zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - November 17, 2023

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - November 17, 2023

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • FBI and CISA Release Advisory on Scattered Spider Group
  • City of Long Beach, California, Issues Official Statement Warning of a Potential Cybersecurity Attack
  • Four Separate Campaigns Exploit a Zero-Day in Zimbra Collaboration
  • Data broker / initial-access broker / hacktivist group: Exploit user Storieo and Exploit user sandocan
  • Vulnerabilities: CVE-2023-40224 and CVE-2023-34058
  • Breaches: Credit Card Data Breach: 2023-11-16 (7f8ce9 | 2913) and Combolist: '50k_Fortnite.txt' (49,921 Records)

FBI and CISA Release Advisory on Scattered Spider Group

The Federal Bureau of Investigation (FBI) and U.S. Cybersecurity and Infrastructure Security Agency (CISA) have published a joint advisory on Scattered Spider, a cybercriminal group that has been observed targeting large companies and their contracted IT help desks. Scattered Spider (also known as Starfraud, UNC3944, Scatter Swine, and Muddled Libra) uses various social-engineering techniques, especially phishing, push bombing, and SIM-swapping attacks, to obtain credentials, install remote access tools, and/or bypass multi-factor authentication (MFA). The gang has historically evaded detection on target networks by using living-off-the-land techniques and allowlisted applications to navigate victim networks, as well as frequently modifying its tactics, techniques, and procedures.

City of Long Beach, California, Issues Official Statement Warning of a Potential Cybersecurity Attack

On November 14, the City of Long Beach became aware of a probable cybersecurity attack threatening its network security. At the time of reporting, the source and scope of the attack remain unidentified. There has also been no indication of any impact this incident might have had on the City’s public safety systems such as the Emergency Communications Center and emergency response (police, fire services, etc). In response to this incident, the City has decided to take systems offline during the investigation and the remediation thereafter, which could take several days.

Four Separate Campaigns Exploit a Zero-Day in Zimbra Collaboration

In June 2023, cybersecurity researchers discovered an in-the-wild exploit of a zero-day cross-site scripting (XSS) vulnerability (CVE-2023-37580) in Zimbra Collaboration email software. In the next two months, this vulnerability was actively exploited by three threat groups to target government organizations in Greece, Moldova and Tunisia, and Vietnam respectively. Zimbra released a patch for CVE-2023-37580 on July 25, 2023. Even after this, another campaign was discovered in August, 2023, which used the vulnerability against a government organization in Pakistan.

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

VULNERABILITIES

  • CVE-2023-40224: MISP 2.4.174 allows XSS in app/View/Events/index[.]ctp.
  • CVE-2023-34058: VMware Tools contains a SAML token signature bypass vulnerability.

BREACHES

Tags: DIB, tlp:green