ZeroFox Weekly Threat Bulletin: 09/29/2023 - 10/05/2023
|by Alpha Team

ZeroFox Weekly Threat Bulletin: 09/29/2023 - 10/05/2023
ZeroFox Daily Intelligence:
ZeroFox Daily Intelligence Brief - October 5, 2023
Brief Highlights
- Cisco Addresses Root Credential Access Vulnerability
- Apple Releases Emergency Updates for Kernel-Level Bug
- Lyca Mobile Blames Cyberattack for Network Disruption
- Data broker / initial-access broker / hacktivist group: XSS user spartanking and GhostSec
- Vulnerabilities: CVE-2023-4911 and CVE-2023-26237
- Exploits: CVE-2021-42694 and CVE-2021-34527
- Breaches: Telegram: "ArtHouse Cloud FREE.zip" Botnet Breach
Report: https://zerofox.com/advisories/21986
ZeroFox Daily Intelligence Brief - October 4, 2023
Brief Highlights
- ShellTorch Exposes Tens of Thousands of Servers Worldwide to Attacks
- Qualcomm: Four Bugs Actively Exploited in the Wild
- Major Linux Distributions Affected by Root Access Vulnerability
- Data broker / initial-access broker / hacktivist group: Exploit user: yesdaddy and Exploit user: budda12
- Vulnerabilities: CVE-2023-5370 and CVE-2023-30738
- Exploits: CVE-2021-21975
- Breaches: BreachForums: Aakash Institute Data Breach and Combolist: '1900 NORD VPN ACC.txt'
Report: https://zerofox.com/advisories/21980
ZeroFox Daily Intelligence Brief - October 3, 2023
Brief Highlights
- "Phantom Hacker" Scams Target Senior Citizens and Result in Victims Losing their Life Savings
- CloudFlare Firewall and DDoS Prevention Vulnerable to Bypass
- New Critical Security Flaws Expose Exim Mail Servers to Remote Attacks
- Data broker / initial-access broker / hacktivist group: Anonymous Sudan and BreachForums user N1k7
- Vulnerabilities: CVE-2023-43669 and CVE-2023-5217
- Exploits: CVE-2021-42013 and CVE-2021-36260
- Breaches: Brokers Alliance and Combolist: '204k_Spotify_targeted.txt'
Report: https://zerofox.com/advisories/21970
ZeroFox Daily Intelligence Brief - October 2, 2023
Brief Highlights
- The Marvin Attack
- ALPHV Claims to Have Breached McLaren Health Care Corporation
- New Critical Security Flaws Expose Exim Mail Servers to Remote Attacks
- Data broker / initial-access broker / hacktivist group: XSS user SocketSilence and RAMP user xss_0x2
- Vulnerabilities: CVE-2023-32828 and CVE-2023-5217
- Breaches: Combolist: '100K_VPN_000098.txt' (99,744 Records) and Credit Card Data Breach: 2023-9-30 (378596 | 1294)
Report: https://zerofox.com/advisories/21958
ZeroFox Daily Intelligence Brief - September 30, 2023
Brief Highlights
- U.S. Official Highlights Cybersecurity Risks of Low-Cost Chinese Hardware
- Cisco Catalyst SD-WAN Manager flaw allows remote server access
- CISA Adds Red HAT JBoss Flaw to Known Vulnerabilities Catalog
- Data broker / initial-access broker / hacktivist group: Exploit user Azterion & Exploit user kamzzzzz
- Vulnerabilities: CVE-2023-43014 and CVE-2023-41235
- Breaches: Combolist: 'faucetcrypto.com.txt' and Combolist: 'getpocket.com.txt'
Report: https://zerofox.com/advisories/21950
ZeroFox Daily Intelligence Brief - September 29, 2023
Brief Highlights
- ZeroFox Intelligence Brief - India-Canada Tensions
- Progress Software Releases Patches for WS_FTP Server
- FBI: Multiple Ransomware Variants Impacting the Same Victims and Data Destruction Trends
- Data broker / initial-access broker / hacktivist group: Exploit user Hexlite & Exploit user l29
- Vulnerabilities: CVE-2023-43868 and CVE-2023-40441
- Breaches: Leakbase: CasualSport Data Breach and BreachForums: Central Restaurants Group Data Breach
Report: https://zerofox.com/advisories/21947
Breach Disclosures:
Breach Disclosure: Luxuriant168
An alleged data breach at Luxuriant168 – a Thailand-based manufacturer and retailer of health and personal care products – exposed 239 email addresses which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21987
Breach Disclosure: Brokers Alliance
An alleged data breach at Brokers Alliance – a U.S.-based insurance broker – exposed 6,113 email addresses which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21979
Breach Disclosure: Aakash Institute
An alleged data breach at Aakash Institute – an India-based educational institute – exposed 2,214,459 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/21977
Breaking News:
Global CRM Provider Exposed Millions of Clients’ Files Online
Researcher discovered that global B2B CRM provider Really Simple Systems exposed online a non-password-protected database with million records. The documents appeared to be associated with internal invoices, communications, and customer’s stored CRM files.
