zerofox logo
Advisories

Threat Intelligence Bulletin: 07/14/2023 - 07/20/2023

|by Alpha Team

banner image

ZeroFox Weekly Threat Bulletin: 07/14/2023 - 07/20/2023


ZeroFox Daily Intelligence:


ZeroFox Daily Intelligence Brief - July 20, 2023

Brief Highlights -ZeroFox Intelligence: Clop Releases Exfiltrated Data On Surface Web Domain

  • Adobe Rolls Out New Patches for Actively Exploited ColdFusion Vulnerability
  • VirusTotal Data Breach Exposes Registered Customer Information
  • Ukraine Takes Down Massive Bot Farm, Seizes 150,000 SIM Cards
  • Data broker / initial-access broker / hacktivist group: UserSec: Claims to have defaced the website of London City Airport and Anonymous Italia: DDoS attack on French hotel La Voile d'Or
  • Vulnerabilities: CVE-2023-28531 and CVE-2023-37964
  • Exploits: CVE-2009-3548 and CVE-2019-12840
  • Breaches: BreachForums/XSS: Imgur Data Breach and BreachForums/XSS: Canva Data Breach_Additional Dataset

Report: https://zerofox.com/advisories/21308


ZeroFox Daily Intelligence Brief - July 19, 2023

Brief Highlights

  • Citrix Urges Immediate Action to Address Critical Vulnerability in NetScaler ADC and Gateway
  • VirusTotal Data Breach Exposes Registered Customer Information
  • CISA Orders Federal Agencies to Mitigate Zero-Days Abused in NATO Phishing Attacks
  • Data broker / initial-access broker / hacktivist group: Private Telegram Channel: Exposure of U.S. Senate and Staff Credentials and BlackPass: Compromised E-commerce Account of Heineken Executive for Sale
  • Vulnerabilities: CVE-2023-32623 and CVE-2023-3755
  • Exploits: CVE-2017-11610 and CVE-2017-8464
  • Breaches: BreachForums/XSS: Aternos Data Breach and BreachForums/XSS: Manga Traders Data Breach

Report: https://zerofox.com/advisories/21286


ZeroFox Daily Intelligence Brief - July 18, 2023

Brief Highlights

  • ZeroFox Intelligence Brief: Analysis of Clop Activity
  • JumpCloud Discloses Breach by State-Backed Hackers
  • NSA and CISA Release Guidelines for Secure Network Slicing
  • Data broker / initial-access broker / hacktivist group: Exploit user twofactor and Anonymous Sudan
  • Vulnerabilities: CVE-2023-27390 and CVE-2023-31194
  • Exploits: CVE-2006-5143 and CVE-2006-1495
  • Breaches: Credit Card Data Breach: BreachForums/XSS: Petflow Data Breach and BreachForums/XSS: Psyonix Data Breach

Report: https://zerofox.com/advisories/21264


ZeroFox Daily Intelligence Brief - July 17, 2023

Brief Highlights

  • Russia-Backed Gamaredon Hackers Steal Data Within an Hour After a Breach
  • Dark Web Domain and Infrastructure of Genesis Market Sold
  • Tens of Thousands of Public Docker Container Images Expose Secret Keys
  • Vulnerabilities: CVE-2023-2156 and CVE-2023-36813
  • Breaches: Credit Card Data Breach and BreachForums/Leakforums: Eternity Modern Data Breach

Report: https://zerofox.com/advisories/21255


ZeroFox Daily Intelligence Brief - July 14, 2023

Brief Highlights

  • Ongoing PicassoLoader Campaign Targets Entities in Ukraine and Poland
  • CISA Advisory: Mitigate Risks to Rockwell Automation Modules
  • Cisco SD-WAN vManage Vulnerability Allows Unauthorized API Access
  • Data broker / initial-access broker / hacktivist group: BlackDragonSec and Anonymous Sudan
  • Vulnerabilities: CVE-2022-33324 and CVE-2023-3668
  • Exploits: CVE-2013-4975 and CVE-2011-3416
  • Breaches: BreachForums/XSS: Whitepages Data Breach and Coinbulb Data Breach

Report: https://zerofox.com/advisories/21244


Breach Disclosures:


