zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - September 12, 2023

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - September 12, 2023

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Ransomware Group BianLian Claims Large-Scale Breach of Non-Profit Organization
  • MGM Resorts Takes Down Systems Due to Cybersecurity Incident
  • CISA Urges Federal Agencies to Patch Pegasus Exploit in iPhones
  • Data broker / initial-access broker / hacktivist group: BreachForums user USDoD and Exploit user sandocan
  • Vulnerabilities: CVE-2023-40953 and CVE-2023-41107
  • Exploits: CVE-2020-14883 and CVE-2020-8289
  • BreachForums: Chevrolet Data Breach and Credit Card Data Breach

Ransomware Group BianLian Claims Large-Scale Breach of Non-Profit Organization

Cybercriminal group BianLian claims to have breached a prominent non-profit body's IT systems. Experts suspect the victim to be Save The Children International, which employs 25,000 people and operates in 116 countries to protect the rights and interests of children. The group claims to have seized 6.8 TB of data, including international HR files, personal data, financial records, emails, and health data. BianLian threatens to leak or sell the data unless a ransom is paid.

MGM Resorts Takes Down Systems Due to Cybersecurity Incident

MGM Resorts International disclosed a cybersecurity incident that affected some of the company’s systems. The company’s main website, online reservations, and in-casino services (ATMs, slots, credit card machines) have been reportedly affected in this incident. MGM Resort initiated an immediate investigation, took action to secure data by shutting down some systems, and notified law enforcement. Investigations are underway to determine the nature and scope of the attack.

CISA Urges Federal Agencies to Patch Pegasus Exploit in iPhones

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has urged federal agencies to patch security vulnerabilities (CVE-2023-41064 and CVE-2023-41061) exploited in zero-click attacks to infect iPhones with NSO Group's Pegasus spyware. Vulnerable devices include various iPhone models, iPads, Macs, and Apple Watches. CISA designated the flaws as "frequent attack vectors" and set an October 2, 2023 deadline to secure affected devices within federal agencies. CISA also advised private companies to prioritize patching these vulnerabilities.

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

VULNERABILITIES

  • CVE-2023-40953 : icms 7.0.16 is vulnerable to Cross Site Request Forgery (CSRF).
  • CVE-2023-41107 : TEF portal 2023-07-17 is vulnerable to a persistent cross site scripting (XSS )attack.

EXPLOITS

  • CVE-2020-14883 : Oracle WebLogic Server Administration Console Handle Remote Code Execution
  • CVE-2020-8289 : Remote Code Execution as SYSTEM/root via Backblaze

BREACHES

Tags: DIB, tlp:green