ZeroFox Daily Intelligence Brief - November 7, 2023
|by Alpha Team

ZeroFox Daily Intelligence Brief - November 7, 2023
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- HC3 Analyst Note: BlackSuit Ransomware
- QNAP Releases Patch for 2 Critical Flaws Threatening NAS Devices
- Critical Confluence Bug Actively Exploited in Attacks
- Data broker / initial-access broker / hacktivist group: Exploit user organon and ThreatSec
- Vulnerabilities: CVE-2021-29439 and CVE-2023-35784
- Breaches: Combolist: '58k valid.txt' (58,085 Records)
HC3 Analyst Note: BlackSuit Ransomware
The U.S. Health Sector Cybersecurity Coordination Center (HC3) has published an advisory stating that the relatively new BlackSuit ransomware will likely be a credible threat to the public-health sector. The advisory notes how this double-extortion (data encryption and exfiltration) group shares similarities with Royal ransomware, which is believed to be a direct successor to the notorious Russia-based Conti operation. BlackSuit’s impact on the sector, MITRE ATT&CK techniques, indicators of compromise, and possible defense and mitigation measures are also detailed in the document. ZeroFox Intelligence has detected more than 150 victims of this operation in the past year, nearly 75 percent of which are in the U.S.-Canada region.
QNAP Releases Patch for 2 Critical Flaws Threatening NAS Devices
Leading network-attached storage (NAS) manufacturer QNAP has released patches for two critical command injection vulnerabilities (CVE-2023-23368: CVSS score: 9.8 and CVE-2023-23369: CVSS score: 9.0) that affects the QTS operating system and several applications. The company warned that a successful exploit could allow remote attackers to execute commands via a network. Admins should update to the latest version at the earliest possible, because vulnerable NAS devices are known to be targeted by ransomware operators.
Critical Confluence Bug Actively Exploited in Attacks
Atlassian has escalated the severity of a critical bug (CVE-2023-22518) disclosed on October 31 from CVSS 9.1 to the highest critical rating of 10 after observing its active exploitation in the wild, including by ransomware operators. The improper authorization vulnerability affects all versions prior to the recently deployed fixed versions of Confluence Data Center and Server. While Atlassian urges administrators to patch the instances as soon as possible, the company has also shared temporary mitigation measures (backing up, disconnecting from the internet, and mitigating known attack vectors by blocking access on specific endpoints) in case upgrading to a fixed version is not possible immediately.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- Exploit user organon: Advertising network access to a U.S.-based law firm
- ThreatSec: Claims to have breached the official government website of a province in Argentina
VULNERABILITIES
- CVE-2021-29439: The Grav admin plugin prior to version 1.10.11 does not correctly verify caller's privileges.
- CVE-2023-35784: A double free or use after free could occur after SSL_clear in OpenBSD 7.2 before errata 026 and 7.3 before errata 004, and in LibreSSL before 3.6.3 and 3.7.x before 3.7.3.
BREACHES
- Combolist: '58k valid.txt' (58,085 Records) : Email address and password
Tags: DIB, tlp:green