DLH

An alleged data breach at DLH – a U.S.-based website that provides gaming information, gaming reviews, cheats, and news – exposed 3,154,725 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21326


Suba Games

An alleged data breach at Suba Games – a Canada-based online games publisher – exposed 3,404,698 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21325


GameSalad

An alleged data breach at GameSalad – a U.S.-based platform that allows rapid design, publish and distribute games – exposed 1,108,240 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21324


GameTuts

An alleged data breach at GameTuts – an Australia-based online game developing and tutorial sharing community – exposed 1,121,947 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21323


Hacker

An alleged data breach at Hacker – a South Korea-based electronics retail store – exposed 1,401,981 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21322


Nihonomaru

An alleged data breach at Nihonomaru – a Netherlands-based online anime and manga discussions community – exposed 1,562,289 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21321


Leet

An alleged data breach at Leet – a U.S.-based multiplayer for Minecraft PE – exposed 1,902,117 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21320


Imgur

An alleged data breach at Imgur – a U.S.-based online content hosting site to view and share content such as images, GIFs, memes, videos and reviews – exposed 1,752,915 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21319


Avvo_Additional Dataset

An alleged data breach at Avvo – a U.S.-based online marketplace for legal services – exposed 1,833,867 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21318


Canva_Additional Dataset

An alleged data breach at Canva – an Australia-based graphic design platform – exposed 903,872 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21317


CoreVin

An alleged data breach at CoreVin – a Portugal-based company that provides audit and consultancy service in wine regulations – exposed 732,512 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21306


Fitbit

An alleged data breach at Fitbit – a U.S.-based consumer electronics and fitness company – exposed 1,999,973 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21305


Over-blog

An alleged data breach at Over-blog – a France-based blog service – exposed 1,935,329 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21304


Shadi.com

An alleged data breach at Shadi.com – a U.S.-based matchmaking company – exposed 2,023,212 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21303


ClixSense

An alleged data breach at ClixSense now known as ySense – a U.S.-based online money making site – exposed 2,222,498 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21302


Kaidown

An alleged data breach at Kaidown – a Thailand-based gaming site – exposed 860,919 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21301


Funimation

An alleged data breach at Funimation – a U.S.-based anime streaming platform – exposed 848,051 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21300


Mpgh

An alleged data breach at Mpgh – a U.S.-based marketplace for gamers – exposed 2,529,887 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21299


TheWarinc

An alleged data breach at TheWarinc – a U.S.-based online gaming site – exposed 873,801 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21298


Manga Traders

An alleged data breach at Manga Traders – a U.S.-based online site for english translated manga – exposed 845,232 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21297


Aternos

An alleged data breach at Aternos – a U.S.-based Minecraft server – exposed 851,589 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21296


New Zealand Society of Conveyancers

An alleged data breach at New Zealand Society of Conveyancers – a New Zealand-based company that operates in legal process of transferring property or land ownership – exposed 59,801 email addresses and/or usernames, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21295


Mmorg.net

An alleged data breach at Mmorg.net – an online gaming site – exposed 2,346,459 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21294


Poloniex

An alleged data breach at Poloniex – a U.S.-based online crypto trading and exchange platfrom – exposed 952,456 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21281


Eternity Modern

An alleged data breach at Eternity Modern – a U.S.-based furniture manufacturer and design company – exposed 36,397 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21272


Making Fun

An alleged data breach at Making Fun – a U.S.-based game developer and publisher – exposed 87,174 email addresses, usernames and hashed passwords, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21271


Gamecom

An alleged data breach at Gamecom – a China-based gaming forum – exposed 1,004,886 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21270


Elance

An alleged data breach at Elance – a U.S.-based online marketplace for freelancers – exposed 1,105,658 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21269


NextGenUpdate

An alleged data breach at NextGenUpdate – a U.S.-based video game website – exposed 995,704 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21268


LotRO

An alleged data breach at LotRO – a U.S.-based online multiplayer game – exposed 898,578 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21267


Psyonix

An alleged data breach at Psyonix – a U.S.-based video game developer – exposed 1,003,235 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21266


Petflow

An alleged data breach at Petflow – a U.S.-based online retailer of pet food – exposed 956,505 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21265


Qiannao

An alleged data breach at Qiannao – a China-based E-commerce website – exposed 661,925 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21254


Whitepages_Additional Dataset

An alleged data breach at Whitepages – a U.S.-based company that provides online directory services, fraud screening, and identity verification – exposed 672,574 email addresses, which were subsequently shared on a deep web platform.

