zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - October 12, 2023

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - October 12, 2023

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • ZeroFox Intelligence Flash Report: Threat Actor Seeks to Profit from Conflict in Israel
  • State Hackers Exploiting Confluence Zero Day Since September
  • Simpson Manufacturing Shuts Down IT Systems After Cyberattack
  • Data broker / initial-access broker / hacktivist group: Exploit user: slezer and yameiii
  • Vulnerabilities: CVE-2023-20588 and CVE-2023-44488
  • Exploits: CVE-2021-32537 and CVE-2021-22911
  • Data Breach: BreachForums: TURF-FR Data Breach​ and BreachForums: Journal of Sports Science and Medicine Data Breach

ZeroFox Intelligence Flash Report: Threat Actor Seeks to Profit from Conflict in Israel

ZeroFox researchers have observed a threat actor advertising compromised personally identifiable information (PII) from the Israeli Defense Force (IDF) and the Israel Security Agency on a predominantly Russian-language dark web forum. Another prominent forum member, whom ZeroFox assesses to be likely an affiliate of a ransomware gang, responded that they would purchase the data if provided a discount. Such data (photos, phone numbers, other PII, and even access to social-media profiles) is perceived to be more valuable after the recent attack on Israel and consequent escalating hostilities.

State Hackers Exploiting Confluence Zero Day Since September

A week after Atlassian alerted customers about the active exploitation of a zero day (CVE-2023-22515), researchers have traced attacks occurring since September 14, 2023, to a Chinese-backed group, "Storm-0062." The group was previously charged by the United States government with extensive data theft and is known for targeting various sectors globally. While exploitation appears limited for now, users of vulnerable Confluence Data Center and Server versions should update to the latest versions.

Simpson Manufacturing Shuts Down IT Systems After Cyberattack

Simpson Manufacturing faced severe disruptions in its services, infrastructure, and business operations because of a cybersecurity incident on October 10, 2023. Upon detecting the intrusion, the manufacturer took steps to contain the activity, including taking systems offline, and consulted security experts to investigate the scope of the attack and plan recovery. The possibility of data theft remains a significant concern, considering the scale of operations, number of clients, and large amounts of proprietary information.

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

VULNERABILITIES

  • CVE-2023-20588:: A division-by-zero error on some AMD processors can potentially return speculative data
  • CVE-2023-44488:: VP9 in libvpx before 1.13.1 mishandles widths, leading to a crash

EXPLOITS

  • CVE-2021-32537: Out-of-bounds access in RTKVHD64 leading to pool corruption
  • CVE-2021-22911: Rocket.Chat 3.12.1 NoSQL Injection / Code Execution

BREACHES

Tags: DIB, tlp:green