zerofox logo
Advisories

Threat Intelligence Bulletin: 07/07/2023 - 07/13/2023

|by Alpha Team

banner image

ZeroFox Weekly Threat Bulletin: 07/07/2023 - 07/13/2023


ZeroFox Daily Intelligence:


ZeroFox Daily Intelligence Brief - July 13, 2023

Brief Highlights

  • Event Assessment: 2023 FIFA Women's World Cup (Australia & New Zealand)
  • Vulnerability Discovered in Ghostscript Library Poses Threat to Windows and Linux Systems
  • New Malware “AVrecon” Targets Small and Home Office Routers
  • Data broker / initial-access broker / hacktivist group: Telegram channel 0x_dump and vigilante group Ghostsec
  • Vulnerabilities: CVE-2019-5997 and CVE-2023-3343
  • Exploits: CVE-2016-6079 and CVE-2018-1160
  • Breaches: Leakbase: Hodnik Data Breach and BreachForums/XXS: Coding-Talk Data Breach

Report: https://zerofox.com/advisories/21227


ZeroFox Daily Intelligence Brief - July 12, 2023

Brief Highlights

  • Chinese Hackers Gained Access to Government Email Accounts
  • Hackers Exploit Windows Kernel Loophole with Malicious Driver Signings
  • Financially Motivated Threat Actor ScarletEel Exploiting AWS for Malicious Activities
  • Data broker / initial-access broker / hacktivist group: Telegram channel 0x_dump and NoName057(16)
  • Vulnerabilities: CVE-2022-39280 and CVE-2022-39294
  • Exploits: CVE-2015-1701 and CVE-2013-6282
  • Breaches: BreachForums/XSS: Corevin Data Breach and Belly Ballot Data Breach

Report: https://zerofox.com/advisories/21201


ZeroFox Daily Intelligence Brief - July 11, 2023

Brief Highlights

  • Apple Issues Urgent Patch for Actively Exploited Zero-Day Flaw
  • RomCom Hackers Target NATO Summit Attendees in Spear-Phishing Campaign
  • HCA Healthcare Suffers Data Breach Affecting 27 Million Patients
  • Initial-access brokers, data brokers, and hacktivists: Telegram Channel UserSec and Exploit user “nljfdjkl”
  • Vulnerabilities: CVE-2023-36922, CVE-2023-36925, and CVE-2023-21640
  • Exploits: CVE-2010-1240 and CVE-2016-4998
  • Breaches: BreachForums/XSS: Capital Games Data Breach and Moneyman Data Breach

Report: https://zerofox.com/advisories/21189


ZeroFox Daily Intelligence Brief - July 10, 2023

Brief Highlights

  • Further Vulnerabilities Patched in MOVEit Transfer Software
  • Mastodon Releases Patch to Address Critical Vulnerabilities
  • CISA Warns Govt. Agencies to Patch Android Driver At Risk of Active Exploitation
  • Vulnerabilities: CVE-2023-20773 and CVE-2023-20766
  • Exploits: CVE-2020-29372 and CVE-2016-0075
  • Breaches: Credit Card Data Breach: 2023-7-8 and BreachForums/XSS: EvgexaСraft Data Breach

Report: https://zerofox.com/advisories/21149


ZeroFox Daily Intelligence Brief - July 7, 2023

Brief Highlights

  • CISA and Partners Release Joint Cybersecurity Advisory on Newly Identified Truebot Malware Variants
  • Critical Vulnerabilities Leave SolarView Devices in Solar Farms Exposed to Exploits
  • JumpCloud Notifies Customers of Incident: Admin API Keys Invalidated as Security Measure
  • INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS: ShadowHacker Leaks and BreachForum user TIA
  • Vulnerabilities: CVE-2023-3439 and CVE-2023-21518
  • Exploits: CVE-2004-2687
  • Breaches: BreachForums/XSS: EDA Board Data Breach and BreachForums/XSS: Forbes Data Breach

Report: https://zerofox.com/advisories/21133


Breach Disclosures:


