zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - June 7, 2023

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - June 7, 2023

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Malicious Actors Manipulating Photos and Videos to Create Explicit Content for Sextortion Schemes
  • NASA Website Flaw Jeopardized Astrobiology Fans
  • New “Powerdrop” Powershell Malware Targets U.S. Aerospace Industry
  • Vulnerabilities: CVE-2023-28321, CVE-2023-28322, and CVE-2023-33536
  • Exploits: CVE-2002-0289, CVE-2015-0336, and CVE-2020-11738
  • Breaches: BreachForums/XSS: Btc60.net Data Breach, Credit Card Data Breach: 2023-6-5, and Telegram: “TG hulk_logs 700LOGS .zip" Botnet Breach

Malicious Actors Manipulating Photos and Videos to Create Explicit Content for Sextortion Schemes

The FBI is warning Americans about the abuse of high-quality synthetic content ("deepfakes")—morphed from people’s innocent photos or videos via AI-enabled content-creation tools—to target victims. Victims, including minors, have reported having their photos or videos altered into explicit content and then circulated on social media or pornographic websites for harassment or sextortion. People should immediately report any such incident to the FBI's Internet Crime Complaint Center at www.ic3.gov or call 1-800-CALL-FBI (225-5324).

NASA Website Flaw Jeopardized Astrobiology Fans

NASA's Astrobiology website reportedly had an open redirect vulnerability that posed a risk to visitors. Attackers could have manipulated the flaw to redirect visitors to malicious websites and deceive them into revealing sensitive data. The flaw was first discovered by an open bug-bounty program researcher in January 2023, but was patched only in May 2023.

New “Powerdrop” Powershell Malware Targets U.S. Aerospace Industry

A new PowerShell malware script called "PowerDrop" has been discovered targeting the U.S. aerospace industry. The malware uses PowerShell and WMI to create a persistent remote access trojan (RAT) on compromised networks. PowerDrop demonstrates tactics between off-the-shelf malware and advanced APT techniques, indicating a possible state-sponsored attacker.

VULNERABILITIES

  • CVE-2023-28321 - An improper certificate validation vulnerability exists in curl <v8.1.0.
  • CVE-2023-28322 - An information disclosure vulnerability exists in curl <v8.1.0.
  • CVE-2023-33536 - TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 contain a buffer overflow via the component /userRpm/WlanMacFilterRpm.

EXPLOITS

  • CVE-2002-0289 - Phusion WebServer 1.0 - Long URL Denial of Service
  • CVE-2015-0336 - Adobe Flash Player NetConnection Type Confusion
  • CVE-2020-11738 - WordPress Duplicator 1.3.26 Directory Traversal / File Read

BREACHES

Tags: DIB, tlp:green