ZeroFox Cyber Intelligence Daily Brief - January 25, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - January 25, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- ZeroFox Intelligence Flash Report - Fortra Discloses Critical MFT Vulnerability
- North American Subsidiary of Environmental Services Giant Targeted in a Ransomware Attack
- Millions at Risk As “Parrot” Web Server Compromises Take Flight
ZeroFox Intelligence Flash Report - Fortra Discloses Critical MFT Vulnerability
On January 22, 2024, Fortra publicly disclosed a critical authentication bypass flaw in its GoAnywhere managed file transfer (MFT) software, for which a security patch has been released to end users. Although no active exploitation in the wild has been observed as of this writing, recent public disclosure and the publication of a proof-of-concept (PoC) suggests that attacks against unpatched systems are very likely. In Q1 2023, the Cl0p extortion collective successfully exploited a zero-day vulnerability in Fortra’s MFT software in what became one of the most widespread and lucrative Ransomware & Digital Extortion (R&DE) campaigns of the year.
North American Subsidiary of Environmental Services Giant Targeted in a Ransomware Attack
A ransomware attack targeting Veolia North America affected some services in its Municipal Water division and hindered its bill payment systems. Veolia has found no evidence suggesting the cyberattack impacted its water or wastewater treatment operations. The company has stated it had temporarily taken the targeted back-end systems and servers offline to check the breach, causing delays in bill payments. However, it has assured customers that the payments made during that period have been applied. Veolia is cooperating with law enforcement and other third parties to investigate the breach.
Millions at Risk As “Parrot” Web Server Compromises Take Flight
A traffic redirecting system (TDS) also known as Parrot TDS is injecting websites with malicious scripts, and has control over thousands of servers worldwide. Cyberactors employing Parrot TDS have improved their tactics to better avoid detection and can now target millions of people. These scripts first profile the victim to check specific conditions and then deliver a payload script. This payload can redirect the victim's browser to a malicious location or content. To enhance evasion of detection and analysis, the attackers reportedly employ techniques such as multiple lines of injected JavaScript code instead of a single line, making it more challenging for security researchers to identify in a script file.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- RansomHouse user RansomHouse: Hawbaker Engineerin
- SecretForums user SecretForums: New DarkNet Forum Emerges
VULNERABILITIES
- CVE-2023-48795: The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message).
- CVE-2024-0625: The WPFront Notification Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wpfront-notification-bar-options[custom_class]’ parameter in all versions up to, and including, 3.3.2 due to insufficient input sanitization and output escaping.
BREACHES
- LeakBase: kaasak.com Breach (2863 Records): IP Address, Name, Email Address
- BreachForums: nordangliaeducation.com Breach (1121 Records): Password, Phone Number, Email Address, Username, IP Address, Physical Address, Name
Tags: DIB, tlp:green