Threat Intelligence Bulletin: 07/14/2023 - 07/20/2023
|by Alpha Team

ZeroFox Weekly Threat Bulletin: 07/14/2023 - 07/20/2023
ZeroFox Daily Intelligence:
ZeroFox Daily Intelligence Brief - July 20, 2023
Brief Highlights -ZeroFox Intelligence: Clop Releases Exfiltrated Data On Surface Web Domain
- Adobe Rolls Out New Patches for Actively Exploited ColdFusion Vulnerability
- VirusTotal Data Breach Exposes Registered Customer Information
- Ukraine Takes Down Massive Bot Farm, Seizes 150,000 SIM Cards
- Data broker / initial-access broker / hacktivist group: UserSec: Claims to have defaced the website of London City Airport and Anonymous Italia: DDoS attack on French hotel La Voile d'Or
- Vulnerabilities: CVE-2023-28531 and CVE-2023-37964
- Exploits: CVE-2009-3548 and CVE-2019-12840
- Breaches: BreachForums/XSS: Imgur Data Breach and BreachForums/XSS: Canva Data Breach_Additional Dataset
Report: https://zerofox.com/advisories/21308
ZeroFox Daily Intelligence Brief - July 19, 2023
Brief Highlights
- Citrix Urges Immediate Action to Address Critical Vulnerability in NetScaler ADC and Gateway
- VirusTotal Data Breach Exposes Registered Customer Information
- CISA Orders Federal Agencies to Mitigate Zero-Days Abused in NATO Phishing Attacks
- Data broker / initial-access broker / hacktivist group: Private Telegram Channel: Exposure of U.S. Senate and Staff Credentials and BlackPass: Compromised E-commerce Account of Heineken Executive for Sale
- Vulnerabilities: CVE-2023-32623 and CVE-2023-3755
- Exploits: CVE-2017-11610 and CVE-2017-8464
- Breaches: BreachForums/XSS: Aternos Data Breach and BreachForums/XSS: Manga Traders Data Breach
Report: https://zerofox.com/advisories/21286
ZeroFox Daily Intelligence Brief - July 18, 2023
Brief Highlights
- ZeroFox Intelligence Brief: Analysis of Clop Activity
- JumpCloud Discloses Breach by State-Backed Hackers
- NSA and CISA Release Guidelines for Secure Network Slicing
- Data broker / initial-access broker / hacktivist group: Exploit user twofactor and Anonymous Sudan
- Vulnerabilities: CVE-2023-27390 and CVE-2023-31194
- Exploits: CVE-2006-5143 and CVE-2006-1495
- Breaches: Credit Card Data Breach: BreachForums/XSS: Petflow Data Breach and BreachForums/XSS: Psyonix Data Breach
Report: https://zerofox.com/advisories/21264
ZeroFox Daily Intelligence Brief - July 17, 2023
Brief Highlights
- Russia-Backed Gamaredon Hackers Steal Data Within an Hour After a Breach
- Dark Web Domain and Infrastructure of Genesis Market Sold
- Tens of Thousands of Public Docker Container Images Expose Secret Keys
- Vulnerabilities: CVE-2023-2156 and CVE-2023-36813
- Breaches: Credit Card Data Breach and BreachForums/Leakforums: Eternity Modern Data Breach
Report: https://zerofox.com/advisories/21255
ZeroFox Daily Intelligence Brief - July 14, 2023
Brief Highlights
- Ongoing PicassoLoader Campaign Targets Entities in Ukraine and Poland
- CISA Advisory: Mitigate Risks to Rockwell Automation Modules
- Cisco SD-WAN vManage Vulnerability Allows Unauthorized API Access
- Data broker / initial-access broker / hacktivist group: BlackDragonSec and Anonymous Sudan
- Vulnerabilities: CVE-2022-33324 and CVE-2023-3668
- Exploits: CVE-2013-4975 and CVE-2011-3416
- Breaches: BreachForums/XSS: Whitepages Data Breach and Coinbulb Data Breach
Report: https://zerofox.com/advisories/21244
Breach Disclosures:
DLH
An alleged data breach at DLH – a U.S.-based website that provides gaming information, gaming reviews, cheats, and news – exposed 3,154,725 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21326
Suba Games
An alleged data breach at Suba Games – a Canada-based online games publisher – exposed 3,404,698 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21325
GameSalad
An alleged data breach at GameSalad – a U.S.-based platform that allows rapid design, publish and distribute games – exposed 1,108,240 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21324
GameTuts
An alleged data breach at GameTuts – an Australia-based online game developing and tutorial sharing community – exposed 1,121,947 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21323
Hacker
An alleged data breach at Hacker – a South Korea-based electronics retail store – exposed 1,401,981 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21322
Nihonomaru
An alleged data breach at Nihonomaru – a Netherlands-based online anime and manga discussions community – exposed 1,562,289 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21321
Leet
An alleged data breach at Leet – a U.S.-based multiplayer for Minecraft PE – exposed 1,902,117 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21320
Imgur
An alleged data breach at Imgur – a U.S.-based online content hosting site to view and share content such as images, GIFs, memes, videos and reviews – exposed 1,752,915 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21319
Avvo_Additional Dataset
