ZeroFox Weekly Threat Bulletin: 10/13/2023 - 10/19/2023
|by Alpha Team

ZeroFox Weekly Threat Bulletin: 10/13/2023 - 10/19/2023
ZeroFox Daily Intelligence:
ZeroFox Daily Intelligence Brief - October 19, 2023
Brief Highlights
- Navigating the Mis- and Disinformation Minefield in the Current Israel-Hamas War
- Russia and China-Backed Hackers Exploiting WinRAR Zero-Day Bug
- Israel-Hamas War Monitoring: October 18, 2023 (ZeroFox Situation Report)
- Data broker / initial-access broker / hacktivist group: Team One Piece and Soldiers Of Solomon
- Vulnerabilities: CVE-2019-9514 and CVE-2023-37503
- Exploits: CVE-2023-0297 and CVE-2023-3640
- Data Breach: BreachForums: Breeze Systems Forum Data Breach and BreachForums: Fuerteadventure Excursions Data Breach
Report: https://zerofox.com/advisories/22108
ZeroFox Daily Intelligence Brief - October 18, 2023
Brief Highlights
- Israeli Cyber Experts Start “War Room” to Track Missing Persons
- Widespread Kwik Trip Disruption Attributed to “Network Incident”
- Critical Vulnerabilities Uncovered in Open Source CasaOS Cloud Software
- Data broker / initial-access broker / hacktivist group: Ransomed
- Vulnerabilities: CVE-2023-22032 and CVE-2023-5450
- Exploits: CVE-2023-1454 and CVE-2023-33246
- Data Breach: Combolist: '100k_Hotmail.txt' and Combolist: 'CRUNCHYROLL X 11000.txt'
Report: https://zerofox.com/advisories/22094
ZeroFox Daily Intelligence Brief - October 17, 2023
Brief Highlights
- Israel Cyber Agency Warn Home-Camera Owners Against Potential Hacking
- Unpatched Cisco Zero-Day Vulnerability Actively Targeted in the Wild
- EPA Withdraws Cyber Audit Requirement for Water Systems
- Data broker / initial-access broker / hacktivist group: Exploit user sandocan and RAMP user Krendel
- Vulnerabilities: CVE-2023-5556 and CVE-2023-4750
- Exploits: CVE-2023-27163 and CVE-2023-1671
- Data Breach: Combolist: 'Epic Games Store -HACKER PHONE-.txt' and '184K @Gmail.com Country GOOD FOR EVERY SITE.txt'
Report: https://zerofox.com/advisories/22084
ZeroFox Daily Intelligence Brief - October 16, 2023
Brief Highlights
- Women Political Leaders Summit Targeted in RomCom Malware Phishing
- 530,000 Customer Records Stolen After Cloud Gaming Provider Breach
- US Space Force Temporarily Halts Use of Generative AI Over Security Concerns
- Data broker / initial-access broker / hacktivist group: XSS user SocketSilence and RAMP user Pwnstar
- Vulnerabilities: CVE-2023-5591 and CVE-2023-5590
- Credit Card Data Breach and Combolist: '68k.txt'
Report: https://zerofox.com/advisories/22072
ZeroFox Daily Intelligence Brief - October 14, 2023
Brief Highlights
- Location of Israeli Festival May Have Been Exposed in Hack Before Hamas Massacre
- ShellBot Uses Hex IPs to Evade Detection in Attacks on Linux SSH Servers
- WhatsApp Refutes Claims of Malicious Forwards Targeting Jewish People
- Data broker / initial-access broker / hacktivist group: Exploit user: AnonGhost Indonesian and Killnet
- Vulnerabilities: CVE-2023-5554 and CVE-2023-5344
- Exploits: CVE-2023-34960 and CVE-2023-31497
- Data Breach: Telegram: '850 LOGS JUNE.rar' Botnet Breach and '788.rar' Botnet Breach
Report: https://zerofox.com/advisories/22058
ZeroFox Daily Intelligence Brief - October 13, 2023
Brief Highlights
- ZeroFox Situation Report: “Global Day of Jihad” Monitoring
- Disinformation and Opportunistic Hacktivism in the Wake of Violence
- 35 Squid Proxy Bugs Still Unpatched After 2 Years
- Vulnerabilities: CVE-2023-39361 and CVE-2023-39514
- Exploits: CVE-2023-23752 and CVE-2023-37979
- Credit Card Data Breach
Report: https://zerofox.com/advisories/22054
Breach Disclosures:
Upkar Prakashan
An alleged data breach at Upkar Prakashan – an India-based publishing house which is in to publishing of books and magazines related to careers and competitive examinations – exposed 217,518 email addresses which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/22113
Breeze Systems Forum
An alleged data breach at Breeze Systems Forum – a U.K.-based discussion forum – exposed 4,554 email addresses which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/22112
USA Database
An alleged data breach of USA Database – exposed 127,897 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/22111
Fuerteadventure
