zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - October 25, 2023

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - October 25, 2023

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Flaws in Certain Implementations of Industry-Standard OAuth
  • South-Western Ontario Hospitals Reschedule Appointments After Cyberattack
  • Scammers Exploit Israel-Hamas War for Donation Scams
  • Data broker / initial-access broker / hacktivist group: Exploit user SHERIFF and Exploit user Howell
  • Vulnerabilities: CVE-2023-46006 and CVE-2023-45602
  • Exploits: CVE-2023-36844 and CVE-2023-2982
  • Data Breach: Combolist: '200K+ MIXED COMBOLIST.txt'

Flaws in Certain Implementations of Industry-Standard OAuth

Researchers have discovered flaws in the implementation of the common OAuth standard across major online services. The standard allows users to sign in to various platforms through the use of major account providers, such as prominent social-media platforms. Attackers could exploit API misconfigurations on these platforms through a "Pass-The-Token" technique, where account tokens generated from one service (including attacker owned-sites) could be used to access other services. While these flaws were fixed in some sites after researchers reported the flaw, many other websites may remain vulnerable.

South-Western Ontario Hospitals Reschedule Appointments After Cyberattack

Five Southwestern Ontario hospitals faced online service disruptions due to a cyberattack that began on 23 October 2023, as confirmed by their IT provider, TransForm—which is a local non-profit established by several healthcare organizations. The hospitals will try to contact patients with appointments scheduled for the next few days to reschedule or recommend alternative arrangements. TransForm is investigating the incident's cause and impact on patient information records. The impacted hospitals urged patients with non-emergency cases to seek primary care to reduce the strain on hospital resources.

Scammers Exploit Israel-Hamas War for Donation Scams

Scammers are exploiting the ongoing Israel-Hamas conflict by purporting to be charities and relief-fund collectors on social media, enticing donations with dubious cryptocurrency addresses. Researchers have found over 500 fraudulent fundraising emails impersonating charities. These accounts share graphic images to manipulate the emotions of sympathizers. To avoid falling victim to such scams, well-wishers should scrutinize donation pages, validate charities through reputable sources, and exercise caution when donating online.

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

VULNERABILITIES

  • CVE-2023-46006:: Sourcecodester Best Courier Management System 1.0 is vulnerable to SQL Injection via the parameter id in /edit_user.php.
  • CVE-2023-45602:: Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Shopfiles Ltd Ebook Store plugin <= 5.785 versions.

EXPLOITS

  • CVE-2023-36844:: Remote Code Execution in Juniper JunOS within SRX and EX Series products.
  • CVE-2023-2982:: Essential Addons for Elementor 5.4.0-5.7.1 - Unauthenticated Privilege Escalation

BREACHES

Tags: DIB, tlp:green