zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - May 26, 2023

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - May 26, 2023

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • CISA Alert: Social Engineering Attacks Could Target Potential Disaster Victims
  • Scandinavian Airlines Operations Disrupted by Anonymous Sudan
  • Operation Magalenha Targets Portuguese Banks via Phishing Attacks
  • CVE-2023-2713
  • CVE-2020-36694
  • CVE-2023-2837
  • CVE-2016-8584
  • CVE-2009-4484
  • CVE-2019-7195
  • Credit Card Data Breach: 2023-5-25

CISA Alert: Social Engineering Attacks Could Target Potential Disaster Victims

The U.S Cybersecurity and Infrastructure Security Agency (CISA) has warned people to be cautious of social engineering attacks masquerading as hurricane-related communication from trustworthy organizations, including charities. The attacks might be masked as social media pleas, texts, or door-to-door solicitations related to severe weather events. The Federal Trade Commission’s “Staying Alert to Disaster-related Scams” advisory recommends best practices to guard against such scams.

Scandinavian Airlines Operations Disrupted by Anonymous Sudan

Threat group Anonymous Sudan—which has been previously associated with pro-Russian and Islamic hacktivism—has claimed responsibility for disrupting operations of Scandinavian Airlines (SAS) via a barrage of distributed denial-of-service (DDoS) attacks. ZeroFox Intelligence observed social-media users complaining about their inability to access SAS websites and applications; the official SAS website was inaccessible at the time of writing. Anonymous Sudan has demanded a “ransom” of USD 175,000 to cease the attacks.

Operation Magalenha Targets Portuguese Banks via Phishing Attacks

A Brazilian hacking group has targeted Portuguese government and private financial institutions since 2021 in a campaign dubbed “Operation Magalenha." A server misconfiguration allowed security researchers to deduce the threat actor's origin and tactics. The operation’s victims include ActivoBank, Caixa Geral de Depósitos, CaixaBank, Citibanamex, Santander, Millennium BCP, ING, Banco BPI, and Novobanco.

VULNERABILITIES

  • CVE-2023-2713 - Authorization bypass through user-controlled key vulnerability in "Rental Module" developed by a third party for Ideasoft's e-commerce platform allows authentication abuse and authentication bypass.
  • CVE-2020-36694 - An issue discovered in netfilter in the Linux kernel before 5.10.
  • CVE-2023-2837 - Stack-based buffer overflow in GitHub repository gpac/gpac prior to 2.2.2.

EXPLOITS

  • CVE-2016-8584 - Trend Micro Threat Discovery Appliance 2.6.1062r1 Session Generation Authentication Bypass
  • CVE-2009-4484 - MySQL - yaSSL CertDecoder::GetName Buffer Overflow (Metasploit)
  • CVE-2019-7195 - QNAP QTS and Photo Station Local File Inclusion

BREACHES

Tags: DIB, tlp:green