zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - May 19, 2023

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - May 19, 2023

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup that aim to give you and your clients an advantage over the adversary.

Brief Highlights

  • Six-Year-Old Bug Weaponized by Notorious Cryptojacker 8220 Gang
  • Security Bugs Revealed in Parental Control App Downloaded over Five Million Times
  • KeePass Flaw Allows Retrieval of Master Password Through Memory Dumps
  • CVE-2023-1729
  • CVE-2023-24805
  • CVE-2023-2704
  • CVE-2016-0189
  • CVE-2011-4642
  • Credit Card Data Breach: 2023-5-18
  • XIII_LOGS.zip

Six-Year-Old Bug Weaponized by Notorious Cryptojacker 8220 Gang

The 8220 cryptojacking gang is exploiting a six-year-old security flaw (CVE-2017-3506) in Oracle WebLogic servers to execute arbitrary commands. The group scans for vulnerable hosts and utilizes SSH brute force attacks for lateral movement. The group deploys off-the-shelf malware downloaders like PureCrypter and ScrubCrypt to evade detection. The exploit allows the attackers to deliver a PowerShell payload, disable Windows AMSI detection, and load cryptocurrency miners. Recent attacks have also involved abusing the Linux tool lwp-download to compromise systems.

Security Bugs Revealed in Parental Control App Downloaded over Five Million Times

Security researchers have discovered five security vulnerabilities in versions 3.8.49 and older of popular parental control app Kids Place. The bugs allow children to surreptitiously bypass parental restrictions and threat actors to perform malicious actions—including stealing login credentials, injecting malicious scripts into the app’s parental dashboard via cross-site scripting attacks, and sending malware-ridden files to the child’s device. Users should update to version 3.8.50 (released on February 14, 2023) to secure their devices.

KeePass Flaw Allows Retrieval of Master Password Through Memory Dumps

A vulnerability (CVE-2023-32784) in the KeePass password manager allows retrieval of the master password from system memory dumps, even when the system is locked or not running. The app's developer announced that it would release a patch in KeePass 2.54 within the next two months. A proof-of-concept tool demonstrates the memory analysis technique to retrieve the master password, with the exclusion of the first character. While the vulnerability could be exploited during forensic investigations, using full disk encryption with a strong password provides protection from the vulnerability. Certain KeePass forks, including KeePassXC, are not affected by this bug.

VULNERABILITIES

  • CVE-2023-1729 - A flaw was found in LibRaw. A heap-buffer-overflow in raw2image_ex() caused by a maliciously crafted file may lead to an application crash.
  • CVE-2023-24805 - OpenPrinting CUPS filters and backends for CUPS 2.X
  • CVE-2023-2704 - The BP Social Connect plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.5.

EXPLOITS

BREACHES

Tags: DIB, tlp:green