Hongfire

An alleged data breach at Hongfire – a U.S.-based online gaming site – exposed 697,232 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21241


Lookbook

An alleged data breach at Lookbook – a U.S.-based online community source for fashion – exposed 1,118,595 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21240


Coinbulb

An alleged data breach at Coinbulb – a U.S.-based bitcoin faucet website – exposed 586,844 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21239


Kickstarter

An alleged data breach at Kickstarter – a U.S.-based public benefit corporation – exposed 678,256 email addresses and plain-text passwords, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21238


Instabet

An alleged data breach at Instabet – a Mexico-based sports betting platform – exposed 12,426 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21237


Coding-Talk

An alleged data breach at Coding-Talk – a U.S.-based coding forum – exposed 80,371 email addresses, usernames and hashed passwords, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21236


Hodnik

An alleged data breach at Hodnik – a France-based online plant retailer – exposed 16,815 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21235


PayAsUGym

An alleged data breach at PayAsUGym – a U.K.-based online fitness marketplace – exposed 123,874 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21217


Yingjiesheng

An alleged data breach at Yingjiesheng – a China-based online recruitment website – exposed 732,031 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21216


Storybird

An alleged data breach at Storybird – a U.S.-based visual stories and illustrators website – exposed 690,686 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21215


Rekrute

An alleged data breach at Rekrute – a Morocco-based recruitment and career management company – exposed 677,549 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21214


Belly Ballot

An alleged data breach at Belly Ballot – a U.S.-based online website for infant names – exposed 665,244 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21213


TaxNetUSA

An alleged data breach at TaxNetUSA – a U.S.-based company that provides comprehensive property tax information to real estate and property tax industries – exposed 231,178 email addresses and/or usernames, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21212


Funny Games

An alleged data breach at Funny Games – a U.S.-based gaming site – exposed 725,783 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21211


Xpgamesaves

An alleged data breach at Xpgamesaves – a U.K.-based online gaming platform – exposed 2743,992 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21210


Brazzers

An alleged data breach at Brazzers – a Canada-based adult entertainment site – exposed 798,921 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21209


ForumCommunity

An alleged data breach at ForumCommunity – an Italy-based free forum hosting, blog and community site – exposed 754,556 email addresses and plain-text passwords, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21208


HazeCash

An alleged data breach at HazeCash – a U.S.-based online adult entertainment site – exposed 801,297 email addresses and plain-text passwords, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21207


Euronote

An alleged data breach at Euronote – a Hungary-based online stationery shop – exposed 364,519 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21206


Intellego

An alleged data breach at Intellego – a U.S.-based online site – exposed 482,327 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21205


Final Fantasy Shrine Forums

An alleged data breach at Final Fantasy Shrine Forums – a U.S.-based online discussion forum – exposed 491,790 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21204


Megadate

An alleged data breach at Megadate – a Germany-based dating site – exposed 513,515 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21203


Openraid_Additional Dataset

An alleged data breach at Openraid – a U.S.-based community for discussions related to World of Warcraft – exposed 254,922 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21190


GameTag

An alleged data breach at GameTag – a U.S.-based online platform for players of massively multiplayer online (MMO) games to buy, sell and trade digital in game accounts – exposed 212,537 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21188


Buxp

An alleged data breach at Buxp – a Sri Lanka-based organization that operates in PPC (pay-per-click) advertising – exposed 458,136 email addresses and plain-text passwords, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21187


Ueber18

An alleged data breach at Ueber18 – a Germany-based age verification system – exposed 500,749 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21186


Powerbot

An alleged data breach at Powerbot – a U.S.-based role-playing game site – exposed 401,751 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21185


Foxy Bingo

An alleged data breach at Foxy Bingo – a U.K.-based gaming website – exposed 137,344 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21184


GateHub

An alleged data breach at GateHub – a U.K.-based Internet of Value platform, built on XRP Ledger protocol – exposed 284,888 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21183


Paxful

An alleged data breach at Paxful – a U.S.-based cryptocurrency trading platform – exposed 295,333 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21182


