ZeroFox Daily Intelligence Brief - September 13, 2023
|by Alpha Team

ZeroFox Daily Intelligence Brief - September 13, 2023
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- NSA, U.S. Federal Agencies Advise on Deepfake Threats
- Adobe Issues Patches for Zero-Day in Acrobat and Reader
- Chrome, Firefox, and Mozilla Thunderbird Receive Fixes for Actively-Exploited WebP Vulnerability
- Data broker / initial-access broker / hacktivist group: Exploit user nopiro and SiegedSec
- Vulnerabilities: CVE-2023-2071 and CVE-2023-40834
- Exploits: CVE-2020-2883
- Breaches: Combolist: '300k paypal.txt' and Combolist: 'x100 Onlyfans Accounts.txt'
NSA, U.S. Federal Agencies Advise on Deepfake Threats
U.S. authorities have jointly published updated guidance on the synthetic media threat called “deepfakes.” The ease and scale with which cyber actors are using these techniques create new challenges to national security. Organizations need real-time verification capabilities, passive detection techniques, and protection of high-priority officers and their communications to guard against this threat. The guidance recommends ways to minimize the impact of deepfakes, including information sharing, planning and rehearsing responses to exploitation attempts, and personnel training.
Adobe Issues Patches for Zero-day in Acrobat and Reader
Adobe has issued patches for an actively-exploited zero-day vulnerability (CVE-2023-26369) in Acrobat and Reader products on both Windows and macOS systems. The flaw permits code execution via an out-of-bounds write exploit. The exploit is of low complexity and doesn't demand additional privileges; however, local access and user interaction are prerequisites. Adobe recommends installing updates within 72 hours. Additionally, Adobe has addressed security flaws in its Connect (CVE-2023-29305 and CVE-2023-29306) and Experience Manager (CVE-2023-38214 and CVE-2023-38215) products, thwarting cross-site scripting attacks that could access sensitive data.
Chrome, Firefox, and Mozilla Thunderbird Receive Fixes for Actively-Exploited WebP Vulnerability
Google and Mozilla released critical updates to address an actively-exploited zero-day vulnerability (CVE-2023-4863) affecting their products. The flaw, a heap buffer overflow in the WebP code library (libwebp), can result in crashes and arbitrary code execution. Users are strongly urged to update their Chrome, Firefox, and Thunderbird installations to the latest available versions. The vulnerability could potentially extend to any other software using the vulnerable WebP code library.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- Exploit user nopiro: Selling network access to two companies based in Italy and Mexico
- SiegedSec: Posted databases allegedly stolen from Ethereum Name Service and The Masonry Society
VULNERABILITIES
- CVE-2023-2071: Rockwell Automation FactoryTalk View Machine Edition on the PanelView Plus improperly verifies user’s input, which allows unauthenticated attacker to achieve remote code executed via crafted malicious packets.
- CVE-2023-40834: OpenCart v4.0.2.2 is vulnerable to brute force attack.
EXPLOIT
- CVE-2020-2883: WebLogic Server Deserialization Remote Code Execution
BREACHES
- Combolist: '300k paypal.txt': (299,974 Records) | Email address and password
- Combolist: 'x100 Onlyfans Accounts.txt' : (100 Records) | Email address and password
Tags: DIB, tlp:green