ZeroFox Weekly Threat Bulletin: 09/08/2023 - 09/14/2023
|by Alpha Team

ZeroFox Weekly Threat Bulletin: 09/08/2023 - 09/14/2023
ZeroFox Daily Intelligence:
ZeroFox Daily Intelligence Brief - September 14, 2023
Brief Highlights
- FDA Mandates New Regulations for Medical Device Manufacturers
- Airbus Suffers Breach After Compromise of Third-Party Access Credentials
- Kubernetes Releases Patches for Security Flaws
- Data broker / initial-access broker / hacktivist group: Exploit user Aveng3rs_Supp and XSS user thx4drugs
- Vulnerabilities: CVE-2023-41081 and CVE-2023-29306
- BreachForums/Leakbase: EscapadaRural Data Breach and BreachForums: DJ Forums Data Breach
Report: https://zerofox.com/advisories/21837
ZeroFox Daily Intelligence Brief - September 13, 2023
Brief Highlights
- NSA, U.S. Federal Agencies Advise on Deepfake Threats
- Adobe Issues Patches for Zero-Day in Acrobat and Reader
- Chrome, Firefox, and Mozilla Thunderbird Receive Fixes for Actively-Exploited WebP Vulnerability
- Data broker / initial-access broker / hacktivist group: Exploit user nopiro and SiegedSec
- Vulnerabilities: CVE-2023-2071 and CVE-2023-40834
- Exploits: CVE-2020-2883
- Breaches: Combolist: '300k paypal.txt' and Combolist: 'x100 Onlyfans Accounts.txt'
Report: https://zerofox.com/advisories/21827
ZeroFox Daily Intelligence Brief - September 12, 2023
Brief Highlights
- Ransomware Group BianLian Claims Large-Scale Breach of Non-Profit Organization
- MGM Resorts Takes Down Systems Due to Cybersecurity Incident
- CISA Urges Federal Agencies to Patch Pegasus Exploit in iPhones
- Data broker / initial-access broker / hacktivist group: BreachForums user USDoD and Exploit user sandocan
- Vulnerabilities: CVE-2023-40953 and CVE-2023-41107
- Exploits: CVE-2020-14883 and CVE-2020-8289
- BreachForums: Chevrolet Data Breach and Credit Card Data Breach
Report: https://zerofox.com/advisories/21822
Breach Disclosures:
EscapadaRural
An alleged data breach at EscapadaRural – a Spain-based website that provides information regarding rural accommodations – exposed 2,950,834 email addresses which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21826
Winamax
An alleged data breach at Winamax – a France-based online gambling site – exposed 40,047 email addresses which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21825
DJ Forums
An alleged data breach at DJ Forums – a U.S.-based music events discussion forum – exposed 31,522 email addresses which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21824
Surplus Motos
An alleged data breach at Surplus Motos – a France-based company that provides reconditioned used parts for motorcycles, scooters, and quads – exposed 71,907 email addresses which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21823
Chevrolet
An alleged data breach at Chevrolet – an Argentina-based automobile company – exposed 21,648 email addresses which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21812
My Book Qatar
An alleged data breach at My Book Qatar – a Qatar-based online digital platform that provides customers through a network of merchants and partners across the country – exposed 267,461 email addresses which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21811
UAE Investment Users
An alleged data breach of UAE Investment Users – exposed 102,931 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21788
Indian Government Employees
An alleged data breach of Indian Government Employees – exposed 67,820 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21787
Breaking News:
Threat actor leaks sensitive data belonging to Airbus
The multinational aerospace corporation Airbus announced that it is investigating a data leak after a cybersecurity firm reported that a hacker posted information on thousands of the company’s vendors to the dark web.
See the full report here: https://securityaffairs.com/150794/data-breach/airbus-investigates-data-leak.html
N-Able's Take Control Agent Vulnerability Exposes Windows Systems to Privilege Escalation
A high-severity security flaw has been disclosed in N-Able's Take Control Agent that could be exploited by a local unprivileged attacker to gain SYSTEM privileges.Tracked as CVE-2023-27470 (CVSS score: 8.8), the issue relates to a Time-of-Check to Time-of-Use (TOCTOU) race condition vulnerability, which, when successfully exploited, could be leveraged to delete arbitrary files on a Windows
See the full report here: https://thehackernews.com/2023/09/n-ables-take-control-agent.html
Federal Mandates on Medical-Device Cybersecurity Get Serious
The US Food and Drug Administration will start rejecting medical devices that lack a secure design or a post-market cybersecurity plan according to new regulations that will be enforced from October 2023.