An alleged data breach at Avvo – a U.S.-based online marketplace for legal services – exposed 1,833,867 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21318
Canva_Additional Dataset
An alleged data breach at Canva – an Australia-based graphic design platform – exposed 903,872 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21317
CoreVin
An alleged data breach at CoreVin – a Portugal-based company that provides audit and consultancy service in wine regulations – exposed 732,512 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21306
Fitbit
An alleged data breach at Fitbit – a U.S.-based consumer electronics and fitness company – exposed 1,999,973 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21305
Over-blog
An alleged data breach at Over-blog – a France-based blog service – exposed 1,935,329 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21304
Shadi.com
An alleged data breach at Shadi.com – a U.S.-based matchmaking company – exposed 2,023,212 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21303
ClixSense
An alleged data breach at ClixSense now known as ySense – a U.S.-based online money making site – exposed 2,222,498 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21302
Kaidown
An alleged data breach at Kaidown – a Thailand-based gaming site – exposed 860,919 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21301
Funimation
An alleged data breach at Funimation – a U.S.-based anime streaming platform – exposed 848,051 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21300
Mpgh
An alleged data breach at Mpgh – a U.S.-based marketplace for gamers – exposed 2,529,887 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21299
TheWarinc
An alleged data breach at TheWarinc – a U.S.-based online gaming site – exposed 873,801 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21298
Manga Traders
An alleged data breach at Manga Traders – a U.S.-based online site for english translated manga – exposed 845,232 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21297
Aternos
An alleged data breach at Aternos – a U.S.-based Minecraft server – exposed 851,589 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21296
New Zealand Society of Conveyancers
An alleged data breach at New Zealand Society of Conveyancers – a New Zealand-based company that operates in legal process of transferring property or land ownership – exposed 59,801 email addresses and/or usernames, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21295
Mmorg.net
An alleged data breach at Mmorg.net – an online gaming site – exposed 2,346,459 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21294
Poloniex
An alleged data breach at Poloniex – a U.S.-based online crypto trading and exchange platfrom – exposed 952,456 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21281
Eternity Modern
An alleged data breach at Eternity Modern – a U.S.-based furniture manufacturer and design company – exposed 36,397 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21272
Making Fun
An alleged data breach at Making Fun – a U.S.-based game developer and publisher – exposed 87,174 email addresses, usernames and hashed passwords, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21271
Gamecom
An alleged data breach at Gamecom – a China-based gaming forum – exposed 1,004,886 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21270
Elance
An alleged data breach at Elance – a U.S.-based online marketplace for freelancers – exposed 1,105,658 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21269
NextGenUpdate
An alleged data breach at NextGenUpdate – a U.S.-based video game website – exposed 995,704 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21268
LotRO
An alleged data breach at LotRO – a U.S.-based online multiplayer game – exposed 898,578 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21267
Psyonix
An alleged data breach at Psyonix – a U.S.-based video game developer – exposed 1,003,235 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21266
Petflow
An alleged data breach at Petflow – a U.S.-based online retailer of pet food – exposed 956,505 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21265
Qiannao
An alleged data breach at Qiannao – a China-based E-commerce website – exposed 661,925 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21254
Whitepages_Additional Dataset
An alleged data breach at Whitepages – a U.S.-based company that provides online directory services, fraud screening, and identity verification – exposed 672,574 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21243
Breaking News:
US govt bans European spyware vendors Intellexa and Cytrox
The U.S. government has banned European commercial spyware manufacturers Intellexa and Cytrox, citing risks to U.S. national security and foreign policy interests.This decision was motivated by the four companies' involvement in trafficking cyber exploits used to gain unauthorized access to the devices of high-risk individuals worldwide, threatening their security and privacy.
