ZeroFox Daily Intelligence Brief - August 31, 2023
|by Alpha Team

ZeroFox Daily Intelligence Brief - August 30, 2023
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Breach Hits Forever 21 Employees Enrolled in Firm’s Health Plan
- Stealthy Threat Actor Steals Data from Governments and International Organizations
- Cybercriminals Employ Various Tactics to Compromise Airbnb Accounts
- Data broker / initial-access broker / hacktivist group: Exploit user “Invisables” and Mysterious Team Bangladesh, Team_insane_pk official, and Cyb3r Drag0nz
- Vulnerabilities: CVE-2023-40901 and CVE-2023-41163
- Exploits: CVE-2021-26084 and CVE-2017-9101
- Combolist: '50x NordVpn.txt' (66 Records) and BreachForums/XSS: BitcoinSecurity Data Leak (9,401,440 Records)
Breach Hits Forever 21 Employees Enrolled in Firm’s Health Plan
Fashion retailer Forever 21 is notifying over 539,000 current and former employees that an unauthorized party accessed employee data from certain systems between January and March 2023. The breach compromised health information of employees enrolled in the company’s health plan (including name, Social Security number, date of birth, bank account numbers and Forever21 health plan details). Forever 21 has reportedly “has no indication that the unauthorized third party further copied, retained, or shared any of the data.”
Stealthy Threat Actor Steals Data from Governments and International Organizations
A newly uncovered threat actor, "Earth Estries," is silently stealing data from global governments and tech entities. This ongoing campaign began in at least 2020 and shares some links with the cyber espionage group FamousSparrow. While targets span industries worldwide, Earth Estries uses DLL sideloading and a diverse malware toolkit, including Zingdoor, TrillClient, and HemiGate. The group's adeptness, resourcefulness, and worldwide infrastructure make it challenging to pinpoint its origins.
Cybercriminals Employ Various Tactics to Compromise Airbnb Accounts
Cybercriminals have been observed deploying stealers, stolen cookies, and account checkers to gain unauthorized access to Airbnb accounts. Once breached, criminals can make fraudulent transactions, book properties, steal personal info and perform identity theft. Thousands of compromised Airbnb accounts are sold for as low as a dollar, emphasizing the scale of the issue.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- [Exploit user “Invisables”:] (https://cloud.zerofox.com/intelligence/search?sources=advanceddark%20web&created_before=2023-08-31T18:29:59.999Z&created_after=2023-08-30T05:50:10.434Z&date_delta=1 ): Selling alleged network access to a U.S.-based manufacturing company.
- [Mysterious Team Bangladesh, Team_insane_pk official, and Cyb3r Drag0nz:] (https://cloud.zerofox.com/intelligence/search?sources=advanceddark%20web&created_before=2023-08-31T18:29:59.999Z&created_after=2023-08-30T05:50:10.434Z&date_delta=1): Continue to target French entities (#OpFrance) in religiously motivated attacks
VULNERABILITIES
- CVE-2023-40901: Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter macFilterType and parameter deviceList at url /goform/setMacFilterCfg.
- CVE-2023-41163: A Reflected Cross-site scripting (XSS) vulnerability in the file manager tab in Usermin 2.000 allows remote attackers to inject arbitrary web script or HTML via the replace in results field while replacing the results under the tools drop down.
EXPLOITS
- [CVE-2021-26084] (https://cloud.zerofox.com/intelligence/search?sources=exploits&created_before=2023-08-31T18:29:59.999Z&created_after=2023-08-30T05:21:08.809Z&date_delta=1 ): Confluence Server Webwork OGNL injection.
- [CVE-2017-9101] (https://cloud.zerofox.com/intelligence/search?sources=exploits&created_before=2023-08-31T18:29:59.999Z&created_after=2023-08-30T05:21:08.809Z&date_delta=1 ): PlaySMS 1.4 - 'import.php' Remote Code Execution
BREACHES
- [Combolist: '50x NordVpn.txt'] (https://cloud.zerofox.com/intelligence/search?sources=exploits&created_before=2023-08-31T18:29:59.999Z&created_after=2023-08-30T05:21:08.809Z&date_delta=1 ): (66 Records)| Email Address and Password
- [ reachForums/XSS: Truecaller Data Breach] (https://cloud.zerofox.com/intelligence/search?sources=breaches&created_before=2023-08-31T18:29:59.999Z&created_after=2023-08-30T05:21:08.809Z&date_delta=1): (9,401,440 Records) |Email address and password
Tags: DIB, tlp:green