ZeroFox Cyber Intelligence Daily Brief - December 8, 2023
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - December 8, 2023
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- ZeroFox Intelligence Brief: New Underground Market Comes Online Just in Time for the Holidays
- Russian Intelligence Held Accountable for Unsuccessful Cyber Interference in U.K. Political and Democratic Processes
- "Sierra:21" Vulnerabilities Impact Critical Infrastructure Routers
ZeroFox Intelligence Brief: New Underground Market Comes Online Just in Time for the Holidays
In this Intelligence Brief, ZeroFox researchers report a new underground market known as OLVX Marketplace that is gaining notoriety just in time for the holidays. It came online with legitimate and well-respected threat actors advertising various tools in July, 2023. OLVX has implemented numerous tactics to ensure customer service is a priority while serving its illicit customers. OLVX is currently utilizing Cloudflare to masquerade its actual hosting location and Simple Carrier LLC (known to host questionable content) to advertise its distributed denial of service (DDoS) protection services.
Russian Intelligence Held Accountable for Unsuccessful Cyber Interference in U.K. Political and Democratic Processes
Russian Intelligence Services has unsuccessfully targeted U.K. government entities, including politicians, civil servants, journalists, NGOs, and other civil society organizations, in a series of cyberattacks. The U.K. Foreign, Commonwealth, and Development Office has summoned the Russian Ambassador and sanctioned individuals associated with the Federal Security Service (FSB), successor to the KGB and the agency responsible for these sustained attacks. Although the attacks have not impacted overall government processes, certain documents have been reportedly leaked.
"Sierra:21" Vulnerabilities Impact Critical Infrastructure Routers
Twenty-one vulnerabilities have been discovered in Sierra Wireless routers that threaten essential infrastructure. Over 86,000 AirLink routers used in critical organizations engaged in power distribution, vehicle tracking, waste management, and national health services are “exposed online.” The vulnerabilities present in Sierra’s systems affect Sierra Wireless AirLink cellular routers and open-source components like TinyXML and OpenNDS (open Network Demarcation Service), where critical and high severity vulnerabilities including CVE-2023-41101 and CVE-2023-38316 can lead to remote code execution, unauthorized access, cross-site scripting, and denial of service attacks.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- BreachForums user BreachForums: Actor Claims to Leak Data from Vascular Wellness
VULNERABILITIES
- CVE-2023-46575: IA SQL injection vulnerability exists in Meshery prior to version v0.6.179, enabling a remote attacker to retrieve sensitive information and execute arbitrary code through the “order” parameter.
- CVE-2023-26158: All versions of the package mockjs are vulnerable to Prototype Pollution via the Util.extend function due to missing check if the attribute resolves to the object prototype.
EXPLOITS
- CVE-2023-26469: In Jorani 1.0.0, an attacker could leverage path traversal to access files and execute code on the server.
- CVE-2023-36846: A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity.
BREACHES
- Combolist: 'Disney Plus Combolist.txt' (95,207 Records): Email Address, Password
- Combolist: '85k HQ Combolist Email-Pass (Netflix-Steam-Disney)3FwskYVhJc4zDA7(1).txt' (119,882 Records): Email Address, Password
Tags: DIB, tlp:green