zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - October 16, 2023

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - October 16, 2023

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Women Political Leaders Summit Targeted in RomCom Malware Phishing
  • 530,000 Customer Records Stolen After Cloud Gaming Provider Breach
  • US Space Force Temporarily Halts Use of Generative AI Over Security Concerns
  • Data broker / initial-access broker / hacktivist group: XSS user SocketSilence and RAMP user Pwnstar
  • Vulnerabilities: CVE-2023-5591 and CVE-2023-5590
  • Credit Card Data Breach and Combolist: '68k.txt'

Women Political Leaders Summit Targeted in RomCom Malware Phishing

A lightweight RomCom backdoor variant targeted participants of the Women Political Leaders (WPL) Summit in Brussels. The new variant, operated by "Void Rabisu," employs a stealthier backdoor with TLS-enforcement, making it harder to detect. The campaign used a fake website mimicking the official WPL portal to lure attendees. Attendees of major conferences are advised to exercise caution and avoid duplicitous sites, as Void Rabisu may target other major conferences. The group is previously known to have targeted attendees of the Munich Security Conference, Ukrainian World Congress, and a NATO summit.

530,000 Customer Records Stolen After Cloud Gaming Provider Breach

Shadow, a cloud gaming service, suffered a data breach after falling victim to a social-engineering attack. The attack began on Discord when an attacker tricked an employee into downloading an infected Steam game. The download hid a token grabber tool, which later led to the exfiltration of a sensitive database, exposing 533,624 records of customer data. The compromised data includes full names, email addresses, dates of birth, billing addresses and credit card expiration dates. However, no passwords or sensitive banking data had been breached.

US Space Force Temporarily Halts Use of Generative AI Over Security Concerns

The United States Space Force issued a temporary ban against the use of artificial intelligence tools such as ChatGPT, citing possibilities of data security issues. Details of the ban were contained within a memorandum dated September 29 2023, and sent to Space Force members, restricting personnel from using AI tools and large-language models without formal sanction. The document indicated that the regulation aims to protect personnel and agency data while the agency works on policies to integrate AI capabilities into supporting missions. It further acknowledged the transformative potential of generative AI, but highlighted the need for "responsible" adoption given uncertainties. The author of the memo, committed that the agency would provide more detailed guidelines within 30 days.

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

VULNERABILITIES

  • CVE-2023-5591:: SQL Injection in GitHub repository librenms/librenms prior to 23.10.0.
  • CVE-2023-5590:: NULL Pointer Dereference in GitHub repository seleniumhq/selenium prior to 4.14.0.

BREACHES

Tags: DIB, tlp:green