zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - August 07, 2023

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - August 07, 2023

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Beware of Criminals Posing as Non-Fungible Token (NFT) Developers
  • New Acoustic Attack Steals Data From Keystrokes With 95% Accuracy
  • Colorado Department of Higher Education (CDHE) Hit by Massive Data Breach
  • Data broker / initial-access broker / hacktivist group: Telegram channel NEFARIAN EMPIRE and Pro-Russia group Killnet
  • Vulnerabilities: CVE-2023-20817 and CVE-2023-20800
  • BreachForums: Vietanamobile Data Breach and BreachForums: İstanbul Büyükşehir Belediyesi

Beware of Criminals Posing as Non-Fungible Token (NFT) Developers

The FBI has warned the NFT community of criminals impersonating developers and promoting fraudulent offerings. Such announcements link to spoofed websites that ask victims to connect their cryptocurrency wallets—and subsequently empty them via a drainer smart contract. Be cautious when linking crypto wallets to any platform and verify its legitimacy; beware of offers that seem too good to be true, and report any suspicious activity to the FBI Internet Crime Complaint Center at www.ic3.gov.

New Acoustic Attack Steals Data From Keystrokes With 95% Accuracy

Researchers have trained a deep learning model to steal data from keyboard keystrokes recorded via microphone, with 95% accuracy. When Zoom was used, accuracy dropped to 93%, which is still alarmingly high. Unlike complex side-channel attacks, acoustic attacks are easier due to prevalent microphone devices and thus pose higher risks. Mitigation options include altering typing styles (touch typing), randomized passwords, and software-based audio filters.

Colorado Department of Higher Education (CDHE) Hit by Massive Data Breach

The CDHE has disclosed a significant data breach that exposed details of current and past students as well as teachers following a June ransomware attack. CDHE detected the cybersecurity incident on June 19, 2023. In response to the attack, CDHE secured the network, conducted an investigation with third-party experts, and restored the affected systems. The stolen information includes names, social security numbers, addresses, IDs, and more.

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

VULNERABILITIES

  • CVE-2023-20817 - In WLAN service, there is a possible out of bounds write due to improper input validation.
  • CVE-2023-20800 -In imgsys, there is a possible system crash due to a mssing ptr check.

BREACHES

Tags: DIB, tlp:green