zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - October 15, 2023

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - October 15, 2023

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Mirai Botnet Variant Expands Targets with 13 Router Exploits
  • US Agencies Release Guidance on Securing OSS in IT/ICS Environments
  • HTTP/2 Zero-Day Vulnerability Used to Target Major Tech Companies

Mirai Botnet Variant Expands Targets with 13 Router Exploits

The IZ1H9 Mirai-based DDoS malware botnet has resurfaced and expanded its reach to target Linux-based routers from D-Link, Zyxel, TP-Link, TOTOLINK, among others. Researchers noted a surge in exploitation attempts in early September 2023, which included recently released exploit codes. Once a device is compromised, the botnet deploys a payload, conceals its activity, and establishes communication with a command and control server. The threat is considered "critical" due to its scale, potential for remote control over affected devices and exploitation of vulnerabilities from 2015 to 2023, making this wave of Mirai activity a significant concern.

US Agencies Release Guidance on Securing OSS in IT/ICS Environments

US agencies have released guidance for securing open source software (OSS) in operational technology (OT) and industrial control systems (ICS). The guide offers recommendations for supporting OSS development, vulnerabilities, and utilizing goals to adopt key cybersecurity practices. CISA has also published the Securing OSS in OT web page, detailing the Joint Cyber Defense Collaborative's OSS planning initiative. It aims to boost collaboration between the public and private sectors. CISA encourages OT/ICS organizations to adopt these recommendations.

HTTP/2 Zero-Day Vulnerability Used to Target Major Tech Companies

Cloudflare, Google, and AWS disclosed a new zero-day vulnerability, “HTTP/2 Rapid Reset,” which an unknown threat actor harnessed to execute "enormous, hyper-volumetric" DDoS attacks. Google observed an attack peaking at 398 million RPS(requests per second), seven times larger than their previous record. The attacks that struck AWS and Cloudflare exceeded a volume of 155 million and 201 million RPS, respectively. The zero-day provides threat actors with a new DDoS to target victims at a wider magnitude while requiring only a modestly-sized botnet of 20,000 machines.

Tags: DIB, tlp:green