ZeroFox Daily Intelligence Brief - November 23, 2023
|by Alpha Team

ZeroFox Daily Intelligence Brief - November 23, 2023
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- ALPHV Ransomware Targets Autonomous Flight Technologies (AFT)
- Personal Data of Almost 8.5 Million Patients Exposed in Healthcare SaaS Provider Breach
- ZeroFox Intelligence Flash Report - Ceasefire Between Israel and Hamas
- Data broker / initial-access broker / hacktivist group: Mysterious Team Bangladesh and BreachForums user IntelBroker
- Vulnerabilities: CVE-2023-29076 and CVE-2023-47688
- Breaches: Credit Card Data Breach: 2023-11-22
ALPHV Ransomware Targets Autonomous Flight Technologies (AFT)
ZeroFox intelligence has observed ALPHV ransomware gang list Autonomous Flight Technologies (AFT), a commercial Unmanned Aircraft Systems (UAS) operator in the United States, as a victim on its leak site. AFT specializes in the advancement of small-scale aircraft related to the UAV/UAS industry and is also a vendor to notable names in the American aerospace industry. ALPHV (also known as BlackCat) claims to have stolen some data from AFT’s systems and stated that “We gave away you [sic] data to another country. “
Personal Data of Almost 8.5 Million Patients Exposed in Healthcare SaaS Provider Breach
Healthcare SaaS (software as a service) provider Welltok has reported a data breach, confirming that the personal data of 8,493,379 people has been exposed. Earlier, in a notice sent out to impacted people, Welltok notified that the data exposed varies from person to person and possibly includes details such as names, Social Security numbers, and Medicare/Medicaid ID Numbers. The notice also states that Welltok’s MOVEit Transfer server was subjected to the breach in July, 2023, which happened despite the company applying the patches for the MOVEit vulnerability as soon as they were released.
ZeroFox Intelligence Flash Report - Ceasefire Between Israel and Hamas
During the early morning hours local time on November 22, 2023, Israel’s Cabinet approved a hostage exchange and four-day ceasefire with Hamas. Daily extensions to the ceasefire are possible but unlikely to expand beyond 10 days in total. Hamas could use the ceasefire to regroup militarily in an attempt to increase the cost to Israel for restarting military operations. ZeroFox assesses that cyber threat actors will likely continue targeting the Israeli government and private entities while continuing to amplify reports on supposed ceasefire violations.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- Mysterious Team Bangladesh: DDoS Claimed Against Saudi National Bank
- BreachForums user IntelBroker: Offers to Sell Alleged Access to General Electric Company
VULNERABILITIES
- CVE-2023-29076: A maliciously crafted MODEL, SLDASM, SAT or CATPART file when parsed through Autodesk AutoCAD 2024 and 2023 could cause memory corruption vulnerability.
- CVE-2023-47688: Cross-Site Request Forgery (CSRF) vulnerability in Alexufo Youtube SpeedLoad plugin <= 0.6.3 versions.
BREACHES
- Credit Card Data Breach: 2023-11-22 (51eb83 | 3607)
Tags: DIB, tlp:green