zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - August 15, 2023

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - August 15, 2023

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • FBI Warns Users About Companies Claiming to Recover Stolen Cryptocurrency
  • Data of 760,000 Individuals Leaked from Third-Party Discord Service
  • Multiple Vulnerabilities Discovered in Globally-Used ATM Management Software
  • Data broker / initial-access broker / hacktivist group: NDT Sec and Hacktivist Indonesia
  • Vulnerabilities: CVE-2023-34966 and CVE-2023-38208
  • Leakbase: Lash FX Data Breach and Foodmazone Data Breach

FBI Warns Users About Companies Claiming to Recover Stolen Cryptocurrency

The FBI has warned people of scammers increasingly targeting victims of cryptocurrency frauds—promising to recover stolen funds in lieu of an up-front payment. Such “recovery agents”, claiming to be aligned with law enforcement to gain legitimacy, typically cease communication with the victim (after being paid the initial up-front amount), provide inaccurate/incomplete tracing reports, or demand more money. The FBI reminds people to thoroughly research any company that claims to help deal with cryptocurrency frauds, and contact law enforcement in case of any concerns.

Data of 760,000 Individuals Leaked from Third-Party Discord Service

An unidentified person leaked data from 760,000 Discord[.]io users on a darknet forum. Discord.io is a third-party unofficial service that allows server owners to create custom invite links. The compromised database includes email addresses, hashed passwords, and user-specific details. Discord.io confirmed the breach, while experts authenticated that the sample data matched real users and poses phishing and spamming threats. Users should change passwords for their accounts and activate two-factor authentication.

Multiple Vulnerabilities Discovered in Globally-Used ATM Management Software

Multiple vulnerabilities were uncovered in Iagona's ScrutisWeb software, which could be exploited for remote ATM attacks. ScrutisWeb enables web-based remote tasks like hardware monitoring, rebooting, file transmission, and data modification of banking or retail ATM fleets. The bugs include path traversal, authorization bypass, cryptographic flaws, and file upload issues, granting unauthorized remote access. The vendor patched these flaws in July 2023 in ScrutisWeb version 2.1.38. Clients are advised to update to the latest version immediately and minimize network exposure in vulnerable devices.

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

  • NDT Sec:: Allegedly DDoS attacked the website of Royal Thai Navy, as part of #Opthailand.
  • Hacktivist Indonesia:: Claims to have stolen data from the Department of Commercial Tax in Madhya Pradesh (India)

VULNERABILITIES

  • CVE-2023-34966 - An infinite loop vulnerability was found in Samba's mdssvc RPC service for Spotlight.
  • CVE-2023-38208 -Exploitation of this issue does not require user interaction.

BREACHES

  • Leakbase:: Lash FX Data Breach (9,007 Records)
  • Leakbase:: Foodmazone Data Breach (46,097 Records)

Tags: DIB, tlp:green