zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - January 4, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - January 4, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Russian Intelligence Hack Webcams in Kyiv to Aid Missile Strikes
  • Mandiant Gets its X Account Hacked
  • Population Health Management Firm's Breach Affects Millions

Russian Intelligence Hack Webcams in Kyiv to Aid Missile Strikes

A recent missile strike on Kyiv, aided by two webcams in the Ukranian capital city hacked by Russian agents, has evoked concerns among Ukraine’s security agencies. The Security Service of Ukraine (SSU) has stated that Russian intelligence services gained operational control of the two webcams, both of which were situated in residential areas, to monitor the surroundings, collect data, and "adjust strikes on Kyiv." The SSU has also asked webcam owners and operators to restrict broadcasts from their devices to prevent Russian intelligence from further using the feeds for military surveillance against strategic targets.

Mandiant Gets its X Account Hacked

In a crypto currency scam, Mandiant’s X account has been hacked by an unknown threat actor to redirect users to a website where the hackers could steal user’s cryptocurrencies from their wallets. The hacker also changed Mandiant’s username to @phantomsolw before Mandiant’s account was restored. The hacker posed as the cryptocurrency company, Phantom, and shared a link to a supposed legitimate website for users to see if their wallet was one of 250,000 that were eligible for an award of tokens.

Population Health Management Firm's Breach Affects Millions

HealthEC has undergone a cyber incident by an unknown threat actor where more than four million patient data and clients' certain data were reportedly breached. On December 22, the AI-enabled health management platform HealthEC reported a data breach initially listing 112,005 victims. By January 3, the number of impacted individuals increased to 4,452,782, as per the U.S. Department of Health and Human Services breach portal, which constitutes over half of HealthEC's 8 million-plus members. The compromised information may include names, addresses, dates of birth, Social Security, and medical record numbers.

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

VULNERABILITIES

  • CVE-2023-6733: The WP-Members Membership Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.4.8 via the wpmem_field shortcode.
  • CVE-2023-6738: The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pagelayer_header_code', 'pagelayer_body_open_code', and 'pagelayer_footer_code' meta fields in all versions up to, and including, 1.7.8 due to insufficient input sanitization and output escaping on user supplied attributes.

EXPLOITS

  • CVE-2020-10567: An issue was discovered in Responsive Filemanager through 9.14.0. In the ajax_calls.php file in the save_img action in the name parameter, there is no validation of what kind of extension is sent.
  • CVE-2023-25355: CoreDial sipXcom up to and including 21.04 is vulnerable to Insecure Permissions. A user who has the ability to run commands as the daemon user on a sipXcom server can overwrite a service file, and escalate their privileges to root.

BREACHES

Tags: DIB, tlp:green