zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - October 20, 2023

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - October 20, 2023

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Casio Confirms Data Breach of Customers Across 149 Countries
  • Five Eyes intelligence Chiefs Warn on China's “Theft” of Intellectual Property
  • CISA, NSA, FBI, and MS-ISAC Release Update to #StopRansomware Guide
  • Data broker / initial-access broker / hacktivist group: Exploit users: maveboy and Roblette
  • Vulnerabilities: CVE-2023-45822 and CVE-2023-27795
  • Exploits: CVE-2023-3460 and CVE-2023-23488
  • Data Breach: Telegram: '1000 LOGS 2022 #1q16.rar' Botnet Breach

Casio Confirms Data Breach of Customers Across 149 Countries

Casio has confirmed a breach affecting more than 126,000 customers across the world. The breach occurred after an attack on a “ClassPad.net'' database, a web application operated by Casio to support the digitization of graphs, statistics & analytics, geometry, and CAS functions. Further investigation revealed that some network security settings were accidentally disabled due to operational error, allowing the attack to take place. The breached data includes customer names, emails, country/region of residence, purchase information (order details, payment method, license code, etc.), and service usage information (log data, nicknames, etc.).

Five Eyes intelligence Chiefs Warn on China's “Theft” of Intellectual Property

The intelligence chiefs of the Five Eyes alliance have accused China of intellectual property theft and the use of artificial intelligence for espionage purposes. The accusation followed a discussion with tech companies from Silicon Valley and listed a variety of tactics such as cyber intrusions, human-intelligence operations, strategic corporate investments, and academic plants at research institutions. All five countries have reportedly observed a “sharp rise in aggressive attempts by other states to steal competitive advantage.” The chiefs further suggested that China operated the most massive and wide-scale intellectual theft operation among major nations. The Chinese government dismissed the statements as a “collective disinformation campaign.”

CISA, NSA, FBI, and MS-ISAC Release Update to #StopRansomware Guide

U.S. authorities have released an updated version of the #StopRansomware Guide, which includes new prevention tips such as hardening Server Message Block (SMB) protocols, revised response steps, and added threat hunting insights. The guide intends to help organizations minimize ransomware risks through best practices to detect, prevent, respond, and recover, including step-by-step approaches to address potential attacks.

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

VULNERABILITIES

  • CVE-2023-45822:: This Artifact Hub bug has been resolved in version 1.16.0, and there are no known workarounds.
  • CVE-2023-27795:: An issue found in IXP Data Easy Install v.6.6.14884.0 allows a local attacker to gain privileges via a static XOR key.

EXPLOITS

  • CVE-2023-3460: Unauthorized admin access for Ultimate Member plugin
  • CVE-2023-23488: WordPress Paid Memberships Pro 2.9.8 SQL Injection

BREACHES

Tags: DIB, tlp:green