zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - August 28, 2023

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - August 28, 2023

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Metropolitan Police on High Alert After Supplier IT Security Breach
  • Flax Typhoon Using LOLBins to Evade Detection
  • Cloud and Hosting Provider Leaseweb Took Down Critical Systems After a Cyberattack
  • Data broker / initial-access broker / hacktivist group: Explot user: Roblette and maveboy
  • Exploits: CVE-2020-8840
  • Vulnerabilities: CVE-2023-38026 and CVE-2023-20197
  • Leakbase: Ethnigo Data Breach and BreachForums: David Fischman Data Breach

Metropolitan Police on High Alert After Supplier IT Security Breach

The United Kingdom’s Metropolitan Police is on high alert following a security breach involving the IT system of one of its suppliers. Scotland Yard is collaborating with the company to assess the breach's extent. The breached company had access to names, ranks, photos, and pay numbers of officers/staff, but not personal info like addresses or finances. The exact breach date and impacted personnel are unknown. The incident has been reported to the National Crime Agency and the Information Commissioner's Office.

Flax Typhoon Using LOLBins to Evade Detection

A newly identified hacking group, Flax Typhoon, has been targeting government agencies, education, critical manufacturing, and IT organizations, presumably for espionage. Flax Typhoon avoids malware, relying on living-off-the-land binaries and legitimate software. Active since mid-2021, it has mainly targeted Taiwan, with victims in Southeast Asia, North America, and Africa. The group exploits server vulnerabilities through tools such as China Chopper web shells and Juicy Potato to elevate privileges, disable network-level authentication, and set up RDP (Remote Desktop Protocol) connections.

Cloud and Hosting Provider Leaseweb Took Down Critical Systems After a Cyberattack

Leaseweb, one of the world's largest cloud and hosting providers, has issued customer notifications after a recent breach, while stating that it is working on restoring systems. Unusual activity was discovered on August 22, 2023 during an investigation on the Customer Portal downtime. The affected systems were promptly taken down to manage the threat and the company’s security measures improved. No further unauthorized activity was found.

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

EXPLOITS

  • CVE-2020-8840 - FasterXML Jackson-databind Injection Vulnerability in Huawei Products

VULNERABILITIES

  • CVE-2023-38026 - SpotCam Co., Ltd. SpotCam FHD 2 has a vulnerability of using hard-coded uBoot credentials.
  • CVE-2023-20197 - A vulnerability in the filesystem image parser for Hierarchical File System Plus (HFS+) of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.

BREACHES

  • Leakbase: : Ethnigo Data Breach (42,673 Records)| Company name, email address, name, phone number, date of birth, gender, and physical address.
  • BreachForums:: Botnet Breach (33,151 Records) | Company name, email address, name, phone number, and physical address

Tags: DIB, tlp:green