ZeroFox Cyber Intelligence Daily Brief - February 7, 2024
|by Alpha Team

ZeroFox Daily Intelligence Brief - February 7, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Ministry of Defence of the Netherlands Uncovers COATHANGER, a Stealthy Chinese FortiGate RAT
- Critical Canon Printer Flaws Allowing Code Execution DoS Now Patched
- Data Breach at French Healthcare Services Firm Puts Millions at Risk
Ministry of Defence of the Netherlands Uncovers COATHANGER, a Stealthy Chinese FortiGate RAT
In 2023, the Ministry of Defence (MOD) of the Netherlands experienced a cyberattack on one of its networks, although the impact was mitigated due to prior network segmentation. Incident response efforts uncovered a previously undisclosed malware, a remote access trojan (RAT) tailored for FortiGate appliances, known as COATHANGER. This malware, functioning as second-stage malware, is reportedly stealthy and persistent, evading detection by concealing itself through various methods, including hooking system calls and surviving reboots and firmware upgrades.
Critical Canon Printer Flaws Allowing Code Execution DoS Now Patched
Canon has released patches for seven critical (all with CVSS score of 9.8) vulnerabilities affecting its small office multifunction printers and laser printers. Unauthenticated remote actors can execute arbitrary code or conduct a denial-of-service (DoS) attack by leveraging these vulnerabilities. Canon advises its customers to assign a private IP address to the affected products and restrict network access by creating a network environment with a firewall or wired/Wi-Fi router.
Data Breach at French Healthcare Services Firm Puts Millions at Risk
The French healthcare services firm Viamedis suffered a cyberattack that exposed the data of millions of policyholders and healthcare professionals. While the breach consists of sensitive information such as beneficiary's marital status, date of birth, social security number, name of health insurer, and guarantees open to third-party, the company confirmed that no banking information, medical, postal details, telephone numbers, or email addresses were stored in the hacked system. A data breach notification has been sent to the company’s clients informing them about the alleged cyberattack, and an investigation is underway to determine the impact and scope of the data breach.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- Telegram user SeigedSec: Actor Claims to Acquire Data From GLF Connect
- Telegram user Anonymous Collective: Actor Claims Cyber Attack Against Jordan
VULNERABILITIES
- CVE-2024-23447: An issue was discovered in the Windows Network Drive Connector when using Document Level Security to assign permissions to a file, with explicit allow write and deny read. Although the document is not accessible to the user in Network Drive it is visible in search applications to the user.
- CVE-2024-23446: An issue was discovered by Elastic, whereby the Detection Engine Search API does not respect Document-level security (DLS) or Field-level security (FLS) when querying the .alerts-security.alerts-{space_id} indices.
EXPLOITS
- CVE-2022-23626: m1k1o/blog is a lightweight self-hosted facebook-styled PHP blog. Errors from functions
imagecreatefrom*andimage*have not been checked properly. Although PHP issued warnings and the upload function returnedfalse, the original file (that could contain a malicious payload) was kept on the disk. - CVE-2022-26352: An issue was discovered in the ContentResource API in dotCMS 3.0 through 22.02. Attackers can craft a multipart form request to post a file whose filename is not initially sanitized.
BREACHES
- Combolist: '80K_Mix_Fresh_UHQ_Combo.txt' (80,872 Records): Email Address, Password
- Combolist: 'output.txt' (157,280 Records): Email Address, Password
Tags: DIB, tlp:green