ZeroFox Daily Intelligence Brief - August 03, 2023
|by Alpha Team

ZeroFox Daily Intelligence Brief - August 03, 2023
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Hackers Exploit Zero-Day Flaw in Salesforce Email Services to Target Social Media Accounts
- Collide+Power Side-Channel Vulnerability Present in Almost All CPUs
- Ivanti Declares New Critical Bug, Days After CISA Advisory on Exploitation of Two Other Bugs
- Data broker / initial-access broker / hacktivist group: NET - WORKER ALLIANCE and Anonymous Sudan
- Vulnerabilities: CVE-2023-38602 and CVE-2023-4125
- Exploits: CVE-2020-12800 and CVE-2013-5945
- BreachForums: Nerdweb Data Breach and BreachForums: BuyPersonalProxy Data Breach
Hackers Exploit Zero-Day Flaw in Salesforce Email Services to Target Social Media Accounts
A sophisticated phishing campaign targeting specific social-media accounts exploited a zero-day vulnerability in Salesforce's email services and SMTP servers. Dubbed "PhishForce," the flaw allowed attackers to bypass sender verification safeguards on prominent social media platforms to mass-send phishing emails. By using Salesforce's reputable email gateway, the attackers evaded security checks and rule filters. While the issue is remediated, platform engineers are still investigating why existing platform protections failed to stop the attacks.
Collide+Power Side-Channel Vulnerability Present in Almost All CPUs
Researchers from the Graz University of Technology observed a new side-channel vulnerability (CVE-2023-20583) in Intel, AMD, and ARM architecture devices that could allow attackers to leak data from the CPU memory by monitoring power consumption changes. The attack is possible through two modes: MDS-Power (which requires the attacker and victim to run via the same parallel core) or the Meltdown-Power mode (which can operate at rest). Though the finding holds research significance, the researchers have stated that it is hard to exploit in a real scenario and have deemed it low severity.
Ivanti Declares New Critical Bug, Days After CISA Advisory on Exploitation of Two Other Bugs
Ivanti has disclosed details of a critical bug in MobileIron Core—a mobile management software engine that enables IT teams to set policies for mobile devices, applications, and content. The bug can allow an unauthorized remote actor to access users’ personally identifiable information and make limited changes to the server. Because the affected versions have been out of support since last year, the company will not issue patches. Ivanti urged users to upgrade to the latest version of Ivanti Endpoint Manager Mobile (EPMM).
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- NET - WORKER ALLIANCE: : DDoS attacks on NATO entities
- Anonymous Sudan: DDoS attack on MTN telecom network in Nigeria
VULNERABILITIES
- CVE-2023-38602 - A permissions issue was addressed with additional restrictions.
- CVE-2023-4125 -Weak Password Requirements in GitHub repository answerdev/answer prior to v1.1.0.
EXPLOITS
- CVE-2020-12800 - WordPress Drag And Drop Multi File Uploader Remote Code Execution
- CVE-2013-5945 - D-Link DSR Router Series - Remote Command Execution
BREACHES
- BreachForums/XSS: Nerdweb Data Breach - (10,275 Records) Company name | financial information | name | phone number | physical address | IP address | user activity
- BreachForums/XSS: BuyPersonalProxy Data Breach - (25,141 Records) Company name | email address | financial information | physical address | IP address | name | nationality | password | phone number | user activity | username
Tags: DIB, tlp:green