Report: https://zerofox.com/advisories/21243


Breaking News:


US govt bans European spyware vendors Intellexa and Cytrox

The U.S. government has banned European commercial spyware manufacturers Intellexa and Cytrox, citing risks to U.S. national security and foreign policy interests.This decision was motivated by the four companies' involvement in trafficking cyber exploits used to gain unauthorized access to the devices of high-risk individuals worldwide, threatening their security and privacy.

See the full report here: https://www.bleepingcomputer.com/news/security/us-govt-bans-european-spyware-vendors-intellexa-and-cytrox/


Ukraine takes down massive bot farm, seizes 150,000 SIM cards

The Cyber ​​Police Department of the National Police of Ukraine dismantled another massive bot farm linked to more than 100 individuals after searches at almost two dozen locations. The bots were used to push Russian propaganda justifying Russia's war in Ukraine, to disseminate illegal content and personal information, and in various other fraudulent activities.

See the full report here: https://www.bleepingcomputer.com/news/security/ukraine-takes-down-massive-bot-farm-seizes-150-000-sim-cards/


OpenAI credentials stolen by the thousands for sale on the dark web

Threat actors are showing an increased interest in generative artificial intelligence tools, with hundreds of thousands of OpenAI credentials for sale on the dark web and access to a malicious alternative for ChatGPT.

See the full report here: https://www.bleepingcomputer.com/news/security/openai-credentials-stolen-by-the-thousands-for-sale-on-the-dark-web/


Estée Lauder beauty giant breached by two ransomware gangs

Two ransomware actors, ALPHV/BlackCat and Clop, have listed beauty company Estée Lauder on their data leak sites as a victim of separate attacks. In a disgruntled message to the company, the BlackCat gang mocked the security measures, saying that they were still present on the network.

See the full report here: https://www.bleepingcomputer.com/news/security/est-e-lauder-beauty-giant-breached-by-two-ransomware-gangs/


Chinese APT41 Hackers Target Mobile Devices with New WyrmSpy and DragonEgg Spyware

The prolific China-linked nation-state actor known as APT41 has been linked to two previously undocumented strains of Android spyware called WyrmSpy and DragonEgg. APT41, also tracked under the names Axiom, Blackfly, Brass Typhoon (formerly Barium), Bronze Atlas, HOODOO, Wicked Panda, and Winnti, is known to be operational since at least 2007, targeting a wide range of industries to conduct intellectual property theft.

See the full report here: https://thehackernews.com/2023/07/chinese-apt41-hackers-target-mobile.html


CISA and NSA Issue New Guidance to Strengthen 5G Network Slicing Against Threats

U.S. cybersecurity and intelligence agencies have released a set of recommendations to address security concerns with 5G standalone network slicing and harden them against possible threats. In the latest guidance, the authorities cited denial-of-service attacks on the signaling plane, misconfiguration attacks, and adversary-in-the-middle attacks as the three prominent 5G threat vectors, noting that a zero trust architecture (ZTA) can help secure network deployments.

See the full report here: https://thehackernews.com/2023/07/cisa-and-nsa-issue-new-guidance-to.html


Adobe Rolls Out New Patches for Actively Exploited ColdFusion Vulnerability

Adobe has released a fresh round of updates to address an incomplete fix for a recently disclosed ColdFusion flaw that has come under active exploitation in the wild. The critical shortcoming, tracked as CVE-2023-38205 (CVSS score: 7.5), has been described as an instance of improper access control that could result in a security bypass.

