ZeroFox Daily Intelligence Brief - June 14, 2023
|by Alpha Team

ZeroFox Daily Intelligence Brief - June 14, 2023
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- CISA: Binding Operational Directive 23-02
- Pirated Copies of Windows 10 Conceal Malicious Code in EFI Partition
- Over 3,000 Domains Used for Impersonating Apparel and Lifestyle Brands in Phishing Campaign
- Vulnerabilities: CVE-2023-24329, CVE-2023-26555, and CVE-2023-3203
- Exploits: CVE-2018-19423, CVE-2018-17463, and CVE-2009-0182
- Breaches: Credit Card Data Breach: 2023-6-12 and BreachForums: Watchfinder & Co. Data Breach
CISA: Binding Operational Directive 23-02
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a new binding operational directive to reduce the attack surface created by insecure or misconfigured management interfaces across certain classes of devices. Federal civilian executive branch (FCEB) agencies are mandated to take specific remedial measures within 14 days of notification by CISA or the discovery of a networked management interface in the scope of the directive.
Pirated Copies of Windows 10 Conceal Malicious Code in EFI Partition
Cybercriminals are distributing malicious Windows 10 ISOs through torrents that conceal cryptojacking malware in the EFI (Extensible Firmware Interface) partition. The EFI partition contains the bootloader and related files executed before the operating system starts up. Due to limited scanning of the EFI partition by standard antivirus tools, such malware can potentially bypass detection.
Over 3,000 Domains Used for Impersonating Apparel and Lifestyle Brands in Phishing Campaign
Threat actors are impersonating the domains of over 100 popular clothing and footwear brands as part of a massive phishing campaign utilizing around 3,000 registered domains and 6,000 websites. The campaign was at its peak between November 2022 and February 2023, with nearly 300 fraudulent sites added per month during that period. The use of old domains helped boost the success of this scam, as they tend to rank higher in search results and are less likely to be flagged as malicious by security tools.
VULNERABILITIES
- CVE-2023-24329 - An issue in the urllib.parse component of Python before 3.11.4 allows attackers to bypass blocklisting methods by supplying a URL that starts with blank characters.
- CVE-2023-26555 - praecis_parse in ntpd/refclock_palisade.c in NTP 4.2.8p15 has an out-of-bounds write.
- CVE-2023-3203 - The MStore API plugin for WordPress is vulnerable to Cross-Site Request Forgery due to missing nonce validation on the mstore_update_limit_product function.
EXPLOITS
- CVE-2018-19423 - Codiad 2.8.4 Shell Upload
- CVE-2018-17463 - Google Chrome 67 / 68 / 69 Object.create Type Confusion
- CVE-2009-0182 - VUPlayer 2.49 Buffer Overflow
BREACHES
- Credit Card Data Breach: 2023-6-12 : (0ab2b4 | 2956) - Credit card
- BreachForums: Watchfinder & Co. Data Breach : (681,753 Records) - Name, phone number, and email address
Tags: DIB, tlp:green