zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - August 04, 2023

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - August 04, 2023

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Five Eyes Authorities Release Joint Report on Top Exploited Vulnerabilities of 2022
  • 1.7 TB of Leaked Mondee Database Exposes Sensitive Customer Information
  • Serco Inc. Discloses Data Breach of 10,000 Individuals' Personal Information from Third-Party Vendor's Server
  • Data broker / initial-access broker / hacktivist group: Exploit user “proper12” and Exploit user “sandocan”:
  • Vulnerabilities: CVE-2023-36053 and CVE-2023-4056
  • Exploits: CVE-2020-12800
  • BreachForums: Turkey İş Bankası Data Breach and Credit Card Data Breach

Five Eyes Authorities Release Joint Report on Top Exploited Vulnerabilities of 2022

Cybersecurity bodies from the “Five Eyes” alliance released a list of the 12 most exploited vulnerabilities in 2022. Threat actors targeted outdated software vulnerabilities instead of recently disclosed ones, focusing on unpatched internet-facing systems and proof of concept available facilitated exploitation. The advisory urges organizations to address these flaws and emphasizes implementing measures to secure systems and reduce risks.

1.7 TB of Leaked Mondee Database Exposes Sensitive Customer Information

U.S. travel giant Mondee has addressed an exposed database containing sensitive customer data, including flight and hotel details and unencrypted credit card numbers. A security researcher alerted the company, disclosing that the database was accessible without a password and from an easily guessable subdomain. The 1.7 TB database held data including names, addresses, flight info, and passport numbers, with some customer data exposed.

Serco Inc. Discloses Data Breach of 10,000 Individuals' Personal Information from Third-Party Vendor's Server

Serco Inc. reported a data breach affecting 10,000 individuals. Attackers stole personal information from a third-party vendor, CBIZ, in a ransomware attack on their MoveIT managed file transfer (MFT) server. The breach, starting in May 2023, compromised data including names, Social Security numbers, and health benefits. Serco is collaborating with CBIZ to investigate and enhance security measures. The Clop ransomware gang initiated the large-scale data theft, affecting numerous organizations, including U.S. federal agencies and commercial customers.

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

VULNERABILITIES

  • CVE-2023-36053 - In Django 3.2 before 3.2.20, 4 before 4.1.10, and 4.2 before 4.2.3, EmailValidator and URLValidator are subject to a potential ReDoS (regular expression denial of service) attack via a very large number of domain name labels of emails and URLs.
  • CVE-2023-4056 -Memory safety bugs are present in Firefox 115, Firefox ESR 115.0, Firefox ESR 102.13, Thunderbird 115.0, and Thunderbird 102.13.

EXPLOITS

  • CVE-2020-12800 - WordPress Drag And Drop Multi File Uploader Remote Code Execution

BREACHES

Tags: DIB, tlp:green