An alleged data breach at Fuerteadventure – a Spain-based adventure sports company – exposed 19,181 email addresses which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/22110
LiveLaps
An alleged data breach at LiveLaps – a U.S.-based website that provide live scoring for sporting events – exposed 865 email addresses which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/22109
Indian Insurance Company
An alleged data breach of Indian Insurance Company – exposed 30,835 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/22097
ETX DB
An alleged data breach of ETX DB – exposed 8,702 email addresses, which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/22096
TypeMatch
An alleged data breach at TypeMatch – an Europe-based dating application – exposed 21,042 email addresses which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/22095
Askarasoft
An alleged data breach at Askarasoft – an Indonesia-based software company – exposed 5,350 email addresses which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/22073
Central Security Distribution
An alleged data breach at Central Security Distribution – a U.S.-based manufacturer and distributer of electronic security devices – exposed 720 email addresses which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/22057
Audi
An alleged data breach at Audi – a Germany-based automobile company – exposed 3,009,941 email addresses which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/22056
Bodog
An alleged data breach at Bodog – a Canada-based online gambling site – exposed 999,423 email addresses which were subsequently shared on a deep web platform.
Report: https://zerofox.com/advisories/22055
Breaking News:
Ukrainian Hacktivists Claim Trigona Ransomware Takedown
Pro-Ukrainian hackers known as the Ukrainian Cyber Alliance claim to have wiped out the servers of the Trigona ransomware gang, a group linked to the Russian cybercriminal underground.
See the full report here: https://www.bankinfosecurity.com/ukrainian-hacktivists-claim-trigona-ransomware-takedown-a-23343?&web_view=true
Iran-Linked OilRig Targets Middle East Governments in 8-Month Cyber Campaign
The Iran-linked OilRig threat actor targeted an unnamed Middle East government between February and September 2023 as part of an eight-month-long campaign. The attack led to the theft of files and passwords and, in one instance, resulted in the deployment of a PowerShell backdoor called PowerExchange
See the full report here: https://thehackernews.com/2023/10/iran-linked-oilrig-targets-middle-east.html
North Korean Hackers Exploiting Recent TeamCity Vulnerability
Multiple North Korean threat actors have been observed exploiting a recent vulnerability in JetBrains’ TeamCity continuous integration and continuous deployment (CI/CD) server. Tracked as CVE-2023-42793, the critical-severity flaw allows unauthenticated attackers to execute code remotely on vulnerable on-premises TeamCity instances and gain administrator-level permissions.
See the full report here: https://www.securityweek.com/north-korean-hackers-exploiting-recent-teamcity-vulnerability/
Operations of Healthcare Solutions Giant Henry Schein Disrupted by Cyberattack
Healthcare solutions giant Henry Schein recently disclosed a cybersecurity incident that disrupted some of its business operations and may have resulted in a data breach. The company revealed on October 15 that its manufacturing and distribution businesses had been hit by a cyberattack a day earlier. Henry Schein said it took some of its systems offline to contain the incident, which caused temporary disruption to business operations, but the practice management software used by customers has not been impacted.
See the full report here: https://www.securityweek.com/operations-of-healthcare-solutions-giant-henry-schein-disrupted-by-cyberattack/
Casio discloses data breach impacting customers in 149 countries
Japanese electronics manufacturer Casio disclosed a data breach impacting customers from 149 countries after hackers gained to the servers of its ClassPad education platform. Casio detected the incident on Wednesday, October 11 2023, following the failure of a ClassPad database within the company's development environment. Evidence suggests that the attacker accessed customers' personal information a day later, on October 12 2023.