See the full report here: https://www.bleepingcomputer.com/news/security/us-govt-bans-european-spyware-vendors-intellexa-and-cytrox/
Ukraine takes down massive bot farm, seizes 150,000 SIM cards
The Cyber Police Department of the National Police of Ukraine dismantled another massive bot farm linked to more than 100 individuals after searches at almost two dozen locations. The bots were used to push Russian propaganda justifying Russia's war in Ukraine, to disseminate illegal content and personal information, and in various other fraudulent activities.
See the full report here: https://www.bleepingcomputer.com/news/security/ukraine-takes-down-massive-bot-farm-seizes-150-000-sim-cards/
OpenAI credentials stolen by the thousands for sale on the dark web
Threat actors are showing an increased interest in generative artificial intelligence tools, with hundreds of thousands of OpenAI credentials for sale on the dark web and access to a malicious alternative for ChatGPT.
See the full report here: https://www.bleepingcomputer.com/news/security/openai-credentials-stolen-by-the-thousands-for-sale-on-the-dark-web/
Estée Lauder beauty giant breached by two ransomware gangs
Two ransomware actors, ALPHV/BlackCat and Clop, have listed beauty company Estée Lauder on their data leak sites as a victim of separate attacks. In a disgruntled message to the company, the BlackCat gang mocked the security measures, saying that they were still present on the network.
See the full report here: https://www.bleepingcomputer.com/news/security/est-e-lauder-beauty-giant-breached-by-two-ransomware-gangs/
Chinese APT41 Hackers Target Mobile Devices with New WyrmSpy and DragonEgg Spyware
The prolific China-linked nation-state actor known as APT41 has been linked to two previously undocumented strains of Android spyware called WyrmSpy and DragonEgg. APT41, also tracked under the names Axiom, Blackfly, Brass Typhoon (formerly Barium), Bronze Atlas, HOODOO, Wicked Panda, and Winnti, is known to be operational since at least 2007, targeting a wide range of industries to conduct intellectual property theft.
See the full report here: https://thehackernews.com/2023/07/chinese-apt41-hackers-target-mobile.html
CISA and NSA Issue New Guidance to Strengthen 5G Network Slicing Against Threats
U.S. cybersecurity and intelligence agencies have released a set of recommendations to address security concerns with 5G standalone network slicing and harden them against possible threats. In the latest guidance, the authorities cited denial-of-service attacks on the signaling plane, misconfiguration attacks, and adversary-in-the-middle attacks as the three prominent 5G threat vectors, noting that a zero trust architecture (ZTA) can help secure network deployments.
See the full report here: https://thehackernews.com/2023/07/cisa-and-nsa-issue-new-guidance-to.html
Adobe Rolls Out New Patches for Actively Exploited ColdFusion Vulnerability
Adobe has released a fresh round of updates to address an incomplete fix for a recently disclosed ColdFusion flaw that has come under active exploitation in the wild. The critical shortcoming, tracked as CVE-2023-38205 (CVSS score: 7.5), has been described as an instance of improper access control that could result in a security bypass.
See the full report here: https://thehackernews.com/2023/07/adobe-rolls-out-new-patches-for.html
New P2PInfect Worm Targeting Redis Servers on Linux and Windows Systems
Cybersecurity researchers have uncovered a new cloud targeting, peer-to-peer (P2P) worm called P2PInfect that targets vulnerable Redis instances for follow-on exploitation. P2PInfect exploits Redis servers running on both Linux and Windows Operating Systems making it more scalable and potent than other worms. It's estimated that as many as 934 unique Redis systems may be vulnerable to the threat. The first known instance of P2PInfect was detected on July 11, 2023.
