zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - June 29, 2023

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - June 29, 2023

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • ZeroFox Intelligence Assessment: Key Personnel Security Risks of Fitness Trackers
  • Auth-Bypass Vulnerability Discovered in Arcserve UDP
  • U.S. Patent and Trademark Office Discloses Years-Long Data Leak
  • Vulnerabilities: CVE-2023-2235 and CVE-2023-34652
  • Exploits: CVE-2001-1013 and CVE-2019-0841
  • Breaches: BreachForums/XSS: InstaForex Data Breach and Credit Card Data Breach: 2023-6-27

ZeroFox Intelligence Assessment: Key Personnel Security Risks of Fitness Trackers

Recent reports of exposure risks in fitness trackers (including in Strava’s heat map feature) serve as a reminder of the potential safety and security hazards these trackers can pose. In this brief, ZeroFox reviews the recent concerns and analyzes the overall potential risks for key personnel. While it is unlikely that key personnel will discontinue the use of fitness apps altogether, ZeroFox provides some recommendations to manage their exposure and limit the risks.

Auth-Bypass Vulnerability Discovered in Arcserve UDP

Data-protection vendor Arcserve fixed a high-severity security flaw (CVE-2023-26258) in its Unified Data Protection (UDP) backup software that allowed attackers to bypass authentication and gain admin privileges. The flaw, present in UDP versions 7.0 to 9.0, enabled attackers on the local network to access the admin interface and potentially destroy data through ransomware attacks. Arcserve released UDP 9.1 on June 27, 2023 to fix the problem.

U.S. Patent and Trademark Office Discloses Years-Long Data Leak

The U.S. patent and Trademark Office (USPTO) inadvertently exposed approximately 61,000 filers' private addresses in a data spill lasting several years. The agency notified affected applicants that their private domicile addresses were mistakenly included in public records from February 2020 to March 2023. USPTO temporarily blocked access to non-critical APIs and removed affected bulk data products until a permanent solution was implemented. The agency believes that the data has not been misused.

VULNERABILITIES

  • CVE-2023-2235 - A use-after-free vulnerability in the Linux Kernel Performance Events system can be exploited to achieve local privilege escalation.
  • CVE-2023-34652 - PHPgurukl Hostel Management System v.1.0 is vulnerable to Cross Site Scripting (XSS) via Add New Course.

EXPLOITS

BREACHES

Tags: DIB, tlp:green