ZeroFox Daily Intelligence Brief - July 19, 2023
|by Alpha Team

ZeroFox Daily Intelligence Brief - July 19, 2023
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Citrix Urges Immediate Action to Address Critical Vulnerability in NetScaler ADC and Gateway
- VirusTotal Data Breach Exposes Registered Customer Information
- CISA Orders Federal Agencies to Mitigate Zero-Days Abused in NATO Phishing Attacks
- Data broker / initial-access broker / hacktivist group: Private Telegram Channel: Exposure of U.S. Senate and Staff Credentials and BlackPass: Compromised E-commerce Account of Heineken Executive for Sale
- Vulnerabilities: CVE-2023-32623 and CVE-2023-3755
- Exploits: CVE-2017-11610 and CVE-2017-8464
- Breaches: BreachForums/XSS: Aternos Data Breach and BreachForums/XSS: Manga Traders Data Breach
Citrix Urges Immediate Action to Address Critical Vulnerability in NetScaler ADC and Gateway
Citrix has issued an alert about a critical vulnerability (CVE-2023-3519) in NetScaler ADC and NetScaler Gateway, urging customers to install updated versions immediately. The flaw, already exploited in the wild, may be the same zero-day vulnerability advertised on a hacker forum earlier this month. Citrix advised customers to upgrade to the recommended versions and noted that certain older versions have reached end-of-life.
VirusTotal Data Breach Exposes Registered Customer Information
The names and email addresses of about 5,600 registered customers of VirusTotal were accidentally exposed when an employee inadvertently uploaded an internal database on the platform. Google (which acquired VirusTotal in 2012) confirmed the leak, promptly removing the data and pledging to enhance internal processes and technical controls. The exposed accounts include those of prominent U.S. organizations as well as government agencies from various countries.
CISA Orders Federal Agencies to Mitigate Zero-Days Abused in NATO Phishing Attacks
The Cybersecurity and Infrastructure Security Agency (CISA) has instructed U.S. federal agencies to implement mitigation measures for a set of zero-day bugs (CVE-2023-36884) actively exploited by Russian threat group Storm-0978 (RomCom). The vulnerabilities were exploited in targeted attacks against government entities across North America and Europe. Recently, attackers abused malicious Office documents purportedly from the Ukrainian World Congress organization to target participants of the 2023 NATO Summit in Vilnius, Lithuania.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- Private Telegram Channel: Exposure of U.S. Senate and Staff Credentials
- BlackPass: Compromised E-commerce Account of Heineken Executive for Sale
VULNERABILITIES
- CVE-2023-32623 - Directory traversal vulnerability in Snow Monkey Forms v5.1.1 and earlier allows a remote unauthenticated attacker to delete arbitrary files on the server.
- CVE-2023-3755 - A vulnerability has been found in Creativeitem Atlas Business Directory Listing 2.13 and classified as problematic.
EXPLOITS
- CVE-2017-11610: Supervisor XML-RPC Authenticated RCE
- CVE-2017-8464: LNK Code Execution Vulnerability
BREACHES
- BreachForums/XSS: Aternos Data Breach (851,589 Records) Email address and password
- BreachForums/XSS: Manga Traders Data Breach (845,232 Records) Email address and password
Tags: DIB, tlp:green