zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - June 2, 2023

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - June 2, 2023

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • iOS Exploits Infect iPhones with Never-Before-Seen Malware
  • CISA Alert: Security Advisory for MOVEit Transfer
  • ZeroFox Event Assessment: UEFA Champions League Final
  • Vulnerabilities: CVE-2023-30394, CVE-2023-29746, and CVE-2022-45938
  • Exploits: CVE-2012-0003, CVE-2006-2369, and CVE-2020-10884
  • Breaches: Telegram: XIII_LOGS Botnet Breach and Credit Card Data Breach: 2023-5-31

iOS Exploits Infect iPhones with Never-Before-Seen Malware

Zero-click iOS exploits were reportedly used to infect iPhones belonging to several Kaspersky employees with sophisticated spyware dubbed Triangulation. Kaspersky stated that the spyware deployment was “completely hidden” and the trojan collected sensitive data such as microphone recordings, photos from instant messengers, and geolocation data. Russian cybersecurity officials allege that the attack is part of an ongoing campaign infecting thousands of iPhones belonging to diplomatic missions in the country.

CISA Alert: Security Advisory for MOVEit Transfer

An SQL injection vulnerability affects several versions of managed file transfer product SoftwareMOVEit Transfer, potentially allowing an unauthenticated attacker access to the database. An attacker could gain escalated privileges to execute SQL statements: for altering or deleting elements and obtaining information about the database structure and contents, depending on the database engine used. MOVEit Transfer customers should immediately apply the available patches and follow the recommended remedial measures.

ZeroFox Event Assessment: UEFA Champions League Final

ZeroFox Intelligence has examined physical and cybersecurity risks to the UEFA Champions League final, to be played between Manchester City and Inter Milan in Istanbul on June 10, 2023. People should beware of financial scams masquerading as earthquake-relief initiatives as well as possible impersonation of websites and mobile apps related to the event or its sponsors.

VULNERABILITIES

  • CVE-2023-30394 - Progress Ipswitch MoveIT 1.1.11 was discovered to contain a cross-site scripting (XSS) vulnerability via the API authentication function.
  • CVE-2023-29746 - An issue found in The Thaiger v.1.2 for Android allows unauthorized apps to cause a code execution attack by manipulating the SharedPreference files.
  • CVE-2022-45938 - An issue was discovered in Comcast Defined Technologies microeisbss through 2021.

EXPLOITS

  • CVE-2012-0003 - MS12-004 midiOutPlayNextPolyEvent Heap Overflow
  • CVE-2006-2369 - RealVNC 4.1.0 < 4.1.1 - VNC Null Authentication Bypass
  • CVE-2020-10884 - TP-Link Archer A7/C7 Unauthenticated LAN Remote Code Execution

BREACHES

Tags: DIB, tlp:green