zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - January 13, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - January 13, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Phishing Attack Targeting Accountant Results in Data Breach of Laptop Manufacturer
  • HMG Healthcare Data Breach Affects Forty Nursing Facilities
  • CISA Adds Six Known Exploited Vulnerabilities to Catalog

Phishing Attack Targeting Accountant Results in Data Breach of Laptop Manufacturer

Framework Computer Inc., a California-based laptop computer manufacturer, has suffered a data breach exposing the personal information of several customers due to a phishing attack on its accounting services provider, Keating Consulting Group. An accountant from the consulting firm was tricked into engaging with an email that seemed to be from the Framework CEO. The email asked the accountant to share a spreadsheet containing customers' personally identifiable information (PII), including names, email addresses of customers, and outstanding balances with Framework. The dataset can potentially be used for phishing attacks involving affected customers in payment scams or exfiltration attempts.

HMG Healthcare Data Breach Affects Forty Nursing Facilities

HMG Healthcare, a healthcare services provider, has experienced a data breach affecting the personal health information of employees and residents at forty affiliated nursing facilities. The breach involved hackers gaining unauthorized access to a server and stealing unencrypted files. The compromised data includes names, contact information, dates of birth, health information, medical treatment details, Social Security numbers, and employee records. The incident affected facilities in Texas and Kansas, and while the total number of impacted individuals is not specified, it encompasses both employees and residents.

CISA Adds Six Known Exploited Vulnerabilities to Catalog

CISA has added six new vulnerabilities to its Known Exploited Vulnerabilities Catalog based on evidence of active exploitation. These vulnerabilities tracked in Adobe ColdFusion (CVE-2023-38203 and CVE-2023-29300), Apache Superset (CVE-2023-27524), multiple Apple products (CVE-2023-41990), D-Link (CVE-2016-20017), and Joomla! (CVE-2023-23752) are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise.

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

VULNERABILITIES

  • CVE-2023-40250: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Hancom HCell on Windows allows Overflow Buffers.
  • CVE-2023-34194: StringEqual in TiXmlDeclaration::Parse in tinyxmlparser.cpp in TinyXML through 2.6.2 has a reachable assertion (and application exit) via a crafted XML document with a '\0' located after whitespace.

BREACHES

Tags: DIB, tlp:green