ZeroFox Daily Intelligence Brief - December 3, 2023
|by Alpha Team

ZeroFox Daily Intelligence Brief - December 3, 2023
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- General Electric Investigates Claims of Cyber Attack, Data Theft
- Exploitation of Unitronics PLCs used in Water and Wastewater Systems
- ZeroFox Intelligence Flash Report - Mass Access Brokering Event Impacting Corporate Citrix VPN Users
General Electric Investigates Claims of Cyber Attack, Data Theft
General Electric has reportedly confirmed that it is investigating an alleged data breach conducted by threat actor Intelbroker. On November 24, ZeroFox Intelligence observed IntelBroker advertising on underground marketplace BreachForums about a data set supposedly stolen after breaching General Electric’s systems. IntelBroker claims that the data he has in his possession includes "a lot of DARPA-related military information," besides SSH and SVN access, SQL files, and documents.
Exploitation of Unitronics PLCs used in Water and Wastewater Systems
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is addressing the exploitation of Unitronics programmable logic controllers (PLCs) in the water and wastewater systems sector. This exploitation is forcing authorities to take their operations offline and rely on manual processes. Threat actors may have gained a foothold by taking advantage of the system’s weak password security and its connectivity to the internet. Among other best practices detailed in the CISA alert, multifactor authentication and firewall/VPN installations can make systems less vulnerable to such risks.
ZeroFox Intelligence Flash Report - Mass Access Brokering Event Impacting Corporate Citrix VPN Users
Threat actor Punktir announced that they are selling at least 711 compromised Citrix Virtual Private Network instances with verified credentials on the Russian-speaking forum exploit[.]in. Ransomware cartels—which frequently leverage exploit[.]in to purchase access from brokers—are very likely to deem the access sale affordable and to have a potentially high return on investment. Targets included in the access sale are alleged to have a revenue of over USD 5 million and are all based in either Europe or the United States.
Tags: DIB, tlp:green