EDA Board

An alleged data breach at EDA Board – a U.S.-based electronics discussion forum – exposed 354,146 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21181


Connect Press

An alleged data breach at Connect Press – a U.S.-based online magazine – exposed 336,678 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21180


CD Projekt RED

An alleged data breach at CD Projekt RED – a U.S.-based discussion forum – exposed 623,244 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21179


Mortal Online

An alleged data breach at Mortal Online – a Sweden-based gaming website – exposed 476,758 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21178


EvgexaСraft

An alleged data breach at EvgexaСraft – a Russia-based online gaming website – exposed 296,731 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21177


TechIMO.com

An alleged data breach at TechIMO.com – a U.S.-based discussion forum – exposed 303,375 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21176


Forbes Data

An alleged data breach at Forbes Data – a U.S.-based business magazine – exposed 270,690 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21175


Servicio de Impuestos Internos

An alleged data breach at Servicio de Impuestos Internos – a Chile-based company that operates in the accounting industry – exposed 43,664 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21174


Gamesforum

An alleged data breach at Gamesforum – a Germany-based gaming discussion forum – exposed 80,263 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21173


Capital Games

An alleged data breach at Capital Games – a U.S.-based mobile game production company – exposed 430,954 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21172


Animoto

An alleged data breach at Animoto – a U.S.-based online video maker site – exposed 494,780 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21171


Stickam

An alleged data breach at Stickam – a U.S.-based adult entertainment site – exposed 529,199 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21170


Moneyman

An alleged data breach at Moneyman – a site on money making opportunities – exposed 530,571 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21169


EmuParadise

An alleged data breach at EmuParadise – a Sweden-based game ROM download site – exposed 554,008 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21168


Morele

An alleged data breach at Morele – a Poland-based electronics retail site – exposed 614,461 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21167


Faucet Hub

An alleged data breach at Faucet Hub – a U.S.-based bitcoin earning site – exposed 553,678 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21166


Gamesnord

An alleged data breach at Gamesnord – an online gaming site – exposed 595,830 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21165


CheatGamer

An alleged data breach at CheatGamer – a gaming-related site – exposed 337,558 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21164


NaughtyAmerica

An alleged data breach at NaughtyAmerica – a U.S.-based adult entertainment site – exposed 399,492 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21163


Kaboom

An alleged data breach at Kaboom – a Russia-based company that operates in hospitality – exposed 51,230 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21162


ViperMC

An alleged data breach at ViperMC – a U.S.-based Minecraft Mod site – exposed 3,604 email addresses and plain-text passwords, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21161


Creocommunity

An alleged data breach at Creocommunity – a France-based gaming news website – exposed 189,813 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21147


Mystical World

An alleged data breach at Mystical World – a U.S.-based book store – exposed 42,864 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21145


Abandonia_Additional Dataset

An alleged data breach at Abandonia – a Sweden-based gaming and discussion forum – exposed 14,509 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21144


Klerk

An alleged data breach at Klerk – a U.S.-based company that produces independent research and investment content – exposed 8,874,860 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21143


WarcraftRealms

An alleged data breach at WarcraftRealms – a U.S.-based fansite that specializes in providing facts, historical data, and trends in the population of the World of Warcraft game – exposed 129,459 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21142


IqraShop

An alleged data breach at IqraShop – a France-based merchant site specializing in Islamic cultural products – exposed 130,568 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21132


Breaking News:


Security flaws in Honeywell devices could be used to disrupt critical industries

Security researchers have discovered numerous vulnerabilities in Honeywell devices used in critical industries that could, if exploited, allow hackers to cause physical disruption and potentially impact the safety of human lives. Researchers specializing in asset security, uncovered nine vulnerabilities in Honeywell’s Experion distributed control system (DCS) products.

See the full report here: https://techcrunch.com/2023/07/13/security-flaws-in-honeywell-devices-could-be-used-to-disrupt-critical-industries/


CISA and FBI Release Cybersecurity Advisory on Enhanced Monitoring to Detect APT Activity Targeting Outlook Online

The Cybersecurity and Infrastructure Security Agency (CISA) and Federal Bureau of Investigation (FBI) have released a joint Cybersecurity Advisory (CSA), Enhanced Monitoring to Detect APT Activity Targeting Outlook Online, to provide guidance to agencies and critical infrastructure organizations on enhancing monitoring in Microsoft Exchange Online environments.

