zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - October 4, 2023

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - October 4, 2023

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • ShellTorch Exposes Tens of Thousands of Servers Worldwide to Attacks
  • Qualcomm: Four Bugs Actively Exploited in the Wild
  • Major Linux Distributions Affected by Root Access Vulnerability
  • Data broker / initial-access broker / hacktivist group: Exploit user: yesdaddy and Exploit user: budda12
  • Vulnerabilities: CVE-2023-5370 and CVE-2023-30738
  • Exploits: CVE-2021-21975
  • Breaches: BreachForums: Aakash Institute Data Breach and Combolist: '1900 NORD VPN ACC.txt'

ShellTorch Exposes Tens of Thousands of Servers Worldwide to Attacks

A critical set of vulnerabilities in the TorchServe AI tool, dubbed "ShellTorch," impacts tens of thousands of internet-exposed servers. TorchServe, maintained by Meta and Amazon, serves PyTorch ML models in production and is used by academic researchers and tech giants such as Amazon, OpenAI, Tesla, Azure, Google, and Intel. The flaws could lead to unauthorized server access and remote code execution. Attacks can be prevented by configuring servers to bind exclusively to local hosts and to fetch models only from trusted domains. Meta and Amazon have acknowledged the issue and encourage developers to use the latest version of TorchServe (0.8.2).

Qualcomm: Four Bugs Actively Exploited in the Wild

American semiconductor company Qualcomm has disclosed that four vulnerabilities are possibly under limited, targeted exploitation. The company has issued patches for the bugs—which affect Adreno GPU and Compute DSP drivers—and urges original equipment manufacturers (OEMs) to deploy security updates for users at the earliest possible. While details of one of the vulnerabilities (CVE-2022-22071) were disclosed in Qualcomm’s May 2022 public bulletin, the other three (CVE-2023-33107, CVE-2023-33106, and CVE-2023-33063) will be elaborated in the December 2023 issue.

Major Linux Distributions Affected by Root Access Vulnerability

A high-severity Linux vulnerability (CVE-2023-4911), known as "Looney Tunables," allows local attackers to obtain root privileges by exploiting a buffer overflow weakness in the GNU C Library's ld[.]so dynamic loader. The library (glibc) is a critical component in most Linux kernel-based systems, providing functionalities like system calls, program preparation, and execution. The vulnerability has existed since April 2021 with the release of glibc 2.34, and poses a significant risk to major distributions like Fedora, Ubuntu, and Debian.

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

VULNERABILITIES

  • CVE-2023-5370:: arm64 boot CPUs may lack speculative execution protections
  • CVE-2023-30738:: An improper input validation in UEFI Firmware prior to Firmware update Oct-2023 Release in Galaxy Book, Galaxy Book Pro, Galaxy Book Pro 360 and Galaxy Book Odyssey allows local attackers to execute SMM memory corruption.

EXPLOITS

  • CVE-2021-21975: VMware vRealize Operations Manager Server-Side Request Forgery / Code Execution.

BREACHES

Tags: DIB, tlp:green