ZeroFox Weekly Threat Bulletin: 10/06/2023 - 10/12/2023
|by Alpha Team

ZeroFox Weekly Threat Bulletin: 10/06/2023 - 10/12/2023
ZeroFox Daily Intelligence:
ZeroFox Daily Intelligence Brief - October 12, 2023
Brief Highlights
- ZeroFox Intelligence Flash Report: Threat Actor Seeks to Profit from Conflict in Israel
- State Hackers Exploiting Confluence Zero Day Since September
- Simpson Manufacturing Shuts Down IT Systems After Cyberattack
- Data broker / initial-access broker / hacktivist group: Exploit user: slezer and yameiii
- Vulnerabilities: CVE-2023-20588 and CVE-2023-44488
- Exploits: CVE-2021-32537 and CVE-2021-22911
- Data Breach: BreachForums: TURF-FR Data Breach and BreachForums: Journal of Sports Science and Medicine Data Breach
Report: https://zerofox.com/advisories/22045
ZeroFox Daily Intelligence Brief - October 11, 2023
Brief Highlights
- US Agencies Release Guidance on Securing OSS in IT/ICS Environments
- HTTP/2 Zero-Day Vulnerability Used to Target Major Tech Companies
- Mirai Botnet Variant Expands Targets with 13 Router Exploits
- Data broker / initial-access broker / hacktivist group: XSS user: zjdue123 and Exploit user: slezer
- Vulnerabilities: CVE-2023-3550 and CVE-2023-5214
- Exploits: CVE-2021-29447 and CVE-2021-22204
- Data Breach: 2023-10-11T03:02:29_exbl_v4.json and Combolist: 'free easy mailpass.txt'
Report: https://zerofox.com/advisories/22035
ZeroFox Daily Intelligence Brief - October 10, 2023
Brief Highlights
- Pro-Hamas Hackers Abuse Alert Service to Send Fake Missile Alerts
- Massive Ad Fraud Botnet Powered by Millions of Hacked Android and iOS
- Linux Distributions Running Gnome Affected by Audio Metadata Exploit
- Data broker / initial-access broker / hacktivist group: Exploit user mute and Exploit user Th1nkAb0ut
- Vulnerabilities: CVE-2023-44826 and CVE-2020-18336
- Breaches: Credit Card Data Breach and Combolist: 'THEBIG_3.txt'
Report: https://zerofox.com/advisories/22023
ZeroFox Daily Intelligence Brief - October 9, 2023
Brief Highlights
- D.C. Board of Elections Confirms Breach of Website Hosting Provider
- Curl Maintainers Rush to Patch High Severity Vulnerability
- Flagstar Bank Breach Exposes Details of Over 800,000 US Customers
- Data broker / initial-access broker / hacktivist group: GhostSec and SiegedSec
- Vulnerabilities: CVE-2023-43615 and CVE-2023-5182
- Breaches: Telegram: 'APRIL 11 - 928 LOGS.rar' Botnet Breach and Data Breach: 2023-10-09T03:02:20_exbl_v4.json
Report: https://zerofox.com/advisories/22008
ZeroFox Daily Intelligence Brief - October 7, 2023
Brief Highlights
- European Commission Moves to Strengthen Cybersecurity of the Space Sector
- Multiple Critical Vulnerabilities Revealed in Supermicro's BMC Firmware
- “Operation Jacana” Reveals DinodasRAT Custom Backdoor
- Data broker / initial-access broker / hacktivist group: XSS user p3rf and XSS user Jettix
- Vulnerabilities: CVE-2023-44488 and CVE-2023-43269
- Exploits: CVE-2022-21881
- Breaches: Combolist: 'x80 Chatgpt.txt' and BreachForums: xpdel.com Breach
Report: https://zerofox.com/advisories/22001
ZeroFox Daily Intelligence Brief - October 6, 2023
Brief Highlights
- NSA and CISA Release Joint Advisory on Common Cyber Security Misconfigurations
- Chinese-Linked Hackers Eavesdrop on Semiconductor Firms of Neighboring Countries
- “Information Technology Security Event” Affects Operations of First Judicial Circuit Court of Florida
- Data broker / initial-access broker / hacktivist group: RansomedVC and NoName057(16)
- Vulnerabilities: CVE-2023-5217 and CVE-2023-45243
- Exploits: CVE-2021-25374 and CVE-2021-26084
- Breaches: BreachForums: SpotUno.mx Breach
Report: https://zerofox.com/advisories/21998
Breach Disclosures:
Elias Ghali & Sons
An alleged data breach at Elias Ghali & Sons – a Syria-based electro-industrial equipments manufacturing company – exposed 121 email addresses which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/22052
TURF-FR
