ZeroFox Cyber Intelligence Daily Brief - January 6, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - January 6, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Kyivstar Attack Wipes Core Network Systems; Russian Hackers Claim Responsibility
- CISA Adds Two Known Exploited Vulnerabilities to Catalog
- Cybercriminals Flood Dark Web With X (Twitter) Gold Accounts
Kyivstar Attack Wipes Core Network Systems; Russian Hackers Claim Responsibility
Russian hacker group Solntsepek, believed to be linked to Russia-linked APT Sandworm, has wiped out almost all systems on Kyivstar’s core network after breaching it. On December 12, several thousand customers of Kyivstar, Ukraine’s largest telecommunications service provider, suffered a massive mobile and data services outage because of a cyberattack. A day later, Solntsepek claimed responsibility for the attack and declared on its Telegram channel that it had “destroyed 10 thousand computers, more than 4 thousand servers, all cloud storage and backup systems.” The Security Service of Ukraine (SSU) has now confirmed that a Russian military intelligence unit was indeed behind this severe attack.
CISA Adds Two Known Exploited Vulnerabilities to Catalog
The Cybersecurity and Infrastructure Security Agency (CISA) has identified and added two new vulnerabilities, CVE-2023-7024 and CVE-2023-7101, to its Known Exploited Vulnerabilities Catalog. These vulnerabilities, including a Google Chromium WebRTC Heap Buffer Overflow and Spreadsheet::ParseExcel Remote Code Execution, are actively exploited and present significant risks to federal enterprises. Binding Operational Directive (BOD) 22-01 mandates Federal Civilian Executive Branch agencies to remediate these vulnerabilities promptly to safeguard networks against active threats.
Cybercriminals Flood Dark Web With X (Twitter) Gold Accounts
Researchers have discovered that cybercriminals are targeting verified "Gold" accounts on X (formerly Twitter) and selling them on the Dark Web for up to USD 2,000 each. The Gold badge, signifying independent verification by X for high-profile organizations or celebrities, is being compromised through password brute-forcing, credential theft via malware, and takeover of dormant non-Gold accounts. These accounts, often with substantial follower bases, are offered in underground markets. Buyers exploit them for phishing, disinformation, financial scams, or damaging content.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- Telegram user Народная CyberАрмия: Actor Claims to Leak U.S. Citizen Data From Global Congress on Aesthetics & Anti-Aging [GCAA 2023]
- BreachForums user Anti-NATO: Actor Claims to Leak Data From U.S. Department of Foreign Affairs
VULNERABILITIES
- CVE-2022-4904: A flaw was found in the c-ares package that may cause a denial of service or a limited impact on confidentiality and integrity.
- CVE-2021-22940: Node.js before 16.6.1, 14.17.5, and 12.22.5 is vulnerable to a use after free attack where an attacker might be able to exploit the memory corruption, to change process behavior.
EXPLOITS
- CVE-2022-22942: The vmwgfx driver contains a local privilege escalation vulnerability that allows unprivileged users to gain access to files opened by other processes on the system through a dangling 'file' pointer.
- CVE-2022-1043: A flaw was found in the Linux kernel’s io_uring implementation. This flaw allows an attacker with a local account to corrupt system memory, crash the system or escalate privileges.
BREACHES
- BreachForums: Italy_Casino_43K Data Breach (43,116 Records): Name, Email Address, Phone Number, Nationality
- Combolist: 'totaljerkface-08-17-2010-users.txt' (186,442 Records): Username, Password
Tags: DIB, tlp:green