ZeroFox Daily Intelligence Brief - July 18, 2023
|by Alpha Team

ZeroFox Daily Intelligence Brief - July 18, 2023
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- ZeroFox Intelligence Brief: Analysis of Clop Activity
- JumpCloud Discloses Breach by State-Backed Hackers
- NSA and CISA Release Guidelines for Secure Network Slicing
- Data broker / initial-access broker / hacktivist group: Exploit user twofactor and Anonymous Sudan
- Vulnerabilities: CVE-2023-27390 and CVE-2023-31194
- Exploits: CVE-2006-5143 and CVE-2006-1495
- Breaches: Credit Card Data Breach: BreachForums/XSS: Petflow Data Breach and BreachForums/XSS: Psyonix Data Breach
ZeroFox Intelligence Brief: Analysis of Clop Activity
ZeroFox Intelligence analyzed Clop ransomware group’s activity and noted that Clop’s exploitation of zero-day bugs makes the timing of campaigns unpredictable. Victims are typically targeted by data exfiltration followed by ransom demands, rather than the implementation of encrypting ransomware. This is likely a method deemed at lower risk of failure. Clop (a.k.a. Cl0p) activity is characterized by low levels of activity for several months, followed by several weeks of a high tempo of attacks.
JumpCloud Discloses Breach by State-Backed Hackers
Enterprise-software company JumpCloud has disclosed that a sophisticated state-backed threat group breached its systems last month via a spear-phishing attack. The company is yet to disclose the full scope of the attack. JumpCloud has force-rotated all admin API keys to protect its client organizations and notified them to generate new keys; it has also released indicators of compromise (IOCs) to allow people to secure their networks from similar attacks.
NSA and CISA Release Guidelines for Secure Network Slicing
The National Security Agency (NSA) and CISA have jointly released a publication titled "5G Network Slicing: Security Considerations for Design, Deployment, and Maintenance." The guidance, developed by the Enduring Security Framework (ESF), offers recommendations to address potential threats to 5G standalone network slicing. It provides industry-recognized practices for designing, deploying, operating, and maintaining secure 5G network slices. CISA urges 5G providers, integrators, and network operators to review the guidance and implement the recommended actions.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- Exploit user twofactor: Selling a bundle purportedly containing nine compromised email accounts for unnamed italian companies
- Anonymous Sudan: Claims DDoS attack on NIST, Tumblr, Microsoft OneDrive, and PayPal
VULNERABILITIES
- CVE-2023-27390 - A heap-based buffer overflow vulnerability exists in the Sequence::DrawText functionality of Diagon v1.0.139.
- CVE-2023-31194 - An improper array index validation vulnerability exists in the GraphPlanar::Write functionality of Diagon v1.0.139.
EXPLOITS
- CVE-2006-5143: CA BrightStor ARCserve Message Engine Heap Overflow
- CVE-2006-1495: PHPCollab 2.x / NetOffice 2.x - 'sendpassword.php' SQL Injection
BREACHES
- BreachForums/XSS: Petflow Data Breach: (956,505 Records) | Email Address and password
- BreachForums/XSS: Psyonix Data Breach: (1,003,235 Records) | Email Address and password
Tags: DIB, tlp:green