zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - July 20, 2023

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - July 20, 2023

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

-ZeroFox Intelligence: Clop Releases Exfiltrated Data On Surface Web Domain

  • Adobe Rolls Out New Patches for Actively Exploited ColdFusion Vulnerability
  • VirusTotal Data Breach Exposes Registered Customer Information
  • Ukraine Takes Down Massive Bot Farm, Seizes 150,000 SIM Cards
  • Data broker / initial-access broker / hacktivist group: UserSec: Claims to have defaced the website of London City Airport and Anonymous Italia: DDoS attack on French hotel La Voile d'Or
  • Vulnerabilities: CVE-2023-28531 and CVE-2023-37964
  • Exploits: CVE-2009-3548 and CVE-2019-12840
  • Breaches: BreachForums/XSS: Imgur Data Breach and BreachForums/XSS: Canva Data Breach_Additional Dataset

ZeroFox Intelligence: Clop Releases Exfiltrated Data On Surface Web Domain

On July 19, 2023, the Clop (Cl0p) extortion collective released stolen PricewaterhouseCoopers (PwC) data on a newly registered website with a “[.]com” domain. The group had previously published PwC data to its Tor-based (dark web) leak site. Clop is most likely experimenting with this new shaming tactic to pressure victims into paying ransom demands. The success of this tactic—for future use by Clop as well as other collectives—depends on public reaction to the leak and how victims respond.

Adobe Rolls Out New Patches for Actively Exploited ColdFusion Vulnerability

Adobe has released fresh updates to address an incomplete fix for a recently disclosed ColdFusion flaw, actively exploited in the wild. The flaw, CVE-2023-38205 (CVSS score: 7.5), involves improper access control and can lead to security bypass. Versions impacted include ColdFusion 2023 (Update 2 and earlier), 2021 (Update 8 and earlier), and 2018 (Update 18 and earlier). Users are urged to update to the latest version to protect against potential threats.

Ukraine Takes Down Massive Bot Farm, Seizes 150,000 SIM Cards

Ukrainian cyber authorities have dismantled a massive bot farm involved in propagating Russian propaganda, spreading illegal content, and engaging in fraudulent activities. The bots were used to create social media accounts for disseminating illegal advertisements, personal data, and false messages. After physical searches in over 20 locations in Vinnytsia, Zaporizhzhia, and Lvivand, the authorities seized equipment, phones, 250 GSM gateways, and 150,000 SIM cards.

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

  • UserSec: Claims to have defaced the website of London City Airport
  • Anonymous Italia: DDoS attack on French hotel La Voile d'Or

VULNERABILITIES

  • CVE-2023-28531 - ssh-add in OpenSSH before 9.3 adds smartcard keys to ssh-agent without the intended per-hop destination constraints.
  • CVE-2023-37964 - A cross-site request forgery (CSRF) vulnerability in Jenkins ElasticBox CI Plugin 5.0.1 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

EXPLOITS

BREACHES

Tags: DIB, tlp:green