ZeroFox Daily Intelligence Brief - July 13, 2023
|by Alpha Team

ZeroFox Daily Intelligence Brief - July 13, 2023
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Event Assessment: 2023 FIFA Women's World Cup (Australia & New Zealand)
- Vulnerability Discovered in Ghostscript Library Poses Threat to Windows and Linux Systems
- New Malware “AVrecon” Targets Small and Home Office Routers
- Data broker / initial-access broker / hacktivist group: Telegram channel 0x_dump and vigilante group Ghostsec
- Vulnerabilities: CVE-2019-5997 and CVE-2023-3343
- Exploits: CVE-2016-6079 and CVE-2018-1160
- Breaches: Leakbase: Hodnik Data Breach and BreachForums/XXS: Coding-Talk Data Breach
Event Assessment: 2023 FIFA Women's World Cup (Australia & New Zealand)
ZeroFox Intelligence notes that while geopolitical tensions do exist (particularly between China and Australia), this World Cup is far less controversial than the 2022 Men’s World Cup. Fraudulent ticketing apps are a near certainty, and people should beware of scams targeting tourists. As for social-engineering attacks, a spike in tournament-related lures is expected, as threat actors will aim to capitalize on heightened global interest to harvest credentials, deploy follow-on payloads, and conduct financial fraud.
Vulnerability Discovered in Ghostscript Library Poses Threat to Windows and Linux Systems
Ghostscript, an open-source interpreter for the PostScript language and PDF files widely used in Linux, has a critical vulnerability (CVE-2023-3664) allowing remote code execution. As Ghostscript is default in many Linux distributions and used by various software including Windows apps using a Ghostscript port, the risk is significant. The vulnerability arises from a function that mishandles paths, enabling attackers to bypass validation mechanisms. Linux users should update to version 10.01.2, while caution is advised for Windows users.
New Malware “AVrecon” Targets Small and Home Office Routers
Researchers have discovered a new malware strain called "AVrecon" that specifically targets small and home office (SOHO) routers, with over 70,000 machines infected worldwide. SOHO routers are particularly vulnerable due to infrequent patching, lack of monitoring, and remote workers. Users should regularly reboot and update their routers to stay protected.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
Telegram channel 0x_dump: U.S. citizen database (250 million records; over 200 fields including name, address, phone number, income, no. of pets) Vigilante group Ghostsec: Announces alliance with Stormous, partnership in “Operation Cuba”
VULNERABILITIES
- CVE-2019-5997 - Video Insight VMS versions prior to 7.6.1 allow remote attackers to conduct code injection attacks via unspecified vectors.
- CVE-2023-3343 - The User Registration plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.0.1 via deserialization of untrusted input from the “profile-pic-url” parameter.
EXPLOITS
- CVE-2016-6079 - IBM AIX 5.3/6.1/7.1/7.2 - “lquerylv” Local Privilege Escalation
- CVE-2018-1160 - QNAP Netatalk Authentication Bypass
BREACHES
- Leakbase: Hodnik Data Breach - (16,815 Records) | Company name, email address, gender, name, and user activity
- BreachForums/XXS: Coding-Talk Data Breach - (80,371 Records) | Email address, IP address, password, and username
Tags: DIB, tlp:green