zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - February 13, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - February 13, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Rhysida Ransomware Decryptor Released
  • Roundcube Email Server Bug Now Exploited in Attacks
  • Data Breach Reporting Requirements

Rhysida Ransomware Decryptor Released

Cybersecurity experts, including some from the Korea Internet and Security Agency (KISA), have successfully uncovered an implementation vulnerability in Rhysida ransomware, marking the first-ever decryption of the 2023-born ransomware. The experts used an analysis exposing the ransomware's utilization of LibTomCrypt, intermittent encryption, and a predictable pseudo-random number generator. The decryption applies only to the Windows PE version of the Rhysida. It does not apply to the ESXi or the PowerShell payload versions. KISA is distributing a Rhysida ransomware recovery tool free of charge to help victims of the ransomware.

Roundcube Email Server Bug Now Exploited in Attacks

CISA warns of an actively exploited vulnerability (CVE-2023-43770) in Roundcube email servers. The Roundcube vulnerability is a persistent cross-site scripting (XSS) bug which allows attackers to access restricted information by exploiting maliciously crafted links in plain/text messages. The attacks exploiting this vulnerability are considered low-complexity and require user interaction. Organizations, including U.S. federal agencies, are urged to update promptly. Despite no details on current attacks, CISA emphasizes the risk and orders timely mitigation. Private organizations are also advised to address the flaw.

Data Breach Reporting Requirements

Effective from 13th March, the Federal Communications Commission (FCC) has ordered telecommunication companies to report data breaches impacting customers' personally identifiable information (PII). The updated rules aim to ensure that providers of telecommunications, interconnected Voice over Internet Protocol (VoIP), and telecommunications relay services (TRS) are held accountable in their obligations to safeguard sensitive customer information, and to provide customers with the tools needed to protect themselves in the event that their data is compromised.

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

EXPLOITS

  • CVE-2022-25487: Atom CMS v2.0 was discovered to contain a remote code execution (RCE) vulnerability via /admin/uploads.php.
  • CVE-2022-28381: Mediaserver.exe in ALLMediaServer 1.6 has a stack-based buffer overflow that allows remote attackers to execute arbitrary code via a long string to TCP port 888, a related issue to CVE-2017-17932.

BREACHES

Tags: DIB, tlp:green