See the full report here: https://thehackernews.com/2023/07/new-p2pinfect-worm-targeting-redis.html
Pakistani Entities Targeted in Sophisticated Attack Deploying ShadowPad Malware
An unidentified threat actor compromised an application used by multiple entities in Pakistan to deliver ShadowPad, a successor to the PlugX backdoor that's commonly associated with Chinese hacking crews. Targets included a Pakistan government entity, a public sector bank, and a telecommunications provider. The infections took place between mid-February 2022 and September 2022.
See the full report here: https://thehackernews.com/2023/07/pakistani-entities-targeted-in.html
Google Cloud Build bug lets hackers launch supply chain attacks
A critical design flaw in the Google Cloud Build service can let attackers escalate privileges, providing them with almost nearly-full and unauthorized access to Google Artifact Registry code repositories.
See the full report here: https://www.bleepingcomputer.com/news/security/google-cloud-build-bug-lets-hackers-launch-supply-chain-attacks/
FIN8 deploys ALPHV ransomware using Sardonic malware variant
A financially motivated cybercrime gang has been observed deploying BlackCat ransomware payloads on networks backdoored using a revamped Sardonic malware version. Tracked as FIN8 (aka Syssphinx), this threat actor has been actively operating since at least January 2016, focusing on targeting industries such as retail, restaurants, hospitality, healthcare, and entertainment.
See the full report here: https://www.bleepingcomputer.com/news/security/fin8-deploys-alphv-ransomware-using-sardonic-malware-variant/
New critical Citrix ADC and Gateway flaw exploited as zero-day
Citrix is alerting customers of a critical-severity vulnerability (CVE-2023-3519) in NetScaler ADC and NetScaler Gateway that already has exploits in the wild, and “strongly urges” to install updated versions without delay. The security issue may be the same one advertised earlier this month on a hacker forum as a zero-day vulnerability.
See the full report here: https://www.bleepingcomputer.com/news/security/new-critical-citrix-adc-and-gateway-flaw-exploited-as-zero-day/
Cybersecurity firm Sophos impersonated by new SophosEncrypt ransomware
Cybersecurity vendor Sophos is being impersonated by a new ransomware-as-a-service called SophosEncrypt, with the threat actors using the company name for their operation. The ransomware was initially thought to be part of a red team exercise by Sophos. However, the Sophos X-Ops team tweeted that they did not create the encryptor and that they are investigating its launch.
See the full report here: https://www.bleepingcomputer.com/news/security/cybersecurity-firm-sophos-impersonated-by-new-sophosencrypt-ransomware/
U.S. preparing Cyber Trust Mark for more secure smart devices
A new cybersecurity certification and labeling program called U.S. Cyber Trust Mark is being shaped to help U.S. consumers choose connected devices that are more secure and resilient to hacker attacks. A proposal from the Federal Communications Commission, the program is expected to roll out next year with smart device vendors committing to it voluntarily. Major vendors and makers in the U.S. have already announced their participation. Among them Amazon, Google, Best Buy , LG Electronics U.S.A., Logitech, and Samsung Electronics.
See the full report here: https://www.bleepingcomputer.com/news/security/us-preparing-cyber-trust-mark-for-more-secure-smart-devices/
FBI: Tech support scams now use shipping companies to collect cash
FBI warns of a surge in tech support scams targeting the elderly across the United States and urging victims to dispatch cash concealed within magazines or similar items through shipping firms. While tech support scams have been around for years, the FBI says this is a departure from scammers' conventional tactics of soliciting their targets to send money using bank transfers, cryptocurrencies, or gift cards.
See the full report here: https://www.bleepingcomputer.com/news/security/fbi-tech-support-scams-now-use-shipping-companies-to-collect-cash/
Hackers Exploit WebAPK to Deceive Android Users into Installing Malicious Apps
Threat actors are taking advantage of Android's WebAPK technology to trick unsuspecting users into installing malicious web apps on Android phones that are designed to capture sensitive personal information. The attack began with victims receiving SMS messages suggesting the need to update a mobile banking application," researchers stated in an analysis released last week. The link contained in the message led to a site that used WebAPK technology to install a malicious application on the victim's device.
