ZeroFox Cyber Intelligence Daily Brief - January 13, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - January 13, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Phishing Attack Targeting Accountant Results in Data Breach of Laptop Manufacturer
- HMG Healthcare Data Breach Affects Forty Nursing Facilities
- CISA Adds Six Known Exploited Vulnerabilities to Catalog
Phishing Attack Targeting Accountant Results in Data Breach of Laptop Manufacturer
Framework Computer Inc., a California-based laptop computer manufacturer, has suffered a data breach exposing the personal information of several customers due to a phishing attack on its accounting services provider, Keating Consulting Group. An accountant from the consulting firm was tricked into engaging with an email that seemed to be from the Framework CEO. The email asked the accountant to share a spreadsheet containing customers' personally identifiable information (PII), including names, email addresses of customers, and outstanding balances with Framework. The dataset can potentially be used for phishing attacks involving affected customers in payment scams or exfiltration attempts.
HMG Healthcare Data Breach Affects Forty Nursing Facilities
HMG Healthcare, a healthcare services provider, has experienced a data breach affecting the personal health information of employees and residents at forty affiliated nursing facilities. The breach involved hackers gaining unauthorized access to a server and stealing unencrypted files. The compromised data includes names, contact information, dates of birth, health information, medical treatment details, Social Security numbers, and employee records. The incident affected facilities in Texas and Kansas, and while the total number of impacted individuals is not specified, it encompasses both employees and residents.
CISA Adds Six Known Exploited Vulnerabilities to Catalog
CISA has added six new vulnerabilities to its Known Exploited Vulnerabilities Catalog based on evidence of active exploitation. These vulnerabilities tracked in Adobe ColdFusion (CVE-2023-38203 and CVE-2023-29300), Apache Superset (CVE-2023-27524), multiple Apple products (CVE-2023-41990), D-Link (CVE-2016-20017), and Joomla! (CVE-2023-23752) are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- Telegram user Team Network Nine: Indian Threat Actor Groups Claims to Attack Entities in Maldives
- BreachForums user LULZSEC: Actor Claims to Attack U.S. in Response to the Yemen airstrikes
VULNERABILITIES
- CVE-2023-40250: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Hancom HCell on Windows allows Overflow Buffers.
- CVE-2023-34194: StringEqual in TiXmlDeclaration::Parse in tinyxmlparser.cpp in TinyXML through 2.6.2 has a reachable assertion (and application exit) via a crafted XML document with a '\0' located after whitespace.
BREACHES
- LeakBase: evdsystem[.]com Breach (42 Records): Physical Address, Name, Name, Phone Number, Physical Address, Password, IP Address, Email Address, Username, Physical Address, Physical Address
- LeakBase: evaprofessional[.]com Breach (9653 Records): Name, Username, Password, Email Address, IP Address, Name
Tags: DIB, tlp:green