An alleged data breach at TURF-FR – a France-based online horse racing betting and prediction site – exposed 120,254 email addresses which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/22034
Journal of Sports Science and Medicine
An alleged data breach at Journal of Sports Science and Medicine – a Turkey-based peer reviewed journal publication – exposed 522 email addresses which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/22033
ICT Billet
An alleged data breach at ICT Billet – a U.S.-based manufacturer of automotive vehicles parts and accessories – exposed 101,936 email addresses which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/22000
Breaking News:
BianLian extortion group claims recent Air Canada breach
The BianLian extortion group claims to have stolen 210GB of data after breaching the network of Air Canada, the country's largest airline and a founding member of Star Alliance. While the company said in a statement issued in September that systems compromised in the breach included "limited personal information of some employees and certain records," the attackers now claim that the stolen documents contained much more extensive information.The threat actors also shared screenshots of the stolen data on their dark web data leak website as proof and a detailed description of what was stolen from the airline's network.
See the full report here: https://www.bleepingcomputer.com/news/security/bianlian-extortion-group-claims-recent-air-canada-breach/
New WordPress backdoor creates rogue admin to hijack websites
A new malware has been posing as a legitimate caching plugin to target WordPress sites, allowing threat actors to create an administrator account and control the site's activity. The malware is a backdoor with a variety of functions that let it manage plugins and hide itself from active ones on the compromised websites, replace content, or redirect certain users to malicious locations.
See the full report here: https://www.bleepingcomputer.com/news/security/new-wordpress-backdoor-creates-rogue-admin-to-hijack-websites/
Pan-African Financial Apps Leak Encryption, Authentication Keys
Encryption, authentication, and signing keys are often exposed in mobile fintech apps used across Africa, according to researchers at Approov, who found passwords, application programming interface (API) keys, and private keys for cryptography when the most commonly used apps were reverse-engineered.
See the full report here: https://www.darkreading.com/dr-global/pan-african-financial-apps-leak-encryption-authentication-keys
Simpson Manufacturing Takes Systems Offline Following Cyberattack
Engineering and manufacturing firm Simpson Manufacturing says it has taken some of its IT systems offline following a cyberattack. Simpson Manufacturing produces building materials, including anchors, connectors, and new construction and retrofitting materials. The company told the US Securities and Exchange Commission that it discovered a cyberattack that impacted some of its systems.
See the full report here: https://www.securityweek.com/simpson-manufacturing-takes-systems-offline-following-cyberattack/
Unpatched Vulnerabilities Expose Yifan Industrial Routers to Attacks
Industrial routers made by Chinese company Yifan are affected by several critical vulnerabilities that can expose organizations to attacks.
See the full report here: https://www.securityweek.com/unpatched-vulnerabilities-expose-yifan-industrial-routers-to-attacks/
US Government Releases Security Guidance for Open Source Software in OT, ICS
Several US government agencies have teamed up to create new cybersecurity guidance for the use of open source software (OSS) in operational technology (OT). Designed in line with CISA’s Open Source Software Security Roadmap, which was released in September 2023, the new document (PDF) is meant to promote the understanding of OSS and its implementation in industrial control systems (ICS) and other OT environments, and to detail best practices on the secure use of OSS.
