ZeroFox Cyber Intelligence Daily Brief - December 14, 2023
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - December 14, 2023
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- ZeroFox Intelligence Flash Report: Network Access Sale Linked to Chandrayaan-3 Mission
- CISA and Partners Release Advisory on Russian SVR-affiliated Cyber Actors Exploiting CVE-2023-42793
- Chinese-Linked Botnet Can Potentially Disrupt U.S. Communication Infrastructure
ZeroFox Intelligence Flash Report: Network Access Sale Linked to Chandrayaan-3 Mission
On December 6, 2023, well-regarded access broker “RobinHood” announced on Russian-language dark web forum RAMP the sale of likely network access to an unnamed India-based organization that has an ongoing partnership with India’s Chandrayaan-3 mission. Ransomware cartels frequently leverage RAMP to purchase such accesses from brokers; the post likely represents a legitimate network access sale, judging from RobinHood’s long-standing positive reputation.
CISA and Partners Release Advisory on Russian SVR-affiliated Cyber Actors Exploiting CVE-2023-42793
Cybersecurity officials from the United States, the United Kingdom, and Poland have published a joint advisory on Russian Foreign Intelligence Service (SVR)-affiliated cyber actors targeting servers hosting JetBrains TeamCity software since September 2023. APT 29 (also known as the Dukes, CozyBear, and NOBELIUM/Midnight Blizzard) are exploiting a bug tracked as CVE-2023-42793 at a large scale, bypassing authorization and conducting arbitrary code execution on the compromised servers. The joint advisory provides details, including actionable indicators of compromise (IOCs) and SIGMA and YARA rules, to help defenders guard their networks.
Chinese-Linked Botnet Can Potentially Disrupt U.S. Communication Infrastructure
International cybersecurity authorities are associating Chinese state-sponsored APT group Volt Typhoon with a botnet called KV-botnet, which is known to compromise small office/home office (SOHO) networks. The threat actors have been using living off-the-land tactics that deploy built-in network administration tools to target critical organizations, including telecommunication and internet service providers, a U.S. territorial government entity in Guam, a renewable energy firm in Europe, and U.S. military organizations. The list of targets implies that the attacks are being conducted for espionage and information-gathering purposes.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- BreachForums user Sanggiero: Actor Claims to Leak Financial Data From Morningstar
- BreachForums user Tanaka: Actor Claims to Leak Data From Goa Natural Gas
VULNERABILITIES
- CVE-2023-5869: A flaw was found in PostgreSQL that allows authenticated database users to execute arbitrary code through missing overflow checks during SQL array value modification. This issue exists due to an integer overflow during array modification.
- CVE-2023-39417: IN THE EXTENSION SCRIPT, a SQL Injection vulnerability was found in PostgreSQL if it uses @extowner@, @extschema@, or @extschema:...@ inside a quoting construct (dollar quoting, '', or ""). If an administrator has installed files of a vulnerable, trusted, non-bundled extension, an attacker with database-level CREATE privilege can execute arbitrary code as the bootstrap superuser.
EXPLOITS
- CVE-2023-2068: The File Manager Advanced Shortcode WordPress plugin through 2.3.2 does not adequately prevent uploading files with disallowed MIME types when using the shortcode. This leads to RCE in cases where the allowed MIME type list does not include PHP files. In the worst case, this is available to unauthenticated users.
- CVE-2023-36266: An issue was discovered in Keeper Password Manager for Desktop version 16.10.2, and the KeeperFill Browser Extensions version 16.5.4, allows local attackers to gain sensitive information via plaintext password storage in memory after the user is already logged in, and may persist after logout. NOTE: the vendor disputes this for two reasons: the information is inherently available during a logged-in session when the attacker can read from arbitrary memory locations, and information only remains available after logout because of memory-management limitations of web browsers (not because the Keeper technology itself is retaining the information).
BREACHES
- Combolist: '300K Combo.txt' (165,313 Records): Email Address, Password
- Combolist: 'blockchain.com (3).txt' (93,722 Records): Email Address, Password
Tags: DIB, tlp:green