ZeroFox Daily Intelligence Brief - September 30, 2023
|by Alpha Team

ZeroFox Daily Intelligence Brief - September 30, 2023
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- U.S. Official Highlights Cybersecurity Risks of Low-Cost Chinese Hardware
- Cisco Catalyst SD-WAN Manager flaw allows remote server access
- CISA Adds Red HAT JBoss Flaw to Known Vulnerabilities Catalog
- Data broker / initial-access broker / hacktivist group: Exploit user Azterion & Exploit user kamzzzzz
- Vulnerabilities: CVE-2023-43014 and CVE-2023-41235
- Breaches: Combolist: 'faucetcrypto.com.txt' and Combolist: 'getpocket.com.txt'
U.S. Official Highlights Cybersecurity Risks of Low-Cost Chinese Hardware
The U.S. Homeland Security Secretary cautioned attendees of the recent Western Hemisphere Cyber Conference about the risks of China's infrastructure and technology investments. The secretary warned that while China's offers may seem attractive, they come with long-term cybersecurity risks that could potentially enable cyberattacks; he also emphasized the choice between speed/sovereignty, affordability and security. The conference highlighted growing concerns about China's influence in South and Central America and its potential use of low-cost hardware for cyberattacks.
Cisco Catalyst SD-WAN Manager flaw allows remote server access
Cisco has issued warnings regarding five new vulnerabilities in its Catalyst SD-WAN Manager products, with the most severe flaw enabling unauthenticated remote server access. The critical vulnerability CVE-2023-20252 (CVSS v3.1: 9.8) is linked to Security Assertion Markup Language (SAML) APIs and allows unauthorized access. While no active exploitation is reported, Cisco advises upgrading to patched releases to mitigate these issues.
CISA Adds Red HAT JBoss Flaw to Known Vulnerabilities Catalog
CISA has included the critical CVE-2018-14667 flaw in Red Hat JBoss RichFaces Framework in its Known Exploited Vulnerabilities Catalog. The issue involves an Expression Language (EL) injection via the UserResource resource and impacts RichFaces Framework versions 3.X through 3.3.4. An unauthenticated attacker could use this vulnerability to execute arbitrary remote code through a chain of Java serialized objects using org.ajax4jsf[.]resource[.]UserResource$UriData. CISA mandates that federal agencies address this flaw by October 19, 2023, while private organizations are also advised to review and address vulnerabilities in their infrastructure.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- Exploit user Hexlite: Advertising multifunctional malware with RAT and stealer capabilities.
- Exploit user kamzzzzz Selling alleged VPN access to a Brazilian telecommunications company.
VULNERABILITIES
- CVE-2023-43014: Asset Management System v1.0 is vulnerable to an Authenticated SQL Injection vulnerability.
- CVE-2023-41235: Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Everest Themes Everest News Pro theme <= 1.1.7 versions.
BREACHES
- Combolist: 'faucetcrypto.com.txt': (16,116 Records)
- Combolist: 'getpocket.com.txt': (18,472 Records)
Tags: DIB, tlp:green