ZeroFox Cyber Intelligence Daily Brief - December 28, 2023
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - December 28, 2023
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- CBS, Paramount Owner National Amusements Says it Was Hacked
- Cyberattack Disrupts Emergency Care at German Hospitals
- More Than 1.3 Million Affected in LoanCare Data Breach
CBS, Paramount Owner National Amusements Says it Was Hacked
National Amusements, the parent company of Paramount and CBS, acknowledged a data breach where hackers stole personal information of more than 80,000 individuals in December 2022. The breach included financial details like bank account and credit card numbers, along with security codes and passwords, according to a breach notice filed with the Office of the Maine Attorney General. The company is notifying affected individuals of the breach. However, details about the cyberattack, possible ransom demands, and the type of cyberattack remain unclear.
Cyberattack Disrupts Emergency Care at German Hospitals
German hospital network Katholische Hospitalvereinigung Ostwestfalen (KHO) has been the target of recent service disruptions reportedly by an unknown threat actor, suspected to be the Lockbit ransomware group. The attack affected the IT systems supporting three hospitals in Bielefeld, Rheda-Wiedenbrück, and Herford. The threat actors gained access to the hospital network and encrypted data. Reportedly, all systems were shut down, and necessary parties and institutions were informed. Although essential patient information is accessible through backups, emergency care in the three hospitals is unavailable, leading to the redirection of patients to other facilities and potential delays in medical care.
More Than 1.3 Million Affected in LoanCare Data Breach
Last month, LoanCare LLC, a U.S.-based provider of full-service sub-servicing to the mortgage industry, became aware of a cyberattack that exposed the data of 1,316,938 individuals. Threat actors gained unauthorized access to some of the systems in the IT network of LoanCare’s parent company, Fidelity National Financial, Inc., leading to the exfiltration of information, including Social Security numbers. LoanCare has recently notified the authorities of this incident and is offering the victims free identity monitoring services for two years.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- BreachForums user cocksucker420420: Actor Claims to Leak Data From Direct Trading Technologies
- Telegram user Stormous: Actor Claims to Warn Companies It Sold Internal Network Access to
VULNERABILITIES
- CVE-2023-49228: An issue was discovered in Peplink Balance Two before 8.4.0. Console port authentication uses hard-coded credentials, which allows an attacker with physical access and sufficient knowledge to execute arbitrary commands as root.
- CVE-2023-49229: An issue was discovered in Peplink Balance Two before 8.4.0. A missing authorization check in the administration web service allows read-only, unprivileged users to obtain sensitive information about the device configuration.
EXPLOITS
- CVE-2022-46604: An issue in Tecrail Responsive FileManager v9.9.5 and below allows attackers to bypass the file extension check mechanism and upload a crafted PHP file, leading to arbitrary code execution.
- CVE-2020-5330: Dell EMC Networking X-Series firmware versions 3.0.1.2 and older, Dell EMC Networking PC5500 firmware versions 4.1.0.22 and older and Dell EMC PowerEdge VRTX Switch Modules firmware versions 2.0.0.77 and older contain an information disclosure vulnerability.
BREACHES
- Combolist: 'fortnite2_by_evolution1331.txt' (14,378 Records): Email Address, Password
- Combolist: 'Normalized Passwords.txt' (482 Records): Email Address, Password
Tags: DIB, tlp:green