See the full report here: https://www.securityweek.com/us-government-releases-open-source-security-guidance-for-ot-ics/
Mirai Variant IZ1H9 Adds 13 Exploits to Arsenal
A Mirai-based DDoS (distributed denial of service) malware botnet tracked as IZ1H9 has added thirteen new payloads to target Linux-based routers and routers from D-Link, Zyxel, TP-Link, TOTOLINK, and others. IZ1H9 compromises devices to enlist them to its DDoS swarm and then launches DDoS attacks on specified targets, presumably on the order of clients renting its firepower.
See the full report here: https://www.bleepingcomputer.com/news/security/mirai-ddos-malware-variant-expands-targets-with-13-router-exploits/
Over 17,000 WordPress Sites Compromised by Balada Injector in September 2023
More than 17,000 WordPress websites have been compromised in the month of September 2023 with malware known as Balada Injector. Of these, 9,000 of the websites are said to have been infiltrated using a recently disclosed security flaw in the tagDiv Composer plugin (CVE-2023-3169, CVSS score: 6.1) that could be exploited by unauthenticated users to perform stored cross-site scripting (XSS) attacks.
See the full report here: https://thehackernews.com/2023/10/over-17000-wordpress-sites-compromised.html
Adobe Patches Code Execution Flaws in Adobe Commerce, Photoshop
Software maker Adobe released fixes for at least 13 security vulnerabilities in multiple product lines, warning that critical flaws in Adobe Commerce and Photoshop will require immediate attention. Successful exploitation could lead to arbitrary code execution, privilege escalation, arbitrary file system read, security feature bypass and application denial-of-service.
See the full report here: https://www.securityweek.com/cisa-warns-of-attacks-exploiting-adobe-acrobat-vulnerability/
Air Europa data breach exposed customers’ credit cards
Airline Air Europa disclosed a data breach and warned customers to cancel their credit cards after threat actors accessed their card information.
See the full report here: https://securityaffairs.com/152316/data-breach/airline-air-europa-data-breach.html
Organizations Respond to HTTP/2 Zero-Day Exploited for DDoS Attacks
Major tech companies and other organizations have rushed to respond to the newly disclosed HTTP/2 zero-day vulnerability that has been exploited to launch the largest distributed denial-of-service (DDoS) attacks seen to date. The existence of the attack method, named HTTP/2 Rapid Reset, and the underlying vulnerability, tracked as CVE-2023-44487, were disclosed by researchers from major tech companies.
See the full report here: https://www.securityweek.com/organizations-respond-to-http-2-zero-day-exploited-for-ddos-attacks/
HelloKitty ransomware source code leaked on hacking forum
A threat actor has leaked the complete source code for the first version of the HelloKitty ransomware on a Russian-speaking hacking forum, claiming to be developing a new, more powerful encryptor. The released hellokitty.zip archive contains a Microsoft Visual Studio solution that builds the HelloKitty encryptor and decryptor and the NTRUEncrypt library that this version of the ransomware uses to encrypt files.
See the full report here: https://www.bleepingcomputer.com/news/security/hellokitty-ransomware-source-code-leaked-on-hacking-forum/
High-Severity Flaws in ConnectedIO's 3G/4G Routers Raise Concerns for IoT Security
Multiple high-severity security vulnerabilities have been disclosed in ConnectedIO's ER2000 edge routers and the cloud-based management platform that could be exploited by malicious actors to execute malicious code and access sensitive data. An attacker could have leveraged these flaws to fully compromise the cloud infrastructure, remotely execute code, and leak all customer and device information.
See the full report here: https://thehackernews.com/2023/10/high-severity-flaws-in-connectedios.html
Over 17,000 WordPress sites hacked in Balada Injector attacks last month
Multiple Balada Injector campaigns have compromised and infected over 17,000 WordPress sites using known flaws in premium theme plugins. Balada Injector is a massive operation discovered in December 2022, which has been leveraging various exploits for known WordPress plugin and theme flaws to inject a Linux backdoor. The backdoor redirects visitors of the compromised websites to fake tech support pages, fraudulent lottery wins, and push notification scams.