See the full report here: https://www.cisa.gov/news-events/alerts/2023/07/12/cisa-and-fbi-release-cybersecurity-advisory-enhanced-monitoring-detect-apt-activity-targeting


Fortinet warns of critical RCE flaw in FortiOS, FortiProxy devices

Fortinet has disclosed a critical severity flaw impacting FortiOS and FortiProxy, allowing a remote attacker to perform arbitrary code execution on vulnerable devices. The flaw, discovered by cybersecurity firm Watchtowr is tracked as CVE-2023-33308 and has received a CVS v3 rating of 9.8 out of 10.0, rating it "critical."

See the full report here: https://www.bleepingcomputer.com/news/security/fortinet-warns-of-critical-rce-flaw-in-fortios-fortiproxy-devices/


Critical RCE found in popular Ghostscript open-source PDF library

Ghostscript, an open-source interpreter for PostScript language and PDF files widely used in Linux, has been found vulnerable to a critical-severity remote code execution flaw. The flaw is tracked as CVE-2023-36664, having a CVSS v3 rating of 9.8, and impacts all versions of Ghostscript before 10.01.2, which is the latest available version.

See the full report here: https://www.bleepingcomputer.com/news/security/critical-rce-found-in-popular-ghostscript-open-source-pdf-library/


Russian state hackers lure Western diplomats with BMW car ads

The Russian state-sponsored hacking group "APT29" (aka Nobelium, Cloaked Ursa) has been using unconventional lures like car listings to entice diplomats in Ukraine to click on malicious links that deliver malware. APT29 is linked to the Russian government's Foreign Intelligence Service (SVR) and has been responsible for numerous cyberespionage campaigns targeting high-interest individuals across the globe.

See the full report here: https://www.bleepingcomputer.com/news/security/russian-state-hackers-lure-western-diplomats-with-bmw-car-ads/


SonicWall warns admins to patch critical auth bypass bugs immediately

SonicWall warned customers to urgently patch multiple critical vulnerabilities impacting the company's Global Management System (GMS) firewall management and Analytics network reporting engine software suites. In total, the American cybersecurity company addressed a total of 15 security flaws, including ones that can let threat actors gain access to vulnerable on-prem systems running GMS 9.3.2-SP1 or earlier and Analytics 2.5.0.4-R7 or earlier after bypassing authentication.

See the full report here: https://www.bleepingcomputer.com/news/security/sonicwall-warns-admins-to-patch-critical-auth-bypass-bugs-immediately/


Rockwell Automation ControlLogix Bugs Expose Industrial Systems to Remote Attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has alerted of two security flaws impacting Rockwell Automation ControlLogix EtherNet/IP (ENIP) communication module models that could be exploited to achieve remote code execution and denial-of-service (DoS).

See the full report here: https://thehackernews.com/2023/07/rockwell-automation-controllogix-bugs.html


Russian hackers lured embassy workers in Ukraine with ad for a cheap BMW

Hackers suspected of working for Russia's foreign intelligence agency targeted dozens of diplomats at embassies in Ukraine with a fake used car advert in a bid to break into their computers, The wide-reaching espionage activity targeted diplomats working in at least 22 of the roughly 80 foreign missions in Ukraine's capital, Kyiv.

See the full report here: https://www.reuters.com/world/europe/russian-hackers-lured-embassy-workers-ukraine-with-an-ad-cheap-bmw-2023-07-12/


Beware of Big Head Ransomware: Spreading Through Fake Windows Updates

A developing piece of ransomware called Big Head is being distributed as part of a malvertising campaign that takes the form of bogus Microsoft Windows updates and Word installers.