See the full report here: https://www.darkreading.com/iot/federal-mandates-on-medical-device-cybersecurity-mandate-get-serious
Rollbar discloses data breach after hackers stole access tokens
Software bug-tracking company Rollbar disclosed a data breach after unknown attackers hacked its systems in early August 2023 and gained access to customer access tokens.
See the full report here: https://www.bleepingcomputer.com/news/security/rollbar-discloses-data-breach-after-hackers-stole-access-tokens/
Researchers Detail Eight Vulnerabilities in Azure HDInsight Analytics Service
Details have emerged about a set of now-patched cross-site scripting (XSS) flaw (CVE-2023-35394) in the Microsoft Azure HDInsight service that could be weaponized by a threat actor to carry out malicious activities.
See the full report here: https://thehackernews.com/2023/09/researchers-detail-8-vulnerabilities-in.html?&web_view=true
Russian Journalist's iPhone Compromised by NSO Group's Zero-Click Spyware
The iPhone belonging to a prominent Russian journalist and critic of the government, was compromised with NSO Group's Pegasus spyware, a new collaborative investigation has revealed.The infiltration is said to have happened on or around February 10, 2023.
See the full report here: https://thehackernews.com/2023/09/russian-journalists-iphone-compromised.html
Court Convicts Portuguese Hacker in Football Leaks Trial and Gives Four-Year Suspended Sentence
A Portuguese hacker who was responsible for the “Football Leaks” website was convicted by a Lisbon court of nine crimes and given a suspended prison sentence of four years.
See the full report here: https://www.securityweek.com/court-convicts-portuguese-hacker-in-football-leaks-trial-and-gives-him-a-4-year-suspended-sentence/?&web_view=true
Save the Children confirms it was hit by cyber attack
The charity organization Save the Children International revealed that it was hit by a cyber attack. The company disclosed the security incident after the ransomware gang BianLian listed the organization on its Tor leak site.
See the full report here: https://securityaffairs.com/150750/cyber-crime/save-the-children-cyber-attack.html
Ransomware attack hits Sri Lanka government, causing data loss
Sri Lanka's Computer Emergency Readiness Team (CERT) is currently investigating a ransomware attack on the government's cloud infrastructure that affected around 5,000 email accounts.
See the full report here: https://go.theregister.com/feed/www.theregister.com/2023/09/13/ransomware_attack_hits_sri_lanka/
Mozilla Rushes to Patch WebP Critical Zero-Day Exploit in Firefox and Thunderbird
Mozilla released security updates to resolve a critical zero-day vulnerability in Firefox and Thunderbird that has been actively exploited in the wild, a day after Google released a fix for the issue in its Chrome browser.
See the full report here: https://thehackernews.com/2023/09/mozilla-rushes-to-patch-webp-critical.html?&web_view=true
Adobe Says Critical PDF Reader Zero-Day Being Exploited
As part of its scheduled batch of Patch Tuesday updates, Adobe warned that hackers are exploiting a remotely exploitable vulnerability — CVE-2023-26369 — to launch code execution attacks.
See the full report here: https://www.securityweek.com/adobe-says-critical-pdf-reader-zero-day-being-exploited/?&web_view=true
SAP Patches Critical Vulnerability Impacting NetWeaver, S/4HANA
SAP has released patches for a critical vulnerability (CVE-2023-42472) impacting multiple enterprise applications, including NetWeaver and S/4HANA.
See the full report here: https://www.securityweek.com/sap-patches-critical-vulnerability-impacting-netweaver-s-4hana/
Hackers use new 3AM ransomware to save failed LockBit attack
A new ransomware strain called 3AM has been uncovered after a threat actor used it in an attack that failed to deploy LockBit ransomware on a target network. 3AM is written in Rust and appears to be a completely new malware family.
See the full report here: https://www.bleepingcomputer.com/news/security/hackers-use-new-3am-ransomware-to-save-failed-lockbit-attack/
Beware: MetaStealer Malware Targets Apple macOS in Recent Attacks
A new information stealer malware called MetaStealer has set its sights on Apple macOS. Threat actors are proactively targeting macOS businesses by posing as fake clients in order to socially engineer victims into launching malicious payloads.
See the full report here: https://thehackernews.com/2023/09/beware-metastealer-malware-targets.html
Google Rushes to Patch Critical Chrome Vulnerability Exploited in the Wild
Google rolled out out-of-band security patches to address a critical security flaw in its Chrome web browser that it said has been exploited in the wild. Tracked as CVE-2023-4863, the issue has been described as a case of heap buffer overflow that resides in the WebP image format that could result in arbitrary code execution or a crash.
