ZeroFox Daily Intelligence Brief - November 18, 2023
|by Alpha Team

ZeroFox Daily Intelligence Brief - November 18, 2023
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Fortinet Reports a Critical OS Command Injection Vulnerability in FortiSIEM Report Server
- MySQL Servers Targeted by “Ddostf” DDoS-as-a-Service Botnet
- Toyota Financial Services Subjected to a Cyber Attack Claimed By Medusa Ransomware
- Data broker / initial-access broker / hacktivist group: Exploit user Big-Bro and Exploit user mrbin228
- Vulnerabilities: CVE-2023-5444 and CVE-2023-38324
- Exploits: CVE-2007-3898 and CVE-2018-19246
- Breaches: BreachForums: France Crypto Leads Data Leak (830,538 Records) and BreachForums: USA_PRIVATE_DATA_50M Data Leak (36,434,668 Records)
Fortinet Reports a Critical OS Command Injection Vulnerability in FortiSIEM Report Server
Fortinet has alerted customers about an operating system command-injection vulnerability (CVE-2023-36553) in the FortiSIEM report server. The vulnerability, with a critical CVSSv3 score of 9.3, affects all versions of Fortisiem 4.7, 4.9, 4.10, 5.0, 5.1, 5.2, 5.3, and 5.4. It can be targeted and exploited by unauthorized remote attackers to execute commands via crafted API requests. This bug was initially discovered as a variant of another critical vulnerability fixed in October, 2023. Fortinet has had prior cybersecurity issues in 2023. In September, ZeroFox Intelligence observed a moderately credible threat actor advertise Fortinet’s VPN access to 320 different companies based in the U.S. and Europe on the predominantly Russian language forum Exploit.
MySQL Servers Targeted by “Ddostf” DDoS-as-a-Service Botnet
Security researchers have observed MySQL servers being targeted by the “Ddostf” botnet, which abuses vulnerabilities in unpatched MySQL environments or brute-force weak administrator credentials. This Chinese-origin malware botnet has been observed targeting both Linux and Windows systems. Researchers have highlighted that the botnet’s ability to connect to a new C2 address makes it challenging to take down.
Toyota Financial Services Subjected to a Cyber Attack Claimed By Medusa Ransomware
A disruptive cyberattack has targeted the Germany branch of Toyota Financial Services (TFS), the vehicle financing and leasing subsidiary of the Japanese automobile manufacturer. Medusa ransomware group has claimed to orchestrate this breach and steal sensitive data including leasing contracts, email addresses, usernames and passwords, passport details. The group has also demanded a payment of USD 8 million to delete the data it has allegedly taken from the company’s breached servers. Once the attack was discovered earlier this week, the company decided to take its affected systems offline. Previously, ZeroFox Intelligence observed Medusa naming Auckland Transport and Jockey Club Argentina in its list of victims in September and October, respectively.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- Exploit user Big-Bro: Advertising Citrix and RDP access to undisclosed UAE-based company
- Exploit user mrbin228: Advertising network access to U.S.-based apparel and accessories retail company
VULNERABILITIES
- CVE-2023-5444: A Cross Site Request Forgery vulnerability in ePolicy Orchestrator prior to 5.10.0 CP1 Update 2
- CVE-2023-38324: An issue was discovered in OpenNDS Captive Portal before version 10.1.2.
BREACHES
- BreachForums: France Crypto Leads Data Leak (830,538 Records) Name, email address, and phone number
- BreachForums: USA_PRIVATE_DATA_50M Data Leak (36,434,668 Records) Name, email and postal address, job title, company name, gender, social media profile, and user activity
Tags: DIB, tlp:green