zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - December 7, 2023

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - December 07, 2023

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • U.S. Navy Contractor Austal USA Targeted in a Cyberattack
  • ZeroFox Intelligence Brief: An Introduction to Nation-State Cyber Threats
  • CISA Adds Four Known Exploited Vulnerabilities to Catalog

U.S. Navy Contractor Austal USA Targeted in a Cyberattack

Austal USA, a ship-building contractor for the U.S. Department of Defense (DoD) and the Department of Homeland Security (DHS), has reportedly confirmed a cyberattack and is currently mitigating the situation. Earlier this week, ZeroFox Intelligence observed Hunters International Ransomware group claim to have breached Austal USA. The group has also allegedly leaked some data as proof of the attack and is threatening to release more data supposedly stolen from the navy contractor. However, Austal USA has stated that no personal or classified information was compromised in the attack.

ZeroFox Intelligence Brief: An Introduction to Nation-State Cyber Threats

In this Intelligence Brief, ZeroFox researchers highlight how Nation states’ cyber programs often leverage a range of threat actors falling under three categories: nation-state actors, nation state-sponsored actors, and nation state-aligned actors. The distinctions between these categories almost certainly vary depending on the country, and some nations are assessed to intentionally blur them. Despite the terms often being used interchangeably, Advanced Persistent Threats (APTs) are not synonymous with nation-state actors. APTs span the full-range of nation-state linked threat actors, while some APTs likely lie outside nation-state programs altogether.

CISA Adds Four Known Exploited Vulnerabilities to Catalog

Four Qualcomm vulnerabilities (CVE-2023-33106, CVE-2023-33063, CVE-2023-33107, and CVE-2022-22071) make it to Cybersecurity and Infrastructure Security Agency’s (CISA’s) Known Exploited Vulnerabilities Catalog for the risk they pose to federal enterprises. These vulnerabilities are reported to cause memory corruption in an AUX command, DSP Services, and Graphics Linux and allow possible memory use-after-free errors. Federal Civilian Executive Branch (FCEB) agencies must remediate these vulnerabilities by December 26, 2023, to protect their networks.

VULNERABILITIES

  • CVE-2023-6568: Cross-site Scripting (XSS) - Reflected in GitHub repository mlflow/mlflow prior to 2.9.0.
  • CVE-2023-41106: An issue was discovered in Zimbra Collaboration (ZCS) before 10.0.3. An attacker can gain access to a Zimbra account. This is also fixed in 9.0.0 Patch 35 and 8.8.15 Patch 42.

EXPLOITS

  • CVE-2023-39026: Directory Traversal vulnerability in FileMage Gateway Windows Deployments v.1.10.8 and before allows a remote attacker to obtain sensitive information via a crafted request to the /mgmt/ component.
  • CVE-2022-31470: An XSS vulnerability in the index_mobile_changepass.hsp reset-password section of Axigen Mobile WebMail before 10.2.3.12 and 10.3.x before 10.3.3.47 allows attackers to run arbitrary Javascript code that, using an active end-user session (for a logged-in user), can access and retrieve mailbox content.

BREACHES

Tags: DIB, tlp:green