See the full report here: https://thehackernews.com/2023/07/beware-of-big-head-ransomware-spreading.html


SCARLETEEL Cryptojacking Campaign Exploiting AWS Fargate in Ongoing Campaign

Cloud environments continue to be at the receiving end of an ongoing advanced attack campaign dubbed SCARLETEEL, with the threat actors now setting their sights on Amazon Web Services (AWS) Fargate.

See the full report here: https://thehackernews.com/2023/07/scarleteel-cryptojacking-campaign.html


Python-Based PyLoose Fileless Attack Targets Cloud Workloads for Cryptocurrency Mining

A new fileless attack dubbed PyLoose has been observed striking cloud workloads with the goal of delivering a cryptocurrency miner. The attack consists of Python code that loads an XMRig Miner directly into memory using memfd, a known Linux fileless technique.

See the full report here: https://thehackernews.com/2023/07/python-based-pyloose-fileless-attack.html


Deutsche Bank confirms provider breach exposed customer data

Deutsche Bank AG has confirmed that a data breach on one of its service providers has exposed its customers' data in a likely MOVEit Transfer data-theft attack.

See the full report here: https://www.bleepingcomputer.com/news/security/deutsche-bank-confirms-provider-breach-exposed-customer-data/


Hackers exploit Windows policy to load malicious kernel drivers

Microsoft blocked code signing certificates predominantly used by Chinese hackers and developers to sign and load malicious kernel mode drivers on breached systems by exploiting a Windows policy loophole.

See the full report here: https://www.bleepingcomputer.com/news/security/hackers-exploit-windows-policy-to-load-malicious-kernel-drivers/


Microsoft: Unpatched Office zero-day exploited in NATO summit attacks

Microsoft disclosed an unpatched zero-day security bug in multiple Windows and Office products exploited in the wild to gain remote code execution via malicious Office documents. Unauthenticated attackers can exploit the vulnerability (tracked as CVE-2023-36884) in high-complexity attacks requiring user interaction. Successful exploitation could lead to a total loss of confidentiality, availability, and integrity, allowing the attackers to access sensitive information, turn off system protection, and deny access to the compromised system.

See the full report here: https://www.bleepingcomputer.com/news/security/microsoft-unpatched-office-zero-day-exploited-in-nato-summit-attacks/


Chinese hackers breached US govt Exchange email accounts

A Chinese hacking group has breached the email accounts of more than two dozen organizations worldwide, including U.S. and Western European government agencies. The attacks have been pinned on a threat group tracked as Storm-0558, believed to be a cyber-espionage outfit focused on collecting sensitive information by breaching email systems.

See the full report here: https://www.bleepingcomputer.com/news/security/microsoft-chinese-hackers-breached-us-govt-exchange-email-accounts/


UK battles hacking wave as ransomware gang claims "biggest ever" NHS breach

The U.K.’s largest NHS trust has confirmed it’s investigating a ransomware incident as the country’s public sector continues to battle a rising wave of cyberattacks. Barts Health NHS Trust, which runs five London-based hospitals and serves more than 2.5 million patients, was recently added to the dark web leak site of the ALPHV ransomware gang. Samples of the allegedly stolen data include employee identification documents, including passports and driver licenses, and internal emails labeled “confidential.”

See the full report here: https://techcrunch.com/2023/07/10/uk-hacks-public-sector-nhs-ransomware/


Critical Infrastructure Services Firm Ventia Takes Systems Offline Due to Cyberattack

Critical infrastructure services provider Ventia announced that it has taken some of its systems offline to contain a cyberattack. In an incident notice, the company announced that it decided to take some key systems offline in response to the incident, and that it had engaged with external experts and law enforcement to investigate it.

See the full report here: https://www.securityweek.com/critical-infrastructure-services-firm-ventia-takes-systems-offline-due-to-cyberattack/


HCA Healthcare Suffers Data Breach Affecting 27 Million Patients

The data of around 27 million patients of HCA Healthcare, one of the largest medical companies in the US, had been compromised. HCA has alerted patients that their full name, city, and details of their last provider visit have been breached.

