ZeroFox Weekly Intelligence Brief – November 6, 2023
|by Alpha Team

ZeroFox Weekly Intelligence Brief – November 6, 2023
TLP:GREEN
ZeroFox’s Weekly Intelligence Briefing highlights the major developments and trends across the cyber threat landscape. ZeroFox Intelligence is derived from a variety of sources, including—but not limited to—curated open-source accesses, vetted social media, proprietary data sources, and direct access to threat actors and groups through covert communication channels. Information relied upon to complete any report cannot always be independently verified. As such, ZeroFox applies rigorous analytic standards and tradecraft in accordance with best practices and includes caveat language and source citations to clearly identify the veracity of our Intelligence reporting and substantiate our assessments and recommendations. All sources used in this particular Intelligence product were identified prior to 12:00 PM (EDT) on November 3, 2023; per cyber hygiene best practices, caution is advised when clicking on any third-party links.
Read the Brief
View the full report here.
Hackers Use Citrix Bleed Flaw in Attacks on Government Networks Worldwide
What happened: Security researchers have observed at least four ongoing campaigns exploiting “Citrix Bleed,” a critical severity flaw (CVE-2023-4966) affecting Citrix NetScaler ADC and NetScaler Gateway (which was disclosed on October 10, 2023). While these attacks have been significantly stealthy and left behind sparse forensic evidence, researchers have observed post-exploitation activity that indicates credential theft and lateral movement. Tens of thousands of exploited servers have been reportedly observed, with attacks originating from over a hundred individual IP addresses. Moreover, ongoing attacks would require a full incident response, as deploying the available patches will not secure already breached systems.
European Travel Sector Targeted by Iranian APT Group Watering Hole Attacks
What happened: An Iranian APT group targeted the European travel sector with a series of watering hole attacks. Beginning in 2022 and continuing through 2023, Tortoiseshell deployed a malware termed IMAPLoader to conduct credential harvesting and follow-on attacks against European targets. Tortoiseshell, an Iranian Islamic Republican Guard Corps (IRGC)-aligned APT group, has a history of targeting logistics and transportation-related entities in Israel and elsewhere.
Atlassian Warns of New Critical Confluence Vulnerability Threatening Data Loss
What happened: Atlassian has warned users of a critical security flaw (CVE-2023-22518; CVSS score of 9.1) in Confluence Data Center and Server that could lead to significant data loss in the event of a successful attack. Atlassian stated that the “improper authorization vulnerability” would not affect confidentiality as an attacker cannot exfiltrate any instance data.
Tags: global, tlp:green