zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - September 14, 2023

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - September 14, 2023

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • FDA Mandates New Regulations for Medical Device Manufacturers
  • Airbus Suffers Breach After Compromise of Third-Party Access Credentials
  • Kubernetes Releases Patches for Security Flaws
  • Data broker / initial-access broker / hacktivist group: Exploit user Aveng3rs_Supp and XSS user thx4drugs
  • Vulnerabilities: CVE-2023-41081 and CVE-2023-29306
  • BreachForums/Leakbase: EscapadaRural Data Breach and BreachForums: DJ Forums Data Breach

FDA Mandates New Regulations for Medical Device Manufacturers

A new wave of cybersecurity regulations requires medical device manufacturers to implement post-market patching capabilities and strengthen device security. The US Food and Drug Administration (FDA) will no longer refrain from rejecting devices lacking in these cybersecurity controls, signaling the end of its grace period on October 1, 2023. Manufacturers are now required to establish monitoring and patching plans for post-market cybersecurity vulnerabilities, ensure secure device design and development processes, and provide a software bill of materials (SBOM) to the FDA.

Airbus Suffers Breach After Compromise of Third-Party Access Credentials

Aerospace giant Airbus suffered a data breach after attackers obtained the stolen third-party access credentials of a Turkish airline. A cybercriminal named "USDoD" posted the data of 3,200 Airbus vendors on a hacking forum. Airbus reportedly confirmed the intrusion and said that a customer-associated account was used to download business documents. Airbus stated that it was conducting investigations and follow-up measures were taken to prevent its systems from being compromised. The attacker named some prominent American industries operating in the defense industry as its next targets.

Chrome, Firefox, and Mozilla Thunderbird Receive Fixes for Actively-Exploited WebP Vulnerability

Three interconnected high-severity security flaws in Kubernetes tracked as CVE-2023-3676, CVE-2023-3893, and CVE-2023-3955 could lead to remote code execution with elevated privileges on Windows nodes within a cluster. Fixes were released on August 23, 2023, after responsible disclosure by researchers in July 2023. Attackers can exploit these vulnerabilities by deploying a malicious YAML file, granting them SYSTEM privileges on Windows endpoints. Affected cloud providers, including AWS, Google Cloud, and Microsoft Azure, have issued advisories relating to these bugs.

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

VULNERABILITIES

  • CVE-2023-41081: A bug could result in the unintended exposure of the status worker and/or bypass security constraints configured in httpd.
  • CVE-2023-29306: Adobe Connect versions 12.3 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability.

BREACHES

Tags: DIB, tlp:green