zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - January 5, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - January 5, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • RIPE Account Hacking Leads to Major Internet Outage at Orange Spain
  • Ivanti Has Patched a Critical Vulnerability That Gives Hackers Aunauthorised Control
  • Security Breach Drains Over USD 80 Million From Orbit Chain

RIPE Account Hacking Leads to Major Internet Outage at Orange Spain

A cyberattattack leaves Orange Spain without internet access as its account with RIPE (European IP Networks) Network Coordination Center (NCC) was taken control of by a hacker, reportedly going by the handle Snow. The attacker targeted Orange's RIPE account, making unauthorized changes. This led to a disruption in the Border Gateway Protocol (BGP) routing, causing a loss in internet traffic for several hours. The hacker publicly claimed to have gained access to Orange's RIPE account and instructed the company to send a private message to obtain new credentials. Orange reportedly complied with this request and the affected services were subsequently restored. Orange confirmed that no customer data was compromised in the attack.

Ivanti Has Patched a Critical Vulnerability That Gives Hackers Aunauthorised Control

Ivanti has released a patch for a critical flaw (CVE-2023-39366) found in its Endpoint Management software (EPM) that can let hackers take unauthorized control of enrolled devices or the core server. Users can deploy the patch by upgrading their Ivanti EPM systems to version 2022 Service Update 5. Besides, Ivanti has also blocked access to an advisory detailing the bug’s features to prevent hackers from accessing the information and to allow users more time to install the patch. At the time of reporting, Ivanti has yet to find any evidence of impact on its customers caused by the exploit of CVE-2023-39366.

Security Breach Drains Over USD 80 Million From Orbit Chain

Orbit Chain has lost more than USD 80 million in cryptocurrency, particularly Ether and DAI, due to a series of drain attacks targeting Orbit Bridge. Orbit Chain notified its customer via an X post that unauthorized access to Orbit Bridge, “a decentralized Cross-chain protocol,” was detected on December 31. The company has since employed the assistance of the Korean National Police Agency and the Korean Internet and Security Agency (KISA) to investigate the incident.

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

VULNERABILITIES

  • CVE-2023-7113: Mattermost version 8.1.6 and earlier fails to sanitize channel mention data in posts, which allows an attacker to inject markup in the web client.
  • CVE-2023-7114: Mattermost version 2.10.0 and earlier fails to sanitize deeplink paths, which allows an attacker to perform CSRF attacks against the server.

EXPLOITS

  • CVE-2022-31814: pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metacharacters in the HTTP Host header. NOTE: 3.x is unaffected.
  • CVE-2023-26609: ABUS TVIP 20000-21150 devices allows remote attackers to execute arbitrary code via shell metacharacters in the /cgi-bin/mft/wireless_mft ap field.

BREACHES

Tags: DIB, tlp:green