ZeroFox Daily Intelligence Brief - October 23, 2023
|by Alpha Team

ZeroFox Daily Intelligence Brief - October 23, 2023
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- ZeroFox Intelligence Flash Report - Governments Worldwide Issue Caution Alerts for Travel
- American Family Insurance Takes Down IT Systems Following Cyberattacks
- Okta Releases Advisory on Breach of Support System
- Data broker / initial-access broker / hacktivist group: Anonymous Sudan and BlackDragonSec
- Vulnerabilities: CVE-2023-44488 and CVE-2023-37536
- Exploits: CVE-2023-27350 and CVE-2023-28121
- Data Breach: BreachForums: NORRIQ Data Breach and Airtel Data Breach
ZeroFox Intelligence Flash Report - Governments Worldwide Issue Caution Alerts for Travel
The U.S. Department of State has issued a “Worldwide Caution” warning U.S. citizens overseas to exercise increased caution, especially in areas frequented by tourists. The alert was issued amid growing tensions surrounding the Israel-Hamas conflict and subsequent protests targeting U.S. diplomatic compounds, particularly in the Middle East. Meanwhile, Germany, the United Kingdom, and the United States have told all their citizens residing in Lebanon to leave immediately. Nationals based overseas in high-risk locations should ensure their presence is registered with their own respective government body or embassy.
American Family Insurance Takes Down IT Systems Following Cyberattacks
American Family Insurance shut down several of its IT systems and confirmed a cyberattack, after customers reported website outages in the company's phone service, building connectivity and online services. Customers were left unable to pay bills or file for insurance claims online. Upon investigation, technology teams detected unusual activity on their networks. The attack bears similarities with ransomware attacks targeting the industry, with many such attacks taking place on weekends to take advantage of reduced tech-support and monitoring personnel.
Okta Releases Advisory on Breach of Support System
Okta Security disclosed that an attacker breached its support case management system through the use of stolen credentials. The attacker was able to view files uploaded by some of Okta’s customers in support cases. The company clarified that the main Okta service and the Auth0/CIC case management system have not been impacted. Okta notified all impacted customers, shared indicators of compromise, and advised customers to search system logs for suspicious sessions, users, or IP addresses.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- Anonymous Sudan:: DDoS attack on music service Deezer
- BlackDragonSec:: DDoS attack on the Palestinian Ministry of Transport and Communications; threatens to attack Iranian government and educational bodies next.
VULNERABILITIES
- CVE-2023-44488:: VP9 in libvpx before 1.13.1 mishandles widths, leading to a crash related to encoding.
- CVE-2023-37536:: An integer overflow in xerces-c++ 3.2.3 in BigFix Platform allows remote attackers to cause out-of-bound access via HTTP request.
EXPLOITS
- CVE-2023-27350:: PaperCutNG Authentication Bypass
- CVE-2023-28121:: WooCommerce Payments: Unauthorized Admin Access Exploit
BREACHES
- BreachForums: NORRIQ Data Breach: (53,529 Records)
- BreachForums: Airtel Data Breach: (7,847 Records)
Tags: DIB, tlp:green