ZeroFox Daily Intelligence Brief - October 11, 2023
|by Alpha Team

ZeroFox Daily Intelligence Brief - October 11, 2023
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- US Agencies Release Guidance on Securing OSS in IT/ICS Environments
- HTTP/2 Zero-Day Vulnerability Used to Target Major Tech Companies
- Mirai Botnet Variant Expands Targets with 13 Router Exploits
- Data broker / initial-access broker / hacktivist group: XSS user: zjdue123 and Exploit user: slezer
- Vulnerabilities: CVE-2023-3550 and CVE-2023-5214
- Exploits: CVE-2021-29447 and CVE-2021-22204
- Data Breach: 2023-10-11T03:02:29_exbl_v4.json and Combolist: 'free easy mailpass.txt'
US Agencies Release Guidance on Securing OSS in IT/ICS Environments
US agencies have released guidance for securing open source software (OSS) in operational technology (OT) and industrial control systems (ICS). The guide offers recommendations for supporting OSS development, vulnerabilities, and utilizing goals to adopt key cybersecurity practices. CISA has also published the Securing OSS in OT web page, detailing the Joint Cyber Defense Collaborative's OSS planning initiative. It aims to boost collaboration between the public and private sectors. CISA encourages OT/ICS organizations to adopt these recommendations.
HTTP/2 Zero-Day Vulnerability Used to Target Major Tech Companies
Cloudflare, Google, and AWS disclosed a new zero-day vulnerability, “HTTP/2 Rapid Reset,” which an unknown threat actor harnessed to execute "enormous, hyper-volumetric" DDoS attacks. Google observed an attack peaking at 398 million RPS(requests per second), seven times larger than their previous record. The attacks that struck AWS and Cloudflare exceeded a volume of 155 million and 201 million RPS, respectively. The zero-day provides threat actors with a new DDoS to target victims at a wider magnitude while requiring only a modestly-sized botnet of 20,000 machines.
Mirai Botnet Variant Expands Targets with 13 Router Exploits
The IZ1H9 Mirai-based DDoS malware botnet has resurfaced and expanded its reach to target Linux-based routers from D-Link, Zyxel, TP-Link, TOTOLINK, among others. Researchers noted a surge in exploitation attempts in early September 2023, which included recently released exploit codes. Once a device is compromised, the botnet deploys a payload, conceals its activity, and establishes communication with a command and control server. The threat is considered "critical" due to its scale, potential for remote control over affected devices and exploitation of vulnerabilities from 2015 to 2023, making this wave of Mirai activity a significant concern.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- XSS user: zjdue123: Actor selling network access to Japanese textile and chemical manufacturer
- Exploit user: slezer: Multifunctional malware with stealer and clipper capabilities advertised
VULNERABILITIES
- CVE-2023-3550:: Mediawiki v1.40.0 does not validate namespaces used in XML files.
- CVE-2023-5214:: Privilege Escalation path in Puppet Bolt versions prior to 3.27.4.
EXPLOITS
- CVE-2021-29447: WordPress 5.7 - 'Media Library' XML External Entity Injection
- CVE-2021-22204: ExifTool 12.23 - Arbitrary Code Execution
BREACHES
- Telegram: "ArtHouse Cloud FREE.zip" Botnet Breach: (be24fb | 743958)
- Combolist: 'free easy mailpass.txt': (50,249 Records)| Email Address and Password
Tags: DIB, tlp:green