zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - August 9, 2023

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - August 9, 2023

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Joint Law-Enforcement Operation Shuts Down Notorious Phishing Platform “16shop”
  • U.K. Electoral Commission Discloses Data Breach
  • Intel Provides Mitigation for New Downfall Attacks that Can Steal Steal Encryption Keys from CPUs
  • Data broker / initial-access broker / hacktivist group: Killmilk and Anonymous Sudan
  • Vulnerabilities: CVE-2023-22403 and CVE-2023-36213
  • Breaches: XSS/Leakbase: Federal Direct Access Expositions Data Breach and BreachForums: Gameshop Twente Data Breach

Joint Law-Enforcement Operation Shuts Down Notorious Phishing Platform “16shop”

A global law-enforcement operation has taken down the infamous phishing-as-a-service platform “16shop” and arrested three people connected to its activities. The platform’s administrator was arrested in Indonesia and several luxury vehicles as well as electronic items were confiscated.

U.K. Electoral Commission Discloses Data Breach

The U.K. Electoral Commission has issued a public notice regarding a data breach discovered in October 2022. The breach was traced back to August 2021, when malicious actors accessed servers with email, control systems, and electoral registers. Although names and addresses were exposed, anonymous and overseas registrants were unaffected. The compromised data includes personal information from emails and electoral registers. The incident hasn't affected electoral processes, rights, or registration.

Intel Provides Mitigation for New Downfall Attacks that Can Steal Steal Encryption Keys from CPUs

Intel has released a microcode update to mitigate the "Downfall" vulnerability (CVE-2022-40982) in multiple Intel microprocessor families and provided several software-based mitigation options. The bug enabled the theft of passwords, encryption keys, and private data, including that protected by Intel's Software Guard eXtensions (SGX). Affected architectures include Skylake through Ice Lake.

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

  • Killmilk: Claims to have DDoS attacked the website of Heathrow Airport (London), allegedly taking it offline for tens minutes as part of a big flood test.
  • Anonymous Sudan: Posted a video threatening to attack the critical infrastructure of any country (citing Kenya as an example) that interferes in the internal affairs of Sudan.

VULNERABILITIES

  • CVE-2023-22403 - An Allocation of Resources Without Limits or Throttling vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows a network-based, unauthenticated attacker to cause a Denial of Service (DoS).
  • CVE-2023-36213 - SQL injection vulnerability in MotoCMS v.3.4.3 allows a remote attacker to gain privileges via the keyword parameter of the search function.

BREACHES

  • XSS/Leakbase: Federal Direct Access Expositions Data Breach (7,672 Records) | Company name, email address, phone number, physical address, and name
  • BreachForums: Gameshop Twente Data Breach (8,082 records) | Email address, name, phone number, and user activity

Tags: DIB, tlp:green