zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - July 11, 2023

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - July 11, 2023

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Apple Issues Urgent Patch for Actively Exploited Zero-Day Flaw
  • RomCom Hackers Target NATO Summit Attendees in Spear-Phishing Campaign
  • HCA Healthcare Suffers Data Breach Affecting 27 Million Patients
  • Initial-access brokers, data brokers, and hacktivists: Telegram Channel UserSec and Exploit user “nljfdjkl”
  • Vulnerabilities: CVE-2023-36922, CVE-2023-36925, and CVE-2023-21640
  • Exploits: CVE-2010-1240 and CVE-2016-4998
  • Breaches: BreachForums/XSS: Capital Games Data Breach and Moneyman Data Breach

Apple Issues Urgent Patch for Actively Exploited Zero-Day Flaw

On July 10, 2023, Apple released Rapid Security Response updates for iOS, iPadOS, macOS, and Safari web browser to address a zero-day bug (CVE-2023-37450) that the company says “may have been actively exploited.” However, Apple reportedly pulled the software update after the patches led to accessibility problems on browsing several popular browsers via Safari. The updates are likely to be re-released after the browser issues are fixed.

RomCom Hackers Target NATO Summit Attendees in Spear-Phishing Campaign

Threat actor "RomCom" is targeting pro-Ukraine organizations as well as attendees of the 2023 NATO Summit in Vilnius, Lithuania. The threat actor has been observed typosquatting by creating a replica of the Ukrainian World Congress website—using an ".info" domain instead of the legitimate ".org" domain. The attacker spreads RTF file documents containing malicious code through spear-phishing, to deliver malware which takes advantage of the “Follina” vulnerability to steal confidential data.

HCA Healthcare Suffers Data Breach Affecting 27 Million Patients

The data of around 27 million patients of HCA Healthcare, one of the largest medical companies in the US, had been compromised. HCA has alerted patients that their full name, city, and details of their last provider visit have been breached. While the organization reported that clinical information was not disclosed, the hackers claimed to possess “health diagnosis emails corresponding to clientIDs.” As reported last week, ZeroFox Intelligence observed a threat actor purportedly selling 27 records of the stolen data on an underground forum.

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

VULNERABILITIES

  • CVE-2023-36922 - Several SAP NetWeaver ABAP (IS-OIL) versions allow an authenticated attacker to inject an arbitrary operating system command into an unprotected parameter in a common extension.
  • CVE-2023-36925 - SAP Solution Manager (Diagnostics agent) - version 7.20, allows an unauthenticated attacker to blindly execute HTTP requests.
  • CVE-2023-21640 - Memory corruption in Linux when the file upload API is called with parameters having large buffer.

EXPLOITS

BREACHES

Tags: DIB, tlp:green