native environments. This infrastructure is in early stages of testing and deployment, and is mainly consistent of an aggressive cloud worm, designed to deploy on exposed JupyterLab and Docker APIs in order to deploy Tsunami malware, cloud credentials hijack, resource hijack, and further infestation of the worm.
See the full report here: https://thehackernews.com/2023/07/silentbob-campaign-cloud-native.html
New StackRot Linux kernel flaw allows privilege escalation
Technical information has emerged for a serious vulnerability affecting multiple Linux kernel versions that could be triggered with "minimal capabilities." The security issue is being referred to as StackRot (CVE-2023-3269) and can be used to compromise the kernel and elevate privileges. A patch is available for the affected stable kernels since July 1 2023, and full details about the issue along with a complete exploit code are expected by the end of the month.
See the full report here: https://www.bleepingcomputer.com/news/security/new-stackrot-linux-kernel-flaw-allows-privilege-escalation/
Over 130,000 solar energy monitoring systems exposed online
Security researchers are warning that tens of thousands of photovoltaic (PV) monitoring and diagnostic systems are reachable over the public web, making them potential targets for hackers. These systems are used for remote performance monitoring, troubleshooting, system optimization, and other functions to allow remote management of renewable energy production units.
See the full report here: https://www.bleepingcomputer.com/news/security/over-130-000-solar-energy-monitoring-systems-exposed-online/
JumpCloud resets admin API keys amid "ongoing incident"
JumpCloud, a US-based enterprise software firm is notifying several customers of an "ongoing incident." As a caution, the company has invalidated existing admin API keys to protect its customer organizations. Affected organizations will need to generate new keys.
See the full report here: https://www.bleepingcomputer.com/news/security/jumpcloud-resets-admin-api-keys-amid-ongoing-incident/
Cisco warns of bug that lets attackers break traffic encryption
Cisco warned customers of a high-severity vulnerability impacting some data center switch models and allowing attackers to tamper with encrypted traffic. Tracked as CVE-2023-20185, the flaw was found during internal security testing in the ACI Multi-Site CloudSec encryption feature of data center Cisco Nexus 9000 Series Fabric Switches.
See the full report here: https://www.bleepingcomputer.com/news/security/cisco-warns-of-bug-that-lets-attackers-break-traffic-encryption/
AIIMS ransomware attack led to new SOP on cyber breaches: Ex-cybersecurity chief
The ransomware attack on the All-India Institute of Medical Sciences prompted the government to formulate a national cybersecurity response framework (NCRF). The cybersecurity strategy of the government, which has been in the works since 2020, proposes several mitigation measures to combat data breaches.
See the full report here: https://www.hindustantimes.com/india-news/aiims-ransomware-attack-led-to-new-sop-on-cyber-breaches-ex-cybersecurity-chief-pant-101688321198625.html
Mexico-Based Hacker Targets Global Banks with Android Malware
An e-crime actor of Mexican provenance has been linked to an Android mobile malware campaign targeting financial institutions globally, but with a specific focus on Spanish and Chilean banks, from June 2021 to April 2023. The activity is being attributed to an actor codenamed Neo_Net.
See the full report here: https://thehackernews.com/2023/07/mexico-based-hacker-targets-global.html
DDoSia Attack Tool Evolves with Encryption, Targeting Multiple Sectors
The threat actors behind the DDoSia attack tool have come up with a new version that incorporates a new mechanism to retrieve the list of targets to be bombarded with junk HTTP requests in an attempt to bring them down. The updated variant, written in Golang, "implements an additional security mechanism to conceal the list of targets, which is transmitted from the [command-and-control] to the users,.
See the full report here: https://thehackernews.com/2023/07/ddosia-attack-tool-evolves-with.html
Swedish Data Protection Authority Warns Companies Against Google Analytics Use
The Swedish data protection watchdog has warned companies against using Google Analytics due to risks posed by U.S. government surveillance, following similar moves by Austria, France, and Italy. The development comes in the aftermath of an audit initiated by the Swedish Authority for Privacy Protection (IMY) against four companies CDON, Coop, Dagens Industri, and Tele2.
See the full report here: https://thehackernews.com/2023/07/swedish-data-protection-authority-warns.html
Node.js Users Beware: Manifest Confusion Attack Opens Door to Malware
The npm registry for the Node.js JavaScript runtime environment is susceptible to what's called a manifest confusion attack that could potentially allow threat actors to conceal malware in project dependencies or perform arbitrary script execution during installation.
