ZeroFox Cyber Intelligence Daily Brief - January 5, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - January 5, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- RIPE Account Hacking Leads to Major Internet Outage at Orange Spain
- Ivanti Has Patched a Critical Vulnerability That Gives Hackers Aunauthorised Control
- Security Breach Drains Over USD 80 Million From Orbit Chain
RIPE Account Hacking Leads to Major Internet Outage at Orange Spain
A cyberattattack leaves Orange Spain without internet access as its account with RIPE (European IP Networks) Network Coordination Center (NCC) was taken control of by a hacker, reportedly going by the handle Snow. The attacker targeted Orange's RIPE account, making unauthorized changes. This led to a disruption in the Border Gateway Protocol (BGP) routing, causing a loss in internet traffic for several hours. The hacker publicly claimed to have gained access to Orange's RIPE account and instructed the company to send a private message to obtain new credentials. Orange reportedly complied with this request and the affected services were subsequently restored. Orange confirmed that no customer data was compromised in the attack.
Ivanti Has Patched a Critical Vulnerability That Gives Hackers Aunauthorised Control
Ivanti has released a patch for a critical flaw (CVE-2023-39366) found in its Endpoint Management software (EPM) that can let hackers take unauthorized control of enrolled devices or the core server. Users can deploy the patch by upgrading their Ivanti EPM systems to version 2022 Service Update 5. Besides, Ivanti has also blocked access to an advisory detailing the bug’s features to prevent hackers from accessing the information and to allow users more time to install the patch. At the time of reporting, Ivanti has yet to find any evidence of impact on its customers caused by the exploit of CVE-2023-39366.
Security Breach Drains Over USD 80 Million From Orbit Chain
Orbit Chain has lost more than USD 80 million in cryptocurrency, particularly Ether and DAI, due to a series of drain attacks targeting Orbit Bridge. Orbit Chain notified its customer via an X post that unauthorized access to Orbit Bridge, “a decentralized Cross-chain protocol,” was detected on December 31. The company has since employed the assistance of the Korean National Police Agency and the Korean Internet and Security Agency (KISA) to investigate the incident.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- Telegram user Anonymous Collective: Actor Claims Attack Against Queen Alia International Airport
- BreachForums user g0d: Actor Claims to Leak Data From Department of Social Development - South Africa
VULNERABILITIES
- CVE-2023-7113: Mattermost version 8.1.6 and earlier fails to sanitize channel mention data in posts, which allows an attacker to inject markup in the web client.
- CVE-2023-7114: Mattermost version 2.10.0 and earlier fails to sanitize deeplink paths, which allows an attacker to perform CSRF attacks against the server.
EXPLOITS
- CVE-2022-31814: pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metacharacters in the HTTP Host header. NOTE: 3.x is unaffected.
- CVE-2023-26609: ABUS TVIP 20000-21150 devices allows remote attackers to execute arbitrary code via shell metacharacters in the /cgi-bin/mft/wireless_mft ap field.
BREACHES
- Combolist: 'totaljerkface-08-17-2010-users.txt' (186,442 Records): Username, Password
- Combolist: 'Daily 50k Combos - @agressordb_free.txt' (50,028 Records): Email Address, Password
Tags: DIB, tlp:green