ZeroFox Cyber Intelligence Daily Brief - January 18, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - January 18, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- ZeroFox Intelligence Flash Report - Dark Web Actors Promoting Maritime Data
- Iranian Cyberespionage Hackers Use Spearphishin to Target High-Profile Researchers Across EU and U.S.
- Max-Critical Atlassian Bug Allows Unauthenticated RCE
ZeroFox Intelligence Flash Report - Dark Web Actors Promoting Maritime Data
ZeroFox has identified at least two instances in which threat actors are selling data that provides real-time information on maritime vessels, including the geographic positions of vessels, vessel details, journey details, and data on maritime infrastructure. The leaked data has little monetary value for the buyer or seller and may demonstrate that politically-motivated actors will forgo profit to achieve their ideological aims, and there will likely be continued convergence between geopolitical issues and cybersecurity threats. Houthi attacks targeting commercial vessels transiting the Red Sea have resulted in significant political gains for the group and have caused major disruptions to global supply chains. There are other important shipping lanes across the globe, and threat actors may view obtaining similar datasets as helpful to achieving their political aims or harming their political adversaries.
Iranian Cyberespionage Hackers Use Spearphishin to Target High-Profile Researchers Across EU and U.S.
A subset of Iranian-backed cyberespionage group APT 35 (alias Mint Sandstorm, Charming Kitten, and Phosphorus) is reportedly targeting individuals researching Middle Eastern affairs at universities in the European Union and the United States. The notorious threat group has been using customized phishing tactics to “socially engineer targets into downloading malicious files.” This campaign has been designed to steal sensitive data from compromised systems belonging to high-profile researchers.
Max-Critical Atlassian Bug Allows Unauthenticated RCE
A critical unauthenticated remote code execution (RCE) vulnerability, CVE-2023-22527, with a severity rating of 10, is impacting Atlassian Confluence Data Center and Confluence Server in versions released before 5 December 2023. Currently, no mitigations or workarounds are available, so administrators are urged to apply the latest versions from December to ensure full protection. Atlassian recommends removing systems from the Internet and backing up data outside of the Confluence environment, If immediate patching is not possible. Given the platform's extensive use in network environments, admins are urged to monitor for potential malicious activity, acknowledging the difficulty in listing all possible indicators of compromise due to the potential for multiple entry points and chained attacks.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- BreachForums user g0d: Actor Claims Unauthorized Shell Access to German Cloud Company
- BreachForums user IntelBroker: Actor Claims to Leak Data From Vauxhall Motors
VULNERABILITIES
- CVE-2023-6548: Improper Control of Generation of Code ('Code Injection') in NetScaler ADC and NetScaler Gateway allows an attacker with access to NSIP, CLIP or SNIP with management interface to perform Authenticated (low privileged) remote code execution on Management Interface.
- CVE-2023-6549: Improper Restriction of Operations within the Bounds of a Memory Buffer in NetScaler ADC and NetScaler Gateway allows Unauthenticated Denial of Service
EXPLOITS
- CVE-2021-39144: XStream is a simple library to serialize objects to XML and back again.
BREACHES
- LeakBase: almujtama.com.sa Breach (99074 Records): Name, Phone Number, Physical Address, Physical Address, Name, Email Address, Username, Password
- Combolist: '144.172.113.70_4.txt' (18,533,681 Records): Email Address, Password
Tags: DIB, tlp:green