ZeroFox Cyber Intelligence Daily Brief - December 13, 2023
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - December 13, 2023
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Cybercriminals Use Wyoming Shell Companies for Global Hacks
- Apple Releases Security Updates to Patch Critical iOS and macOS Security Flaws
- Ukraine’s GUR Claims Attack on Russian Federal Tax Service
Cybercriminals Use Wyoming Shell Companies for Global Hacks
Cybercriminals are utilizing Wyoming-based limited liability companies (LLCs) for global cyberattacks involving distributed denial of services (DDoS). Cybercriminals reportedly take advantage of Wyoming’s lax regulations for setting up anonymous shell companies as foreign cybercriminals seek to mask their identity and pass internet traffic off as originating from the United States. Reporters have identified instances of Wyoming LLCs being implicated in high-profile hacking activities, including DDoS attacks targeting news organizations and nonprofits worldwide.
Apple Releases Security Updates to Patch Critical iOS and macOS Security Flaws
Apple released security patches for iOS, iPadOS, macOS, tvOS, watchOS, and Safari web browser to smooth over security issues, while also backporting fixes for two recently disclosed zero-days to older devices. The updates address multiple security vulnerabilities, covering areas including AVEVideoEncoder, ExtensionKit, and Safari Private Browsing, and WebKit. These updates also address a critical Bluetooth flaw (CVE-2023-45866) that could enable an attacker to inject keystrokes by impersonating a keyboard.
Ukraine’s GUR Claims Attack on Russian Federal Tax Service
Ukraine's Main Directorate of Intelligence (GUR) has disclosed that Ukrainian military intelligence officers successfully attacked key central servers of Russia’s Federal Taxation Service (FNS) and further breached over 2,300 regional servers across Russia and Crimea. All servers were reportedly infected with malware, leading to databases containing critical configuration files and backup copies being “completely eliminated.” The GUR claims that the paralysis of the FNS will last at least a month, with a complete recovery potentially impossible. This follows the GUR’s admission of a successful attack on Russia's Federal Air Transport Agency (Rosaviatsia) last month.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- Telegram user Anonymous Collective: Actor Claims Attack Against UAE Government
- Telegram user Cyber Toufan Operations: Actor Claims Attack Against Various Israeli Websites
VULNERABILITIES
- CVE-2023-28871: Support Assistant in NCP Secure Enterprise Client before 12.22 allows attackers to read registry information of the operating system by creating a symbolic link.
- CVE-2023-6394: A flaw was found in Quarkus. This issue occurs when receiving a request over websocket with no role-based permission specified on the GraphQL operation, Quarkus processes the request without authentication despite the endpoint being secured. This can allow an attacker to access information and functionality outside of normal granted API permissions.
BREACHES
- Combolist: 'Gaming.txt' (109,430 Records): Email Address, Password
- Combolist: 'Goods_3_10005.txt' (9,996 Records): Email Address, Password
Tags: DIB, tlp:green