ZeroFox Daily Intelligence Brief - November 9, 2023
|by Alpha Team

ZeroFox Daily Intelligence Brief - November 9, 2023
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- ZeroFox Intelligence Brief - Executive Order Outlines U.S. Priorities on AI Governance, Risk Mitigation
- FBI: Ransomware Actors Continue to Gain Access Through Third Parties and Legitimate System Tools
- Major Outage in OpenAI’s ChatGPT and API
- Data broker / initial-access broker / hacktivist group: 20 million PII data from U.S. Department of the Treasury and NoName057(16)
- Vulnerabilities: CVE-2023-21388 and CVE-2023-21387
- Exploits: CVE-2022-31101 and CVE-2022-33891
- Breaches: Combolist: BreachForums: BlackHatProTools Data Breach and BreachForums: The Art Story Data Breach
ZeroFox Intelligence Brief - Executive Order Outlines U.S. Priorities on AI Governance, Risk Mitigation
ZeroFox Intelligence provides an overview of U.S. President Joe Biden’s Executive Order outlining a policy roadmap for artificial intelligence (AI). The roadmap includes measures to safeguard against emerging risks and to orchestrate a framework for the responsible development and deployment of AI. The order reflects a concern that unchecked proliferation of GPT-like models could lead to a heretofore unseen malicious use by bad actors, against which it would be hard to defend. It further seeks to protect U.S.-based data and places the burden for enhanced regulatory oversight on the Secretary of Commerce to improve transparency regarding how AI data is used by non-U.S. entities.
FBI: Ransomware Actors Continue to Gain Access Through Third Parties and Legitimate System Tools
The FBI has published a Private Industry Notification to highlight current and emerging ransomware initial-access trends and recommends mitigation measures to reduce the likelihood and impact of such incidents. The notification primarily focuses on ransomware actors exploiting vulnerabilities in vendor-controlled remote access to casino servers and companies attacked through legitimate system-management tools to elevate network permissions. A notable example provided was Silent Ransom Group (also called Luna Moth) conducting callback-phishing attacks initiated by sending victims a phone number, framed in a fake narrative of pending charges on the victims’ account.
A Major Outage Brought Down OpenAI’s ChatGPT and API
OpenAI investigated a major outage on November 8 that took down its large language model-based chatbot, ChatGPT, along with its Application Programming Interface (API). On November 6, OpenAI had announced improvements and new features for its API and ChatGPT. Following this, there was a partial outage on November 7 before the major outage on November 8. The engineering team identified the issue that was causing high error rates across the API and ChatGPT and implemented a solution, facilitating a return to normal functioning of the affected systems. ZeroFox Intelligence has observed the self-proclaimed hacktivist group Anonymous Sudan claim responsibility for the outage but there is no concrete evidence to support this claim yet.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- Telegram user: Offering to sell 20 million PII data from U.S. Department of the Treasury
- NoName057(16): Targeting the transportation sector of the Czech Republic
VULNERABILITIES
- CVE-2023-21388: This could lead to local escalation of privilege with no additional execution privileges needed.
- CVE-2023-21387: In User Backup Manager, there is a possible way to leak a token to bypass user confirmation for backup due to log information disclosure.
EXPLOITS
- CVE-2022-31101: Prestashop Blockwishlist 2.1.0 SQL Injection
- CVE-2022-33891: Apache Spark Unauthenticated Command Injection
BREACHES
- BreachForums: BlackHatProTools Data Breach (109,001 Records) Email address, username, password, and IP address
- BreachForums: The Art Story Data Breach (1,048,575 Records) Email address, username, password, IP address, and user activity
Tags: DIB, tlp:green