ZeroFox Daily Intelligence Brief - November 29, 2023
|by Alpha Team

ZeroFox Daily Intelligence Brief - November 29, 2023
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- ZeroFox Intelligence Flash Report - Mass Access Brokering Event Impacting Corporate Citrix VPN Users
- Exploitation of Unitronics PLCs used in Water and Wastewater Systems
- Google Releases Emergency Update Fixes for The Sixth Zero-Day Vulnerability This Year
- Data broker / initial-access broker / hacktivist group: BreachForums users iotseek and IntelBroker
- Vulnerabilities: CVE-2023-3812 and CVE-2023-47172
- Breaches: Combolist: '250K UHQ MIX(CTS) SHOPPING COMBO.txt' and Telegram: 'BONUS @SNATCH_CLOUD#1.rar' Botnet Breach
ZeroFox Intelligence Flash Report - Mass Access Brokering Event Impacting Corporate Citrix VPN Users
Threat actor Punktir announced that they are selling at least 711 compromised Citrix Virtual Private Network instances with verified credentials on the Russian-speaking forum exploit[.]in. Ransomware cartels—which frequently leverage exploit[.]in to purchase access from brokers—are very likely to deem the access sale affordable and to have a potentially high return on investment. Targets included in the access sale are alleged to have a revenue of over USD 5 million and are all based in either Europe or the United States.
Exploitation of Unitronics PLCs used in Water and Wastewater Systems
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is addressing the exploitation of Unitronics programmable logic controllers (PLCs) in the water and wastewater systems sector. This exploitation is forcing authorities to take their operations offline and rely on manual processes. Threat actors may have gained a foothold by taking advantage of the system’s weak password security and its connectivity to the internet. Among other best practices detailed in the CISA alert, multifactor authentication and firewall/VPN installations can make systems less vulnerable to such risks.
Google Releases Emergency Update Fixes for The Sixth Zero-Day Vulnerability This Year
Google has released updated versions of Google Chrome (19.0.6045.199 for Mac and Linux and 119.0.6045.199/.200 for Windows) with 7 security fixes, including a patch for a zero-day vulnerability which is being actively exploited in attacks. This high severity zero-day bug (CVE-2023-6345) is the sixth zero-day bug in Chrome this year and arises from an integer overflow in Skia, an open-source 2D graphics library. Google has stated that access to CVE-2023-6345 details and links will remain restricted until a majority of the users are “updated with a fix.”
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- BreachForums user iotseek: Claims to Have Leaked Database from 3D Security Services
- BreachForums user IntelBroker: Claims to Have Leaked Database from Kaggle
VULNERABILITIES
- CVE-2023-3812: An out-of-bounds memory access flaw was found in the Linux kernel’s TUN/TAP device driver functionality.
- CVE-2023-47172: Certain WithSecure products allow Local Privilege Escalation.
BREACHES
- Combolist: '250K UHQ MIX(CTS) SHOPPING COMBO.txt' (249,795 Records): Email address and password
- Telegram: 'BONUS @SNATCH_CLOUD#1.rar' Botnet Breach (45,771 Records): Email address and password
Tags: DIB, tlp:green