See the full report here: https://www.cnbc.com/2023/07/10/hca-healthcare-patient-data-stolen-and-for-sale-by-hackers.html


Razer investigates data breach claims, resets user sessions

Gaming gear company Razer reacted to recent rumors of a massive data breach with a short statement on Twitter, letting users know that they started an investigation into the matter.

See the full report here: https://www.bleepingcomputer.com/news/security/razer-investigates-data-breach-claims-resets-user-sessions/


Former employee charged for attacking water treatment plant

A former employee of Discovery Bay Water Treatment Facility in California was indicted by a federal grand jury for intentionally attempting to cause malfunction to the facility’s safety and protection systems.

See the full report here: https://www.bleepingcomputer.com/news/security/former-employee-charged-for-attacking-water-treatment-plant/


VMware warns of exploit available for critical vRealize RCE bug

VMware warned customers that exploit code is now available for a critical vulnerability in the VMware Aria Operations for Logs analysis tool, which helps admins manage terabytes worth of app and infrastructure logs in large-scale environments. The flaw (CVE-2023-20864) is a deserialization weakness patched in April 2023, and it allows unauthenticated attackers to gain remote execution on unpatched appliances.

See the full report here: https://www.bleepingcomputer.com/news/security/vmware-warns-of-exploit-available-for-critical-vrealize-rce-bug/


RomCom RAT Targeting NATO and Ukraine Support Groups

The threat actors behind the RomCom RAT have been suspected of phishing attacks targeting the upcoming NATO Summit in Vilnius as well as an identified organization supporting Ukraine abroad. Attack chains mounted by the group are geopolitically motivated and have employed spear-phishing emails to point victims to cloned websites hosting trojanized versions of popular software. Targets include militaries, food supply chains, and IT companies.

See the full report here: https://thehackernews.com/2023/07/romcom-rat-targeting-nato-and-ukraine.html


New TOITOIN Banking Trojan Targeting Latin American Businesses

Businesses operating in the Latin American (LATAM) region are the target of a new Windows-based banking trojan called TOITOIN since May 2023. The sophisticated campaign employs a trojan that follows a multi-staged infection chain, utilizing specially crafted modules throughout each stage.

See the full report here: https://thehackernews.com/2023/07/new-toitoin-banking-trojan-targeting.html


New Mozilla Feature Blocks Risky Add-Ons on Specific Websites to Safeguard User Security

Mozilla has announced that some add-ons may be blocked from running on certain sites as part of a new feature called Quarantined Domains. The company said the openness afforded by the add-on ecosystem could be exploited by malicious actors to their advantage.

See the full report here: https://thehackernews.com/2023/07/new-mozilla-feature-blocks-risky-add.html


Apple Issues Urgent Patch for Zero-Day Flaw Targeting iOS, iPadOS, macOS, and Safari

Apple has released Rapid Security Response updates for iOS, iPadOS, macOS, and Safari web browser to address a zero-day flaw that it stated had been actively exploited in the wild. The WebKit bug, cataloged as CVE-2023-37450, could allow threat actors to achieve arbitrary code execution when processing specially crafted web content.

See the full report here: https://thehackernews.com/2023/07/apple-issues-urgent-patch-for-zero-day.html


Cyber frauds siphon off USD 250 million from India-based firm after hacking their financial portal

In one of the biggest cyber heists in Thane (India) unknown hackers got access to the escrow bank account of a Thane-based company and siphoned off around 250 million.

See the full report here: https://www.hindustantimes.com/cities/mumbai-news/massive-cyber-heist-in-thane-hackers-steal-25-crore-from-company-s-escrow-bank-account-101688931094429.html


Bangladesh government website leaks citizens’ personal data

A Bangladeshi government website leaked the personal information of citizens, including full names, phone numbers, email addresses and national ID numbers.

See the full report here: https://techcrunch.com/2023/07/07/bangladesh-government-website-leaks-citizens-personal-data/


Critical TootRoot bug lets attackers hijack Mastodon servers

Mastodon, the free and open-source decentralized social networking platform, has patched four vulnerabilities, one of them critical that allows hackers to create arbitrary files on the server using specially crafted media files. Mastodon has about 8.8 million users spread across 13,000 separate servers (instances) hosted by volunteers to support distinct yet inter-connected (federated) communities.