See the full report here: https://thehackernews.com/2023/09/google-rushes-to-patch-critical-chrome.html
CISA adds recently discovered Apple zero-days to Known Exploited Vulnerabilities Catalog
The US Cybersecurity and Infrastructure Security Agency (CISA) added two security vulnerabilities chained in the zero-click iMessage exploit BLASTPASS to its Known Exploited Vulnerabilities Catalog. The flaws, tracked as CVE-2023-41064 and CVE-2023-41061, were used to install NSO Group’s Pegasus spyware on iPhones.
See the full report here: https://securityaffairs.com/150642/security/known-exploited-vulnerabilities-catalog-apple-flaws.html
US senators seek federal response on security of critical infrastructure amid AI advancements
Two U.S. senators called upon the White House to provide updates on efforts to reduce artificial intelligence’s potential threat to the nation’s cyber infrastructure.
See the full report here: https://industrialcyber.co/ai/us-senators-seek-federal-response-on-security-of-critical-infrastructure-amid-ai-advancements/
Huge DDoS attack against US financial institution thwarted
Cybersecurity experts thwarted a major distributed denial-of-service (DDoS) attack aimed at a US bank that peaked at 55.1 million packets per second in the early part of September 2023.
See the full report here: https://go.theregister.com/feed/www.theregister.com/2023/09/11/ddos_attack_against_us_bank/
MGM Resorts shuts down computer systems after "cybersecurity incident"
MGM Resorts has shut down some of its IT systems following a "cybersecurity incident" that the casino-and-hotel giant says is currently under investigation.
See the full report here: https://go.theregister.com/feed/www.theregister.com/2023/09/11/mgm_resorts_cybersecurity_incident/
New WiKI-Eve attack can steal numerical passwords over WiFi
A new attack dubbed "WiKI-Eve" can intercept the cleartext transmissions of smartphones connected to modern WiFi routers and deduce individual numeric keystrokes at an accuracy rate of up to 90%, allowing numerical passwords to be stolen.
See the full report here: https://www.bleepingcomputer.com/news/security/new-wiki-eve-attack-can-steal-numerical-passwords-over-wifi/
Iran's Charming Kitten Pounces on Israeli Exchange Servers
An Iranian state-backed threat actor breached 32 Israeli organizations running unpatched Microsoft Exchange servers, deploying a new backdoor along the way.
See the full report here: https://www.darkreading.com/dr-global/irans-charming-kitten-israeli-exchange-servers
Save the Children feared hit by ransomware, 7TB stolen
Cybercrime crew BianLian claims to have broken into the IT systems of a top non-profit and stolen a ton of files, including what the miscreants claim is financial, health, and medical data.
See the full report here: https://go.theregister.com/feed/www.theregister.com/2023/09/11/bianlian_save_the_children/
Vulnerabilities Allow Hackers to Hijack, Disrupt Socomec UPS Devices
A researcher has found 7 vulnerabilities in Socomec UPS products that can be exploited to hijack and disrupt devices.
See the full report here: https://www.securityweek.com/vulnerabilities-allow-hackers-to-hijack-disrupt-socomec-ups-devices/
Cisco warns of VPN zero-day exploited by ransomware gangs
Cisco is warning users about a vulnerability (CVE-2023-20269) allows attackers to conduct password spraying and brute-force attacks, potentially leading to the identification of valid credentials and unauthorized remote access VPN sessions.
See the full report here: https://www.bleepingcomputer.com/news/security/cisco-warns-of-vpn-zero-day-exploited-by-ransomware-gangs/
Dymocks Booksellers suffers data breach impacting 836k customers
Dymocks Booksellers is warning customers their personal information was exposed in a data breach after the company's database was shared on hacking forums.
See the full report here: https://www.bleepingcomputer.com/news/security/dymocks-booksellers-suffers-data-breach-impacting-836k-customers/
Notepad++ 8.5.7 released with fixes for four security vulnerabilities
Notepad++ version 8.5.7 has been released with fixes for multiple buffer overflow zero-days(CVE-2023-40031, CVE-2023-40036, CVE-2023-40164, and CVE-2023-40166), with one marked as potentially leading to code execution by tricking users into opening specially crafted files.