See the full report here: https://securityaffairs.com/151999/data-breach/crm-provider-really-simple-systems-data-leak.html
NATO is investigating a new cyber attack claimed by the SiegedSec group
NATO is investigating claims that a group called SiegedSec has breached its systems and leaked a cache of unclassified documents online. On September 30 2023, the group announced on its Telegram channel the theft of approximately 3,000 North Atlantic Treaty Organization’ documents, more than 9 GB of data. The group published a series of screenshots showing access to hacked systems as proof of the hack.
See the full report here: https://securityaffairs.com/152007/hacking/nato-investigating-new-siegedsec-attack.html
Critical Atlassian Confluence Bug Under Attack
Atlassian said miscreants have exploited a critical bug in on-premises instances of Confluence Server and Confluence Data Center to create and abuse admin accounts within the enterprise colab software. The privilege-escalation vulnerability, tracked as CVE-2023-22515, affects versions 8.0.0 through 8.5.1. Versions prior to 8.0.0 are not impacted by the flaw.
See the full report here: https://www.theregister.com/2023/10/04/critical_confluence_privilege_escalation_bug/?&web_view=true
Cisco Fixes Hardcoded Root Credentials in Emergency Responder
The vulnerability, which affects CER version 12.5(1)SU4, could be exploited to execute arbitrary commands as the root user. Admins are urged to update their vulnerable installations promptly, as there are no temporary workarounds available.
See the full report here: https://www.bleepingcomputer.com/news/security/cisco-fixes-hard-coded-root-credentials-in-emergency-responder/?&web_view=true
Lorenz ransomware accidentally leaks two years of contact page submission details
A security researcher noticed Lorenz's dark web victim blog was leaking backend code, pulled the data from the site, and uploaded to it a public GitHub repository. The data includes names, email addresses, and the subject line entered into the ransomware group's limited online form to request information from Lorenz.
See the full report here: https://www.theregister.com/2023/10/05/lorenz_ransomware_group_leaks_details/
New Supermicro BMC Vulnerabilities Could Expose Many Servers to Remote Attacks
Supermicro has released updates to address multiple vulnerabilities (CVE-2023-40290) in Baseboard Management Controllers (BMC) IPMI firmware that could allow remote attackers to gain root access to the system.
See the full report here: https://www.securityweek.com/new-supermicro-bmc-vulnerabilities-could-expose-many-servers-to-remote-attacks/?&web_view=true
GoldDigger Android Trojan Targets Banking Apps in Asia Pacific Countries
A new Android banking trojan named GoldDigger has been found targeting several financial applications with an aim to siphon victims' funds and backdoor infected devices. The malware targets more than 50 Vietnamese banking, e-wallet and crypto wallet applications. There are indications that this threat might extend its reach across the wider APAC region and to to Spanish-speaking countries.
See the full report here: https://thehackernews.com/2023/10/golddigger-android-trojan-targets.html
Guyana Governmental Entity Hit by DinodasRAT in Cyber Espionage Attack
A governmental entity in Guyana has been targeted as part of a cyber espionage campaign dubbed Operation Jacana. The activity, which was detected February 2023, entailed a spear-phishing attack that led to the deployment of a hitherto undocumented implant written in C++ called DinodasRAT.
See the full report here: https://thehackernews.com/2023/10/guyana-governmental-entity-hit-by.html
San Francisco’s transport agency Metropolitan Transportation Commission (MTC) exposes drivers’ plate numbers and addresses
A misconfiguration in the Metropolitan Transportation Commission (MTC) systems caused a leak of over 26K files, exposing clients’ home addresses and the plate numbers of their vehicles.
See the full report here: https://securityaffairs.com/151889/data-breach/san-franciscos-transport-agency-metropolitan-transportation-commission-mtc-exposes-drivers-plate-numbers-and-addresses.html
Trio of TorchServe flaws means PyTorch users need an urgent upgrade
A trio of now-patched security issues in TorchServe, an open-source tool for scaling PyTorch machine-learning models in production, could lead to server takeover and remote code execution (RCE).
