ZeroFox Daily Intelligence Brief - October 9, 2023
|by Alpha Team

ZeroFox Daily Intelligence Brief - October 9, 2023
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- D.C. Board of Elections Confirms Breach of Website Hosting Provider
- Curl Maintainers Rush to Patch High Severity Vulnerability
- Flagstar Bank Breach Exposes Details of Over 800,000 US Customers
- Data broker / initial-access broker / hacktivist group: GhostSec and SiegedSec
- Vulnerabilities: CVE-2023-43615 and CVE-2023-5182
- Breaches: Telegram: 'APRIL 11 - 928 LOGS.rar' Botnet Breach and Data Breach: 2023-10-09T03:02:20_exbl_v4.json
D.C. Board of Elections Confirms Breach of Website Hosting Provider
District and federal agencies are investigating a hacker's claim of accessing 600,000 lines of U.S. voting data maintained by the D.C. Board of Elections. The board confirmed that voter records were accessed through a breach of its website hosting provider, DataNet Systems, with no direct impact on internal databases or servers. The agency's website is temporarily down, and vulnerability scans have been conducted. The authenticity of data posted on the dark web and a hacking forum remains unconfirmed.
Curl Maintainers Rush to Patch High Severity Vulnerability
The maintainers of curl will release version 8.4.0 on October 11, 2023, addressing two vulnerabilities (CVE-2023-38545 & CVE-2023-38546) in curl and libcurl ahead of the release cycle. CVE-2023-38545 is rated "HIGH" severity and described as “the worst curl security flaw in a long time”. The full details of the vulnerability are planned for immediate publication after the patches. cURL is a widely used network file transfer utility, and libcurl is a highly popular HTTP client-side library with over 10 billion installations embedded in operating systems, servers, medical devices, printers, cars, docker files, and more.
Flagstar Bank Breach Exposes Details of Over 800,000 US Customers
Flagstar Bank, is alerting over 800,000 US customers about a data breach caused by a third-party service provider, Fiserv. Fiserv, a provider for payment processing and mobile banking services to hundreds of banks, suffered a breach during the CLOP MOVEit Transfer data theft attacks. Cybercriminals exploited MOVEit Transfer to access Fiserv's systems and steal Flagstar customer data, including names and Social Security Numbers (SSNs). Flagstar has issued a breach notification and will provide free identity monitoring to affected individuals.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- GhostSec:: Claims to have hacked Future Wave Ultratech, an Iran based telecommunication company
- SiegedSec:: Threaten to attack industrial control systems throughout the U.S. in #OpJane
VULNERABILITIES
- CVE-2023-43615 :: Mbed TLS 2.x before 2.28.5 and 3.x before 3.5.0 has a Buffer Overflow.
- CVE-2023-5182:: Sensitive data could be exposed in logs of subiquity version 23.09.1 and earlier.
BREACHES
- Telegram: 'APRIL 11 - 928 LOGS.rar' Botnet Breach: (21,213 Records)| Email address and password.
- Data Breach: 2023-10-09T03:02:20_exbl_v4.json: (663533 Records)
Tags: DIB, tlp:green