See the full report here: https://thehackernews.com/2023/07/adobe-rolls-out-new-patches-for.html


New P2PInfect Worm Targeting Redis Servers on Linux and Windows Systems

Cybersecurity researchers have uncovered a new cloud targeting, peer-to-peer (P2P) worm called P2PInfect that targets vulnerable Redis instances for follow-on exploitation. P2PInfect exploits Redis servers running on both Linux and Windows Operating Systems making it more scalable and potent than other worms. It's estimated that as many as 934 unique Redis systems may be vulnerable to the threat. The first known instance of P2PInfect was detected on July 11, 2023.

See the full report here: https://thehackernews.com/2023/07/new-p2pinfect-worm-targeting-redis.html


Pakistani Entities Targeted in Sophisticated Attack Deploying ShadowPad Malware

An unidentified threat actor compromised an application used by multiple entities in Pakistan to deliver ShadowPad, a successor to the PlugX backdoor that's commonly associated with Chinese hacking crews. Targets included a Pakistan government entity, a public sector bank, and a telecommunications provider. The infections took place between mid-February 2022 and September 2022.

See the full report here: https://thehackernews.com/2023/07/pakistani-entities-targeted-in.html


Google Cloud Build bug lets hackers launch supply chain attacks

A critical design flaw in the Google Cloud Build service can let attackers escalate privileges, providing them with almost nearly-full and unauthorized access to Google Artifact Registry code repositories.

See the full report here: https://www.bleepingcomputer.com/news/security/google-cloud-build-bug-lets-hackers-launch-supply-chain-attacks/


FIN8 deploys ALPHV ransomware using Sardonic malware variant

A financially motivated cybercrime gang has been observed deploying BlackCat ransomware payloads on networks backdoored using a revamped Sardonic malware version. Tracked as FIN8 (aka Syssphinx), this threat actor has been actively operating since at least January 2016, focusing on targeting industries such as retail, restaurants, hospitality, healthcare, and entertainment.

See the full report here: https://www.bleepingcomputer.com/news/security/fin8-deploys-alphv-ransomware-using-sardonic-malware-variant/


New critical Citrix ADC and Gateway flaw exploited as zero-day

Citrix is alerting customers of a critical-severity vulnerability (CVE-2023-3519) in NetScaler ADC and NetScaler Gateway that already has exploits in the wild, and “strongly urges” to install updated versions without delay. The security issue may be the same one advertised earlier this month on a hacker forum as a zero-day vulnerability.

See the full report here: https://www.bleepingcomputer.com/news/security/new-critical-citrix-adc-and-gateway-flaw-exploited-as-zero-day/


Cybersecurity firm Sophos impersonated by new SophosEncrypt ransomware

Cybersecurity vendor Sophos is being impersonated by a new ransomware-as-a-service called SophosEncrypt, with the threat actors using the company name for their operation. The ransomware was initially thought to be part of a red team exercise by Sophos. However, the Sophos X-Ops team tweeted that they did not create the encryptor and that they are investigating its launch.

See the full report here: https://www.bleepingcomputer.com/news/security/cybersecurity-firm-sophos-impersonated-by-new-sophosencrypt-ransomware/


U.S. preparing Cyber Trust Mark for more secure smart devices

A new cybersecurity certification and labeling program called U.S. Cyber Trust Mark is being shaped to help U.S. consumers choose connected devices that are more secure and resilient to hacker attacks. A proposal from the Federal Communications Commission, the program is expected to roll out next year with smart device vendors committing to it voluntarily. Major vendors and makers in the U.S. have already announced their participation. Among them Amazon, Google, Best Buy , LG Electronics U.S.A., Logitech, and Samsung Electronics.

See the full report here: https://www.bleepingcomputer.com/news/security/us-preparing-cyber-trust-mark-for-more-secure-smart-devices/


FBI: Tech support scams now use shipping companies to collect cash

FBI warns of a surge in tech support scams targeting the elderly across the United States and urging victims to dispatch cash concealed within magazines or similar items through shipping firms. While tech support scams have been around for years, the FBI says this is a departure from scammers' conventional tactics of soliciting their targets to send money using bank transfers, cryptocurrencies, or gift cards.

