zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - July 14, 2023

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - July 14, 2023

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Ongoing PicassoLoader Campaign Targets Entities in Ukraine and Poland
  • CISA Advisory: Mitigate Risks to Rockwell Automation Modules
  • Cisco SD-WAN vManage Vulnerability Allows Unauthorized API Access
  • Data broker / initial-access broker / hacktivist group: BlackDragonSec and Anonymous Sudan
  • Vulnerabilities: CVE-2022-33324 and CVE-2023-3668
  • Exploits: CVE-2013-4975 and CVE-2011-3416
  • Breaches: BreachForums/XSS: Whitepages Data Breach and Coinbulb Data Breach

Ongoing PicassoLoader Campaign Targets Entities in Ukraine and Poland

Government entities, military organizations, and civilians in Ukraine and Poland have been targeted in a series of campaigns aimed at stealing data and establishing remote access to compromised systems. The attacks involve phishing lures and decoy documents to deploy the PicassoLoader malware. Some of the attacks have been attributed to the threat actor GhostWriter and linked to the Belarusian government. A playbook adopted by Russian military intelligence (GRU) hackers has been observed, emphasizing speed, scale, and intensity in attacks.

CISA Advisory: Mitigate Risks to Rockwell Automation Modules

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an alert regarding two flaws in Rockwell Automation ControlLogix EtherNet/IP (ENIP) communication module models. These vulnerabilities (CVE-2023-3595 - CVSS score: 9.8 and CVE-2023-3596 - CVSS score: 7.5) could enable remote code execution and denial-of-service (DoS) attacks and cause disruptions in industrial processes. The affected devices include 1756 EN2*, 1756 EN3*, and 1756 EN4* products.

Cisco SD-WAN vManage Vulnerability Allows Unauthorized API Access

The Cisco SD-WAN vManage management software has a vulnerability that could allow an unauthenticated remote attacker to gain read or limited write permissions to the affected instance's configuration. The flaw arises from insufficient request validation in the REST API feature, allowing specially-crafted requests to exploit it. Attackers could retrieve sensitive information, modify configurations, and disrupt network operations. Cisco has provided fixed releases for affected versions and recommends using access control lists and API keys for added security as well as monitoring logs for REST API access attempts.

Threat Activity: Data broker / initial-access broker / hacktivist group

VULNERABILITIES

  • CVE-2022-33324 - Improper Resource Shutdown or Release vulnerability in Mitsubishi Electric Corporation products.
  • CVE-2023-3668 - Improper Encoding or Escaping of Output in GitHub repository froxlor/froxlor prior to 2.0.21.

EXPLOITS

  • CVE-2013-4975 - Hikvision IP Cameras 4.1.0 b130111 allows attackers can obtain the admin password from a non-privileged user account
  • CVE-2011-3416 - Microsoft ASP.NET Forms Authentication Bypass

BREACHES

Tags: DIB, tlp:green