See the full report here: https://thehackernews.com/2023/07/nodejs-users-beware-manifest-confusion.html
Evasive Meduza Stealer Targets 19 Password Managers and 76 Crypto Wallets
In yet another sign of a lucrative crimeware-as-a-service (CaaS) ecosystem, cybersecurity researchers have discovered a new Windows-based information stealer called Meduza Stealer that's actively being developed by its author to evade detection by software solutions.
See the full report here: https://thehackernews.com/2023/07/evasive-meduza-stealer-targets-19.html
Mexico-Based Hacker Targets Global Banks with Android Malware
An e-crime actor of Mexican provenance has been linked to an Android mobile malware campaign targeting financial institutions globally, but with a specific focus on Spanish and Chilean banks, from June 2021 to April 2023.
See the full report here: https://thehackernews.com/2023/07/mexico-based-hacker-targets-global.html
300,000+ Fortinet firewalls vulnerable to critical FortiOS RCE bug
Hundreds of thousands of FortiGate firewalls are vulnerable to a critical security issue identified as CVE-2023-27997, almost a month after Fortinet released an update that addresses the problem.
See the full report here: https://www.bleepingcomputer.com/news/security/300-000-plus-fortinet-firewalls-vulnerable-to-critical-fortios-rce-bug/
Hackers target European government entities in SmugX campaign
A phishing campaign that security researchers named SmugX and attributed to a Chinese threat actor has been targeting embassies and foreign affairs ministries in the UK, France, Sweden, Ukraine, Czech, Hungary, and Slovakia, since December 2022.
See the full report here: https://www.bleepingcomputer.com/news/security/hackers-target-european-government-entities-in-smugx-campaign/
Microsoft denies data breach, theft of 30 million customer accounts
Microsoft has denied the claims of the so-called hacktivists “Anonymous Sudan” that it had breached the company's servers and stole credentials for 30 million customer accounts. Anonymous Sudan offered to sell this database to interested parties for USD 50,000 and urged interested buyers to engage in contact with their Telegram bot to arrange the purchase of the data.
See the full report here: https://www.bleepingcomputer.com/news/security/microsoft-denies-data-breach-theft-of-30-million-customer-accounts/
CISA warns Samsung handset bugs and D-Link router flaws are being exploited in wild
The Cybersecurity and Infrastructure Security Agency (CISA) added eight new vulnerabilities to its known exploited vulnerabilities (KEV) catalog, of which six were now-patched security flaws that impacted Samsung mobile devices and the two others were D-Link router and access point vulnerabilities, also with available patches, exploited by a variant of a Mirai botnet.
See the full report here: https://www.scmagazine.com/news/vulnerability-management/cisa-android-d-link-flaws-exploited-iwild
Attacker pockets USD 10 million from Poly Network security attack
An unknown attacker managed to swap out over USD 10 million worth of ether (ETH) in gains following a security attack on Poly Network. While hackers have minted billions in various tokens, the amount they may be able to cash out is likely far less.
See the full report here: https://www.theblock.co/post/237452/attacker-pockets-10-million-from-poly-network-security-attack-beosin
Pay And Benefits Information Of 2,000 Dublin Airport Staff Compromised
Almost 2,000 employees' pay and benefits information at Dublin airport's operator, DAA, was compromised in a recent cyber attack on Aon, a professional service provider.
See the full report here: https://simpleflying.com/dublin-airport-staff-information-compromised-july-2023/
TSMC denies LockBit hack as ransomware gang demands USD 70 million
Chipmaking giant TSMC (Taiwan Semiconductor Manufacturing Company) denied being hacked after the LockBit ransomware gang demanded a ransom of USD 70 million.
See the full report here: https://www.bleepingcomputer.com/news/security/tsmc-denies-lockbit-hack-as-ransomware-gang-demands-70-million/
CISA issues DDoS warning after attacks hit multiple US orgs
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned of ongoing distributed denial-of-service (DDoS) attacks after U.S. organizations across multiple industry sectors were hit. All U.S. orgs were advised to take proactive measures to ensure that their security teams are ready to thwart or mitigate the effects of such attacks.