See the full report here: https://thehackernews.com/2023/07/hackers-exploit-webapk-to-deceive.html
Cybercriminals Exploiting WooCommerce Payments Plugin Flaw to Hijack Websites
Threat actors are actively exploiting a recently disclosed critical security flaw in the WooCommerce Payments WordPress plugin as part of a massive targeted campaign. The flaw, tracked as CVE-2023-28121 (CVSS score: 9.8), is a case of authentication bypass that enables unauthenticated attackers to impersonate arbitrary users and perform some actions as the impersonated user, including an administrator, potentially leading to site takeover.
See the full report here: https://thehackernews.com/2023/07/cybercriminals-exploiting-woocommerce.html
Owner of BreachForums Pleads Guilty to Cybercrime and Child Pornography Charges
The owner of the now-defunct BreachForums website, has pleaded guilty to charges related to his operation of the cybercrime forum as well as having child pornography images.
See the full report here: https://thehackernews.com/2023/07/owner-of-breachforums-pleads-guilty-to.html
JumpCloud discloses breach by state-backed APT hacking group
US-based enterprise software firm JumpCloud says a state-backed hacking group breached its systems almost one month ago as part of a highly targeted attack focused on a limited set of customers. The company discovered the incident on June 27 2023, one week after the attackers breached its systems via a spear-phishing attack. While JumpCloud did not find evidence that its customers were impacted at the time, the company decided to rotate credentials and rebuild compromised infrastructure.
See the full report here: https://www.bleepingcomputer.com/news/security/jumpcloud-discloses-breach-by-state-backed-apt-hacking-group/
Meet NoEscape: Avaddon ransomware gang's likely successor
The new NoEscape ransomware operation is believed to be a rebrand of Avaddon, a ransomware gang that shut down and released its decryption keys in 2021. NoEscape launched in June 2023 when it began targeting the enterprise in double-extortion attacks. As part of these attacks, the threat actors steal data and encrypt files on Windows, Linux, and VMware ESXi servers. The threat actors then threaten to publicly release stolen data if a ransom is not paid.
See the full report here: https://www.bleepingcomputer.com/news/security/meet-noescape-avaddon-ransomware-gangs-likely-successor/
Police arrests Ukrainian scareware developer after 10-year hunt
The Spanish National Police has apprehended a Ukrainian national wanted internationally for his involvement in a scareware operation spanning from 2006 to 2011. This extensive operation led to the infection of hundreds of thousands of computers with malicious software designed to display pop-up messages intended to mislead the users into thinking their computers were infected by malware.
See the full report here: https://www.bleepingcomputer.com/news/security/police-arrests-ukrainian-scareware-developer-after-10-year-hunt/
Critical ColdFusion flaws exploited in attacks to drop webshells
Hackers are actively exploiting two ColdFusion vulnerabilities to bypass authentication and remotely execute commands to install webshells on vulnerable servers. The active exploitation was observed by cybersecurity researchers, which says threat actors are chaining together exploits for an access control bypass vulnerability (CVE-2023-29298) and what appears to be CVE-2023-38203, a critical remote code execution vulnerability.
See the full report here: https://www.bleepingcomputer.com/news/security/critical-coldfusion-flaws-exploited-in-attacks-to-drop-webshells/
Hackers exploiting critical WordPress WooCommerce Payments bug
Hackers are conducting widespread exploitation of a critical WooCommerce Payments plugin to gain the privileges of any users, including administrators, on vulnerable WordPress installation. On March 23, 2023, the developers released version 5.6.2 to fix the critical 9.8-rated vulnerability tracked as CVE-2023-28121. The flaw affects WooCommerce Payment plugin versions 4.8.0 and higher, with it being fixed in versions 4.8.2, 4.9.1, 5.0.4, 5.1.3, 5.2.2, 5.3.1, 5.4.1, 5.5.2, 5.6.2, and later.