See the full report here: https://www.bleepingcomputer.com/news/security/over-17-000-wordpress-sites-hacked-in-balada-injector-attacks-last-month/
New Magecart Campaign Alters 404 Error Pages to Steal Shoppers' Credit Cards
A sophisticated Magecart campaign has been observed manipulating websites' default 404 error page to conceal malicious code in what's been described as the latest evolution of the attacks. The activity targets Magento and WooCommerce websites, with some of the victims belonging to large organizations in the food and retail industries.
See the full report here: https://thehackernews.com/2023/10/new-magecart-campaign-alters-404-error.html
UK Power and Data Manufacturer Volex Hit by Cyberattack
British power and data transmission products manufacturer Volex PLC is the latest victim of a cyberattack. The incident resulted from unknown threat actor(s) gaining unauthorized access to some of the company’s IT systems and data at several global sites. However, Volex claims that attackers could not access financial data, and the incident had no material financial impact.
See the full report here: https://www.hackread.com/uk-power-data-manufacturer-volex-cyberattack/
Hacktivists in Palestine and Israel after SCADA and other industrial control systems
Both pro-Israeli and pro-Palestinian hacktivists have joined the fight and are targeting SCADA and ICS systems.
See the full report here: https://securityaffairs.com/152224/hacktivism/hacktivists-palestine-israel-after-scada-ics.html
libcue Library Flaw Opens GNOME Linux Systems Vulnerable to RCE Attacks
The libue vulnerability, tracked as CVE-2023-43641, allows for remote code execution (RCE) on affected hosts. The issue is related to memory corruption in libcue and affects versions 2.2.1 and earlier. It affects any Linux distribution shipped with the GNOME desktop environment, including the latest versions.
See the full report here: https://thehackernews.com/2023/10/libcue-library-flaw-opens-gnome-linux.html?&web_view=true
Researchers Uncover Grayling APT's Ongoing Attack Campaign Across Industries
A previously undocumented threat actor of unknown provenance has been linked to a number of attacks targeting organizations in the manufacturing, IT, and biomedical sectors in Taiwan. Researchers attributed the attacks to an advanced persistent threat (APT) tracked under the name Grayling. Evidence shows that the campaign began in February 2023 and continued until at least May 2023.
See the full report here: https://thehackernews.com/2023/10/researchers-uncover-grayling-apts.html
Taiwan Probes Firms Suspected of Selling Chip Equipment to China’s Huawei Despite US Sanctions
Taiwan authorities are investigating four Taiwan-based companies suspected of helping China’s Huawei Technologies to build semiconductor facilities.
See the full report here: https://www.theregister.com/2023/10/08/asia_tech_news_roundup/
CDW data to be leaked next week after negotiations with LockBit break down
CDW, one of the largest providers of technology products and services for business, government and education, will have its data leaked by LockBit after negotiations over the ransom fee broke down, a spokesperson for the cybercrime gang says. According to the countdown timer on LockBit's victim blog, CDW's files are scheduled to be published in the early hours of the morning on October 11, 2023. CDW has yet to comment on the incident, which appears to have been ongoing since at least September 3, 2023 when the company was first posted to LockBit's blog.
See the full report here: https://www.theregister.com/2023/10/06/cdw_lockbit_negotiations/
US lawmakers want China export bans to include open source tech like RISC-V
Three members of the US Congress have expressed concerns that the nation's export controls regime are ineffective because they allow free sharing of open source technology with China. The chairman of the US House select committee on China indicated that he would want the Department of Commerce to "require any American person or company to receive an export license prior to engaging with PRC (People's Republic of China) entities on RISC-V technology."
See the full report here: https://www.theregister.com/2023/10/08/asia_tech_news_roundup/
QakBot Threat Actors Still in Action, Using Ransom Knight and Remcos RAT in Latest Attacks
Despite the disruption to its infrastructure, the threat actors behind the QakBot malware have been linked to an ongoing phishing campaign since early August 2023 that led to the delivery of Ransom Knight (aka Cyclops) ransomware and Remcos RAT. This indicates that "the law enforcement operation may not have impacted Qakbot operators' spam delivery infrastructure but rather only their command-and-control (C2) servers.