See the full report here: https://www.bleepingcomputer.com/news/security/casio-discloses-data-breach-impacting-customers-in-149-countries/
Hacker Leaks Millions of New 23andMe Genetic Data Profiles
A hacker has leaked an additional 4.1 million stolen 23andMe genetic data profiles for people in Great Britain and Germany on a hacking forum. Earlier this month, a threat actor leaked the stolen data of 1 million Ashkenazi Jews who used 23andMe services to find their ancestry info and genetic predispositions.
See the full report here: https://www.bleepingcomputer.com/news/security/hacker-leaks-millions-of-new-23andme-genetic-data-profiles/?&web_view=true
US plans to push other countries not to pay hacker ransoms ahead of meeting
The US is pushing a group of governments to publicly commit to not make ransom payments to hackers ahead of an annual meeting of more than 45 nations in Washington. In addition, the US wants governments around the world to establish cybersecurity labeling standards so consumers can assess them before they make purchases for decisions on how secure are internet-connected devices such as baby monitors and home alarms.
See the full report here: https://www.business-standard.com/world-news/us-plans-to-push-other-countries-not-to-pay-hacker-ransoms-ahead-of-meeting-123101700099_1.html
TetrisPhantom: Cyber Espionage via Secure USBs Targets APAC Governments
Government entities in the Asia-Pacific (APAC) region are the target of a long-running cyber espionage campaign dubbed TetrisPhantom. The attacker covertly spied on and harvested sensitive data from APAC government entities by exploiting a particular type of secure USB drive, protected by hardware encryption to ensure the secure storage and transfer of data between computer systems.
See the full report here: https://thehackernews.com/2023/10/tetrisphantom-cyber-espionage-via.html
BLOODALCHEMY provides backdoor to southeast Asian nations' secrets
Security researchers have uncovered a backdoor used in attacks against governments and organizations in the Association of Southeast Asian Nations (ASEAN). Dubbed "BLOODALCHEMY" by researchers, the backdoor targets x86 systems and is part of the REF5961 intrusion set recently adopted by a group with links to China.
See the full report here: https://go.theregister.com/feed/www.theregister.com/2023/10/16/bloodalchemy_backdoor/
FBI Warns of Extortion Groups Targeting Plastic Surgery Offices
The FBI has issued a warning about cybercriminals targeting plastic surgery offices through phishing attacks. These attackers gain access to the networks and steal sensitive data, including personal information and medical records.
See the full report here: https://www.bleepingcomputer.com/news/security/fbi-warns-of-extortion-groups-targeting-plastic-surgery-offices/?&web_view=true
A flaw in Synology DiskStation Manager allows admin account takeover
A vulnerability in Synology DiskStation Manager (DSM), tracked as CVE-2023-2729 (CVSS score 5.9), could be exploited to decipher an administrator’s password.
See the full report here: https://securityaffairs.com/152645/hacking/synology-diskstation-manager-admin-account-takeover.html
Qubitstrike attacks rootkit Jupyter Linux servers to steal credentials
Hackers are scanning for internet-exposed Jupyter Notebooks to breach servers and deploy a cocktail of malware consisting of a Linux rootkit, crypto miners, and password-stealing scripts. Jupyter Notebooks are open-source interactive computing environments for data analysis, machine learning, and scientific research.
See the full report here: https://www.bleepingcomputer.com/news/security/qubitstrike-attacks-rootkit-jupyter-linux-servers-to-steal-credentials/
New Admin Takeover Vulnerability Exposed in Synology's DiskStation Manager
A medium-severity flaw (CVE-2023-2729 ) has been discovered in Synology's DiskStation Manager (DSM) that could be exploited under some rare conditions, an attacker could leak enough information to restore the seed of the pseudorandom number generator (PRNG), reconstruct the admin password, and remotely take over the admin account.
