ZeroFox Daily Intelligence Brief - June 15, 2023
|by Alpha Team

ZeroFox Daily Intelligence Brief - June 15, 2023
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Understanding Ransomware Threat Actors: LockBit
- CISA and NSA Release Joint Guidance on Hardening Baseboard Management Controllers
- Fake Zero-Day PoC Exploits on GitHub Push Malware
- Vulnerabilities: CVE-2023-3193, CVE-2023-35029, and CVE-2022-32757
- Exploits: CVE-2018-8897, CVE-2015-3073, and CVE-2013-4113
- Breaches: Telegram: 'Logs_8.8.7z' Botnet Breach, Credit Card Data Breach: 2023-6-14, and BreachForums/XSS: World Poker Tour Data Breach
Understanding Ransomware Threat Actors: LockBit
Cybersecurity officials from the Five Eyes alliance and Germany have analyzed the details of LockBit ransomware incidents in a joint advisory and recommended measures to proactively guard against this ransomware operation. Over 1,700 U.S. organizations fell victim to LockBit in the past three years, resulting in nearly USD 91 million paid in ransom since January 2020.
CISA and NSA Release Joint Guidance on Hardening Baseboard Management Controllers (BMCs)
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the National Security Agency (NSA) have highlighted the threats to BMC implementations and provided specific mitigation measures. BMCs are trusted components in computer hardware that can allow for remote management and control, even when the system is shut down. Threat actors can leverage a vulnerable BMC to set up a beachhead with pre-boot execution potential.
Fake Zero-Day PoC Exploits on GitHub Push Malware
Cybercriminals are masquerading as security researchers from a fictitious cybersecurity company named “High Sierra Cyber Security” and targeting legitimate cybersecurity analysts and vulnerability-research firms. These threat actors promote links to alleged proof-of-concept (PoC) exploits for zero-day bugs in popular software applications, but the links lead to fraudulent, malware-ridden code repositories.
VULNERABILITIES
- CVE-2023-3193 - Cross-site scripting (XSS) vulnerability in the Layout module's SEO configuration in Liferay Portal 7.4.3.70 through 7.4.3.73, and Liferay DXP 7.4 update 70 through 73
- CVE-2023-35029 - Open redirect vulnerability in the Layout module's SEO configuration in Liferay Portal 7.4.3.70 through 7.4.3.76, and Liferay DXP 7.4 update 70 through 76
- CVE-2022-32757 - IBM Security Directory Suite VA 8.0.1 through 8.0.1.19 uses an inadequate account lockout setting
EXPLOITS
- CVE-2018-8897 - Microsoft Windows POP/MOV SS Local Privilege Elevation Exploit
- CVE-2015-3073 - Adobe Acrobat Reader AFParseDate Javascript API Restrictions Bypass Vulnerability Exploit
- CVE-2013-4113 - php 5.3.26 heap corruption in the XML parser
BREACHES
- Telegram: 'Logs_8.8.7z' Botnet Breach : (476,171 Records) - Email address and password
- Credit Card Data Breach: 2023-6-14 : (892cdd | 3458) - Credit card
- BreachForums/XSS: World Poker Tour Data Breach : (89,405 Records) - Email address and password
Tags: DIB, tlp:green