See the full report here: https://thehackernews.com/2023/10/qakbot-threat-actors-still-in-action.html
Security Patch for Two New Flaws in Curl Library Arriving on October 11
The maintainers of the Curl library have released an advisory warning of two forthcoming security vulnerabilities that are expected to be addressed as part of updates released on October 11, 2023. This includes a high severity and a low-severity flaw tracked under the identifiers CVE-2023-38545 and CVE-2023-38546, respectively. Additional details about the issues and the exact version ranges impacted have been withheld owing to the possibility that the information could be used to "help identify the problem (area) with a very high accuracy."
See the full report here: https://thehackernews.com/2023/10/security-patch-for-two-new-flaws-in.html
CISA reveals "Admin123" as top security threat in cyber sloppiness chart
The US Cybersecurity and Infrastructure Security Agency (CISA) and the National Security Agency (NSA) hold unchanged default credentials as the prime security misconfiguration responsible for successful cyberattacks.
See the full report here: https://go.theregister.com/feed/www.theregister.com/2023/10/06/cisa_top_10_misconfigurations/
D.C. Board of Elections Confirms Voter Data Stolen in Site Hack
The District of Columbia Board of Elections (DCBOE) is currently probing a data leak involving an unknown number of voter records following breach claims from a threat actor known as RansomedVC. The stolen voter records include personal details such as names, registration IDs, partial Social Security numbers, driver's license numbers, and contact information, raising concerns about potential identity theft and privacy risks.
See the full report here: https://www.bleepingcomputer.com/news/security/dc-board-of-elections-confirms-voter-data-stolen-in-site-hack/?&web_view=true
Facebook’s Official Page Hacked, Spammed with Bizzare Posts
The social network promptly deleted all the posts and issued an official statement to notify users that the page had been compromised. Simultaneously, the platform launched an investigation into the incident and took steps to enhance the page’s security.
See the full report here: https://www.hackread.com/facebooks-official-page-hacked-release-imran-khan/
North Korea-linked Lazarus APT laundered over USD 900 million through cross-chain crime
North Korea-linked APT group Lazarus has laundered USD 900 million worth of cryptocurrency through “Cross-chain crime” (swapping of cryptoassets between different tokens or blockchains) North Korea-linked Lazarus Group laundered USD 900 Million in cryptocurrency between July 2022 and July 2023.
See the full report here: https://securityaffairs.com/152106/apt/north-korea-laundered-900-million.html
Third Flagstar Bank data breach since 2021 affects 800,000 customers
Flagstar Bank is warning that over 800000 US customers had their personal information stolen by cybercriminals due to a breach at a third-party service provider.
See the full report here: https://www.bleepingcomputer.com/news/security/third-flagstar-bank-data-breach-since-2021-affects-800-000-customers/
Android devices shipped with backdoored firmware as part of the BADBOX network
Researchers warn that more than 70,000 Android smartphones, CTV boxes, and tablets were shipped with backdoored firmware as part of BADBOX network.
See the full report here: https://securityaffairs.com/152124/malware/badbox-network-backdoored-firmware.html
Hackers Join In on Israel-Hamas War With Disruptive Cyberattacks
Several hacker groups have joined in on the Israel-Hamas war that started over the weekend after the militant group launched a major attack.
See the full report here: https://www.securityweek.com/hackers-join-in-on-israel-hamas-war-with-disruptive-cyberattacks/
Operation Jacana' Reveals DinodasRAT Custom Backdoor
A fresh malware threat dubbed "DinodasRAT" has been uncovered, after being used in a targeted cyber-espionage campaign against a governmental entity in Guyana. The campaign, named"Operation Jacana" after water birds that are native to the South American country, could be linked to (unnamed) Chinese state-sponsored cyberattackers.
