zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - December 19, 2023

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - December 19, 2023

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Xfinity Confirms Data Breach After October Cyberattack
  • Play Ransomware Group Targets Countries in Europe and the Americas
  • Critical RCE Flaw in Perforce Helix Core Server

Xfinity Confirms Data Breach After October Cyberattack

Xfinity has confirmed that an October cyberattack has exposed customer information, including usernames, hashed passwords, and the last four digits of Social Security numbers. An investigation into the attack revealed that threat actors had gained unauthorized access to Xfinity’s internal systems through a then-unpatched vulnerability in its Citrix software system. The company has asked customers to enable two-factor or multi-factor authentication to secure their Xfinity account.

Play Ransomware Group Targets Countries in Europe and the Americas

The Play ransomware group, operating under aliases such as Playcrypt, has impacted businesses and critical infrastructure across North America, South America, and Europe since June 2022. As ZeroFox reports, this is very likely due to, in part, the abundance of lucrative potential targets in North America owing to its significant digital infrastructure. Within all regions, the manufacturing and construction industries are the most heavily targeted. As of October 2023, the FBI noted around 300 entities affected by the ransomware group. The group prioritizes deal secrecy, utilizing a double-extortion model by encrypting systems after exfiltrating data. Notably, ransom notes lack initial payment instructions, prompting victims to contact the threat actors via email. The FBI, CISA, and ASD's ACSC recommend organizations implement mitigations, including multi-factor authentication, offline backups, recovery plans, and regular updates, to reduce the risk and impact of ransomware incidents.

Critical RCE Flaw in Perforce Helix Core Server

Perforce Helix Core Server, a source-code management platform widely used in the entertainment, government, military, technology and government sectors, has addressed four vulnerabilities. Three of these involve denial of service (DoS) issues that can lead to financial losses in large-scale deployments, while a critical vulnerability allows arbitrary remote code execution as LocalSystem by unauthenticated attackers. Attackers exploiting this vulnerability (CVE-2023-45849) could install backdoors, access sensitive data, modify system settings, and potentially gain complete control over the affected system running a vulnerable version of Perforce Server. Users should download the latest version of Helix Core from the vendor's download portal to mitigate this situation.

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

VULNERABILITIES

  • CVE-2023-49797: PyInstaller bundles a Python application and all its dependencies into a single package. A PyInstaller built application, elevated as a privileged process, may be tricked by an unprivileged attacker into deleting files the unprivileged user does not otherwise have access to. A user is affected if all the following are satisfied: 1. The user runs an application containing either matplotlib or win32com. 2. The application is ran as administrator (or at least a user with higher privileges than the attacker). 3. The user's temporary directory is not locked to that specific user (most likely due to TMP/TEMP environment variables pointing to an unprotected, arbitrary, non default location). Either: A. The attacker is able to very carefully time the replacement of a temporary file with a symlink. This switch must occur exactly between shutil.rmtree()'s builtin symlink check and the deletion itself B: The application was built with Python 3.7.x or earlier which has no protection against Directory Junctions links. The vulnerability has been addressed in PR #7827 which corresponds to pyinstaller >= 5.13.1. Users are advised to upgrade. There are no known workarounds for this vulnerability.
  • CVE-2023-5432: The Jquery news ticker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'jquery-news-ticker' shortcode in versions up to, and including, 3.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

EXPLOITS

  • CVE-2021-45837: It is possible to execute arbitrary commands as root in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517) by sending a specifically crafted input to /tos/index.php?app/del.
  • CVE-2021-45841: In Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517), an attacker can self-sign session cookies by knowing the target's MAC address and the user's password hash. Guest users (disabled by default) can be abused using a null/empty hash and allow an unauthenticated attacker to login as guest.

BREACHES

Tags: DIB, tlp:green