zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - October 3, 2023

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - October 3, 2023

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • "Phantom Hacker" Scams Target Senior Citizens and Result in Victims Losing their Life Savings
  • CloudFlare Firewall and DDoS Prevention Vulnerable to Bypass
  • New Critical Security Flaws Expose Exim Mail Servers to Remote Attacks
  • Data broker / initial-access broker / hacktivist group: Anonymous Sudan and BreachForums user N1k7
  • Vulnerabilities: CVE-2023-43669 and CVE-2023-5217
  • Exploits: CVE-2021-42013 and CVE-2021-36260
  • Breaches: Brokers Alliance and Combolist: '204k_Spotify_targeted.txt'

"Phantom Hacker" Scams Target Senior Citizens and Result in Victims Losing their Life Savings

The FBI has seen a surge in "Phantom Hacker" scams targeting people over 60, with nearly 20 thousand complaints from January to June this year. The scam unfolds in three phases, involving impersonations of tech support, financial institutions, and the government to deceive victims into handing over their assets. The FBI has advised avoiding unsolicited links, downloads, and remote access requests while reiterating that the government never asks for money via wire transfer, cryptocurrency, or gift cards. Report any suspicious activity to your local FBI office or at the website www.ic3.gov.

CloudFlare Firewall and DDoS Prevention Vulnerable to Bypass

A new exploit allows attackers to bypass Cloudflare's Firewall and DDoS prevention through flaws in cross-tenant security controls. The attack requires only a free Cloudflare account and the target web server's IP address. The issue stems from Cloudflare's shared infrastructure accepting connections from all tenants and two vulnerabilities in Cloudflare's "Authenticated Origin Pulls" and "Allowlist Cloudflare IP Addresses" features. To mitigate this weakness, use custom certificates and consider Cloudflare Aegis if available.

Security bug in Mali GPU Driver Vulnerabilities

Chip manufacturer Arm has released security patches to address an actively exploited security bug in the Mali GPU Kernel Driver. The bug (CVE-2023-4211), which Arm says “may be under limited, targeted exploitation,” has been fixed in Bifrost, Valhall, and Arm 5th Gen GPU Architecture Kernel Driver r43p0. The advisory stated that the bug could allow a local non-privileged user to make improper GPU memory processing operations to gain access to already freed memory. While affected users are advised to apply the patches, the availability depends on when specific vendors integrate the patch in official updates.

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

VULNERABILITIES

  • CVE-2023-43669: The Tungstenite crate before 0.20.1 for Rust allows remote attackers to cause a denial of service via an excessive length of an HTTP header in a client handshake.
  • CVE-2023-5345: A use-after-free vulnerability in the Linux kernel's fs/smb/client component can be exploited to achieve local privilege escalation.

EXPLOITS

BREACHES

Tags: DIB, tlp:green