zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - August 11, 2023

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - August 11, 2023

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Cross-Platform TunnelCrack Attack Leaks VPN Traffic by Interrupting Routing Tables
  • CISA Warns Against Newly Exploited Backdoors in Barracuda Email Gateway Devices
  • Researchers Bring Attention to Potential Abuse of ANSI Escape Sequence in Terminal Software
  • Data broker / initial-access broker / hacktivist group: Killmilk/Killnet: and RAWRZ KittenSec group
  • Vulnerabilities: CVE-2023-38333 and CVE-2023-40224
  • Breaches: Telegram: 202305_redline_7386_B_(20230526).zip and GODELESS CLOUD.rar

Cross-Platform TunnelCrack Attack Leaks VPN Traffic by Interrupting Routing Tables

TunnelCrack combines two prevalent VPN vulnerabilities, enabling adversaries to breach VPN tunnels, route traffic, and intercept transmitted data. Examination of over 65 VPNs on five platforms revealed a varying susceptibility—highly susceptible: iPhones, iPads, MacBooks, macOS; vulnerable: a majority of Windows and Linux VPNs; relatively secure: Android (a quarter vulnerable). The technique can reportedly exploit VPNs irrespective of the protocols used. Attacks can be triggered by luring victims to compromised WiFi networks or by leveraging malicious ISPs.

CISA Warns Against Newly Exploited Backdoors in Barracuda Email Gateway Devices

CISA has released an analysis report on actively exploited backdoors on compromised Barracuda Email Security Gateway (ESG) devices, labeling the latest known backdoor “WhirlPool.” The attacks began in October 2022, as pro-China hackers used the CVE-2023-2868 zero-day vulnerability to breach systems using Saltwater and SeaSpy backdoors. Barracuda's replacement offer highlighted the severity of the campaign.

Researchers Bring Attention to Potential Abuse of ANSI Escape Sequence in Terminal Software

ANSI escape sequences are codes that enhance terminal text with color and highlights. However, security researchers reveal that these sequences pose long-neglected security risks. An attacker could embed codes into the log files of commands which IT professionals rely on or alter their outputs to make them seem empty/normal after an attack. These issues stress the need for input sanitization and output escaping, as failing to do so invites consequences like denial of service or log manipulation by ransomware groups.

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

  • Killmilk/Killnet:: Announces “full war on France” in support of Niger; exhorts allies to target the networks and infrastructure of the French state
  • RAWRZ KittenSec group:: Shared data allegedly stolen from French ISP company “Free” (free[.]fr)

VULNERABILITIES

  • CVE-2023-38333 - Zoho ManageEngine Applications Manager through 16530 allows reflected XSS while logged in.
  • CVE-2023-40224 - MISP 2.4174 allows XSS in app/View/Events/index.ctp.

BREACHES

  • Telegram:: "202305_redline_7386_B_(20230526).zip" (126,798 Records)| Email address and password
  • Telegram:: "GODELESS CLOUD.rar" (38,989 Records) | Email address and password

Tags: DIB, tlp:green