zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - December 1, 2023

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - December 1, 2023

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Staples Confirms Cyberattack Behind Service Outages, Delivery Issues
  • NY Attorney General Alerts New Yorkers of Potential Identity Theft After PJ&A Data Breach
  • Apple Releases Patches for Two New iOS Zero-Days in Emergency Updates
  • Data broker / initial-access broker / hacktivist group: We Red Evils (Telegram) and IntelBroker (BreachForums)
  • Vulnerabilities: CVE-2023-45480 and CVE-2023-6264
  • Exploits: CVE-2023-46517
  • Breaches: BreachForums: Winner Data Breach (214,802 Records)

Staples Confirms Cyberattack Behind Service Outages, Delivery Issues

Staples has initiated a service outage to protect customer information after a confirmed cyberattack. Staples’s quick response reportedly limited its attack sphere; no ransomware was deployed in the attack and no files were encrypted. The temporary outage has affected the office supply retailer’s online deliveries, as well as its backend and customer-facing processes. Staples is mitigating the situation by shutting down its network and VPN, disallowing employees access to their email, bizfit, pogs, ehelp desk, and efforts are underway to restore all systems.

NY Attorney General Alerts New Yorkers of Potential Identity Theft After PJ&A Data Breach

New York Attorney General Letitia James advised victims of a data breach at Perry Johnson & Associates (PJ&A), a prominent American medical-transcription services and solutions provider, to be wary of potential identity theft. PJ&A suffered a cyberattack earlier this year, which left the personal information of almost 9 million patients exposed to threat actors. The attorney general has advised the victims to monitor their credit, place a free credit freeze on their credit report, place a fraud alert on their credit report, get copies of their medical records, contest any unrecognized medical bills, and inform their insurance companies of any suspected fraud.

Apple Releases Patches for Two New iOS Zero-Days in Emergency Updates

Apple has notified customers of emergency updates, iOS 17.1.2, Safari 17.1.2, macOS Sonoma 14.1.2, and iPadOS 17.1.2, to patch two zero-day vulnerabilities tracked in the WebKit browser engine that affect iPhones, Macs and iPads. The two bugs (CVE-2023-42916 and CVE-2023-42917) can allow unauthorized actors to access sensitive information through an out-of-bounds read compromise and execute arbitrary code via a memory corruption vulnerability. The security advisory also stated that the company knows that threat actors might have exploited these vulnerabilities against versions of iOS before iOS 16.7.1.

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

VULNERABILITIES

  • CVE-2023-45480: Tenda AC10 version US_AC10V4.0si_V16.03.10.13_cn contains a stack overflow via the src parameter in the function sub_47D878.
  • CVE-2023-6264: Information leak in Content-Security-Policy header in Devolutions Server 2023.3.7.0 allows an unauthenticated attacker to list the configured Devolutions Gateways endpoints.

EXPLOITS

  • CVE-2023-46517: XAMPP v3.3.0 — '.ini' Buffer Overflow (Unicode + SEH)

BREACHES

Tags: DIB, tlp:green