ZeroFox Daily Intelligence Brief - November 12, 2023
|by Alpha Team

ZeroFox Daily Intelligence Brief - November 12, 2023
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Critical Confluence Bug Actively Exploited in Attacks
- ZeroFox Flash Report: Ransomware and Digital Extortion Landscape Diversifying
- FBI: Ransomware Actors Continue to Gain Access Through Third Parties and Legitimate System Tools
Critical Confluence Bug Actively Exploited in Attacks
Atlassian has escalated the severity of a critical bug (CVE-2023-22518) disclosed on October 31 from CVSS 9.1 to the highest critical rating of 10 after observing its active exploitation in the wild, including by ransomware operators. The improper authorization vulnerability affects all versions prior to the recently deployed fixed versions of Confluence Data Center and Server. While Atlassian urges administrators to patch the instances as soon as possible, the company has also shared temporary mitigation measures (backing up, disconnecting from the internet, and mitigating known attack vectors by blocking access on specific endpoints) in case upgrading to a fixed version is not possible immediately.
ZeroFox Flash Report: Ransomware and Digital Extortion Landscape Diversifying
ZeroFox Intelligence reports a fall in the operational tempo of attacks by major strains (such as LockBit and ALPHV), both in the number of observed incidents and as a proportion of all ransomware and digital extortion (R&DE) activity. Newly-observed R&DE threat collectives—some of these likely to be rebrands of established threat collectives and former affiliates of LockBit and ALPHV—are launching their own operations and are more than offsetting the decline in LockBit and ALPHV activity. This will likely drive significant change across the threat landscape in coming quarters.
FBI: Ransomware Actors Continue to Gain Access Through Third Parties and Legitimate System Tools
The FBI has published a Private Industry Notification to highlight current and emerging ransomware initial-access trends and recommends mitigation measures to reduce the likelihood and impact of such incidents. The notification primarily focuses on ransomware actors exploiting vulnerabilities in vendor-controlled remote access to casino servers and companies attacked through legitimate system-management tools to elevate network permissions. A notable example provided was Silent Ransom Group (also called Luna Moth) conducting callback-phishing attacks initiated by sending victims a phone number, framed in a fake narrative of pending charges on the victims’ account.
Tags: DIB, tlp:green