ZeroFox Cyber Intelligence Daily Brief - January 16, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - January 16, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- U.S. Court Docs Expose Fake Antivirus Renewal Phishing Tactics
- Several High Severity Security Vulnerabilities in Bosch Thermostats and Netrunners Reported
- ZeroFox Intelligence Flash Report - Critical Microsoft SharePoint Vulnerability Actively Exploited
U.S. Court Docs Expose Fake Antivirus Renewal Phishing Tactics
U.S. Secret Service uncovers threat actors using fake Norton antivirus renewal subscription notifications to gain access to a victim's PC and bank account and scam victims of USD 34,000. The threat actors redirected the victim to a site where they were tricked into downloading remote access software on their computer among other actions, including entering their payment information. The threat actors now face charges for wire fraud, involvement in a phishing scam, money laundering, and bank fraud among other transgressions.
Several High Severity Security Vulnerabilities in Bosch Thermostats and Netrunners Reported
A cybersecurity firm has discovered several flaws in Bosch BCC100 thermostats and Rexroth NXA015S-36V-B smart nutrunners that let threat actors gain control of the compromised systems. The high-severity BCC100 flaw (CVE 2023-49722) allows attackers to connect to vulnerable devices via the same WiFi network. Bosch has resolved this issue in firmware version 4.13.33 by closing the flawed network port. Meanwhile, over two dozen vulnerabilities in Nexo cordless nutrunner, ranging in severity from medium to high, can be leveraged to disrupt the functioning of the compromised systems, perform distributed denial of service (DDoS) attacks, and install ransomware. Bosch is yet to release patches for these flaws.
ZeroFox Intelligence Flash Report - Critical Microsoft SharePoint Vulnerability Actively Exploited
U.S. Cybersecurity & Infrastructure Security Agency (CISA) added CVE-2023-29357–a critical severity privilege escalation flaw in Microsoft SharePoint–to its Known Exploited Vulnerabilities Catalog, indicating its active exploitation in the wild. This vulnerability enables threat actors targeting unpatched servers to obtain administrator privileges, facilitating follow-on malicious activity and lateral movement. The vulnerability has been assigned a critical CVSS score of 9.8, and can be exploited alongside Remote Code Execution (RCE) vulnerability CVE-2023-24955, forming an attack chain able to further compromise the confidentiality, integrity, and availability of a target system.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- Telegram user Anonymous Sudan: Actor Claims Attack Against Various Entities From Multiple Countries
- Telegram user The Five Families: Actor Claims Attack Against PT Kereta Api Indonesia
VULNERABILITIES
- CVE-2024-22428: Dell iDRAC Service Module, versions 5.2.0.0 and prior, contain an Incorrect Default Permissions vulnerability. It may allow a local unprivileged user to escalate privileges and execute arbitrary code on the affected system. Dell recommends customers upgrade at the earliest opportunity.
- CVE-2022-34364:
EXPLOITS
- CVE-2021-22015: The vCenter Server contains multiple local privilege escalation vulnerabilities due to improper permissions of files and directories.
- CVE-2022-44900: A directory traversal vulnerability in the SevenZipFile.extractall() function of the python library py7zr v0.20.0 and earlier allows attackers to write arbitrary files via extracting a crafted 7z file.
BREACHES
- Combolist: '24k_Instagram.txt' (23,225 Records): Email Address, Password
- Combolist: 'combolistbiz82part.txt' (35,000 Records): Email Address, Password
Tags: DIB, tlp:green