See the full report here: https://www.bleepingcomputer.com/news/security/cisa-issues-ddos-warning-after-attacks-hit-multiple-us-orgs/
Hackers exploit zero-day in Ultimate Member WordPress plugin with 200K installs
Hackers exploit a zero-day privilege escalation vulnerability in the "Ultimate Member" WordPress plugin to compromise websites by bypassing security measures and registering rogue administrator accounts. The exploited flaw, tracked as CVE-2023-3460 and having a CVSS v3.1 score of 9.8 ("critical"), impacts all versions of the Ultimate Member plugin, including its latest version, v2.6.6.
See the full report here: https://www.bleepingcomputer.com/news/security/hackers-exploit-zero-day-in-ultimate-member-wordpress-plugin-with-200k-installs/
Cybercriminals Hijacking Vulnerable SSH Servers in New Proxyjacking Campaign
An active financially motivated campaign is targeting vulnerable SSH servers to covertly ensnare them into a proxy network through a malicious script. The stealthy script further actively searches for and terminates competing instances running bandwidth-sharing programs, before launching Docker services that share the victim's bandwidth for profits.
See the full report here: https://thehackernews.com/2023/06/cybercriminals-hijacking-vulnerable-ssh.html
New RustBucket Malware Variant Targeting macOS Users
Researchers have pulled back the curtain on an updated version of an Apple macOS malware called RustBucket that comes with improved capabilities to establish persistence and avoid detection by security software.
See the full report here: https://thehackernews.com/2023/07/beware-new-rustbucket-malware-variant.html
Hackers Exploiting Unpatched WordPress Plugin Flaw to Create Secret Admin Accounts
As many as 200,000 WordPress websites are at risk of ongoing attacks exploiting a critical unpatched security vulnerability in the Ultimate Member plugin. The flaw, tracked as CVE-2023-3460 (CVSS score: 9.8), impacts all versions of the Ultimate Member plugin, including the latest version (2.6.6) that was released on June 29, 2023.
See the full report here: https://thehackernews.com/2023/07/unpatched-wordpress-plugin-flaw-could.html
BlackCat ransomware pushes Cobalt Strike via WinSCP search ads
The BlackCat ransomware group (aka ALPHV) is running malvertizing campaigns to lure people into fake pages that mimic the official website of the WinSCP file-transfer application for Windows but instead push malware-ridden installers.
See the full report here: https://www.bleepingcomputer.com/news/security/blackcat-ransomware-pushes-cobalt-strike-via-winscp-search-ads/
French, UK watchdogs say hackers-for-hire are targeting law firms
Mercenary hackers increasingly are targeting law firms in a bid to steal data that could tip the balance in legal cases, French and British authorities say, echoing an investigation that uncovered the phenomenon. The cyber watchdog agencies of France and the United Kingdom cataloged an array of digital challenges faced by law firms, including threats posed by ransomware and malicious insiders.
See the full report here: https://www.reuters.com/world/europe/french-uk-watchdogs-say-hackers-for-hire-are-targeting-law-firms-2023-06-28/
Hackers attack Russian satellite telecom provider, claim affiliation with Wagner Group
Unidentified hackers claimed to have targeted Dozor, a satellite telecommunications provider that services power lines, oil fields, Russian military units and the Federal Security Service (FSB), among others, according to a message posted to Telegram.
See the full report here: https://cyberscoop.com/russian-satellite-hack-wagner-group/
Fluhorse: Flutter-Based Android Malware Targets Credit Cards and 2FA Codes
Cybersecurity researchers have shared the inner workings of an Android malware family called Fluhorse. The malware represents a significant shift as it incorporates the malicious components directly within the Flutter code.
See the full report here: https://thehackernews.com/2023/06/fluhorse-flutter-based-android-malware.html
From MuddyC3 to PhonyC2: Iran's MuddyWater Evolves with a New Cyber Weapon
The Iranian state-sponsored group dubbed MuddyWater has been attributed to a previously unseen command-and-control (C2) framework called PhonyC2 that's been put to use by the actor since 2021. Evidence shows that the custom made, actively developed framework has been leveraged in the February 2023 attack on Technion, an Israeli research institute.