See the full report here: https://www.bleepingcomputer.com/news/security/hackers-exploiting-critical-wordpress-woocommerce-payments-bug/
Microsoft Bug Allowed Hackers to Breach Over Two Dozen Organizations via Forged Azure AD Tokens
Microsoft stated that a validation error in its source code allowed for Azure Active Directory (Azure AD) tokens to be forged by a malicious actor known as Storm-0558 using a Microsoft account (MSA) consumer signing key to breach two dozen organizations.
See the full report here: https://thehackernews.com/2023/07/microsoft-bug-allowed-hackers-to-breach.html
WormGPT: New AI Tool Allows Cybercriminals to Launch Sophisticated Cyber Attacks
A new generative AI cybercrime tool called WormGPT has been advertised on underground forums as a way for adversaries to launch sophisticated phishing and business email compromise (BEC) attacks. This tool presents itself as a blackhat alternative to GPT models.
See the full report here: https://thehackernews.com/2023/07/wormgpt-new-ai-tool-allows.html
Cybercriminals Exploit Microsoft Word Vulnerabilities to Deploy LokiBot Malware
Microsoft Word documents exploiting known remote code execution flaws are being used as phishing lures to drop malware called LokiBot on compromised systems. LokiBot, also known as Loki PWS, has been a well-known information-stealing Trojan active since 2015. It primarily targets Windows systems and aims to gather sensitive information from infected machines.
See the full report here: https://thehackernews.com/2023/07/cybercriminals-exploit-microsoft-word.html
Malicious USB Drives Targetinging Global Targets with SOGU and SNOWYDRIVE Malware
Cyber attacks using infected USB infection drives as an initial access vector have witnessed a three-fold increase in the first half of 2023, new findings, detail two such campaigns – SOGU and SNOWYDRIVE – targeting both public and private sector entities across the world.
See the full report here: https://thehackernews.com/2023/07/malicious-usb-drives-targetinging.html
Genesis Market infrastructure and inventory sold on hacker forum
The administrators of the Genesis Market for stolen credentials announced on a hacker forum that they sold the store and a new owner would get the reins “next month.” This announcement comes about three months after law enforcement seized some of the marketplace’s domains on the clearnet in Operation Cookie Monster.
See the full report here: https://www.bleepingcomputer.com/news/security/genesis-market-infrastructure-and-inventory-sold-on-hacker-forum/
Gamaredon hackers start stealing data 30 minutes after a breach
Ukraine's Computer Emergency Response Team (CERT-UA) is warning that the Gamaredon hacking operates in rapid attacks, stealing data from breached systems in under an hour. Gamaredon, aka Armageddon, UAC-0010, and Shuckworm, is a Russian, state-sponsored cyber-espionage hacking group with cybersecurity researchers linking them to the FSB (Russian Federal Security Service) and having members who are former SSU officers who defected to Russia in 2014.
See the full report here: https://www.bleepingcomputer.com/news/security/gamaredon-hackers-start-stealing-data-30-minutes-after-a-breach/
Thousands of images on Docker Hub leak auth secrets
Researchers at the RWTH Aachen University in Germany published a study revealing that tens of thousands of container images hosted on Docker Hub contain confidential secrets, exposing software, online platforms, and users to a massive attack surface.
See the full report here: https://www.bleepingcomputer.com/news/security/thousands-of-images-on-docker-hub-leak-auth-secrets-private-keys/
Cisco SD-WAN vManage impacted by unauthenticated REST API access
The Cisco SD-WAN vManage management software is impacted by a flaw that allows an unauthenticated, remote attacker to gain read or limited write permissions to the configuration of the affected instance. Cisco SD-WAN vManage is a cloud-based solution allowing organizations to design, deploy, and manage distributed networks across multiple locations.