See the full report here: https://go.theregister.com/feed/www.theregister.com/2023/10/04/shelltorch_vulnerabilities/
Qualcomm Releases Patch for Three New Zero-Days Under Active Exploitation
Qualcomm has published an advisory about the set of flaws (CVE-2023-33106, CVE-2023-33107, CVE-2022-22071, and CVE-2023-33063) that may be under targeted exploitation. Users are advised to apply updates from original equipment manufacturers (OEMs) as soon as they become available.
See the full report here: https://thehackernews.com/2023/10/qualcomm-releases-patch-for-3-new-zero.html?&web_view=true
Phishing campaign targeted US executives exploiting a flaw in Indeed job search platform
Threat actors exploited an open redirection vulnerability in the job search platform Indeed to carry out phishing attacks. The phishing attacks were aimed at senior executives across various industries, primarily in Banking, Financial, Insurance, Property Management and Real Estate, and Manufacturing sectors.
See the full report here: https://securityaffairs.com/151897/cyber-crime/phishing-campaign-indeed-flaw.html
New "Looney Tunables" Linux Bug Gives Root Privileges on Major Distros
A new Linux vulnerability (CVE-2023-4911) known as "Looney Tunables" enables local attackers to gain root privileges by exploiting a buffer overflow weakness in the GNU C Library's ld.so dynamic loader.
See the full report here: https://www.bleepingcomputer.com/news/security/new-looney-tunables-linux-bug-gives-root-on-major-distros/?&web_view=true
Arm Issues Patch for Mali GPU Kernel Driver Vulnerability Amidst Ongoing Exploitation
Arm has released security patches to contain a security flaw (CVE-2023-4211) in the Mali GPU Kernel Driver that has come under active exploitation in the wild.
See the full report here: https://thehackernews.com/2023/10/arm-issues-patch-for-mali-gpu-kernel.html
Iran-Linked APT34 Spy Campaign Targets Saudis
A phishing campaign dropping cyber espionage malware is taking aim at users in the Middle East. The campaign is mounted by the infamous advanced persistent threat known as APT34 (aka OilRig, Helix Kitten, Cobalt Gypsy), and employs a custom tool that researchers have dubbed "Menorah." This malware is capable of identifying the target's machine, reading and uploading files from the machine, and downloading other files or malware.
See the full report here: https://www.darkreading.com/dr-global/iran-linked-apt34-spy-campaign-targets-saudis
KillNet Claims DDoS Attack Against Royal Family Website
The official Royal Family site was briefly taken down by Killnet, one of Russia's notorious hacker groups.
See the full report here: https://www.darkreading.com/cloud/killnet-ddos-attack-royal-family-website
European Telecommunications Standards Institute (ETSI) suffered a data breach
The European Telecommunications Standards Institute (ETSI) disclosed a data breach, threat actors had access to a database of its users. Threat actors stole a database containing the list of users of the portal of the European Telecommunications Standards Institute (ETSI). The organization focuses on developing global standards for information and communications technology (ICT) and telecommunications, such as: GSM, TETRA, 3G, 4G, 5G and DECT.
See the full report here: https://securityaffairs.com/151845/data-breach/etsi-data-breach.html
Exim Patches Three of Six Zero-Day Bugs Disclosed Last Week
The EXIM security flaw (CVE-2023-42115) discovered by an anonymous security researcheris due to an Out-of-bounds Write weakness found in the SMTP service and which could be exploited by remote attackers has now been patched.
See the full report here: https://www.bleepingcomputer.com/news/security/exim-patches-three-of-six-zero-day-bugs-disclosed-last-week/?&web_view=true
Researcher Reveals New Techniques to Bypass Cloudflare's Firewall and DDoS Protection
Firewall and distributed denial-of-service (DDoS) attack prevention mechanisms in Cloudflare can be circumvented by exploiting gaps in cross-tenant security controls. Attackers can utilize their own Cloudflare accounts to abuse the per-design trust-relationship between Cloudflare and the customers' websites.
