ZeroFox Cyber Intelligence Daily Brief - January 01, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - January 01, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Researchers Develop New Black Basta Decryptor to Recover Files
- North Korea-Linked Hackers Deliver Backdoors and Tools Via Spear Phishing Attacks
- Pentagon Wants Feedback on Revised Cybersecurity Maturity Model Certification Program
Researchers Develop New Black Basta Decryptor to Recover Files
Cybersecurity researchers have developed a new decrypting tool that leverages a vulnerability in Black Basta Ransomware, letting victims recover their encrypted files for free. The decryptor Black Basta Buster exploits an encryption algorithm flaw in the ransomware’s encryptor tools. It can recover files that are more than 5,000 bytes and were targeted by Black Basta from November 2022 to this month—full recovery is possible for files between 5,000 bytes and 1 GB in size. For files larger than 1 GB, the first 5,000 bytes of data will be lost.
North Korea-Linked Hackers Deliver Backdoors and Tools Via Spear Phishing Attacks
Cybersecurity agencies have observed North Korean-affiliated hackers employing spear-phishing to distribute backdoors and tools like AppleSeed, Meterpreter, and TinyNuke to control compromised systems. Researchers have noted that using Appleseed in these attacks is similar to the modus operandi of Kimsuky, an advanced persistent threat (APT) group. Windows-based AppleSeed and its Golang variant, AlphaSeed, allow control through actor-controlled servers.
Pentagon Wants Feedback on Revised Cybersecurity Maturity Model Certification Program
The U.S. Department of Defense (DoD) is seeking comments from the interested public on a new proposal under the ambit of its Cybersecurity Maturity Model Certification (CMMC) Program. The proposal relates to a mechanism to ensure defense contractors and subcontractors have implemented necessary security measures for specific priority programs. The department will receive the comments till February 26, 2024.
VULNERABILITIES
- CVE-2023-50035: PHPGurukul Small CRM 3.0 is vulnerable to SQL Injection on the Users login panel because of "password" parameter is directly used in the SQL query without any sanitization and the SQL Injection payload being executed.
- CVE-2023-50070: Sourcecodester Customer Support System 1.0 has multiple SQL injection vulnerabilities.
BREACHES
- Combolist: 'Hotmail_102K.txt' (97,251 Records): Email Address, Password
- Combolist: 'TheHackerMod.txt' (102 Records): Email Address, Password
Tags: DIB, tlp:green