ZeroFox Cyber Intelligence Daily Brief - January 19, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - January 19, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- ZeroFox Intelligence Flash Report: Mass Access Sale to Retail E-Commerce System
- CISA Releases Incident Response Guide for the WWS Sector
- Kansas State University Cyberattack Disrupts IT Network and Services
ZeroFox Intelligence Flash Report: Mass Access Sale to Retail E-Commerce System
Threat actor isabellavonbiz announced the sale of the source code, business operations data, and documentation of an unspecified e-commerce content management system (CMS) services vendor on the predominantly Russian-language dark web forum exploit[.]in. The actor claimed that the CMS is used by 470 vendors, totaling an excess of two million orders per month and a combined annual revenue of more than USD 2.5 billion. The entire package was instantly purchased (or “blitzed”) by guru-level actor “s4l0_” for USD 6,000, leaving no chance for any competition. S4l0_ is a highly competent and popular threat actor, with additional intelligence indicating they are buying and potentially hoarding access to as many online shops as possible.
CISA Releases Incident Response Guide for the WWS Sector
The Incident Response Guide for the Water and Wastewater Systems (WWS) Sector includes contributions from over 25 WWS Sector organizations spanning private industry, nonprofit, and government entities. Specifically, the guide provides information about the federal support available at each stage of the cyber incident response (IR) lifecycle and aims to enhance WWS Sector cybersecurity. Measures detailed in the guide include establishing clear guidance for reporting cyber incidents and connecting utilities with available cybersecurity resources, services, and no-cost training.
Kansas State University Cyberattack Disrupts IT Network and Services
Kansas State University (K-State) is currently dealing with a cybersecurity incident that has disrupted key network systems, impacting services such as VPN, K-State Today emails, and video services on Canvas and Mediasite. In response to the attack, K-State took affected systems offline immediately upon detection. To manage the impact on users, K-State announced that services would resume in a temporary format, featuring changes such as a different header image and reduced volume with select content. Currently, no major ransomware groups have claimed responsibility for the cyberattack on Kansas State University.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- Exploit user sandocan: Remote desktop access to U.S.-based metals and mining company
- Exploit user Sanggiero_: Network access to U.S.-based cloud services company
VULNERABILITIES
- CVE-2023-49994: Espeak-ng 1.52-dev was discovered to contain a Floating Point Exception via the function PeaksToHarmspect at wavegen.c.
- CVE-2023-49993: Espeak-ng 1.52-dev was discovered to contain a Buffer Overflow via the function ReadClause at readclause.c.
EXPLOITS
- CVE-2022-37061: All FLIR AX8 thermal sensor cameras version up to and including 1.46.16 are vulnerable to Remote Command Injection.
- CVE-2022-37661: SmartRG SR506n 2.5.15 and SR510n 2.6.13 routers are vulnerable to Remote Code Execution (RCE) via the ping host feature.
BREACHES
- LeakBase: karzoun.com Breach (25556 Records): Password, Email Address, Name, Phone Number, Username
- LeakBase: almujtama.com.sa Breach (99074 Records): Name, Phone Number, Physical Address, Email Address, Username, Password
Tags: DIB, tlp:green