ZeroFox Daily Intelligence Brief - October 6, 2023
|by Alpha Team

ZeroFox Daily Intelligence Brief - October 6, 2023
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- NSA and CISA Release Joint Advisory on Common Cyber Security Misconfigurations
- Chinese-Linked Hackers Eavesdrop on Semiconductor Firms of Neighboring Countries
- “Information Technology Security Event” Affects Operations of First Judicial Circuit Court of Florida
- Data broker / initial-access broker / hacktivist group: RansomedVC and NoName057(16)
- Vulnerabilities: CVE-2023-5217 and CVE-2023-45243
- Exploits: CVE-2021-25374 and CVE-2021-26084
- Breaches: BreachForums: SpotUno.mx Breach
NSA and CISA Release Joint Advisory on Common Cyber Security Misconfigurations
U.S. authorities have listed the ten most common cybersecurity misconfigurations in large organizations' networks. These findings underscore the importance of secure-by-design principles to reduce risk of compromise. Key misconfigurations include default software settings, weak multifactor authentication (MFA), and code execution restrictions. NSA and CISA urge network defenders and software manufacturers to follow mitigations and to check for issues, even with software not mentioned in the advisory.
Chinese-Linked Hackers Eavesdrop on Semiconductor Firms of Neighboring Countries
Chinese-speaking semiconductor companies are falling victim to espionage, with hackers using TSMC-themed lures to plant Cobalt Strike beacons. The campaign primarily focuses on firms in Taiwan, Hong Kong, and Singapore, mirroring tactics used by Chinese state-backed groups. Spear-phishing emails likely serve as the initial compromise channel, enabling the hackers to install Cobalt Strike beacons through HyperBro loader. This loader employs DLL side-loading, cloaking the attack in a legitimate guise. The command and control (C2) server address is camouflaged as a jQuery CDN, evading firewall defenses among other tactics and alternative backdoors.
“Information Technology Security Event” Affects Operations of First Judicial Circuit Court of Florida
Court operations at the First Judicial Circuit Court of Florida have been disrupted by an unspecified information technology security event. The incident is expected to affect court operations in Escambia, Okaloosa, Santa Rosa, and Walton counties for an extended period. While essential court proceedings will be prioritized, other proceedings and operations will be canceled and rescheduled for several days.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- RansomedVC: Claims to be selling a 600,000 line database of U.S. voter data belonging to the District of Columbia Board of Elections.
- NoName057(16):: Allegedly conducted a DDoS attack on Australian government websites in response to Australian weapon supplies to Ukraine.
VULNERABILITIES
- CVE-2023-5217:: Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- CVE-2023-45243:: Sensitive information disclosure due to missing authorization.
EXPLOITS
- CVE-2021-25374: Improper authorization vulnerability in Samsung Members "samsungrewards" scheme for deeplink.
- CVE-2021-26084: Atlassian Confluence Namespace OGNL Injection.
BREACHES
- BreachForums: SpotUno.mx Breach: (966 Records)| Username, IP address, physical address, phone number, email address, and password
Tags: DIB, tlp:green