ZeroFox Daily Intelligence Brief - July 11, 2023
|by Alpha Team

ZeroFox Daily Intelligence Brief - July 11, 2023
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Apple Issues Urgent Patch for Actively Exploited Zero-Day Flaw
- RomCom Hackers Target NATO Summit Attendees in Spear-Phishing Campaign
- HCA Healthcare Suffers Data Breach Affecting 27 Million Patients
- Initial-access brokers, data brokers, and hacktivists: Telegram Channel UserSec and Exploit user “nljfdjkl”
- Vulnerabilities: CVE-2023-36922, CVE-2023-36925, and CVE-2023-21640
- Exploits: CVE-2010-1240 and CVE-2016-4998
- Breaches: BreachForums/XSS: Capital Games Data Breach and Moneyman Data Breach
Apple Issues Urgent Patch for Actively Exploited Zero-Day Flaw
On July 10, 2023, Apple released Rapid Security Response updates for iOS, iPadOS, macOS, and Safari web browser to address a zero-day bug (CVE-2023-37450) that the company says “may have been actively exploited.” However, Apple reportedly pulled the software update after the patches led to accessibility problems on browsing several popular browsers via Safari. The updates are likely to be re-released after the browser issues are fixed.
RomCom Hackers Target NATO Summit Attendees in Spear-Phishing Campaign
Threat actor "RomCom" is targeting pro-Ukraine organizations as well as attendees of the 2023 NATO Summit in Vilnius, Lithuania. The threat actor has been observed typosquatting by creating a replica of the Ukrainian World Congress website—using an ".info" domain instead of the legitimate ".org" domain. The attacker spreads RTF file documents containing malicious code through spear-phishing, to deliver malware which takes advantage of the “Follina” vulnerability to steal confidential data.
HCA Healthcare Suffers Data Breach Affecting 27 Million Patients
The data of around 27 million patients of HCA Healthcare, one of the largest medical companies in the US, had been compromised. HCA has alerted patients that their full name, city, and details of their last provider visit have been breached. While the organization reported that clinical information was not disclosed, the hackers claimed to possess “health diagnosis emails corresponding to clientIDs.” As reported last week, ZeroFox Intelligence observed a threat actor purportedly selling 27 records of the stolen data on an underground forum.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- Telegram Channel UserSec: Targeting Ukrainian e-governance platform Diia
- Exploit user “nljfdjkl”: Cisco VPN Access To Unnamed Airline Based In Thailand
VULNERABILITIES
- CVE-2023-36922 - Several SAP NetWeaver ABAP (IS-OIL) versions allow an authenticated attacker to inject an arbitrary operating system command into an unprotected parameter in a common extension.
- CVE-2023-36925 - SAP Solution Manager (Diagnostics agent) - version 7.20, allows an unauthenticated attacker to blindly execute HTTP requests.
- CVE-2023-21640 - Memory corruption in Linux when the file upload API is called with parameters having large buffer.
EXPLOITS
- CVE-2010-1240 - Adobe PDF - Embedded EXE Social Engineering
- CVE-2016-4998 - Linux Kernel 4.6.3 Netfilter Privilege Escalation
BREACHES
- BreachForums/XSS: Capital Games Data Breach: (430,954 Records) - Email address and password
- BreachForums/XSS: Moneyman Data Breach: (530,571 Records) - Email address and password
Tags: DIB, tlp:green