zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - January 03, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - January 03, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Hackers Attack UK’s Nuclear Waste Services Through LinkedIn
  • Met and MoMA’s Museum Software Solutions Provider Hit with Ransomware Attack
  • Xerox Subsidiary Targeted in A Cybersecurity Attack

Hackers Attack UK’s Nuclear Waste Services Through LinkedIn

The United Kingdom's Radioactive Waste Management (RWM) company recently faced a cyberattack attempt that targeted the organization through LinkedIn. The RWM manages the £50 billion Geological Disposal Facility (GDF) project, which aims to create an underground nuclear waste repository in the UK. Specific details, whether it involved phishing or an attempt to trick employees into installing malware, are unknown. The attack was detected and thwarted by the company's multi-layered defense systems, preventing unauthorized access.

Met and MoMA’s Museum Software Solutions Provider Hit with Ransomware Attack

Gallery Systems, museum software solutions provider to the New York's Museum of Modern Art (MoMA), the Metropolitan Museum of Art (Met), and more, has confirmed that a ransomware attack on December 28, 2023, disrupting some of its IT systems. The threat actors were able to encrypt some servers hosting a wide array of Gallery Systems services, including the online public viewing platform called eMuseum. The company has released an official statement saying it has taken the affected systems offline while federal agencies are investigating the incident to determine its impact.

Xerox Subsidiary Targeted in A Cybersecurity Attack

Xerox has confirmed a cybersecurity incident that targeted its subsidiary, Xerox Business Solutions (XBS). Even though the incident did not impact the company’s corporate systems, operations, data, and XBS operations, Xerox is conducting a thorough investigation to ensure the security of XBS systems. On January 3, ZeroFox Intelligence observed a post on the leak site of INC Ransomware group naming Xerox as one of its victims.

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

VULNERABILITIES

  • CVE-2023-7134: A vulnerability was found in SourceCodester Medicine Tracking System 1.0.
  • CVE-2023-7135: A vulnerability classified as problematic has been found in code-projects Record Management System 1.0.

EXPLOITS

  • CVE-2023-22952: In SugarCRM before 12.0. Hotfix 91155, a crafted request can inject custom PHP code through the EmailTemplates because of missing input validation.
  • CVE-2022-43781: There is a command injection vulnerability using environment variables in Bitbucket Server and Data Center.

BREACHES

Tags: DIB, tlp:green