ZeroFox Daily Intelligence Brief - November 21, 2023
|by Alpha Team

ZeroFox Daily Intelligence Brief - November 21, 2023
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- ZeroFox Intelligence Brief - APT41 Primer
- Two Canadian Government Contractors Hacked; Data Breach Confirmed
- SeigedSec Claims Data Breach at Idaho National Laboratory; Details of U.S. National Security Employees Allegedly Exposed
- Data broker / initial-access broker / hacktivist group: GhostSec and Storieo
- Vulnerabilities: CVE-2020-13920 and CVE-2021-26117
- Exploits: CVE-2022-0995 and CVE-2022-39952
- Breaches: Combolist: 'RESULT.txt' (197,853 Records)
ZeroFox Intelligence Brief - APT41 Primer
APT41 is among the first advanced persistent threat (APT) groups the Chinese government utilized to conduct malicious cyber activities, targeting nations and sectors of strategic relevance to China; however, the group is one of the very few APTs that also conduct cybercrime. China leverages a number of highly competent APT groups in pursuit of its strategic objectives, such as regional and global leadership in economic and security issues, control over claimed territory, and domestic regime stability. The group tends to focus on specific sectors and nations, likely at the direction of the Chinese intelligence service, the Ministry of State Security (MSS).
Two Canadian Government Contractors Hacked; Data Breach Confirmed
Data breaches resulting from the hacking of two Canadian Government contractors—Brookfield Global Relocation Services (BGRS) and SIRVA Worldwide Relocation & Moving Services—have left sensitive information of an unconfirmed number of government employees exposed. Both BGRS and SIRVA have data dating back to 1999 stored in the compromised systems. LockBit ransomware group has already taken responsibility for the cyberattack on SIRVA and published allegedly stolen data after a supposed failed negotiation with SIRVA.
SeigedSec Claims Data Breach at Idaho National Laboratory; Details of U.S. National Security Employees Allegedly Exposed
ZeroFox Intelligence has observed SeigedSec, a hacktivist group, claiming that it has gained unauthorized access to the Idaho National Laboratory, an institution under the U.S. Department of Energy that is primarily involved in nuclear research. Through a post on its Telegram channel, SeigedSec announced that it has acquired a substantial amount of sensitive data, including personal information such as full names, dates of birth, email addresses, phone numbers, Social Security numbers, addresses, and employment details. ZeroFox has also observed the group selling the allegedly stolen data on BreachForums, an underground forum and marketplace. Last month, ZeroFox had further observed SeigedSec take responsibility for DDoS attacks against Israel’s industrial control systems.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- Telegram: DDoS Claimed Against Israel Weapon Industries (GhostSec)
- Exploit: Actor advertised Citrix access to Swisscom (Storieo)
VULNERABILITIES
- CVE-2020-13920: It is possible to connect to the registry without authentication and call the rebind method to rebind jmxrmi to something else.
- CVE-2021-26117: The optional ActiveMQ LDAP login module can be configured to use anonymous access to the LDAP server.
EXPLOITS
- CVE-2022-0995: Linux Kernel Watch Queue Out-Of-Bounds Write
- CVE-2022-39952: Fortinet FortiNAC keyUpload[.]jsp Arbitrary File Write
BREACHES
- Combolist: 'RESULT.txt' (197,853 Records) Email address and password
Tags: DIB, tlp:green