ZeroFox Cyber Intelligence Daily Brief - January 4, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - January 4, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Russian Intelligence Hack Webcams in Kyiv to Aid Missile Strikes
- Mandiant Gets its X Account Hacked
- Population Health Management Firm's Breach Affects Millions
Russian Intelligence Hack Webcams in Kyiv to Aid Missile Strikes
A recent missile strike on Kyiv, aided by two webcams in the Ukranian capital city hacked by Russian agents, has evoked concerns among Ukraine’s security agencies. The Security Service of Ukraine (SSU) has stated that Russian intelligence services gained operational control of the two webcams, both of which were situated in residential areas, to monitor the surroundings, collect data, and "adjust strikes on Kyiv." The SSU has also asked webcam owners and operators to restrict broadcasts from their devices to prevent Russian intelligence from further using the feeds for military surveillance against strategic targets.
Mandiant Gets its X Account Hacked
In a crypto currency scam, Mandiant’s X account has been hacked by an unknown threat actor to redirect users to a website where the hackers could steal user’s cryptocurrencies from their wallets. The hacker also changed Mandiant’s username to @phantomsolw before Mandiant’s account was restored. The hacker posed as the cryptocurrency company, Phantom, and shared a link to a supposed legitimate website for users to see if their wallet was one of 250,000 that were eligible for an award of tokens.
Population Health Management Firm's Breach Affects Millions
HealthEC has undergone a cyber incident by an unknown threat actor where more than four million patient data and clients' certain data were reportedly breached. On December 22, the AI-enabled health management platform HealthEC reported a data breach initially listing 112,005 victims. By January 3, the number of impacted individuals increased to 4,452,782, as per the U.S. Department of Health and Human Services breach portal, which constitutes over half of HealthEC's 8 million-plus members. The compromised information may include names, addresses, dates of birth, Social Security, and medical record numbers.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- BreachForums user FidFlight: Actor Claims to Leak Data From DisneylandForward
- BreachForums user zelda: Actor Claims to Leak Secret Messages From Iranian Nuclear Power
VULNERABILITIES
- CVE-2023-6733: The WP-Members Membership Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.4.8 via the wpmem_field shortcode.
- CVE-2023-6738: The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pagelayer_header_code', 'pagelayer_body_open_code', and 'pagelayer_footer_code' meta fields in all versions up to, and including, 1.7.8 due to insufficient input sanitization and output escaping on user supplied attributes.
EXPLOITS
- CVE-2020-10567: An issue was discovered in Responsive Filemanager through 9.14.0. In the ajax_calls.php file in the save_img action in the name parameter, there is no validation of what kind of extension is sent.
- CVE-2023-25355: CoreDial sipXcom up to and including 21.04 is vulnerable to Insecure Permissions. A user who has the ability to run commands as the
daemonuser on a sipXcom server can overwrite a service file, and escalate their privileges toroot.
BREACHES
- Combolist: '400K MAİL PASS COMBO.txt' (421,936 Records): Email Address, Password
- Combolist: '207K TR MAILPASS COMBO.txt' (207,150 Records): Email Address, Password
Tags: DIB, tlp:green