zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - July 28, 2023

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - July 28, 2023

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Zimbra Patches Zero-Day Exploited in XSS Attacks
  • CISA and Partners Release Joint Cybersecurity Advisory on Preventing Web Application Access Control Abuse
  • U.S. Government Contractor Maximus Discloses Data Breach
  • Data broker / initial-access broker / hacktivist group: XSS user Fluxter and XSS user blackh4t
  • Vulnerabilities: CVE-2023-38408 and CVE-2023-3984
  • Exploits: CVE-2001-1442 and CVE-2007-1785
  • Breaches: BreachForums/XSS: Yahoo! Data Breach and BreachForums/XSS: Bitly Data Breach

Zimbra Patches Zero-Day Exploited in XSS Attacks

Zimbra has released security updates to patch a zero-day vulnerability in Zimbra Collaboration Suite (ZCS) email servers. The flaw (CVE-2023-38750) is a reflected Cross-Site Scripting (XSS) bug that could enable hackers to steal sensitive information or execute malicious code. The company urged users to apply the fix manually. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has mandated federal agencies to secure their systems against the attacks by August 17, 2023.

CISA and Partners Release Joint Cybersecurity Advisory on Preventing Web Application Access Control Abuse

Australian and American cybersecurity officials have published an advisory to warn web-application users about insecure direct object reference (IDOR) vulnerabilities. These access-control bugs allow threat actors to access and modify sensitive data by issuing requests to a website or a web application programming interface (API) specifying the user identifier of legitimate users. The advisory guides vendors, designers, developers, and end-user organizations towards measures to reduce the prevalence of IDOR flaws and secure confidential data.

U.S. Government Contractor Maximus Discloses Data Breach

U.S. government services contractor Maximus revealed a data breach, stating that hackers stole personal data of 8 to 11 million people during recent MOVEit Transfer attacks. The breach exploited a zero-day flaw in MOVEit (CVE-2023-34362), traced to the Clop ransomware gang. The company is expected to incur expenses of approximately USD 15 million for investigation and remediation efforts.

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

VULNERABILITIES

  • CVE-2023-38408 - The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remote code execution if an agent is forwarded to an attacker-controlled system.
  • CVE-2023-3984 - A vulnerability, which was classified as critical, was found in phpscriptpoint RecipePoint 1.9.

EXPLOITS

  • CVE-2001-1442 - ISC INN 2.x - Command-Line Buffer Overflow
  • CVE-2007-1785 - Computer Associates (CA) Brightstor Backup Mediasvr.exe Remote Code Exploit

BREACHES

Tags: DIB, tlp:green