See the full report here: https://thehackernews.com/2023/06/from-muddyc3-to-phonyc2-irans.html
Cybercriminals Hijacking Vulnerable SSH Servers in New Proxyjacking Campaign
An active financially motivated campaign is targeting vulnerable SSH servers to covertly ensnare them into a proxy network. This is an active campaign in which the attacker leverages SSH for remote access, running malicious scripts that stealthily enlist victim servers into a peer-to-peer (P2P) proxy network, such as Peer2Profit or Honeygain.
See the full report here: https://thehackernews.com/2023/06/cybercriminals-hijacking-vulnerable-ssh.html
Pro-Russia DDoSia hacktivist project sees 2,400% membership increase
The pro-Russia crowdsourced DDoS (distributed denial of service) project, "DDoSia," has seen a massive 2,400% growth in less than a year, with over ten thousand people helping conduct attacks on Western organizations. The project was launched by a pro-Russian hacktivist group known as "NoName057(16)" and quickly reached to about 400 active members and 13,000 users on its Telegram channel.
See the full report here: https://www.bleepingcomputer.com/news/security/pro-russia-ddosia-hacktivist-project-sees-2-400-percent-membership-increase/
MITRE releases new list of top 25 most dangerous software bugs
MITRE shared the 2023 list of the top 25 most dangerous weaknesses plaguing software during the previous two years. Software weaknesses encompass a wide range of issues, including flaws, bugs, vulnerabilities, and errors in software solutions' code, architecture, implementation, or design.
See the full report here: https://www.bleepingcomputer.com/news/security/mitre-releases-new-list-of-top-25-most-dangerous-software-bugs/
New EarlyRAT malware linked to North Korean Andariel hacking group
Security analysts have discovered a previously undocumented remote access trojan (RAT) named "EarlyRAT," used by Andariel, a sub-group of the Lazarus North Korean state-sponsored hacking group. Andariel (aka Stonefly) is believed to be part of the Lazarus hacking group known for employing the DTrack modular backdoor to collect information from compromised systems, such as browsing history, typed data (keylogging), screenshots, running processes, and more.
See the full report here: https://www.bleepingcomputer.com/news/security/new-earlyrat-malware-linked-to-north-korean-andariel-hacking-group/
K-12 schools are revisiting their cyber strategies after year of ransomware attacks
School IT leaders are revisiting their cybersecurity strategies after trying and sometimes failing to fend off a wave of ransomware attacks over the past year. Across school districts, revised cybersecurity strategies include new employee trainings on best security practices, a review of what applications teachers and students can use, and requirements for multifactor authentication to log in to their accounts.
See the full report here: https://www.axios.com/2023/06/27/school-cyber-teams-hacking-ransomware
ZeroFox Intelligence Reports:
ZeroFox Intelligence Event Assessment - NATO Summit 2023
In this assessment, ZeroFox Intelligence researchers provide an analysis of the upcoming NATO Summit in Vilnius, Lithuania, on July 11-12, 2023. Given the event’s location near Russia and Sweden’s application for membership, the event is garnering significant attention over strained diplomatic relations and the possibility of disruptive activity.
Report: https://zerofox.com/advisories/21078
ZeroFox Intelligence Flash Report - Ongoing Social Unrest in France
In this flash report, ZeroFox’s Geopolitical Working Group provides an overview of the current social unrest occurring in France, the government’s response measures, and international responses to it thus far.
Report: https://zerofox.com/advisories/21056
ZeroFox Intelligence Geopolitical Brief for July 2023
In this ZeroFox Intelligence Geopolitical Brief for July 2023, the primary topic is the global implications of Ukraine's counteroffensive in Russia, which include further supply chain disruptions if Russian economic output is restricted and more cyber attacks ahead of the NATO summit. Disruptive protests, including those in France as well as transportation strikes, are also discussed in the Europe section. Latin America has a series of protests upcoming that are occurring alongside a regionwide crime wave that is occupying voter concerns. In Asia, the primary concern remains the geopolitical dispute between Western nations and China. China appears to have laid the groundwork to punish further companies that comply with Western sanctions. In the Middle East, developments regarding possible judicial reforms in Israel as well as the worst violence in decades in the West Bank are discussed. In Africa, there is a high risk of social unrest, and the major economies of Nigeria and Kenya are preparing to raise taxes on the middle class.
Report: https://zerofox.com/advisories/21055
Tags: tlp:clear, all industries, global