zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - December 18, 2023

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - December 18, 2023

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • QakBot Malware Reborn in a Phishing Campaign Targeting Hospitality Industry Companies
  • CISA Urges Manufacturers to Eliminate Default Passwords
  • MongoDB Says Customer Data Was Exposed in a Cyberattack

QakBot Malware Reborn in a Phishing Campaign Targeting Hospitality Industry Companies

QakBot Malware, disrupted by a global law enforcement operation (Operation Duck Hunt) in August 2023, is now making a comeback via a phishing campaign targeting the hospitality industry. The malware strain is being distributed via an attachment to a phishing email seemingly sent by an IRS employee. However, clicking the attachment leads to an MSI (Microsoft Software Installer) being downloaded which when installed, launches the Qakbot malware DLL (Dynamic Link Library) into memory.

CISA Urges Manufacturers to Eliminate Default Passwords

CISA has released guidelines on how technology manufacturers can eliminate the risk of default password exploitation, as part of its new Secure by Design (SbD) Alert series. Default passwords continue to be implicated as the cause of many cyberattacks every year. To eliminate such incidents, the guidelines recommend administrators set a strong password during installation and configuration of a product or for the product to ship with a unique, strong password for each device. Furthermore, manufacturers should consider what password practices should be implemented, such as minimum password length and disallowing known breached passwords.

MongoDB Says Customer Data Was Exposed in a Cyberattack

MongoDB confirms that corporate systems were breached resulting in exposed customer data in this cyberattack. The company reports that the hackers did not access customer data stored in MongoDB Atlas although the unauthorized access had been ongoing for some time before the threat was discovered. MongoDB advises its customers to enable multi-factor authentication, rotate passwords, and remain vigilant against potential phishing and social engineering attacks.

VULNERABILITIES

  • CVE-2023-50976: Redpanda before 23.1.21 and 23.2.x before 23.2.18 has missing authorization checks in the Transactions API.
  • CVE-2023-6905: A vulnerability, which was classified as problematic, has been found in Jahastech NxFilter 4.3.2.5. This issue affects some unknown processing of the file user,adap.jsp?actionFlag=test&id=1 of the component Bind Request Handler.

BREACHES

Tags: DIB, tlp:green