ZeroFox Daily Intelligence Brief - August 01, 2023
|by Alpha Team

ZeroFox Daily Intelligence Brief - August 01, 2023
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- ZeroFox: Brand Protection Trend Report
- Unsecured Canon Inkjet Bug Could Put Users at Risk
- Spear-Phishing Campaign Deploying Android Spyware
- Data broker / initial-access broker / hacktivist group: Killnet and Anonymous Sudan: Claim to have DDoS attacked the London Metal Exchange (LME) and Telegram channel 0x_dump: Posted data from identity management software company Avatier
- Vulnerabilities: CVE-2023-0009 and CVE-2023-20593
- Exploits: CVE-2016-4997 and CVE-2015-3113
- Breaches: Telegram: 'SEGA 2006 @segacloud.rar' and BreachForums/XSS:HauteLook Data Breach
ZeroFox: Brand Protection Trend Report
ZeroFox Intelligence has noted a significant increase in external cybersecurity threats to brands in the second quarter of 2023, relative to the first quarter. The most significant change related to fraud, scams, and piracy—with verified alerts increasing 35 percent across the ZeroFox customer base. “Money flipping” scams, impersonations, and spoofed domains continue to lure users. The advisory mentions steps taken by various platforms to deal with such illegitimate activities and also recommends measures people can adopt to protect themselves.
Unsecured Canon Inkjet Bug Could Put Users at Risk
Canon has warned inkjet printer users that their Wi-Fi connection settings are not entirely wiped during initialization, leaving data vulnerable to unauthorized access. The flaw could affect home, office, and large format printers, exposing sensitive information, including SSID, password, and IP address. Canon advises users to wipe Wi-Fi settings and isolate printers from valuable assets. Firmware updates and disabling unnecessary services are also recommended security measures.
Spear-Phishing Campaign Deploying Android Spyware
The threat actor "Bahamut" is targeting individuals in South Asia via a spear-phishing campaign and deploying Android spyware "SafeChat" — in order to steal call logs, texts, and GPS data. SafeChat deceives users with a realistic interface and abuses Accessibility Services to hijack permissions while requesting the user to exclude it from Battery optimization. Encrypted stolen data is sent to the attacker's server through port 2053, evading interception..
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- Killnet and Anonymous Sudan:: Claim to have DDoS attacked the London Metal Exchange (LME)
- Telegram channel 0x_dump:: Posted data allegedly from identity management software company Avatier
VULNERABILITIES
- CVE-2023-0009 - A local privilege escalation (PE) vulnerability in the Palo Alto Networks GlobalProtect app on Windows enables a local user to execute programs with elevated privileges.
- CVE-2023-20593 - An issue in “Zen 2” CPUs, under specific microarchitectural circumstances, may allow an attacker to potentially access sensitive information.
EXPLOITS
- CVE-2016-4997 - Linux Kernel 4.6.3 Netfilter Privilege Escalation Exploit
- CVE-2015-3113 - Adobe Flash Player Nellymoser Audio Decoding Buffer Overflow
BREACHES
- Telegram: 'SEGA 2006 @segacloud.rar' - (6,355 Records) | Email address and password
- BreachForums/XSS:HauteLook Data Breach - (6,510,520 Records)| Email address and password
Tags: DIB, tlp:green