See the full report here: https://www.bleepingcomputer.com/news/security/notepad-plus-plus-857-released-with-fixes-for-four-security-vulnerabilities/
Microsoft Teams phishing attack pushes DarkGate malware
The campaign started in late August 2023, when Microsoft Teams phishing messages were seen being sent by two compromised external Office 365 accounts to other organizations. A recent phishing campaign leverages Microsoft Teams messages to disseminate the powerful DarkGate Loader malware via malicious attachments. The existing security measures in Microsoft Teams, such as Safe Attachments and Safe Links, were unable to identify or prevent this attack.
See the full report here: https://www.bleepingcomputer.com/news/security/microsoft-teams-phishing-attack-pushes-darkgate-malware/
Associated Press warns that AP Stylebook data breach led to phishing attack
The Associated Press is warning of a data breach impacting AP Stylebook customers where the attackers used the stolen data to conduct targeted phishing attacks.
See the full report here: https://www.bleepingcomputer.com/news/security/associated-press-warns-that-ap-stylebook-data-breach-led-to-phishing-attack/
Millions Infected by Spyware Hidden in Fake Telegram Apps on Google Play
Researchers discovered several Telegram mods on the Google Play Store that contained spyware, the campaign was tracked as Evil Telegram. One of the apps was downloaded more than ten million times before it was removed from Google Play.
See the full report here: https://thehackernews.com/2023/09/millions-infected-by-spyware-hidden-in.html
New HijackLoader Modular Malware Loader Making Waves in the Cybercrime World
A new malware loader called HijackLoader is gaining traction among the cybercriminal community to deliver various payloads such as DanaBot, SystemBC, and RedLine Stealer. Even though HijackLoader does not contain advanced features, it is capable of using a variety of modules for code injection and execution since it uses a modular architecture, a feature that most loaders do not have.
See the full report here: https://thehackernews.com/2023/09/new-hijackloader-modular-malware-loader.html
Cybercriminals Using PowerShell to Steal NTLMv2 Hashes from Compromised Windows
A new cyber attack campaign is leveraging the PowerShell script associated with a legitimate red teaming tool to plunder NTLMv2 hashes from compromised Windows systems primarily located in Australia, Poland, and Belgium. The activity has been codenamed Steal-It by researchers.
See the full report here: https://thehackernews.com/2023/09/cybercriminals-using-powershell-to.html
The International Criminal Court Will Now Prosecute Cyberwar Crimes
Cybersecurity defenders and advocates have called for a kind of Geneva Convention for cyberwar, new international laws that would create clear consequences for anyone hacking civilian critical infrastructure, like power grids, banks, and hospitals. Now the lead prosecutor of the International Criminal Court at the Hague has made it clear that he intends to enforce those consequence. He has stated that the Hague will investigate and prosecute any hacking crimes that violate existing international law, just as it does for war crimes committed in the physical world.
See the full report here: https://www.wired.com/story/icc-cyberwar-crimes/
US and UK sanction 11 TrickBot and Conti cybercrime gang members
The USA and the United Kingdom have sanctioned eleven Russian nationals associated with the TrickBot and Conti ransomware cybercrime operations.The TrickBot malware operation launched in 2015 and focused on stealing banking credentials. However, over time, it developed into a modular malware that provided initial access to corporate networks for other cybercrime operations, such as Ryuk and, later, Conti ransomware operations.
See the full report here: https://www.bleepingcomputer.com/news/security/us-and-uk-sanction-11-trickbot-and-conti-cybercrime-gang-members/
Johnson & Johnson discloses IBM data breach impacting patients
Johnson & Johnson Health Care Systems ("Janssen") has informed its CarePath customers that their sensitive information has been compromised in a third-party data breach involving IBM. According to the notice on Janssen's site, the pharmaceutical firm became aware of a previously undocumented method that could give unauthorized users access to the CarePath database. Unfortunately, the investigation that was concluded on August 2nd, 2023, showed that unauthorized users accessed the following CarePath user details:
See the full report here: https://www.bleepingcomputer.com/news/security/johnson-and-johnson-discloses-ibm-data-breach-impacting-patients/
Google Looker Studio abused in cryptocurrency phishing attacks
Cybercriminals are abusing Google Looker Studio to create counterfeit cryptocurrency phishing websites that phish digital asset holders, leading to account takeovers and financial losses. The cybercriminals embed the URLs of these pages in phishing emails to bypass email security checks due to Looker Studio's legitimate nature and good reputation.