See the full report here: https://www.bleepingcomputer.com/news/security/fbi-tech-support-scams-now-use-shipping-companies-to-collect-cash/


Hackers Exploit WebAPK to Deceive Android Users into Installing Malicious Apps

Threat actors are taking advantage of Android's WebAPK technology to trick unsuspecting users into installing malicious web apps on Android phones that are designed to capture sensitive personal information. The attack began with victims receiving SMS messages suggesting the need to update a mobile banking application," researchers stated in an analysis released last week. The link contained in the message led to a site that used WebAPK technology to install a malicious application on the victim's device.

See the full report here: https://thehackernews.com/2023/07/hackers-exploit-webapk-to-deceive.html


Cybercriminals Exploiting WooCommerce Payments Plugin Flaw to Hijack Websites

Threat actors are actively exploiting a recently disclosed critical security flaw in the WooCommerce Payments WordPress plugin as part of a massive targeted campaign. The flaw, tracked as CVE-2023-28121 (CVSS score: 9.8), is a case of authentication bypass that enables unauthenticated attackers to impersonate arbitrary users and perform some actions as the impersonated user, including an administrator, potentially leading to site takeover.

See the full report here: https://thehackernews.com/2023/07/cybercriminals-exploiting-woocommerce.html


Owner of BreachForums Pleads Guilty to Cybercrime and Child Pornography Charges

The owner of the now-defunct BreachForums website, has pleaded guilty to charges related to his operation of the cybercrime forum as well as having child pornography images.

See the full report here: https://thehackernews.com/2023/07/owner-of-breachforums-pleads-guilty-to.html


JumpCloud discloses breach by state-backed APT hacking group

US-based enterprise software firm JumpCloud says a state-backed hacking group breached its systems almost one month ago as part of a highly targeted attack focused on a limited set of customers. The company discovered the incident on June 27 2023, one week after the attackers breached its systems via a spear-phishing attack. While JumpCloud did not find evidence that its customers were impacted at the time, the company decided to rotate credentials and rebuild compromised infrastructure.

See the full report here: https://www.bleepingcomputer.com/news/security/jumpcloud-discloses-breach-by-state-backed-apt-hacking-group/


Meet NoEscape: Avaddon ransomware gang's likely successor

The new NoEscape ransomware operation is believed to be a rebrand of Avaddon, a ransomware gang that shut down and released its decryption keys in 2021. NoEscape launched in June 2023 when it began targeting the enterprise in double-extortion attacks. As part of these attacks, the threat actors steal data and encrypt files on Windows, Linux, and VMware ESXi servers. The threat actors then threaten to publicly release stolen data if a ransom is not paid.

See the full report here: https://www.bleepingcomputer.com/news/security/meet-noescape-avaddon-ransomware-gangs-likely-successor/


Police arrests Ukrainian scareware developer after 10-year hunt

The Spanish National Police has apprehended a Ukrainian national wanted internationally for his involvement in a scareware operation spanning from 2006 to 2011. This extensive operation led to the infection of hundreds of thousands of computers with malicious software designed to display pop-up messages intended to mislead the users into thinking their computers were infected by malware.

See the full report here: https://www.bleepingcomputer.com/news/security/police-arrests-ukrainian-scareware-developer-after-10-year-hunt/


Critical ColdFusion flaws exploited in attacks to drop webshells

Hackers are actively exploiting two ColdFusion vulnerabilities to bypass authentication and remotely execute commands to install webshells on vulnerable servers. The active exploitation was observed by cybersecurity researchers, which says threat actors are chaining together exploits for an access control bypass vulnerability (CVE-2023-29298) and what appears to be CVE-2023-38203, a critical remote code execution vulnerability.

See the full report here: https://www.bleepingcomputer.com/news/security/critical-coldfusion-flaws-exploited-in-attacks-to-drop-webshells/


Hackers exploiting critical WordPress WooCommerce Payments bug

Hackers are conducting widespread exploitation of a critical WooCommerce Payments plugin to gain the privileges of any users, including administrators, on vulnerable WordPress installation. On March 23, 2023, the developers released version 5.6.2 to fix the critical 9.8-rated vulnerability tracked as CVE-2023-28121. The flaw affects WooCommerce Payment plugin versions 4.8.0 and higher, with it being fixed in versions 4.8.2, 4.9.1, 5.0.4, 5.1.3, 5.2.2, 5.3.1, 5.4.1, 5.5.2, 5.6.2, and later.

