zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - October 2, 2023

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - October 2, 2023

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • The Marvin Attack
  • ALPHV Claims to Have Breached McLaren Health Care Corporation
  • New Critical Security Flaws Expose Exim Mail Servers to Remote Attacks
  • Data broker / initial-access broker / hacktivist group: XSS user SocketSilence and RAMP user xss_0x2
  • Vulnerabilities: CVE-2023-32828 and CVE-2023-5217
  • Breaches: Combolist: '100K_VPN_000098.txt' (99,744 Records) and Credit Card Data Breach: 2023-9-30 (378596 | 1294)

The Marvin Attack

A bug that was known to be able to break the confidentiality of TLS when used with RSA encryption in 1998 is reportedly still potent today, with many cryptographic implementations vulnerable to variants of the same attack (Marvin Attack). The flaw allows an attacker to perform RSA decryption and signing operations, upon being able to observe the time of the decryption performed with the private key. With this backdrop, security researchers have advised against using RSA PKCS#1 v1.5 encryption and urged developers to deprecate and disable support for PKCS#1 v1.5 padding for encryption.

ALPHV Claims to Have Breached McLaren Health Care Corporation

Last Friday, ZeroFox Intelligence observed the ALPHV/BlackCat ransomware group claim that it has breached one of Michigan's largest healthcare companies; the group bragged to have stolen more than 6 TB of data and teased “one of the biggest leaks of all time.” Now, ALPHV has listed McLaren Health Care as a victim on its leak site—indicating that it has access to 2.5 million people’s sensitive data and that its backdoor is still active. ALPHV is known to be especially unscrupulous and depraved, even among ransomware groups. The group had targeted healthcare facilities in the past, even leaking unclothed photos of female cancer patients to coerce the victim hospital to pay the ransom demanded.

New Critical Security Flaws Expose Exim Mail Servers to Remote Attacks

A critical severity bug (CVE-2023-42115; CVSS 3.0 base score 9.8) in the widely used Exim mail transfer agent can enable remote, unauthenticated attackers to execute arbitrary code on Exim installations. Until patches are available, admins have been advised to “restrict interaction with the application,” that is, to restrict remote access via the internet so as to thwart possible exploitation attempts. In addition to this bug, several other Exim bugs have been disclosed that can allow information disclosure and remote code execution.

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

VULNERABILITIES

  • CVE-2023-32828: In vpu, there is a possible out of bounds write due to an integer overflow.
  • CVE-2023-5217: Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

BREACHES

Tags: DIB, tlp:green