ZeroFox Cyber Intelligence Daily Brief - April 23, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - April 23, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- APT28 Exploited Windows Print Spooler Flaw to Steal Credentials
- Hacktivist Cyberattack Caused A Water System to Overflow in a Rural Texas City
- Synlab Italia Suspends Operations Following Ransomware Attack
APT28 Exploited Windows Print Spooler Flaw to Steal Credentials
Security researchers have observed Russian GRU-linked APT28 (Forest Blizzard / STRONTIUM / Sednit / Fancy Bear) abusing a bug (CVE-2022-38028) in Windows Print Spooler to elevate privileges and steal credentials. The attacks—which target European and North American government, non-governmental, education, and transportation entities—have continued from around April 2019. Patches for the bug were issued in October 2022; users should apply the patches at the earliest possible to guard their networks against such attacks.
Hacktivist Cyberattack Caused A Water System to Overflow in a Rural Texas City
Researchers have linked a Russian hacktivist group, tracked as CyberArmyofRussia_Reborn, to a cyberattack that led to a water system overflowing in the small rural Texas town of Muleshow. This attack was one of the three attacks that targeted small towns in the rural Texas Panhandle. Even though officials curbed attempts to hack into Hale Center systems, the hackers managed to cause an overflow in one water system in Muleshoe before the officials took prompt steps to shut it down and took over manually. Local officials have confirmed that the attack had not subjected the public to any danger and had no impact on the Muleshoe’s water disinfectant system.
Synlab Italia Suspends Operations Following Ransomware Attack
Synlab Italia has suspended all its medical diagnostic and testing services following a recent ransomware attack. The lab has shut down all computers to limit further damage. Medical samples received before the cyberattack are stored in low-temperature conditions, but customers might have to submit new samples depending on system restoration time. The company has advised its customers to contact them via phone or check their website/social media channels for updates.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- BreachForums user mrwan: Actor Claims to Leak Chinese Citizen's Database
VULNERABILITIES
- CVE-2023-50471: cJSON v1.7.16 was discovered to contain a segmentation violation via the function cJSON_InsertItemInArray at cJSON.c.
- CVE-2024-3846: Inappropriate implementation in Prompts in Google Chrome prior to 124.0.6367.60 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
EXPLOITS
- CVE-2023-46454: In GL.iNET GL-AR300M routers with firmware v4.3.7, it is possible to inject arbitrary shell commands through a crafted package name in the package information functionality.
- CVE-2023-46214: In Splunk Enterprise versions below 9.0.7 and 9.1.2, Splunk Enterprise does not safely sanitize extensible stylesheet language transformations (XSLT) that users supply. This means that an attacker can upload malicious XSLT which can result in remote code execution on the Splunk Enterprise instance.
BREACHES
- BreachForums: mediaoks[.]com Breach (10159 Records): Name, Phone Number, Physical Address, Name, Email Address, Password, Username
- Combolist: '370K gmail[.]com combolist.txt' (366,449 Records): Email Address, Password
Tags: DIB, tlp:green