See the full report here: https://www.bleepingcomputer.com/news/security/google-looker-studio-abused-in-cryptocurrency-phishing-attacks/
CISA warns of critical Apache RocketMQ bug exploited in attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added to its catalog of known exploited vulnerabilities (KEV) a critical–severity issue tracked as CVE-2023-33246 that affects Apache’s RocketMQ distributed messaging and streaming platform. Multiple threat actors are possibly exploiting the vulnerability at the moment to install various payloads on impacted systems (RocketMQ versions 5.1.0 and below).
See the full report here: https://www.bleepingcomputer.com/news/security/cisa-warns-of-critical-apache-rocketmq-bug-exploited-in-attacks/
Dunghill Leak Ransomware Gang Claims Credit for Sabre Data Breach
Travel booking giant Sabre said it was investigating claims of a cyberattack after a tranche of files purportedly stolen from the company appeared on an extortion group’s leak site. The Dunghill Leak group claimed responsibility for the apparent cyberattack in a listing on its dark web leak site, alleging it took about 1.3 terabytes of data, including databases on ticket sales and passenger turnover, employees’ personal data and corporate financial information.
See the full report here: https://techcrunch.com/2023/09/06/ransomware-gang-claims-credit-for-sabre-data-breach/?&web_view=true
Weaponized Windows Installers Target Graphic Designers in Crypto Heist
Attackers are targeting 3D modelers and graphic designers with malicious versions of a legitimate Windows installer tool in a cryptocurrency-mining campaign. The campaign abuses Advanced Installer, a tool for creating software packages, to hide malware in legitimate installers for software used by creative professionals.
See the full report here: https://www.darkreading.com/attacks-breaches/weaponized-windows-installers-target-graphic-designers-in-crypto-heist
Cisco BroadWorks impacted by critical authentication bypass flaw
A critical vulnerability impacting the Cisco BroadWorks Application Delivery Platform and Cisco BroadWorks Xtended Services Platform could allow remote attackers to forge credentials and bypass authentication. The flaw is tracked as CVE-2023-20238 and rated with a maximum CVSS score of 10.0 (critical). By exploiting the flaw, threat actors can freely execute commands, access confidential data, alter user settings, and commit toll fraud.
See the full report here: https://www.bleepingcomputer.com/news/security/cisco-broadworks-impacted-by-critical-authentication-bypass-flaw/
Zero-days fixed by Apple were used to deliver NSO Group’s Pegasus spyware
According to researchers, two vulnerabilities were chained as part of a zero-click exploit, named BLASTPASS, used in attacks on iPhones running the latest version of iOS (16.6). Experts reported that the exploit involved PassKit attachments containing malicious images that were sent to the victim from an attacker’s iMessage account.
See the full report here: https://securityaffairs.com/150492/security/apple-zero-days-pegasus-spyware.html
Two Flaws in Apache SuperSet Allow to Remotely Hack Servers
Apache Superset Version 2.1.1 addressed two vulnerabilities, respectively tracked as CVE-2023-39265 and CVE-2023-37941, that could be exploited to take control of Superset’s metadata database. Researchers pointed out that Superset by design allows privileged users to connect to arbitrary databases and execute arbitrary SQL queries using the SQLLab interface.
See the full report here: https://securityaffairs.com/150461/hacking/apache-superset-flaws.html?&web_view=true
North Korean Hackers Exploit Zero-Day Bug to Target Cybersecurity Researchers
Threat actors associated with North Korea are continuing to target the cybersecurity community using a zero-day bug in unspecified software to infiltrate their machines. Researchers found the adversary setting up fake accounts on social media platforms like X (formerly Twitter) and Mastodon to forge relationships with potential targets and build trust.
See the full report here: https://thehackernews.com/2023/09/north-korean-hackers-exploit-zero-day.html
CISA, FBI, CNMF detail multiple nation-state hackers striking aeronautical sector using Zoho ManageEngine vulnerabilities
U.S. agencies released a joint advisory to highlight the presence of indicators of compromise (IOCs) at an aeronautical sector organization as early as January 2023. The document confirms nation-state advanced persistent threat (APT) actors exploited CVE-2022-47966 to gain unauthorized access to a public-facing application (Zoho ManageEngine ServiceDesk Plus), establish persistence, and move laterally through the network. The vulnerability allows for remote code execution (RCE) on the ManageEngine application.
See the full report here: https://industrialcyber.co/cisa/cisa-fbi-cnmf-detail-multiple-nation-state-hackers-striking-aeronautical-sector-using-zoho-manageengine-vulnerabilities/
Tags: tlp:clear, weekly bulletin, all industries, global