ZeroFox Daily Intelligence Brief - November 5, 2023
|by Alpha Team

ZeroFox Daily Intelligence Brief - November 5, 2023
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Hackers Use Citrix Bleed Flaw in Attacks on Government Networks Worldwide
- Atlassian Warns of New Critical Confluence Vulnerability Threatening Data Loss
- 815 Million Indians’ Data on the Darknet — Possibly the Largest Data Breach in Indian History
Hackers Use Citrix Bleed Flaw in Attacks on Government Networks Worldwide
Security researchers have observed at least four ongoing campaigns exploiting “Citrix Bleed,” a critical severity flaw (CVE-2023-4966) affecting Citrix NetScaler ADC and NetScaler Gateway (which was disclosed on October 10, 2023). While these attacks have been significantly stealthy and left behind sparse forensic evidence, researchers have observed post-exploitation activity that indicates credential theft and lateral movement. Tens of thousands of exploited servers have been reportedly observed, with attacks originating from over a hundred individual IP addresses. Moreover, ongoing attacks would require a full incident response, as deploying the available patches will not secure already breached systems.
Atlassian Warns of New Critical Confluence Vulnerability Threatening Data Loss
Atlassian has warned users of a critical security flaw (CVE-2023-22518; CVSS score of 9.1) in Confluence Data Center and Server that could lead to significant data loss in the event of a successful attack. Atlassian stated that the “improper authorization vulnerability” would not affect confidentiality as an attacker cannot exfiltrate any instance data. Customers should take immediate action to secure their instances and upgrade to the latest (patched) versions; Atlassian recommends disconnecting publicly accessible instances until the patch has been applied. Atlassian Cloud sites are not affected by the issue.
815 Million Indians’ Data on the Darknet — Possibly the Largest Data Breach in Indian History
A massive database containing sensitive personal information of about 815 million Indian citizens is being offered for sale on an underground hacking forum for USD 80,000. The package—which includes fields such as name, age, father’s name, Aadhaar (India’s national identity program) number, and passport details—has been suspected to be leaked from the Indian Council of Medical Research (ICMR) database. The past year has seen a number of high-profile data breaches relating to the Indian healthcare sector, including one from CoWin (India’s COVID-19 management and tracking platform) and a suspected Chinese ransomware attack on India’s premier medical college and hospital, All India Institute of Medical Sciences (AIIMS).
Tags: DIB, tlp:green