zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - November 1, 2023

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - November 1, 2023

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • British Library and Toronto Public Library Face Service Outage
  • Atlassian Warns of New Critical Confluence Vulnerability Threatening Data Loss
  • Prolific Puma Gives Cybercriminals Access to .us Domains
  • Data broker / initial-access broker / hacktivist group: Anonymous Sudan and Exploit user l29
  • Vulnerabilities: CVE-2023-5515 and CVE-2023-2621
  • Exploits: CVE-2022-30333 and CVE-2022-21587
  • Breaches: BreachForums: National Education Association of Disabled Students Data Breach and Compramoto Data Breach

British Library and Toronto Public Library Face Service Outage

A “cyber incident” has led to a significant IT outage in the British Library, affecting its website and various services including phone lines, Reading Rooms, and onsite library services. While limited manual ordering of collection items is possible through printed catalogs in the St Pancras center at London, no access to digital collections or the digital catalog is possible. Meanwhile, Canada's largest public library system, the Toronto Public Library (TPL), disclosed a similar service outage after a cyberattack over the past weekend. While TPL’s WiFi continued to be available, the "Your Account" feature, “tpl:map” passes, digital collections, public computers, and printing services at TPL library branches were offline because of the attack.

Atlassian Warns of New Critical Confluence Vulnerability Threatening Data Loss

Atlassian has warned users of a critical security flaw (CVE-2023-22518; CVSS score of 9.1) in Confluence Data Center and Server that could lead to significant data loss in the event of a successful attack. Atlassian stated that the “improper authorization vulnerability” would not affect confidentiality as an attacker cannot exfiltrate any instance data. Customers should take immediate action to secure their instances and upgrade to the latest (patched) versions; Atlassian recommends disconnecting publicly accessible instances until the patch has been applied. Atlassian Cloud sites are not affected by the issue.

Prolific Puma Gives Cybercriminals Access to .us Domains

A threat actor tracked as “Prolific Puma” is operating a link-shortening service that provides scammers with “.us” top-level domains (TLDs), which makes phishing attacks more challenging to detect. Generating over 75,000 unique domain names in the past 18 months, the actor helps shorten links to enable phishing messages to fit properly in an SMS, hide the destination so that target victims are more likely to click the link, and provide resistance from detection by automated security products. While “.us” TLDs are reserved for American entities (citizens and institutions), the requisite restrictions and verifications are likely not always enforced, leading to the possibility of threat actors such as Prolific Puma exploiting the loopholes.

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

  • Anonymous Sudan: Allegedly targeted the content management system (CMS) system of Fox News
  • Exploit user l29: Selling RDP access to an unnamed U.S.-based retailer

VULNERABILITIES

  • CVE-2023-5515: The responses for web queries with certain parameters disclose internal path of resources.
  • CVE-2023-2621: The McFeeder server (distributed as part of SSW package), is susceptible to an arbitrary file write vulnerability on the MAIN computer system.

EXPLOITS

BREACHES

  • BreachForums: National Education Association of Disabled Students Data Breach (7,631 Records) Name, email address, and user activity
  • BreachForums: Compramoto Data Breach (1,192 Records) Name, email address, password, date of birth, company name, and user activity.

Tags: DIB, tlp:green