See the full report here: https://www.bleepingcomputer.com/news/security/cisco-sd-wan-vmanage-impacted-by-unauthenticated-rest-api-access/
Fake Linux vulnerability exploit drops data-stealing malware
Cybersecurity researchers and threat actors are targeted by a fake proof of concept (PoC) CVE-2023-35829 exploit that installs a Linux password-stealing malware. Analysts discovered the malicious PoC during their routine scans when detection systems flagged irregularities such as unexpected network connections, unauthorized system access attempts, and atypical data transfers. T
See the full report here: https://www.bleepingcomputer.com/news/security/fake-linux-vulnerability-exploit-drops-data-stealing-malware/
Zimbra urges admins to manually fix zero-day exploited in attacks
Zimbra urged admins to manually fix a zero-day vulnerability actively exploited to target and compromise Zimbra Collaboration Suite (ZCS) email servers.
See the full report here: https://www.bleepingcomputer.com/news/security/zimbra-urges-admins-to-manually-fix-zero-day-exploited-in-attacks/
Source code for BlackLotus Windows UEFI malware leaked on GitHub
The source code for the BlackLotus UEFI bootkit has leaked online, allowing greater insight into a malware that has caused great concern among the enterprise, governments, and the cybersecurity community. BlackLotus is a Windows-targeting UEFI bootkit that bypasses Secure Boot on fully patched Windows 11 installs, evades security software, persists on an infected system, and executes payloads with the highest level of privileges in the operating system.
See the full report here: https://www.bleepingcomputer.com/news/security/source-code-for-blacklotus-windows-uefi-malware-leaked-on-github/
Shutterfly says Clop ransomware attack did not impact customer data
Shutterfly, an online retail and photography manufacturing platform, is among the latest victims hit by Clop ransomware. Over the last few months, Clop ransomware gang has been exploiting a vulnerability in the MOVEit File Transfer utility to breach hundreds of companies to steal their data and attempt extortion against them.
See the full report here: https://www.bleepingcomputer.com/news/security/shutterfly-says-clop-ransomware-attack-did-not-impact-customer-data/
PicassoLoader Malware Used in Ongoing Attacks on Ukraine and Poland
Government entities, military organizations, and civilian users in Ukraine and Poland have been targeted as part of a series of campaigns designed to steal sensitive data and gain persistent remote access to the infected systems. The intrusion set, which stretches from April 2022 to July 2023, leverages phishing lures and decoy documents to deploy a downloader malware called PicassoLoader, which acts as a conduit to launch Cobalt Strike Beacon and njRAT.
See the full report here: https://thehackernews.com/2023/07/picassoloader-malware-used-in-ongoing.html
TeamTNT's Silentbob Botnet Infecting 196 Hosts in Cloud Attack Campaign
As many as 196 hosts have been infected as part of an aggressive cloud campaign mounted by the TeamTNT group called Silentbob. The botnet run by TeamTNT has set its sights on Docker and Kubernetes environments, Redis servers, Postgres databases, Hadoop clusters, Tomcat and Nginx servers, Weave Scope, SSH, and Jupyter applications.
See the full report here: https://thehackernews.com/2023/07/teamtnts-silentbob-botnet-infecting-196.html
Blinken meets Chinese diplomat Wang amid hacking accusations
The US Secretary of State has held talks with a senior Chinese in the latest meeting aimed at addressing cybersecurity tensions between China and the United States. The discussions on the sidelines of the Association of Southeast Asian Nations (ASEAN) summit in Indonesia came one day after Microsoft accused hackers linked to China of accessing the emails of US and other Western officials.
See the full report here: https://www.aljazeera.com/news/2023/7/13/blinken-meets-chinese-diplomat-wang-amid-hacking-accusations
ZeroFox Intelligence Reports:
ZeroFox Intelligence Flash Report - New Gold-Backed Currency Potentially Introduced by BRICS
In this flash report, ZeroFox’s Geopolitical Working Group provides updates and analysis around recent news that the BRICS countries (Brazil, Russia, India, China, and South Africa) plan to introduce a new trading currency, which will be backed by gold.
Report: https://zerofox.com/advisories/21327
ZeroFox Intelligence Brief - Analysis of Clop Activity
In this ZeroFox Intelligence Brief, ZeroFox researchers provide an overview of Clop activity, including the timing of campaigns and typical timescales implemented when extorting victims.
Report: https://zerofox.com/advisories/21263
Tags: tlp:clear, all industries, global