ZeroFox Cyber Intelligence Daily Brief - December 21, 2023
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - December 21, 2023
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Healthcare SaaS Provider Confirms Data Breach Affected 2.7 Million Patients
- New Chrome Zero-Day Vulnerability Exploited in the Wild - Update Now
- New Web Injections Campaign Steals Banking Data from 50,000 People
Healthcare SaaS Provider Confirms Data Breach Affected 2.7 Million Patients
ESO, a prominent U.S.-based provider of software products for hospitals and healthcare systems, confirmed that a “sophisticated ransomware incident” has exposed the data of 2,700,000 individuals. On September 28, 2023, threat actors breached and encrypted some of ESO’s systems, gaining access to information stored in one of these systems. The exposed dataset includes names, dates of birth, phone numbers, patient account/medical record numbers, and Social Security numbers, among other details. To mitigate the impact of the breach, the company has sought assistance from federal authorities and is offering identity monitoring at no cost to the victims for 12 months.
New Chrome Zero-Day Vulnerability Exploited in the Wild - Update Now
Google has published new security updates following reports of a new Chrome zero-day vulnerability CVE-2023-7024 being actively exploited in the wild. The high-severity flaw, a heap-based buffer overflow bug in the WebRTC framework, poses risks of program crashes and arbitrary code execution. Users should update to Chrome versions 120.0.6099.129/130 (Windows) and 120.0.6099.129 (macOS and Linux) to mitigate potential threats. Additionally, users of Chromium-based browsers like Microsoft Edge, Brave, Opera, and Vivaldi are advised to apply fixes once available.
New Web Injections Campaign Steals Banking Data from 50,000 People
A new campaign has targeted 40 banks in the Americas, Europe, and Japan using JavaScript web injections to access over 50,000 users’ data. The attack starts with the victim's device getting infected with a strain of malware, which injects a new script tag pointing to an externally hosted script when the user visits compromised websites. The attack mechanism further leads to an obfuscated script getting loaded on the browser. This targets online banking pages that have a similar structure across organizations – enabling the attacker to gain access to user credentials and one-time passwords. Moreover, the script adapts its behavior based on instructions from its actual server, which coordinate its actions on the compromised device. Moreover, the attack paradigm is stealthy and potentially undetectable by static analysis checks.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- Exploit user Reve: Remote desktop access to travel company based in Singapore
- Exploit user crypmans: Remote desktop access to Spanish software licenses retail company
VULNERABILITIES
- CVE-2023-49760: Cross-Site Request Forgery (CSRF) vulnerability in Giannopoulos Kostas WPsoonOnlinePage.This issue affects WPsoonOnlinePage: from n/a through 1.9.
- CVE-2023-49759: Cross-Site Request Forgery (CSRF) vulnerability in gVectors Team WooDiscuz – WooCommerce Comments.This issue affects WooDiscuz – WooCommerce Comments: from n/a through 2.3.0.
EXPLOITS
- CVE-2023-28770: The sensitive information exposure vulnerability in the CGI “Export_Log” and the binary “zcmd” in Zyxel DX5401-B0 firmware versions prior to V5.17(ABYO.1)C0 could allow a remote unauthenticated attacker to read the system files and to retrieve the password of the supervisor from the encrypted file.
- CVE-2022-43769: Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x allow certain web services to set property values which contain Spring templates that are interpreted downstream.
BREACHES
- Combolist: 'netflix.com.txt' (183,083 Records): Email Address, Password
- Combolist: 'Mail_access.txt' (31,821 Records): Email Address, Password
Tags: DIB, tlp:green