ZeroFox Daily Intelligence Brief - October 20, 2023
|by Alpha Team

ZeroFox Daily Intelligence Brief - October 20, 2023
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Casio Confirms Data Breach of Customers Across 149 Countries
- Five Eyes intelligence Chiefs Warn on China's “Theft” of Intellectual Property
- CISA, NSA, FBI, and MS-ISAC Release Update to #StopRansomware Guide
- Data broker / initial-access broker / hacktivist group: Exploit users: maveboy and Roblette
- Vulnerabilities: CVE-2023-45822 and CVE-2023-27795
- Exploits: CVE-2023-3460 and CVE-2023-23488
- Data Breach: Telegram: '1000 LOGS 2022 #1q16.rar' Botnet Breach
Casio Confirms Data Breach of Customers Across 149 Countries
Casio has confirmed a breach affecting more than 126,000 customers across the world. The breach occurred after an attack on a “ClassPad.net'' database, a web application operated by Casio to support the digitization of graphs, statistics & analytics, geometry, and CAS functions. Further investigation revealed that some network security settings were accidentally disabled due to operational error, allowing the attack to take place. The breached data includes customer names, emails, country/region of residence, purchase information (order details, payment method, license code, etc.), and service usage information (log data, nicknames, etc.).
Five Eyes intelligence Chiefs Warn on China's “Theft” of Intellectual Property
The intelligence chiefs of the Five Eyes alliance have accused China of intellectual property theft and the use of artificial intelligence for espionage purposes. The accusation followed a discussion with tech companies from Silicon Valley and listed a variety of tactics such as cyber intrusions, human-intelligence operations, strategic corporate investments, and academic plants at research institutions. All five countries have reportedly observed a “sharp rise in aggressive attempts by other states to steal competitive advantage.” The chiefs further suggested that China operated the most massive and wide-scale intellectual theft operation among major nations. The Chinese government dismissed the statements as a “collective disinformation campaign.”
CISA, NSA, FBI, and MS-ISAC Release Update to #StopRansomware Guide
U.S. authorities have released an updated version of the #StopRansomware Guide, which includes new prevention tips such as hardening Server Message Block (SMB) protocols, revised response steps, and added threat hunting insights. The guide intends to help organizations minimize ransomware risks through best practices to detect, prevent, respond, and recover, including step-by-step approaches to address potential attacks.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- Exploit user maveboy:: Advertising network access to U.S.-based accounting company
- Exploit user Roblette:: Advertising network access to U.S.-based construction company
VULNERABILITIES
- CVE-2023-45822:: This Artifact Hub bug has been resolved in version 1.16.0, and there are no known workarounds.
- CVE-2023-27795:: An issue found in IXP Data Easy Install v.6.6.14884.0 allows a local attacker to gain privileges via a static XOR key.
EXPLOITS
- CVE-2023-3460: Unauthorized admin access for Ultimate Member plugin
- CVE-2023-23488: WordPress Paid Memberships Pro 2.9.8 SQL Injection
BREACHES
- Telegram: '1000 LOGS 2022 #1q16.rar' Botnet Breach: (22,597 Records) Email Address and Password
Tags: DIB, tlp:green