See the full report here: https://www.darkreading.com/threat-intelligence/operation-jacana-dinodasrat-custom-backdoor
Multiple Critical Vulnerabilities Revealed in Supermicro's BMC Firmware
Multiple security vulnerabilities have been disclosed in the Intelligent Platform Management Interface (IPMI) firmware for Supermicro baseboard management controllers (BMCs) that could result in privilege escalation and execution of malicious code on affected systems. The seven flaws, tracked from CVE-2023-40284 through CVE-2023-40290, vary in severity from High to Critical, according to Binarly, enabling unauthenticated actors to gain root access to the BMC system. Supermicro has shipped a BMC firmware update to patch the bugs.
See the full report here: https://www.supermicro.com/en/support/security_BMC_IPMI_Oct_2023
European Commission launches call to strengthen the security and the resilience of the space sector
The Commission, with the support of the European Union Agency for the Space Programme (EUSPA), launched a call for expression of interest to set up and participate in an EU Space Information Sharing and Analysis Centre (ISAC) to build cyber resilience.
See the full report here: https://defence-industry-space.ec.europa.eu/commission-launches-call-strengthen-security-and-resilience-space-sector-2023-10-05_en
China-linked cyberspies backdoor semiconductor firms with Cobalt Strike
Hackers engaging in cyber espionage have targeted Chinese-speaking semiconductor companies with TSMC-themed lures that infect them with Cobalt Strike beacons. The campaign spotted focuses on firms based in Taiwan, Hong Kong, and Singapore, with the observed TTPs (tactics, techniques, and procedures) bearing similarities to previous activities linked to Chinese state-backed threat groups.
See the full report here: https://www.bleepingcomputer.com/news/security/china-linked-cyberspies-backdoor-semiconductor-firms-with-cobalt-strike/
NSA and CISA Release Advisory on Top Ten Cybersecurity Misconfigurations
The National Security Agency (NSA) and Cybersecurity and Infrastructure Security Agency (CISA) released a joint cybersecurity advisory (CSA), NSA and CISA Red and Blue Teams Share Top Ten Cybersecurity Misconfigurations, which provides the most common cybersecurity misconfigurations in large organizations, and details the tactics, techniques, and procedures (TTPs) actors use to exploit these misconfigurations.
See the full report here: https://www.cisa.gov/news-events/alerts/2023/10/05/nsa-and-cisa-release-advisory-top-ten-cybersecurity-misconfigurations
CISA releases Industrial Control Systems Advisories
CISA released three Industrial Control Systems (ICS) advisories on October 5, 2023. ICSA-23-278-01 Hitachi Energy , Qognify NiceVision, and the Mitsubishi Electric CC-Link IE TSN Industrial Managed Switch. CISA encourages users and administrators to review the newly released ICS advisories for technical details and mitigations.
See the full report here: https://www.cisa.gov/news-events/alerts/2023/10/05/cisa-releases-three-industrial-control-systems-advisories
ZeroFox Intelligence Reports:
ZeroFox Intelligence Flash Report - Threat Actor Seeks to Profit Off of Conflict in Israel
In this flash report, ZeroFox researchers provide updates on their observations that a threat actor is looking to sell compromised personally identifiable information (PII) and other pieces of information from the Israeli Defense Force and the Israel Security Agency on the predominately Russian-language dark web forum RAMP.
Report: https://zerofox.com/advisories/22044
ZeroFox Intelligence Regional Assessment - Asia
In this regional assessment, ZeroFox researchers establish the key geopolitical and security risks currently facing Asia, and provide forward-looking statements on how these will likely impact the region in the coming months.
Report: https://zerofox.com/advisories/22043
ZeroFox Intelligence Assessment – Latin American Elections
In this ZeroFox Intelligence Assessment, ZeroFox researchers delve into the upcoming elections in Latin America which are slated to occur this month. The assessment covers several aspects of the elections, including challenges to these elections, potential economic outcomes of the results, and foreign influence on the elections.
Report: https://zerofox.com/advisories/22032
ZeroFox Intelligence Flash Report – Conflict in Israel
In this flash report, ZeroFox researchers provide updates on the recent cyber and physical security developments in Israel, regional travel to and from the area, and a forward look towards potential outcomes of the incursion.
Report: https://zerofox.com/advisories/22022
Tags: tlp:clear, all industries, global, weekly bulletin