See the full report here: https://www.bleepingcomputer.com/news/security/hackers-exploiting-critical-wordpress-woocommerce-payments-bug/


Microsoft Bug Allowed Hackers to Breach Over Two Dozen Organizations via Forged Azure AD Tokens

Microsoft stated that a validation error in its source code allowed for Azure Active Directory (Azure AD) tokens to be forged by a malicious actor known as Storm-0558 using a Microsoft account (MSA) consumer signing key to breach two dozen organizations.

See the full report here: https://thehackernews.com/2023/07/microsoft-bug-allowed-hackers-to-breach.html


WormGPT: New AI Tool Allows Cybercriminals to Launch Sophisticated Cyber Attacks

A new generative AI cybercrime tool called WormGPT has been advertised on underground forums as a way for adversaries to launch sophisticated phishing and business email compromise (BEC) attacks. This tool presents itself as a blackhat alternative to GPT models.

See the full report here: https://thehackernews.com/2023/07/wormgpt-new-ai-tool-allows.html


Cybercriminals Exploit Microsoft Word Vulnerabilities to Deploy LokiBot Malware

Microsoft Word documents exploiting known remote code execution flaws are being used as phishing lures to drop malware called LokiBot on compromised systems. LokiBot, also known as Loki PWS, has been a well-known information-stealing Trojan active since 2015. It primarily targets Windows systems and aims to gather sensitive information from infected machines.

See the full report here: https://thehackernews.com/2023/07/cybercriminals-exploit-microsoft-word.html


Malicious USB Drives Targetinging Global Targets with SOGU and SNOWYDRIVE Malware

Cyber attacks using infected USB infection drives as an initial access vector have witnessed a three-fold increase in the first half of 2023, new findings, detail two such campaigns – SOGU and SNOWYDRIVE – targeting both public and private sector entities across the world.

See the full report here: https://thehackernews.com/2023/07/malicious-usb-drives-targetinging.html


Genesis Market infrastructure and inventory sold on hacker forum

The administrators of the Genesis Market for stolen credentials announced on a hacker forum that they sold the store and a new owner would get the reins “next month.” This announcement comes about three months after law enforcement seized some of the marketplace’s domains on the clearnet in Operation Cookie Monster.

See the full report here: https://www.bleepingcomputer.com/news/security/genesis-market-infrastructure-and-inventory-sold-on-hacker-forum/


Gamaredon hackers start stealing data 30 minutes after a breach

Ukraine's Computer Emergency Response Team (CERT-UA) is warning that the Gamaredon hacking operates in rapid attacks, stealing data from breached systems in under an hour. Gamaredon, aka Armageddon, UAC-0010, and Shuckworm, is a Russian, state-sponsored cyber-espionage hacking group with cybersecurity researchers linking them to the FSB (Russian Federal Security Service) and having members who are former SSU officers who defected to Russia in 2014.

See the full report here: https://www.bleepingcomputer.com/news/security/gamaredon-hackers-start-stealing-data-30-minutes-after-a-breach/


Thousands of images on Docker Hub leak auth secrets

Researchers at the RWTH Aachen University in Germany published a study revealing that tens of thousands of container images hosted on Docker Hub contain confidential secrets, exposing software, online platforms, and users to a massive attack surface.

See the full report here: https://www.bleepingcomputer.com/news/security/thousands-of-images-on-docker-hub-leak-auth-secrets-private-keys/


Cisco SD-WAN vManage impacted by unauthenticated REST API access

The Cisco SD-WAN vManage management software is impacted by a flaw that allows an unauthenticated, remote attacker to gain read or limited write permissions to the configuration of the affected instance. Cisco SD-WAN vManage is a cloud-based solution allowing organizations to design, deploy, and manage distributed networks across multiple locations.

