zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - July 7, 2023

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - July 7, 2023

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • CISA and Partners Release Joint Cybersecurity Advisory on Newly Identified Truebot Malware Variants
  • Critical Vulnerabilities Leave SolarView Devices in Solar Farms Exposed to Exploits
  • JumpCloud Notifies Customers of Incident: Admin API Keys Invalidated as Security Measure
  • INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS: ShadowHacker Leaks and BreachForum user TIA
  • Vulnerabilities: CVE-2023-3439 and CVE-2023-21518
  • Exploits: CVE-2004-2687
  • Breaches: BreachForums/XSS: EDA Board Data Breach and BreachForums/XSS: Forbes Data Breach

CISA and Partners Release Joint Cybersecurity Advisory on Newly Identified Truebot Malware Variants

Cybersecurity officials from the United States and Canada have published a joint advisory highlighting the threat posed by the Truebot botnet (Silence Downloader), which threat actors use to collect and exfiltrate information from target victims. New variants of the malware allow criminals to gain initial access by exploiting a remote code execution bug (CVE-2022-31199) in the Netwrix Auditor application. The advisory recommends hunting and mitigation measures to deal with this threat.

Critical Vulnerabilities Leave SolarView Devices in Solar Farms Exposed to Exploits

Hundreds of SolarView devices in solar farms remain unpatched against two critical vulnerabilities. One of the bugs (CVE-2022-29303) enables remote execution of commands and has been actively exploited by the Mirai botnet. While the other vulnerability (CVE-2023-23333) is not known to be actively exploited, exploit code for it has been publicly available since February 2023.

JumpCloud Notifies Customers of Incident: Admin API Keys Invalidated as Security Measure

JumpCloud, a U.S.-based enterprise software firm that serves over 180,000 organizations, is notifying customers about an ongoing incident. As a precautionary measure, the company has invalidated existing admin API keys to protect clients. Affected organizations will need to generate new keys. The company is currently investigating the incident, and further details regarding the nature, scope, and impact are awaited.

INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

VULNERABILITIES

  • CVE-2023-3439 - A flaw was found in the MCTP protocol in the Linux kernel.
  • CVE-2023-21518 - Improper access control vulnerability in SearchWidget prior to version 3.3 in China models allows untrusted applications to start arbitrary activity.

EXPLOITS

BREACHES

Tags: DIB, tlp:green