zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - November 18, 2023

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - November 18, 2023

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Fortinet Reports a Critical OS Command Injection Vulnerability in FortiSIEM Report Server
  • MySQL Servers Targeted by “Ddostf” DDoS-as-a-Service Botnet
  • Toyota Financial Services Subjected to a Cyber Attack Claimed By Medusa Ransomware
  • Data broker / initial-access broker / hacktivist group: Exploit user Big-Bro and Exploit user mrbin228
  • Vulnerabilities: CVE-2023-5444 and CVE-2023-38324
  • Exploits: CVE-2007-3898 and CVE-2018-19246
  • Breaches: BreachForums: France Crypto Leads Data Leak (830,538 Records) and BreachForums: USA_PRIVATE_DATA_50M Data Leak (36,434,668 Records)

Fortinet Reports a Critical OS Command Injection Vulnerability in FortiSIEM Report Server

Fortinet has alerted customers about an operating system command-injection vulnerability (CVE-2023-36553) in the FortiSIEM report server. The vulnerability, with a critical CVSSv3 score of 9.3, affects all versions of Fortisiem 4.7, 4.9, 4.10, 5.0, 5.1, 5.2, 5.3, and 5.4. It can be targeted and exploited by unauthorized remote attackers to execute commands via crafted API requests. This bug was initially discovered as a variant of another critical vulnerability fixed in October, 2023. Fortinet has had prior cybersecurity issues in 2023. In September, ZeroFox Intelligence observed a moderately credible threat actor advertise Fortinet’s VPN access to 320 different companies based in the U.S. and Europe on the predominantly Russian language forum Exploit.

MySQL Servers Targeted by “Ddostf” DDoS-as-a-Service Botnet

Security researchers have observed MySQL servers being targeted by the “Ddostf” botnet, which abuses vulnerabilities in unpatched MySQL environments or brute-force weak administrator credentials. This Chinese-origin malware botnet has been observed targeting both Linux and Windows systems. Researchers have highlighted that the botnet’s ability to connect to a new C2 address makes it challenging to take down.

Toyota Financial Services Subjected to a Cyber Attack Claimed By Medusa Ransomware

A disruptive cyberattack has targeted the Germany branch of Toyota Financial Services (TFS), the vehicle financing and leasing subsidiary of the Japanese automobile manufacturer. Medusa ransomware group has claimed to orchestrate this breach and steal sensitive data including leasing contracts, email addresses, usernames and passwords, passport details. The group has also demanded a payment of USD 8 million to delete the data it has allegedly taken from the company’s breached servers. Once the attack was discovered earlier this week, the company decided to take its affected systems offline. Previously, ZeroFox Intelligence observed Medusa naming Auckland Transport and Jockey Club Argentina in its list of victims in September and October, respectively.

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

VULNERABILITIES

  • CVE-2023-5444: A Cross Site Request Forgery vulnerability in ePolicy Orchestrator prior to 5.10.0 CP1 Update 2
  • CVE-2023-38324: An issue was discovered in OpenNDS Captive Portal before version 10.1.2.

BREACHES

Tags: DIB, tlp:green