See the full report here: https://thehackernews.com/2023/10/researcher-reveal-new-technique-to.html
New Marvin attack revives 25-year-old decryption flaw in RSA
A bug that was known to be able to break the confidentiality of TLS when used with RSA encryption in 1998 is reportedly still potent today, with many cryptographic implementations vulnerable to variants of the same attack (Marvin Attack). Security researchers have advised against using RSA PKCS#1 v1.5 encryption and urged developers to deprecate and disable support for PKCS#1 v1.5 padding for encryption
See the full report here: https://www.bleepingcomputer.com/news/security/new-marvin-attack-revives-25-year-old-decryption-flaw-in-rsa/
BunnyLoader: New Malware-as-a-Service Threat Emerges in the Cybercrime Underground
A new malware-as-a-service (MaaS) threat called BunnyLoader is being advertised for sale on the cybercrime underground. A key selling point of BunnyLoader is its fileless loading feature that "makes it difficult for the antiviruses to remove the attackers malware."
See the full report here: https://thehackernews.com/2023/10/bunnyloader-new-malware-as-service.html
OpenRefine's Zip Slip Vulnerability Could Let Attackers Execute Malicious Code
A high-severity security flaw (CVE-2023-37476; CVSS score: 7.8) in the open-source OpenRefine data cleanup and transformation tool could result in arbitrary code execution on affected systems. The vulnerability has been patched in version 3.7.4 released on July 17, 2023.
See the full report here: https://thehackernews.com/2023/10/openrefines-zip-slip-vulnerability.html
Highly worrying and "Chile needs awareness": Experts warn of seriousness of increase in cyber attacks
The National Cybersecurity Coordinator of Chile has warned that the cybersecurity ecosystem in the country is more exposed than it was ever before. In the first first half of the year alone, 21 serious cyberattacks were registered in the public sector, when the past rate was four or five in a year. Of the three critical cyberattacks of the first half of the year, two were reportedly outbreaks for which there were no precedents in the world.
See the full report here: https://www.emol.com/noticias/Economia/2023/09/29/1108571/expertos-advierten-aumento-ciberataques.html
Millions of Exim mail servers exposed to zero-day RCE attacks
A critical severity bug (CVE-2023-42115; CVSS 3.0 base score 9.8) in the widely used Exim mail transfer agent can enable remote, unauthenticated attackers to execute arbitrary code on Exim installations. Until patches are available, admins have been advised to “restrict interaction with the application,” that is, to restrict remote access via the internet so as to thwart possible exploitation attempts. In addition to this bug, several other Exim bugs have been disclosed that can allow information disclosure and remote code execution.
See the full report here: https://www.bleepingcomputer.com/news/security/millions-of-exim-mail-servers-exposed-to-zero-day-rce-attacks/
Cloudflare DDoS protections ironically bypassed using Cloudflare
Cloudflare's Firewall and DDoS prevention can be bypassed by abusing logic flaws in cross-tenant security controls. The only requirement for the attack is for the hackers to create a free Cloudflare account, which is used as part of the attack. However, the attackers must know a targeted web server's IP address to abuse these flaws.
See the full report here: https://www.bleepingcomputer.com/news/security/cloudflare-ddos-protections-ironically-bypassed-using-cloudflare/
Zanubis Android Banking Trojan Poses as Peruvian Government App to Target Users
An emerging Android banking trojan called Zanubis is masquerading as a Peruvian government app to trick unsuspecting users into installing the malware. Zanubis is mainly known for abusing accessibility permissions on the infected device to display fake overlay screens atop the targeted apps in an attempt to steal credentials. It is also capable of harvesting contact data, list of installed apps, and system metadata.
See the full report here: https://thehackernews.com/2023/10/zanubis-android-banking-trojan-poses-as.html
Exploit released for Microsoft SharePoint Server auth bypass flaw
Proof-of-concept exploit code has been published for a critical authentication bypass vulnerability (CVE-2023-29357) in Microsoft SharePoint Server. The security flaw can let unauthenticated attackers gain administrator privileges following successful exploitation in low-complexity attacks that don't require user interaction. It is recommended to apply the security patches issued by Microsoft earlier this year as a preventive measure against potential attacks.
See the full report here: https://www.bleepingcomputer.com/news/security/exploit-released-for-microsoft-sharepoint-server-auth-bypass-flaw/
Meet LostTrust ransomware — A likely rebrand of the MetaEncryptor gang
The LostTrust ransomware operation, whose data leak site lists 53 victims worldwide, is believed to be a rebrand of MetaEncryptor, utilizing almost identical data leak sites and encryptors. Both the LostTrust and MetaEncryptor encryptors are almost identical, with some minor changes to ransom notes, embedded public keys, ransom note names, and encrypted file extensions
See the full report here: https://www.bleepingcomputer.com/news/security/meet-losttrust-ransomware-a-likely-rebrand-of-the-metaencryptor-gang/
Bing Chat ads redirecting users to download malware infected software
Bing Chat is being used by threat actors to spread malware infested software installers by redirecting them to fake download websites. These malware-infested ads mimic the popular utility – Advanced IP Scanner. People are redirected to a fake website called “advenced-ip-scanner[.]com,” where they are asked to download an installer infected with malware.