See the full report here: https://www.bleepingcomputer.com/news/security/cisco-sd-wan-vmanage-impacted-by-unauthenticated-rest-api-access/


Fake Linux vulnerability exploit drops data-stealing malware

Cybersecurity researchers and threat actors are targeted by a fake proof of concept (PoC) CVE-2023-35829 exploit that installs a Linux password-stealing malware. Analysts discovered the malicious PoC during their routine scans when detection systems flagged irregularities such as unexpected network connections, unauthorized system access attempts, and atypical data transfers. T

See the full report here: https://www.bleepingcomputer.com/news/security/fake-linux-vulnerability-exploit-drops-data-stealing-malware/


Zimbra urges admins to manually fix zero-day exploited in attacks

Zimbra urged admins to manually fix a zero-day vulnerability actively exploited to target and compromise Zimbra Collaboration Suite (ZCS) email servers.

See the full report here: https://www.bleepingcomputer.com/news/security/zimbra-urges-admins-to-manually-fix-zero-day-exploited-in-attacks/


Source code for BlackLotus Windows UEFI malware leaked on GitHub

The source code for the BlackLotus UEFI bootkit has leaked online, allowing greater insight into a malware that has caused great concern among the enterprise, governments, and the cybersecurity community. BlackLotus is a Windows-targeting UEFI bootkit that bypasses Secure Boot on fully patched Windows 11 installs, evades security software, persists on an infected system, and executes payloads with the highest level of privileges in the operating system.

See the full report here: https://www.bleepingcomputer.com/news/security/source-code-for-blacklotus-windows-uefi-malware-leaked-on-github/


Shutterfly says Clop ransomware attack did not impact customer data

Shutterfly, an online retail and photography manufacturing platform, is among the latest victims hit by Clop ransomware. Over the last few months, Clop ransomware gang has been exploiting a vulnerability in the MOVEit File Transfer utility to breach hundreds of companies to steal their data and attempt extortion against them.

See the full report here: https://www.bleepingcomputer.com/news/security/shutterfly-says-clop-ransomware-attack-did-not-impact-customer-data/


PicassoLoader Malware Used in Ongoing Attacks on Ukraine and Poland

Government entities, military organizations, and civilian users in Ukraine and Poland have been targeted as part of a series of campaigns designed to steal sensitive data and gain persistent remote access to the infected systems. The intrusion set, which stretches from April 2022 to July 2023, leverages phishing lures and decoy documents to deploy a downloader malware called PicassoLoader, which acts as a conduit to launch Cobalt Strike Beacon and njRAT.

See the full report here: https://thehackernews.com/2023/07/picassoloader-malware-used-in-ongoing.html


TeamTNT's Silentbob Botnet Infecting 196 Hosts in Cloud Attack Campaign

As many as 196 hosts have been infected as part of an aggressive cloud campaign mounted by the TeamTNT group called Silentbob. The botnet run by TeamTNT has set its sights on Docker and Kubernetes environments, Redis servers, Postgres databases, Hadoop clusters, Tomcat and Nginx servers, Weave Scope, SSH, and Jupyter applications.

See the full report here: https://thehackernews.com/2023/07/teamtnts-silentbob-botnet-infecting-196.html


Blinken meets Chinese diplomat Wang amid hacking accusations

The US Secretary of State has held talks with a senior Chinese in the latest meeting aimed at addressing cybersecurity tensions between China and the United States. The discussions on the sidelines of the Association of Southeast Asian Nations (ASEAN) summit in Indonesia came one day after Microsoft accused hackers linked to China of accessing the emails of US and other Western officials.

See the full report here: https://www.aljazeera.com/news/2023/7/13/blinken-meets-chinese-diplomat-wang-amid-hacking-accusations


ZeroFox Intelligence Reports:


ZeroFox Intelligence Flash Report - New Gold-Backed Currency Potentially Introduced by BRICS

In this flash report, ZeroFox’s Geopolitical Working Group provides updates and analysis around recent news that the BRICS countries (Brazil, Russia, India, China, and South Africa) plan to introduce a new trading currency, which will be backed by gold.

Report: https://zerofox.com/advisories/21327


ZeroFox Intelligence Brief - Analysis of Clop Activity

In this ZeroFox Intelligence Brief, ZeroFox researchers provide an overview of Clop activity, including the timing of campaigns and typical timescales implemented when extorting victims.

Report: https://zerofox.com/advisories/21263


Tags: tlp:clear,  all industries,  global