zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - June 30, 2023

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - June 30, 2023

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Best Practices to Secure Cloud Continuous Integration / Continuous Delivery (CI/CD) Environments
  • MITRE Publishes List of Top 25 Software Weaknesses for 2023
  • Clop's MOVEit Campaign Affects Over 15 Million Individuals in Nearly 150 Orgs
  • Vulnerabilities: CVE-2023-36607 and CVE-2023-3465
  • Exploits: CVE-2018-1133 and CVE-2013-4011
  • Breaches: BreachForums/Amunet: American Academy of Psychiatry and the Law Data Breach and Credit Card Data Breach: 2023-6-28

Best Practices to Secure Cloud Continuous Integration / Continuous Delivery (CI/CD) Environments

The NSA and CISA have released a Cybersecurity Information Sheet (CSI) with security best practices to address the risk on software supply chains from threat actors who seek to compromise cloud deployments. These actors tend to exploit DevOps CI/CD environments by introducing malicious code, stealing intellectual property, or disrupting applications. Defending the CI/CD pipeline is crucial, as failure to do so can provide an attack vector that circumvents security policies.

MITRE Publishes List of Top 25 Software Weaknesses for 2023

MITRE has published the 2023 list for “Common Weakness Enumeration (CWE) Top 25 Most Dangerous Software Weaknesses.” The list is derived from analyzing public vulnerability data in the National Vulnerability Database (NVD) and mapping weaknesses to CWE codes. These weaknesses pose significant risks, enabling attackers to take control of systems, steal data, or disrupt applications. CISA encourages developers to review the list and implement mitigation measures to address these vulnerabilities.

Clop's MOVEit Campaign Affects Over 15 Million Individuals in Nearly 150 Orgs

Close to 150 organizations have reportedly fallen victim to Clop ransomware group’s mass exploit of MOVEit Transfer bug CVE-2023-34362, which has compromised the personal data of at least 16 million people. The number is likely to rise as most victims are yet to explicitly quantify the number of affected individuals. ZeroFox Intelligence observed that the latest victims include a global fintech giant; a prominent American law firm; and multinational technology-, compliance-, and tax-consultancy companies.

VULNERABILITIES

  • CVE-2023-36607 - The affected TBox RTUs are missing authorization for running some API commands.
  • CVE-2023-3465 - A vulnerability was found in SimplePHPscripts Classified Ads Script 1.8.

EXPLOITS

BREACHES

Tags: DIB, tlp:green