ZeroFox Daily Intelligence Brief - September 28, 2023
|by Alpha Team

ZeroFox Daily Intelligence Brief - September 28, 2023
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find todayβs daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Sony Investigates Hacking Claims
- U.K. Information Commissioner Warns About Risks to Domestic Abuse Victims from Data Breaches
- Multinational Automation Giant Johnson Controls Struck by Ransomware Attack
- Data broker / initial-access broker / hacktivist group: Killmilk & ππππππ πππππ π ππππ
- Vulnerabilities: CVE-2023-23958 and CVE-2023-5244
- Exploits: CVE-2021-29627
- Breaches: Combolist: '3.2k NordVPN.txt'
United States and Japan Release Advisory on China-Linked Cyber Actors
American and Japanese cybersecurity authorities have released a joint advisory on China-linked threat group BlackTech modifying router firmware without detection and exploiting routersβ domain-trust relationships. The threat actors use custom malware, dual-use tools, and living off the land tactics, such as disabling logging on routers, to conceal their operations. The advisory highlights the need for multinational corporations to review all subsidiary connections, verify access, and consider implementing Zero Trust models to limit the extent of a potential BlackTech compromise.
GPUs Vulnerable to Cross-Origin Pixel Render Attack
GPU[.]zip, a novel side-channel attack, exposes visual data processed on GPUs (Graphic Processing Unit) by exploiting the graphical data compression mechanism found in most modern GPUs. Researchers tested GPUs from major manufacturers, and all tested GPUs were vulnerable. Website developers can guard against this by configuring sites to deny cross-origin page embedding. Browsers like Firefox and Safari remain unaffected as they do not meet the attack criteria.
Multinational Automation Giant Johnson Controls Struck by Ransomware Attack
Multinational conglomerate Johnson Controls International, which specializes in industrial control systems and security equipment, fell victim to a ransomware attack. The incident led to the encryption of numerous company devices, including VMware ESXi servers, severely impacting their operations as well as those of subsidiaries like York, Simplex, and Ruskin. The attack initially targeted the companyβs Asian offices, before spreading to other locations. It has been linked to the Dark Angels ransomware gang, who have demanded USD 51 million for data decryption and deletion.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- Killmilk: Selling access to a Spanish internet provider on the Infinity forum.
- ππππππ πππππ π ππππ: Claimed successful DDoS attacks on several Canadian websites, including that of the Canadian Air Force.
VULNERABILITIES
- CVE-2023-23958: Symantec Protection Engine, prior to 9.1.0, may be susceptible to a Hash Leak vulnerability.
- CVE-2023-5244: Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 2.0.
EXPLOITS
- CVE-2021-29627: FreeBSD Vulnerability in NetApp Products.
BREACHES
- Combolist: '3.2k NordVPN.txt': (1,911 Records)
Tags: DIB,Β tlp:green