zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - May 30, 2023

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - May 30, 2023

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • U.S. Department of Defense Sends Classified Cyber Strategy to Congress
  • GobRAT Malware Attacking Japanese Routers
  • New Hacking Forum “Exposed” Leaks RaidForums User Details
  • Vulnerabilities: CVE-2021-3610, CVE-2023-30253, and CVE-2023-32687
  • Exploits: CVE-2002-0061, CVE-2012-5931, and CVE-2017-5135
  • Breach: Credit Card Data Breach: 2023-5-28

U.S. Department of Defense Sends Classified Cyber Strategy to Congress

The U.S. Department of Defense (DoD) has submitted to Congress an updated cyber strategy fortified by insights gained during the ongoing Russia-Ukraine conflict. It is aimed at protecting citizens and safeguarding U.S. defense priorities—emphasizing defending the nation, preparing for warfare, collaborating with allies, establishing advantages in cyberspace, and maximizing American cyber capabilities in support of integrated deterrence.

GobRAT Malware Attacking Japanese Routers

The Japan Computer Emergency Response Team Coordination Center (JPCERT/CC) has disclosed details of malware attacks on Linux routers in Japan using Go-based malware called GobRAT. The attack flow involves targeting routers with publicly accessible WEBUIs, exploiting vulnerabilities through script execution, and deploying GobRAT. The loader script uses the filename “apached” (which is the name of a legitimate Apache daemon process) to evade detection.

New Hacking Forum “Exposed” Leaks RaidForums User Details

A RaidForums database—containing usernames, email addresses, hashed passwords, and registration dates of 478,870 users—has been leaked on a new forum called Exposed. RaidForums, prior to its April 2022 seizure by international law enforcement, was a popular data-leak forum where members of the cyber underground traded stolen data. This leaked database could allow both security researchers and threat actors to analyze user details and link erstwhile Raidforums users to other illicit activities.

VULNERABILITIES

  • CVE-2021-3610 - A heap-based buffer overflow vulnerability was found in ImageMagick in versions prior to 7.0.11-14 in ReadTIFFImage() in coders/tiff.c.
  • CVE-2023-30253 - Dolibarr before 17.0.1 allows remote code execution by an authenticated user via an uppercase manipulation.
  • CVE-2023-32687 - Starting in version 4.7.0 and prior to 5.12.1 of tgstation-server, instance users with the list chat bots permission can read chat bot connections strings without the associated permission.

EXPLOITS

  • CVE-2002-0061 - Apache Win32 1.3.x/2.0.x - Batch File Remote Command Execution
  • CVE-2012-5931 - Novell NetIQ Privileged User Manager 2.3.1 - 'auth.dll' pa_modify_accounts() Remote Code Execution
  • CVE-2017-5135 - Technicolor DPC3928SL - SNMP Authentication Bypass

BREACHES

Tags: DIB, tlp:green