zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - August 17, 2023

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - August 17, 2023

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • CISA Releases JCDC Remote Monitoring and Management Cyber Defense Plan
  • CISA Cautions Against Actively Exploited Citrix ShareFile Vulnerability
  • Vulnerabilities in PowerShell Gallery Allow Attackers to Spoof Genuine Packages
  • Data broker / initial-access broker / hacktivist group: Killnet and NoName057(16)
  • Vulnerabilities: CVE-2023-4392 and CVE-2023-34213
  • Telegram: 'Logs 1.rar' Botnet Breach and 'Logs 5k.rar'

CISA Releases JCDC Remote Monitoring and Management Cyber Defense Plan

The U.S. Cybersecurity and Infrastructure Security Agency (CISA), in collaboration with private and governmental partners, has released an inaugural plan to tackle security concerns surrounding remote monitoring and management (RMM) tools. These tools are used by global IT departments to monitor machines, check system health/status, and enable remote access. Attackers increasingly attack these tools, particularly in government networks, to breach security systems. The new plan focuses on vulnerability sharing, industry coordination, user education, and advisory amplification to reduce risks.

CISA Cautions Against Actively Exploited Citrix ShareFile Vulnerability

CISA has issued an advisory cautioning against a critical vulnerability (CVE-2023-24489) in Citrix ShareFile, a secure SaaS cloud storage and file transfer tool, that is being exploited by unidentified actors. The flaw permits remote compromise of customer-managed storage zones. Researchers have highlighted minor AES encryption errors leading to arbitrary file uploads and remote code execution. CISA stresses swift patching because of targeted exploitation of similar flaws, as seen with the Clop extortion group. FCEB agencies must deploy patches by September 6, 2023.

Vulnerabilities in PowerShell Gallery Allow Attackers to Spoof Genuine Packages

Researchers have warned that active vulnerabilities within the PowerShell Gallery pose a supply chain risk, allowing attackers to execute typosquatting attacks and manipulate module metadata. These flaws result from lenient package name policies and API exploitation. These allow attackers to upload harmful modules that appear genuine by spoofing Author(s), Copyright, and Description fields, and can lead to unauthorized access to the package database, including sensitive information meant to be hidden from public view. While reactive fixes have been implemented, researchers claim that the issue still persists.

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

  • Killnet:: DDoS attack on French urban-mobility entity Regie Autonome des Transports Parisiens (RATP).
  • NoName057(16):: DDoS attacks on airports in Czechia and Canada.

VULNERABILITIES

  • CVE-2023-4392 - A vulnerability was found in Control iD Gerencia Web 1.30 and classified as problematic.
  • CVE-2023-34213 -TN-5900 Series firmware versions v3.3 and prior are vulnerable to command-injection vulnerability.

BREACHES

  • Telegram:: 'Logs 1.rar' Botnet Breach (22,146 Records) | Email address and password
  • Telegram:: 'Logs 5k.rar' Botnet Breach (172,000 Records) | Email address and password

Tags: DIB, tlp:green