See the full report here: https://indianexpress.com/article/technology/tech-news-technology/bing-chat-ads-malware-links-8963731/
Crypto firms beware: Lazarus’ new malware can now bypass detection
North Korean hacking collective Lazarus Group has been using a new malware payload “LightlessCan” as part of its fake employment scams, which is far more challenging to detect than its predecessor.
See the full report here: https://cointelegraph.com/news/crypto-firms-lazarus-group-new-malware-fake-job-scam
CISA adds JBoss RichFaces Framework flaw to its Known Exploited Vulnerabilities catalog
US Cybersecurity and Infrastructure Security Agency (CISA) added the critical flaw CVE-2018-14667 (CVSS score 9.8) affecting Red Hat JBoss RichFaces Framework to its Known Exploited Vulnerabilities Catalog. The issue is an Expression Language (EL) injection via the UserResource resource, it affects RichFaces Framework 3.X through 3.3.4. A remote unauthenticated attacker could exploit this vulnerability to execute arbitrary code using a chain of java serialized objects via org.ajax4jsf.resource.UserResource$UriData.
See the full report here: https://securityaffairs.com/151656/security/cisa-adds-jboss-richfaces-framework-flaw-to-its-known-exploited-vulnerabilities-catalog.html
Bing Chat responses infiltrated by ads pushing malware
Malicious advertisements are now being injected into Microsoft's AI-powered Bing Chat responses by threat actors abusing the platform to promoting fake download sites that distribute malware.
See the full report here: https://www.bleepingcomputer.com/news/security/bing-chat-responses-infiltrated-by-ads-pushing-malware/
Johnson Controls International Disrupted by Major Cyberattack
Johnson Controls International (JCI) reported in a filing with the US Securities and Exchange Commission (SEC) that it had suffered a cyberattack that caused disruptions to its internal IT infrastructure. In addition, two of the company's subsidiaries, Simplex and York, are reportedly displaying messages of a "technical outage" on customer portals and login pages.
See the full report here: https://www.darkreading.com/ics-ot/johnson-controls-international-hit-with-massive-ransomware-attack
Progress warns of maximum severity WS_FTP Server vulnerability
Progress Software, the maker of the MOVEit Transfer file-sharing platform recently exploited in widespread data theft attacks, warned customers to patch a maximum severity vulnerability in its WS_FTP Server software. The company says thousands of IT teams worldwide use its enterprise-grade WS_FTP Server secure file transfer software.
See the full report here: https://www.bleepingcomputer.com/news/security/progress-warns-of-maximum-severity-ws-ftp-server-vulnerability/
US State Department Says 60,000 Emails Taken in Alleged Chinese Hack
The US State Department said that hackers took around 60,000 emails in an attack which Microsoft has blamed on China.
See the full report here: https://www.securityweek.com/us-state-department-says-60000-emails-taken-in-alleged-chinese-hack/
Cisco Warns of Vulnerability in IOS and IOS XE Software After Exploitation Attempts
Cisco is warning of attempted exploitation of a security flaw in its IOS Software and IOS XE Software that could permit an authenticated remote attacker to achieve remote code execution on affected systems. The medium-severity vulnerability is tracked as CVE-2023-20109, and has a CVSS score of 6.6. It impacts all versions of the software that have the GDOI or G-IKEv2 protocol enabled.
See the full report here: https://thehackernews.com/2023/09/cisco-warns-of-vulnerability-in-ios-and.html
ZeroFox Intelligence Reports:
ZeroFox Intelligence Geopolitical Brief for October 2023
In this ZeroFox Intelligence Geopolitical Brief for October 2023, ZeroFox geopolitical researchers focus on the contagion from Russia's war in Ukraine rather than the war itself. Security challenges in Central Asia and the Balkans and reduced support for Ukraine from Eastern Europe are key consequences of the war. Similar developments along a depleted Russian periphery will likely emerge the longer the war goes on. Latin America also has a slew of upcoming elections worth monitoring. In Asia, China's upcoming Golden Week holiday is important for getting a pulse on their struggling economy, while Canada's eventful, yet largely consequenceless, dispute with India is covered.
Report: https://zerofox.com/advisories/21957
Tags: tlp:clear, all industries, global, weekly bulletin