zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - October 13, 2023

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - October 13, 2023

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • ZeroFox Situation Report: “Global Day of Jihad” Monitoring
  • Disinformation and Opportunistic Hacktivism in the Wake of Violence
  • 35 Squid Proxy Bugs Still Unpatched After 2 Years
  • Vulnerabilities: CVE-2023-39361 and CVE-2023-39514
  • Exploits: CVE-2023-23752 and CVE-2023-37979
  • Credit Card Data Breach

ZeroFox Situation Report: “Global Day of Jihad” Monitoring

On October 10, 2023, a former Hamas leader announced "Friday of The Al-Aqsa Flood," encouraging global protests and urging allies to support Hamas in its war against Israel. The comments have been largely reported as a call for a global day of Jihad starting on October 13, 2023. Israel's Foreign Ministry has cautioned Israelis abroad and the Jewish diaspora against planned demonstrations due to potential violence. While no immediate threats beyond the war zone are known, security teams should stay vigilant against possible anti-Semitic attacks, including direct targeting, swatting, doxxing, and cyber threats.

Disinformation and Opportunistic Hacktivism in the Wake of Violence

ZeroFox Intelligence has observed self-proclaimed “Islamic hacktivists” targeting and exhorting others to target entities in Israel and allied countries, in operations with names such as #OP_Israel, #OpIsraelV2, #OPalliesofIsrael, and #Al-Aqsaflood. Such activities include DDoS and defacement of websites, hacking billboards to post anti-Israeli and pro-Hamas footage, data breaches from educational institutions, selling personal information of Israeli soldiers on the dark web, and spreading disinfo. Meanwhile, European Union authorities have ordered prominent social-media platforms to curb the spread of illegal content, disinformation, and propaganda relating to the ongoing scenario.

35 Squid Proxy Bugs Still Unpatched After 2 Years

35 vulnerabilities remain unpatched in the widely used Squid web proxy, over two years after disclosure. The bugs result from use-after-free, memory leak, cache poisoning, assertion failure, and other flaws in various components. All the flaws are found in Squid-5.0.5 and in nearly every component: forward proxying, reverse proxying, all protocols supports (http, https, https intercept, urn, whois, gopher, ftp), responses, requests, “helpers,” DNS, ICAP, ESI, and caching. The proxy is reportedly maintained almost exclusively by volunteers, who may not have adequate support to issue patches quickly.

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

VULNERABILITIES

  • CVE-2023-39361:: Cacti versions prior to 1.2.25 are subject to SQL injection discovered in graph_view.php
  • CVE-2023-39514:: Cacti versions prior to 1.2.25 are subject to a Stored Cross-Site-Scripting (XSS) Vulnerability

EXPLOITS

  • CVE-2023-23752: Joomla! < 4.2.8 - Unauthenticated information disclosure
  • CVE-2023-37979: WordPress Plugin Ninja Forms 3.6.25 - Reflected XSS

BREACHES

Tags: DIB, tlp:green