ZeroFox Cyber Intelligence Daily Brief - December 22, 2023
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - December 22, 2023
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Ransomware Attack on Italian Cloud Service Provider Disrupts Administrative Operations
- Cybersecurity Incident Causes First American to Take IT Systems Offline
- Hackers Exploiting Ancient MS Excel Vulnerability to Spread Agent Tesla Malware
Ransomware Attack on Italian Cloud Service Provider Disrupts Administrative Operations
On December 8, 2023, Italian cloud service provider Westpole, specializing in digital services for public administration, fell victim to a ransomware attack allegedly conducted by Lockbit 3.0 ransomware gang. The attack disrupted services for Westpole’s customer, PA Digitale, impacting several public administrations, including some municipalities. Italian cybersecurity agencies are working to recover data for affected entities. The attack might also affect December salary payments for some government employees. Westpole has restored only 50% of its systems amidst a challenging recovery, making this cyberattack the most serious one suffered by the Italian public administration till now.
Cybersecurity Incident Causes First American to Take IT Systems Offline
First American Financial Corporation, second-largest title insurance company in the United States, has temporarily taken systems offline following a "cybersecurity incident." Even though the company is yet to reveal the nature and scope of the incident, it is working to return to normal business operations as soon as possible. ZeroFox Intelligence has observed over 4,000 victims of ransomware and digital extortion in the past year, over 50 percent of which were in the North American region.
Hackers Exploiting Ancient MS Excel Vulnerability to Spread Agent Tesla Malware
Threat actors are abusing an MS Excel bug—patches for which were released back in 2017—to deploy the Agent Tesla malware. The memory corruption vulnerability (CVE-2017-11882) in Office's Equation Editor is being exploited in phishing attacks that use invoice-themed messages to lure victims. The campaign uses steganographic evasion tactics (involving a malicious JPG file) with the end goal to harvest confidential and sensitive information from victims.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- Telegram user Deanon Club: Actor Claims demolision of its Telegram Forum
- Telegram user KillNet: Actor Claims Attack Against United States
VULNERABILITIES
- CVE-2023-4535: An out-of-bounds read vulnerability was found in OpenSC packages within the MyEID driver when handling symmetric key encryption.
- CVE-2023-49897: An OS command injection vulnerability exists in AE1021PE firmware version 2.0.9 and earlier and AE1021 firmware version 2.0.9 and earlier.
EXPLOITS
- CVE-2023-26360: Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by an Improper Access Control vulnerability that could result in arbitrary code execution in the context of the current user.
- CVE-2023-30350: FS S3900-24T4S devices allow authenticated attackers with guest access to escalate their privileges and reset the admin password.
BREACHES
- Combolist: '450K Hotmail UHQ USA Mixed tematic Target.txt' (449,989 Records): Email Address, Password
- Combolist: '52K ANABELLE PERU.txt' (53,315 Records): Email Address, Password
Tags: DIB, tlp:green