zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - August 16, 2023

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - August 16, 2023

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • XML-Injection Flaw Present in Widely Used Network-Monitoring Tool
  • Ivanti Avalanche Impacted By Stack Buffer Overflows Bugs
  • Cybercriminals Exploit Cloudflare R2 to Hosting Phishing Pages
  • Data broker / initial-access broker / hacktivist group: Türk Hack Team and ACEH ABOUT HACKED WORLD
  • Vulnerabilities: CVE-2019-19921 and CVE-2023-32004
  • Telegram: 'logi5.rar' Botnet Breach and XSS/Leakbase: FPuiki dovana Data Breach

XML-Injection Flaw Present in Widely Used Network-Monitoring Tool

OpenNMS maintainers have patched a critical vulnerability (CVE-2023-0871) in the community-supported and subscription-based versions of the widely-used open source network-monitoring software. The XML-based external entity (XXE) injection flaw allows attackers to interfere with XML data processing, which enables them to exfiltrate data, trigger denial-of-service conditions, and send arbitrary HTTP requests. Affected users are advised to update to secure versions (Meridian 2023.1.6, 2022.1.19, 2021.1.30, 2020.1.38, or Horizon 32.0.2 or newer) immediately.

Ivanti Avalanche Impacted By Stack Buffer Overflows Bugs

Two critical stack-overflow bugs (collectively tracked as CVE-2023-32560; CVSS v3: 9.8) affect Ivanti Avalanche, an enterprise mobility management solution for mobile devices. These flaws allow remote code execution without user authentication. The vulnerability exists in WLAvalancheService.exe v6.4.0.0 and older, which receive TCP communications via port 1777. By sending crafted hex or decimal data packets, attackers can trigger overflows, leading to arbitrary code execution. Ivanti released patches for the issues on August 3, 2023, in Avalanche v6.4.1.

Cybercriminals Exploit Cloudflare R2 to Hosting Phishing Pages

Threat actors are increasingly using Cloudflare R2 to host phishing pages—with security researchers observing a 61-fold spike over the past six months. Microsoft login credentials remain the primary target, though some pages aim at Adobe, Dropbox, and other cloud apps. Malware downloads from 167 cloud apps have risen, with OneDrive, Squarespace, GitHub, SharePoint, and Weebly being prominent. Phishing campaigns use Cloudflare R2 to generate static phishing pages and implement other anti-detection measures to evade security services like URLScan.io.

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

  • Türk Hack Team:: Allegedly defaced websites of Hawaiian Airlines and various educational orgs across the world.
  • ACEH ABOUT HACKED WORLD:: With its allies, continues to target Indian websites for allegedly disgracing Islamic beliefs

VULNERABILITIES

  • CVE-2019-19921 - runc through 1.0.0-rc9 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go.
  • CVE-2023-32004 -A vulnerability has been discovered in Node.js version 20, specifically within the experimental permission model.

BREACHES

  • Telegram:: 'logi5.rar' Botnet Breach (40,585 Records)
  • XSS/Leakbase:: FPuiki dovana Data Breach (5,860 Records)

Tags: DIB, tlp:green