zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - September 22, 2023

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - September 22, 2023

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • ZeroFox Intelligence Assessment – 2023 Phishing Trends
  • Apple Emergency Updates Fix 3 New Zero Days Exploited in Attacks
  • Critical Cache Poisoning Flaw in Drupal’s JSON:API Module
  • Data broker / initial-access broker / hacktivist group: Anonymous Sudan & SkyNet & BreachForums user Seize
  • Vulnerabilities: CVE-2020-35357 and CVE-2023-42482
  • Exploits: CVE-2020-36179 and CVE-2020-15148
  • Breaches: BreachForums: Blockchain.com Data Breach and The Forge Forums Data Breach

ZeroFox Intelligence Assessment – 2023 Phishing Trends

Phishing-as-a-service continues to proliferate in both dark web marketplaces and private messaging channels, where sellers offer varied, competitive services, and contribute to significantly lowered barriers of entry to threat actors. Search engine platforms are likely increasingly able to mitigate against traditional search engine optimization (SEO) poisoning methods, such as typosquatting and keyword stuffing. However, the threat from SEO cloaking, webpage hijacking, and URL redirecting is likely on an upward trajectory.

Apple Emergency Updates Fix 3 New Zero Days Exploited in Attacks

Apple has released critical security updates to patch three zero-day vulnerabilities impacting iPhone and Mac users. Two vulnerabilities, found in WebKit (CVE-2023-41993) and the Security framework (CVE-2023-41991), allowed attackers to bypass signature validation and execute arbitrary code. The third flaw (CVE-2023-41992), which is in the Kernel Framework, enabled privilege escalation by local attackers. Apple addressed these issues in macOS 12.7/13.6, iOS 16.7/17.0.1, iPadOS 16.7/17.0.1, and watchOS 9.6.3/10.0.1.

Critical Cache Poisoning Flaw in Drupal’s JSON:API Module

Researchers discovered a critical security flaw in Drupal's JSON:API module that could output error backtraces causing some configurations to cache sensitive information and make it available to anonymous users, finally leading to privilege escalation. This vulnerability only affects site configurations that have the JSON:API module enabled and can be mitigated by disabling or uninstalling the module. While some platforms may provide mitigations, not all configurations can mitigate the issue. Drupal recommends sites relying on the JSON:API to immediately update to the latest versions.

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

VULNERABILITIES

  • CVE-2020-35357: A buffer overflow can occur when calculating the quantile value using the Statistics Library of GSL (GNU Scientific Library), versions 2.5 and 2.6.
  • CVE-2023-42482: Samsung Mobile Processor Exynos 2200 allows a GPU Use After Free.

EXPLOITS

  • CVE-2020-36179: Deserialization of Untrusted Data in com.fasterxml.jackson.core:jackson-databind.
  • CVE-2020-15148: Deserialization of Untrusted Data in yiisoft/yii2.

BREACHES

Tags: DIB, tlp:green