ZeroFox Daily Intelligence Brief - November 10, 2023
|by Alpha Team

ZeroFox Daily Intelligence Brief - November 10, 2023
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- ZeroFox Intelligence Brief - Executive Order Outlines U.S. Priorities on AI Governance, Risk Mitigation
- FBI: Ransomware Actors Continue to Gain Access Through Third Parties and Legitimate System Tools
- Major Outage in OpenAI’s ChatGPT and API
- Data broker / initial-access broker / hacktivist group: 20 million PII data from U.S. Department of the Treasury and NoName057(16)
- Vulnerabilities: CVE-2023-21388 and CVE-2023-21387
- Exploits: CVE-2022-31101 and CVE-2022-33891
- Breaches: Combolist: BreachForums: BlackHatProTools Data Breach and BreachForums: The Art Story Data Breach
ZeroFox Flash Report: Ransomware and Digital Extortion Landscape Diversifying
ZeroFox Intelligence reports a fall in the operational tempo of attacks by major strains (such as LockBit and ALPHV), both in the number of observed incidents and as a proportion of all ransomware and digital extortion (R&DE) activity. Newly-observed R&DE threat collectives—some of these likely to be rebrands of established threat collectives and former affiliates of LockBit and ALPHV—are launching their own operations and are more than offsetting the decline in LockBit and ALPHV activity. This will likely drive significant change across the threat landscape in coming quarters.
Microsoft’s SysAid Zero-day Vulnerability Faces Exploitation by Lace Tempest
Microsoft has reported that a zero-day vulnerability (CVE-2023-47246) in the SysAid IT support software was exploited in limited attacks by Lace Tempest, a threat actor known to deploy Clop ransomware. Microsoft has subsequently been able to patch this vulnerability in the most recent software update, 23.3.36. In August–September 2023, ZeroFox Intelligence had observed this threat actor release datasets stolen from close to 150 victims, including some of the biggest names in finance, management consultancy, healthcare, education, and other prominent industries.
Ransomware Attack on The Industrial & Commercial Bank of China (ICBC) Disrupts U.S. Treasury Market Trades
The Industrial and Commercial Bank of China (ICBC) is actively trying to restore its system after a ransomware attack disrupted some trades in the U.S. Treasury market on November 8. This in turn caused equities clearing issues, as reported by the Treasury Department. Because of this attack, the ICBC was unable to settle the U.S. Treasury trades for other market participants. A temporary fix supposedly suggested by the bank suggests some of its brokerage clients to reroute their trades. At the time of reporting, there is no official statement from ICBC confirming the severity of the attack.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- Exploit user Roblette: Selling remote desktop access to a U.S.-based advertising and marketing company
VULNERABILITIES
- CVE-2023-21393: This could lead to local escalation of privilege with no additional execution privileges needed.
- CVE-2023-21397: In Setup Wizard, there is a possible way to save a WiFi network due to an insecure default value.
EXPLOITS
- CVE-2022-35405: Zoho Password Manager Pro XML-RPC Java Deserialization
BREACHES
- Combolist: '3544X_Epic_Games__.Vixzz_FREE_Drop.txt' (2,694 Records) Email address and password
Tags: DIB, tlp:green