ZeroFox Cyber Intelligence Daily Brief - December 29, 2023
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - December 29, 2023
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Operation Triangulation: Apple Devices Targeted via Undocumented Hardware Feature
- Poorly Secured Linux SSH Servers Under Attack for Cryptocurrency Mining
- December 2022 Cyberattack Disclosed by Panasonic Avionics Corp.
Operation Triangulation: Apple Devices Targeted via Undocumented Hardware Feature
Cybersecurity experts have determined that the unknown APT group masterminding Operation Triangulation has been using an undocumented hardware feature to target Apple iOS devices with zero-click exploits. The long-running cyber-campaign allegedly developed for information-gathering from NATO countries as well as Israel, China, and Syria involves threat actors sending a message containing an exploit via iMessage to an iOS device. This message prompts a remote code execution (RCE) vulnerability in the undocumented, Apple-only ADJUST TrueType font instruction without user interaction. Attackers can then access the device’s kernel memory and install malicious implants such as spyware.
Poorly Secured Linux SSH Servers Under Attack for Cryptocurrency Mining
Recent research finds that a new multi-platform threat called NKAbuse is leveraging a decentralized, peer-to-peer network connectivity protocol called New Kind of Network (NKN) as a communications channel for DDoS attacks, to single out Linux devices. Cyber attackers are focusing on poorly secured Linux SSH servers, aiming to install port scanners and dictionary attack tools. Reportedly, the threat actors aim to compromise other vulnerable servers, forming a system for cryptocurrency mining and distributed denial-of-service (DDoS) attacks.
December 2022 Cyberattack Disclosed by Panasonic Avionics Corp.
Panasonic Avionics Corporation, an in-flight entertainment and communications devices manufacturer, has reported a year-old cybersecurity incident involving a breach of a device subset in its corporate network. The company has confirmed the exfiltration of some personal information, including names, contact details, and government identifiers, but is yet to determine if the stolen data has been misused. Among mitigation efforts, Panasonic has arranged two years of free identity and credit monitoring services for all the victims.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- BreachForums user BlackAngel: Actor Allegedly Selling Data From Indian Hybrid Company
- BreachForums user Ddarknotevil: Actor Allegedly Selling USA Voter Data From Didit
VULNERABILITIES
- CVE-2023-50828: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Vongries Ultimate Dashboard – Custom WordPress Dashboard allows Stored XSS.
- CVE-2023-7149: A vulnerability was found in code-projects QR Code Generator 1.0. It has been classified as problematic.
EXPLOITS
- CVE-2023-22855: Kardex Mlog MCC 5.7.12+0-a203c2a213-master allows remote code execution.
- CVE-2022-2846: The Calendar Event Multi View WordPress plugin before 1.4.07 does not have any authorisation and CSRF checks in place when creating an event, and is also lacking sanitisation as well as escaping in some of the event fields.
BREACHES
- Breached.co: ahmadtea.com Breach (97728 Records): Password, Email Address, Physical Address, Name, IP Address, Username
- Combolist: '86k EDU Private Combo.txt' (70,872 Records): Email Address, Password
Tags: DIB, tlp:green