ZeroFox Daily Intelligence Brief - August 07, 2023
|by Alpha Team

ZeroFox Daily Intelligence Brief - August 07, 2023
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Beware of Criminals Posing as Non-Fungible Token (NFT) Developers
- New Acoustic Attack Steals Data From Keystrokes With 95% Accuracy
- Colorado Department of Higher Education (CDHE) Hit by Massive Data Breach
- Data broker / initial-access broker / hacktivist group: Telegram channel NEFARIAN EMPIRE and Pro-Russia group Killnet
- Vulnerabilities: CVE-2023-20817 and CVE-2023-20800
- BreachForums: Vietanamobile Data Breach and BreachForums: İstanbul Büyükşehir Belediyesi
Beware of Criminals Posing as Non-Fungible Token (NFT) Developers
The FBI has warned the NFT community of criminals impersonating developers and promoting fraudulent offerings. Such announcements link to spoofed websites that ask victims to connect their cryptocurrency wallets—and subsequently empty them via a drainer smart contract. Be cautious when linking crypto wallets to any platform and verify its legitimacy; beware of offers that seem too good to be true, and report any suspicious activity to the FBI Internet Crime Complaint Center at www.ic3.gov.
New Acoustic Attack Steals Data From Keystrokes With 95% Accuracy
Researchers have trained a deep learning model to steal data from keyboard keystrokes recorded via microphone, with 95% accuracy. When Zoom was used, accuracy dropped to 93%, which is still alarmingly high. Unlike complex side-channel attacks, acoustic attacks are easier due to prevalent microphone devices and thus pose higher risks. Mitigation options include altering typing styles (touch typing), randomized passwords, and software-based audio filters.
Colorado Department of Higher Education (CDHE) Hit by Massive Data Breach
The CDHE has disclosed a significant data breach that exposed details of current and past students as well as teachers following a June ransomware attack. CDHE detected the cybersecurity incident on June 19, 2023. In response to the attack, CDHE secured the network, conducted an investigation with third-party experts, and restored the affected systems. The stolen information includes names, social security numbers, addresses, IDs, and more.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- Telegram channel NEFARIAN EMPIRE:: Claims website taken over by the FBI and Europol
- Pro-Russia group Killnet:: Restarting its Legion project and inviting people to join
VULNERABILITIES
- CVE-2023-20817 - In WLAN service, there is a possible out of bounds write due to improper input validation.
- CVE-2023-20800 -In imgsys, there is a possible system crash due to a mssing ptr check.
BREACHES
- BreachForums: Vietanamobile - (74,272 Records) Name and email address
- BreachForums: İstanbul Büyükşehir Belediyesi - (3,020 Records) Credit card
Tags: DIB, tlp:green