See the full report here: https://www.bleepingcomputer.com/news/security/critical-tootroot-bug-lets-attackers-hijack-mastodon-servers/


CISA warns govt agencies to patch actively exploited Android driver

CISA ordered federal agencies to patch a high-severity Arm Mali GPU kernel driver privilege escalation flaw added to its list of actively exploited vulnerabilities and addressed with this month's Android security updates. The flaw (tracked as CVE-2021-29256) is a use-after-free weakness that can let attackers escalate to root privileges or gain access to sensitive information on targeted Android devices by allowing improper operations on GPU memory.

See the full report here: https://www.bleepingcomputer.com/news/security/cisa-warns-govt-agencies-to-patch-actively-exploited-android-driver/


New "Big Head" ransomware displays fake Windows update alert

Security researchers have dissected a recently emerged ransomware strain named "Big Head" that may be spreading through malvertising that promotes fake Windows updates and Microsoft Word installers. Two samples of the malware have been analyzed by cybersecurity researchers, who looked at the infection vector and how the malware executes.

See the full report here: https://www.bleepingcomputer.com/news/security/new-big-head-ransomware-displays-fake-windows-update-alert/


Charming Kitten hackers use new "NokNok" malware for macOS

Security researchers observed a new campaign they attribute to the Charming Kitten APT group where hackers used new NokNok malware that targets macOS systems. The campaign started in May 2023 and relies on a different infection chain than previously observed, with LNK files deploying the payloads instead of the typical malicious Word documents seen in past attacks from the group.

See the full report here: https://www.bleepingcomputer.com/news/security/charming-kitten-hackers-use-new-noknok-malware-for-macos/


Another Critical Unauthenticated SQLi Flaw Discovered in MOVEit Transfer Software

Progress Software has announced the discovery and patching of a critical SQL injection vulnerability in MOVEit Transfer, popular software used for secure file transfer. The identified SQL injection vulnerability, tagged as CVE-2023-36934, could potentially allow unauthenticated attackers to gain unauthorized access to the MOVEit Transfer database. In addition, Progress Software has patched two other high-severity vulnerabilities.

See the full report here: https://thehackernews.com/2023/07/another-critical-unauthenticated-sqli.html


Vishing Goes High-Tech: New "Letscall" Malware Employs Voice Traffic Routing

Researchers have issued a warning about an emerging and advanced form of voice phishing (vishing) known as "Letscall." This technique is currently targeting individuals in South Korea. The criminals behind "Letscall" employ a multi-step attack to deceive victims into downloading malicious apps from a counterfeit Google Play Store website.

See the full report here: https://thehackernews.com/2023/07/vishing-goes-high-tech-new-letscall.html


Two Spyware Apps on Google Play with 1.5 Million Users Sending Data to China

Two file management apps on the Google Play Store have been discovered to be spyware, putting the privacy and security of up to 1.5 million Android users at risk. These apps engage in deceptive behaviour and secretly send sensitive user data to malicious servers in China.

See the full report here: https://thehackernews.com/2023/07/two-spyware-apps-on-google-play-with-15.html


Hackers Steal USD 20 Million by Exploiting Flaw in Revolut's Payment Systems

Malicious actors exploited an unknown flaw in Revolut's payment systems to steal more than USD 20 million of the company's funds in early 2022. The fault stemmed from discrepancies between Revolut's U.S. and European systems, causing funds to be erroneously refunded using its own money when some transactions were declined.

See the full report here: https://thehackernews.com/2023/07/hackers-steal-20-million-by-exploiting.html


RomCom RAT Targeting NATO and Ukraine Support Groups

The threat actors behind the RomCom RAT have been suspected of phishing attacks targeting the upcoming NATO Summit in Vilnius as well as an identified organization supporting Ukraine abroad.

