ZeroFox Cyber Intelligence Daily Brief - January 24, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - January 24, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Mother of All Breaches Reveals 26 Billion Records
- ZeroFox Intelligence Flash Report - New BEC Campaign Set to Target Western Countries
- Critical Atlassian Confluence Bug Publicly Disclosed on January 16 Actively Exploited
Mother of All Breaches Reveals 26 Billion Records
A massive data leak has been uncovered, containing a staggering 12 terabytes of data from numerous past breaches, totaling 26 billion records. This extensive leak encompasses user data from platforms like LinkedIn, Weibo, Tencent, and others. Reportedly, Tencent’s data amounted to 1.5 billion records leaked followed by the second largest, Weibo — 504 million records. This breach consolidates records from thousands of meticulously compiled and reindexed leaks and privately traded databases. The database contains both old and new, undisclosed information, indicating that the unknown threat actor could be a data-broker service or a malicious actor using this information for identity theft, sophisticated phishing schemes, targeted cyberattacks, and more.
ZeroFox Intelligence Flash Report - New BEC Campaign Set to Target Western Countries
ZeroFox has recently observed the announcement of a new Business Email Compromise (BEC) campaign set to target Western states that promises affiliates substantial monetary profit. There is a roughly even chance that organizations face a heightened threat from BEC attacks in 2024 due to an increase in attacks and the continual diversification of techniques, tactics and procedures (TTPs). BEC is a type of cyberattack that enables the threat actor to gain unauthorized access to a personal or organizational email account before socially engineering victims. Threat actors — who are usually financially-motivated — leverage threat vectors such as account compromise and CEO or vendor impersonation to elicit fraudulent payment or data theft from unsuspecting victims.
Critical Atlassian Confluence Publicly Disclosed Earlier This Month Actively Exploited
A critical remote code execution flaw in Atlassian Confluence Data Center and Confluence Server (CVE-2023-22527) is now being actively exploited by several threat actors. ZeroFox released a flash report on January 17 discussing measures prescribed by Atlassian to ward off attacks leveraging CVE-2023-22527, including a security update to patch the bug. Cybersecurity agencies have discovered almost 40,000 attempts at exploiting the bug. These attempts began three days after Atlassian publicly disclosed the bug and its patch. Researchers have traced the IP addresses of some threat actors in this campaign to various locations worldwide such as Russia, Hong Kong, Singapore, and India.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- Telegram user Anonymous Collective: Actor Claims to DDoS Attack Against Egyptian Airline
- BreachForums user cnHunter: Actor Claims to Leak Data From Australian Companion Card and Affiliates
VULNERABILITIES
- CVE-2023-5341: A heap use-after-free flaw was found in coders/bmp.c in ImageMagick.
- CVE-2023-7008: A vulnerability was found in systemd-resolved. This issue may allow systemd-resolved to accept records of DNSSEC-signed domains even when they have no signature, allowing man-in-the-middles (or the upstream DNS resolver) to manipulate records.
EXPLOITS
- CVE-2022-35513: The Blink1Control2 application <= 2.2.7 uses weak password encryption and an insecure method of storage.
BREACHES
- Combolist: 'netflix%5Bturk%5D%20%23DxM.txt' (3,912 Records): Email Address, Password
- Combolist: 'epicgames[.]com [70259].txt' (68,957 Records): Email Address, Password
Tags: DIB, tlp:green