See the full report here: https://thehackernews.com/2023/10/new-admin-takeover-vulnerability.html
Malicious Notepad++ Google ads evade detection for months
A new Google Search malvertizing campaign targets users looking to download the popular Notepad++ text editor, employing advanced techniques to evade detection and analysis. The malvertising campaign, haad been live for several months but managed to fly under the radar all this time.
See the full report here: https://www.bleepingcomputer.com/news/security/malicious-notepad-plus-plus-google-ads-evade-detection-for-months/
Cybersecurity attack rocks the Columbian government
Multiple prominent government ministries in Colombia are responding to a ransomware attack that is forcing officials to make significant operational changes. The government said the attack had targeted the U.S.-owned company IFX Networks, which provides web hosting services to 17 countries in the Americas. A total of 34 Colombian state entities are affected, including the Ministries of Health and Justice.
See the full report here: https://www.digitaljournal.com/tech-science/cybersecurity-attack-rocks-the-columbian-government/article
Israel's cyber authorities warn home-camera owners against potential hacking by terrorists
The Israeli National Cyber Directorate has issued a warning to Israeli citizens in recent days, urging them to take precautions regarding their home security cameras amidst concerns of potential hacking by hostile entities.
See the full report here: https://thehackernews.com/2023/10/pro-russian-hackers-exploiting-recent.html?&web_view=true
EPA Withdraws Water Sector Cybersecurity Rules Due to Lawsuits
The US Environmental Protection Agency (EPA) has withdrawn cybersecurity rules for public water systems due to lawsuits filed by states and non-profit water associations that cited the new requirements would put a significant financial burden on small towns. The EPA announced in March 2023 that it would require states to report on cybersecurity threats in their public water system audits. The agency offered to provide guidance and technical know-how, but did mention any financial assistance.
See the full report here: https://www.securityweek.com/epa-withdraws-water-sector-cybersecurity-rules-due-to-lawsuits/?&web_view=true
WordPress Websites Hacked via Royal Elementor Plugin Zero-Day
Security researchers are warning of a critical-severity vulnerability in the Royal Elementor Addons and Templates WordPress plugin that has been exploited as a zero-day for more than a month. Developed by WP Royal, the plugin helps domain admins build their websites without any coding experience. The exploited bug, tracked as CVE-2023-5360 (CVSS score of 9.8), is described as an insufficient file type validation in the plugin’s upload function, allowing unauthenticated attackers to upload arbitrary files to vulnerable sites, leading to remote code execution.
See the full report here: https://www.securityweek.com/wordpress-websites-hacked-via-royal-elementor-plugin-zero-day/
US Gov Expects Widespread Exploitation of Atlassian Confluence Vulnerability
US cybersecurity agency CISA, the FBI, and the Multi-State Information Sharing and Analysis Center (MS-ISAC) warn organizations of potential widespread exploitation of a recent zero-day vulnerability in Atlassian Confluence Data Center and Server. Tracked as CVE-2023-22515 (CVSS score of 9.8), the bug has been exploited by a nation-state threat actor since September 14 2023, roughly two weeks before Atlassian released patches for it. Remotely exploitable without authentication, the flaw is described as a broken access control issue leading to privilege escalation.
See the full report here: https://www.securityweek.com/us-gov-expects-widespread-exploitation-of-atlassian-confluence-vulnerability/
11 Ukrainian Telecommunications Providers Hit by Cyberattacks Using POEMGATE and POSEIDON Malware
The Computer Emergency Response Team of Ukraine (CERT-UA) has revealed that threat actors "interfered" with at least 11 telecommunication service providers in the country between May and September 2023. The agency is tracking the activity under the name UAC-0165, stating the intrusions led to service interruptions for customers.
See the full report here: https://thehackernews.com/2023/10/cert-ua-reports-11-ukrainian-telecom.html?&web_view=true
CISA, NSA, FBI, and International Partners Release Updated Secure by Design Guidance
The update to the original April 2023 Secure Design guidance provides additional recommendations for software manufacturers—including manufacturers of artificial intelligence software systems and models—to improve the security of their products.
