ZeroFox Daily Intelligence Brief - July 28, 2023
|by Alpha Team

ZeroFox Daily Intelligence Brief - July 28, 2023
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Zimbra Patches Zero-Day Exploited in XSS Attacks
- CISA and Partners Release Joint Cybersecurity Advisory on Preventing Web Application Access Control Abuse
- U.S. Government Contractor Maximus Discloses Data Breach
- Data broker / initial-access broker / hacktivist group: XSS user Fluxter and XSS user blackh4t
- Vulnerabilities: CVE-2023-38408 and CVE-2023-3984
- Exploits: CVE-2001-1442 and CVE-2007-1785
- Breaches: BreachForums/XSS: Yahoo! Data Breach and BreachForums/XSS: Bitly Data Breach
Zimbra Patches Zero-Day Exploited in XSS Attacks
Zimbra has released security updates to patch a zero-day vulnerability in Zimbra Collaboration Suite (ZCS) email servers. The flaw (CVE-2023-38750) is a reflected Cross-Site Scripting (XSS) bug that could enable hackers to steal sensitive information or execute malicious code. The company urged users to apply the fix manually. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has mandated federal agencies to secure their systems against the attacks by August 17, 2023.
CISA and Partners Release Joint Cybersecurity Advisory on Preventing Web Application Access Control Abuse
Australian and American cybersecurity officials have published an advisory to warn web-application users about insecure direct object reference (IDOR) vulnerabilities. These access-control bugs allow threat actors to access and modify sensitive data by issuing requests to a website or a web application programming interface (API) specifying the user identifier of legitimate users. The advisory guides vendors, designers, developers, and end-user organizations towards measures to reduce the prevalence of IDOR flaws and secure confidential data.
U.S. Government Contractor Maximus Discloses Data Breach
U.S. government services contractor Maximus revealed a data breach, stating that hackers stole personal data of 8 to 11 million people during recent MOVEit Transfer attacks. The breach exploited a zero-day flaw in MOVEit (CVE-2023-34362), traced to the Clop ransomware gang. The company is expected to incur expenses of approximately USD 15 million for investigation and remediation efforts.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- XSS user Fluxter: Selling Jira Access To Unnamed UAE-Based Business Services Company
- XSS user blackh4t: Selling Citrix Access To Undisclosed Australian Company
VULNERABILITIES
- CVE-2023-38408 - The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remote code execution if an agent is forwarded to an attacker-controlled system.
- CVE-2023-3984 - A vulnerability, which was classified as critical, was found in phpscriptpoint RecipePoint 1.9.
EXPLOITS
- CVE-2001-1442 - ISC INN 2.x - Command-Line Buffer Overflow
- CVE-2007-1785 - Computer Associates (CA) Brightstor Backup Mediasvr.exe Remote Code Exploit
BREACHES
- BreachForums/XSS: Yahoo! Data Breach - (76,795,902 Records) | Email address and password
- BreachForums/XSS: Bitly Data Breach - (4,693,622 Records) | Email address and password
Tags: DIB, tlp:green