See the full report here: https://thehackernews.com/2023/07/romcom-rat-targeting-nato-and-ukraine.html


Researchers Uncover New Linux Kernel "StackRot" Privilege Escalation Vulnerability

Details have emerged about a newly identified security flaw in the Linux kernel that could allow a user to gain elevated privileges on a target host. Dubbed StackRot (CVE-2023-3269, CVSS score: 7.8), the flaw impacts Linux versions 6.1 through 6.4. There is no evidence that the shortcoming has been exploited in the wild to date.

See the full report here: https://thehackernews.com/2023/07/researchers-uncover-new-linux-kernel.html


Iranian Hackers' Sophisticated Malware Targets Windows and macOS Users

The Iranian nation-state actor known as TA453 has been linked to a new set of spear-phishing attacks that infect both Windows and macOS operating systems with malware.

See the full report here: https://thehackernews.com/2023/07/iranian-hackers-sophisticated-malware.html


Over 130,000 solar energy monitoring systems exposed online

Security researchers are warning that tens of thousands of photovoltaic (PV) monitoring and diagnostic systems are reachable over the public web, making them potential targets for hackers.

See the full report here: https://www.bleepingcomputer.com/news/security/over-130-000-solar-energy-monitoring-systems-exposed-online/


JumpCloud resets admin API keys amid ongoing incident

JumpCloud, a US-based enterprise software firm is notifying several customers of an "ongoing incident." As a caution, the company has invalidated existing admin API keys to protect its customer organizations. Affected organizations will need to generate new keys.

See the full report here: https://www.bleepingcomputer.com/news/security/jumpcloud-resets-admin-api-keys-amid-ongoing-incident/


Cisco warns of bug that lets attackers break traffic encryption

Cisco warned customers of a high-severity vulnerability impacting some data center switch models and allowing attackers to tamper with encrypted traffic. Tracked as CVE-2023-20185, the flaw was found during internal security testing in the ACI Multi-Site CloudSec encryption feature of data center Cisco Nexus 9000 Series Fabric Switches.

See the full report here: https://www.bleepingcomputer.com/news/security/cisco-warns-of-bug-that-lets-attackers-break-traffic-encryption/


Nickelodeon investigates breach after leak of "decades old" data

Nickelodeon has confirmed that the data leaked from an alleged breach of the company is legitimate but some of it appears to be decades old. At the end of June 2023, a rumor emerged about a major leak from Nickelodeon's animation department. Proof of the alleged data leak started circulating on social media, showing an extensive collection of reportedly 500GB in documents and media files.

See the full report here: https://www.bleepingcomputer.com/news/security/nickelodeon-investigates-breach-after-leak-of-decades-old-data/


CISA: Netwrix Auditor RCE bug exploited in Truebot malware attacks

CISA and the FBI warned of new Truebot malware variants deployed on networks compromised using a critical remote code execution (RCE) vulnerability in the Netwrix Auditor software in attacks targeting organizations across the United States and Canada.

See the full report here: https://www.bleepingcomputer.com/news/security/cisa-netwrix-auditor-rce-bug-exploited-in-truebot-malware-attacks/


Apps with 1.5M installs on Google Play send your data to China

Security researchers discovered two malicious file management applications on Google Play with a collective installation count of over 1.5 million that collected excessive user data that goes well beyond what's needed to offer the promised functionality. The apps, both from the same publisher, can launch without any interaction from the user to steal sensitive data and send it to servers in China.

See the full report here: https://www.bleepingcomputer.com/news/security/apps-with-15m-installs-on-google-play-send-your-data-to-china/


ZeroFox Intelligence Reports:


ZeroFox Intelligence Flash Report - Black Sea Grain Initiative

In this flash report, ZeroFox’s Geopolitical Working Group provides an update on the Black Sea Grain Initiative, which will expire in the next few days.

Report: https://zerofox.com/advisories/21242


ZeroFox Intelligence Event Assessment – 2023 Women’s World Cup

In this event assessment, ZeroFox Intelligence covers a various security topics surrounding the 2023 Women’s World Cup, including geopolitical tensions and the potential for protest and cyberattack activity.

Report: https://zerofox.com/advisories/21226


Tags: tlp:clear,  all industries,  global