See the full report here: https://www.cisa.gov/news-events/alerts/2023/10/16/cisa-nsa-fbi-and-international-partners-release-updated-secure-design-guidance
Victim Count Doubles in Heart Institute Data Theft Hack
The number of people affected by a Tennessee cardiac care clinic hack has more than doubled to 411,000 since the healthcare group first reported the incident to regulators in July 2023. Cybercriminal group Karakurt claimed responsibility for the attack, which has so far triggered five class action suits.
See the full report here: https://www.bankinfosecurity.com/victim-count-doubles-in-heart-institute-data-theft-hack-a-23325?&web_view=true
530K people's info suspected stolen from cloud PC gaming biz Shadow
Shadow, which hosts Windows PC gaming in the cloud among other services, has confirmed criminals stole a database containing customer data following a social-engineering attack against one of its employees. A database of stolen records of 533,624 customers were put up for sale on a cybercrime forum.
See the full report here: https://www.theregister.com/2023/10/13/shadow_data_theft/
ALPHV Gang Stole 5TB of Data From Illinois' Morrison Community Hospital
The group claims to have stolen 5TB of patients’ and employee’s information, backups, PII documents, and more. The gang also published a sample as proof of the stolen data.
See the full report here: https://securityaffairs.com/152486/cyber-crime/alphv-ransomware-morrison-community-hospital.html?&web_view=true
AI algorithm detects MitM attacks on unmanned military vehicles
Professors at the University of South Australia and Charles Sturt University have developed an algorithm to detect and intercept man-in-the-middle (MitM) attacks on unmanned military robots.
See the full report here: https://www.bleepingcomputer.com/news/security/ai-algorithm-detects-mitm-attacks-on-unmanned-military-vehicles/
Steam enforces SMS verification to curb malware-ridden updates
Valve has announced implementing additional security measures for developers publishing games on Steam, including SMS-based confirmation codes. This is to deal with a recent outbreak of malicious updates pushing malware from compromised publisher accounts.
See the full report here: https://www.bleepingcomputer.com/news/security/steam-enforces-sms-verification-to-curb-malware-ridden-updates/
Signal Debunks Zero-Day Vulnerability Reports, Finds No Evidence
Encrypted messaging app Signal has pushed back against "viral reports" of an alleged zero-day flaw in its software, stating it found no evidence to support the claim. "After responsible investigation we have no evidence that suggests this vulnerability is real nor has any additional info been shared via our official reporting channels."
See the full report here: https://thehackernews.com/2023/10/signal-debunks-zero-day-vulnerability.html
Russian intelligence services continue to pose significant threats to US, reveals FBI-NCSC joint bulletin
The U.S. Federal Bureau of Investigation (FBI) and the National Counterintelligence and Security Center (NCSC) issued a joint bulletin highlighting that despite significant military setbacks following the Ukraine invasion, Russian intelligence services persist as a significant threat to the U.S. The document explicitly highlights the continuous focus of Russian intelligence services and their associates on targeting the U.S. through espionage, influence operations, and cyber activities, that strived to undermine U.S. and allied support for Ukraine.
See the full report here: https://industrialcyber.co/critical-infrastructure/russian-intelligence-services-continue-to-pose-significant-threats-to-us-reveals-fbi-ncsc-joint-bulletin/
Milesight Industrial Router Vulnerability Possibly Exploited in Attacks
A vulnerability affecting some industrial routers made by Chinese IoT and video surveillance product maker Milesight may have been exploited in attacks. Several UR-series industrial cellular routers from Milesight (Ursalink) are affected by CVE-2023-43261, a serious vulnerability exposing system log files, such as "httpd.log". The exposed logs contain passwords for administrators and other users, which can be leveraged by remote, unauthenticated attackers to gain unauthorized access to the targeted device.
See the full report here: https://www.securityweek.com/milesight-industrial-router-vulnerability-possibly-exploited-in-attacks/
SpyNote: Beware of This Android Trojan that Records Audio and Phone Calls
The Android banking trojan known as SpyNote has been dissected to reveal its diverse information-gathering features. Typically spread via SMS phishing campaigns, attack chains involving the spyware trick potential victims into installing the app by clicking on the embedded link. Besides requesting invasive permissions to access call logs, camera, SMS messages, and external storage.
