ZeroFox Daily Intelligence Brief - November 16, 2023
|by Alpha Team

ZeroFox Daily Intelligence Brief - November 16, 2023
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- ZeroFox Intelligence Flash Report - Anonymous Sudan Increases Attack Tempo
- #StopRansomware: Rhysida Ransomware
- VMware Reports an Unpatched Critical Authentication Bypass Flaw in VMware Cloud Director Appliance
- Data broker / initial-access broker / hacktivist group: Exploit user Big-Bro and Exploit user resetmyname
- Vulnerabilities: CVE-2023-5217 and CVE-2023-20273
- Breaches: BreachForums: India Bullion and Jewellers Association (IBJA) Data Breach (9,820 Records) and BreachForums: Italian_136k Data Leak (136,660 Records)
ZeroFox Intelligence Flash Report - Anonymous Sudan Increases Attack Tempo
ZeroFox Intelligence has published a flash report highlighting the increased frequency of attacks associated with cyber threat group Anonymous Sudan in Q3 and Q4 2023. The group specializes in distributed denial-of-service (DDoS) attacks, usually against user-facing services such as applications and webpages. Over several days beginning on November 8, 2023, the group targeted various services operated by Open AI, such as ChatGPT and the company's Application Programming Interface (API), with periodic DDoS attacks. The recent increase in its attack tempo is likely tied to the ongoing Israel-Hamas War and the perceived stances taken by Western entities, which also explains the group’s association with attacks targeting aspects of the Israeli government.
#StopRansomware: Rhysida Ransomware
U.S. cybersecurity authorities have sounded an alert against Rhysida ransomware, which has been attacking education, healthcare, manufacturing, information technology, and government sectors since May 2023. Rhysida operators often gain initial access through external-facing remote services, such as virtual private networks (VPNs), via compromised valid credentials. They have been observed using living-off-the-land techniques, such as creating Remote Desktop Protocol (RDP) connections for lateral movement, establishing VPN access, and utilizing PowerShell to evade detection. As reported in an earlier edition of the ZeroFox Daily Intelligence Brief, the U.S. Health Sector Cybersecurity Coordination Center (HC3) had highlighted Rhysida’s high-impact attacks across various industries, including healthcare and public health, in August this year.
VMware Reports an Unpatched Critical Authentication Bypass Flaw in VMware Cloud Director Appliance
VMware has warned users about an authentication bypass vulnerability (CVE-2023-34060) in VMware Cloud Director Appliance. The company has stated that the vulnerability, with a CVSSv3 base score of 9.8, only affects deployments that have upgraded to 10.5 from an older release. Even though a patch is not available at the time of reporting, VMware has listed a workaround to help remediate the flaw till it releases a patch. The workaround is only applicable to the affected versions of VMware Cloud Director 10.5.0; implementing it requires downloading a custom script released by VMware.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- Exploit user Big-Bro: Selling network access to unnamed Dutch financial company
- Exploit user resetmyname: Selling a bundle that allegedly contains 30,000 compromised accounts, impacting various Polish banks
VULNERABILITIES
- CVE-2023-5217: Heap buffer overflow in vp8 encoding in libvpx in Google Chrome allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- CVE-2023-20273: A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to inject commands with the privileges of root.
BREACHES
- BreachForums: India Bullion and Jewellers Association (IBJA) Data Breach (9,820 Records) Email address, phone number, and physical address
- BreachForums: Italian_136k Data Leak (136,660 Records) Email address, name, gender, and phone number
Tags: DIB, tlp:green