zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - November 3, 2023

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - November 3, 2023

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • BlackCat Ransomware Claims Breach of Healthcare Giant Henry Schein
  • Mortgage and Loan Giant Mr. Cooper Attributes Ongoing Outage to Cyberattack
  • FIRST Releases CVSS 4.0 Vuln Scoring Standard

BlackCat Ransomware Claims Breach of Healthcare Giant Henry Schein

Multinational healthcare solutions provider Henry Schein has reportedly suffered a ransomware attack that forced it to take some systems offline and disrupted business operations. Russia-linked BlackCat/ALPHV ransomware group listed Henry Schein on its dark web leak site and claimed to have stolen 35 TB of sensitive files (including payroll data and shareholder information) after breaching the company’s networks. In a cybersecurity advisory earlier this year, the U.S. Health Sector Cybersecurity Coordination Center (H3C) had named ALPHV/BlackCat as one of the most prolific groups targeting critical infrastructure, including healthcare, in the past year.

Mortgage and Loan Giant Mr. Cooper Attributes Ongoing Outage to Cyberattack

Dallas-based financial services giant Mr. Cooper (formerly known as Nationstar Mortgage Holdings Inc.) has disclosed that it is working to resolve an ongoing outage caused by a cybersecurity incident on October 31, 2023. In an SEC filing, Mr. Cooper noted that it does not believe that “this incident will have a material adverse effect on its business, operations or financial results.” The company has also announced that customers will not incur any fees, penalties, or negative credit reporting related to late payments as it works to resolve this issue. The company has not revealed further details of the scope or type of the attack.

FIRST Releases CVSS 4.0 Vuln Scoring Standard

The Forum of Incident Response and Security Teams (FIRST) has published an updated version of the Common Vulnerability Scoring System (CVSS 4.0) as part of its efforts to improve the process of rating the severity of software vulnerabilities. The Forum noted that the revised standard offers finer granularity in base metrics for consumers, removes downstream scoring ambiguity, simplifies threat metrics, and enhances the effectiveness of assessing environment-specific security requirements and compensating controls. Formally incorporated in 1995, FIRST is a collaborative of incident response and security teams from countries across the world to “ensure a safe internet for all.”

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

  • Exploit user jorik_911: Selling remote desktop access to a U.S.-based apparel and accessories retailer
  • Exploit user resetmyname: Selling a bundle that supposedly contains 50,000 compromised accounts impacting various German banks

VULNERABILITIES

  • CVE-2023-34261: Kyocera TASKalfa 4053ci printers through 2VG_S000.002.561 allow identification of valid user accounts via username enumeration.
  • CVE-2023-36621: In Boomerang Parental Control application through 13.83 for Android, a child can use Safe Mode to remove all restrictions temporarily or uninstall the application without the parents noticing.

EXPLOITS

BREACHES

Tags: DIB, tlp:green