zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - November 22, 2023

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - November 22, 2023

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Binance CEO “CZ” Steps Down
  • Government Cybersecurity Agencies Release an Advisory on LockBit Affiliates Leveraging Citrix Bleed Vulnerability
  • Data of Thousands of People Exposed After Auto Parts Giant Suffers a Massive Data Breach
  • Data broker / initial-access broker / hacktivist group: Anonymous Sudan and Cyber Toufan
  • Vulnerabilities: CVE-2023-6248 and CVE-2023-49104
  • Exploits: CVE-2007-3898 and CVE-2018-19246
  • Breaches: BreachForums: Boston College Data Breach (15,768 Records)

Binance CEO “CZ” Steps Down; Pleads Guilty to Federal Charges

Embattled crypto exchange Binance has pleaded guilty and agreed to pay a total of over USD 4 billion to resolve the U.S. Department of Justice’s investigation into violations related to the Bank Secrecy Act, failure to register as a money transmitting business, and the International Emergency Economic Powers Act. Controversial founder and crypto-celebrity Changpeng “CZ” Zhao has also pleaded guilty to failing to maintain an effective anti-money laundering program and resigned as CEO of Binance.

Government Cybersecurity Agencies Release an Advisory on LockBit Affiliates Leveraging Citrix Bleed Vulnerability

U.S. and Australian cybersecurity authorities have released a cybersecurity advisory alerting network defenders about LockBit 3.0 ransomware affiliates and other threat actor groups exploiting Citrix Bleed (CVE-2023-4966). This flaw impacts Citrix's NetScaler ADC and Gateway appliances. LockBit has been known to target diverse sectors, prompting the release of tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) to aid network defenders. The authoring agencies advise defenders to respond to compromises as soon as they are detected utilizing methods provided in the advisory, followed by immediate patching efforts.

Data of Thousands of People Exposed After Auto Parts Giant Suffers a Massive Data Breach

AutoZone, a leading auto-parts retailer, is notifying customers of a data breach that has left the data of 184,995 victims exposed. The breach has been affiliated with a vulnerability in the MOVEit Transfer application. AutoZone has therefore decided to temporarily disable the application, rebuild the compromised systems, and finally, patch the bug. The MOVEit vulnerability has already been exploited several times in 2023, mostly by the Clop ransomware gang. In August–September 2023, ZeroFox Intelligence observed Clop release datasets stolen from some of the biggest names in finance, management consultancy, healthcare, education, and other prominent industries.

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

VULNERABILITIES

  • CVE-2023-6248: The Syrus4 IoT gateway utilizes an unsecured MQTT server to download and execute arbitrary commands.
  • CVE-2023-49104: An issue was discovered in ownCloud owncloud/oauth2 before 0.6.1, when Allow Subdomains is enabled.

BREACHES

Tags: DIB, tlp:green