See the full report here: https://thehackernews.com/2023/10/spynote-beware-of-this-android-trojan.html
X's New Badge System Is a Ripe Cyber-Target
Scammers have targeted the vaunted blue check marks on the platform formerly known as Twitter, smearing individuals and brands alike with various new schemes.
See the full report here: https://www.darkreading.com/application-security/x-twitter-new-badge-system-cyber-target
35 security holes still unpatched in proxy after 2 years, now public
35 vulnerabilities in the Squid caching proxy remain unfixed more than two years after being found and disclosed to the open source project's maintainers, according to the researchers who reported them.
See the full report here: https://go.theregister.com/feed/www.theregister.com/2023/10/13/squid_proxy_bugs_remain_unfixed/
NSA unveils Elitewolf repository of intrusion detection signatures and analytics for OT environments
The U.S. National Security Agency (NSA) made a significant contribution to the realm of cybersecurity by publishing a repository of intrusion detection signatures and analytics crafted for OT (operational technology) environments. The resource, known as "Elitewolf" can enable defenders of critical infrastructure, defense industrial base, and national security systems to identify and detect potentially malicious cyber activity in their OT environments.
See the full report here: https://industrialcyber.co/critical-infrastructure/nsa-unveils-elitewolf-repository-of-intrusion-detection-signatures-and-analytics-for-ot-environments/
ShellBot Uses Hex IPs to Evade Detection in Attacks on Linux SSH Servers
ShellBot is capable of launching DDoS attacks and deploying cryptocurrency miners, highlighting the importance of strong passwords and regular password changes to resist dictionary attacks.
See the full report here: https://thehackernews.com/2023/10/shellbot-uses-hex-ips-to-evade.html?&web_view=true
Apple Releases iOS 16 Update to Patch Exploited Vulnerability
Apple has released iOS and iPadOS updates to fix a local privilege escalation kernel vulnerability (CVE-2023-42824) that has been actively exploited in attacks, potentially by commercial spyware vendors.
See the full report here: https://www.securityweek.com/apple-releases-ios-16-update-to-patch-exploited-vulnerability/?&web_view=true
DarkGate Malware Spreading via Messaging Services Posing as PDF Files
A piece of malware known as DarkGate has been observed being spread via instant messaging platforms such as Skype and Microsoft Teams. In these attacks, the messaging apps are used to deliver a Visual Basic for Applications (VBA) loader script that masquerades as a PDF document, which, when opened, triggers the download and execution of an AutoIt script designed to launch the malware.
See the full report here: https://thehackernews.com/2023/10/darkgate-malware-spreading-via.html
Researchers Unveil ToddyCat's New Set of Tools for Data Exfiltration
The advanced persistent threat (APT) actor known as ToddyCat has been linked to a new set of malicious tools that are designed for data exfiltration, offering a deeper insight into the hacking crew's tactics and capabilities.
See the full report here: https://thehackernews.com/2023/10/researchers-unveil-toddycats-new-set-of.html
ZeroFox Intelligence Reports:
ZeroFox Intelligence Brief - Chinese Threat Actors Targeting Semiconductor Firms
In this Intelligence Brief, ZeroFox researchers assess a new Chinese state-sponsored threat actor that has been observed to be conducting a cyber espionage campaign targeting semiconductor firms in Taiwan, Hong Kong, and Singapore.
Report: https://zerofox.com/advisories/22107
ZeroFox Intelligence Brief - North Korean and Chinese APT Groups Targeting the Aerospace Sector
In this Intelligence Brief, ZeroFox researchers assess the targeting of the aerospace industry over the last two years through cyber espionage efforts.
Report: https://zerofox.com/advisories/22069
ZeroFox Intelligence Assessment - 2023 Polish Elections
In this ZeroFox Intelligence Assessment, ZeroFox researchers delve into the upcoming elections in Poland, which are slated to occur on October 15, 2023. The assessment covers several aspects of the elections, including challenges to these elections, what is impacting the elections, and potential foreign influence.
Report: https://zerofox.com/advisories/22067
Tags: tlp:clear, weekly bulletin, all industries, global