zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - October 17, 2023

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - October 17, 2023

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Israel Cyber Agency Warn Home-Camera Owners Against Potential Hacking
  • Unpatched Cisco Zero-Day Vulnerability Actively Targeted in the Wild
  • EPA Withdraws Cyber Audit Requirement for Water Systems
  • Data broker / initial-access broker / hacktivist group: Exploit user sandocan and RAMP user Krendel
  • Vulnerabilities: CVE-2023-5556 and CVE-2023-4750
  • Exploits: CVE-2023-27163 and CVE-2023-1671
  • Data Breach: Combolist: 'Epic Games Store -HACKER PHONE-.txt' and '184K @Gmail.com Country GOOD FOR EVERY SITE.txt'

Israel Cyber Agency Warn Home-Camera Owners Against Potential Hacking

The Israeli Cyber Directorate has issued advice for private homes to secure security cameras, anticipating that attackers could use these devices for espionage purposes. The guidance includes steps such as changing the camera's admin password, enabling two-step verification, configuring automatic updates, disconnecting cameras, or even covering them. The guidance comes amidst rising cybersecurity incidents relating to the war, with recent observations including the breach of several Palestinian government agencies and of the UN Mission in Palestine which reportedly included access to monitoring of missions, meetings, contacts, and agreements in Gaza. Killnet made ambiguous claims over the testing of a new attack that could potentially deactivate Israel’s nuclear arsenal.

Unpatched Cisco Zero-Day Vulnerability Actively Targeted in the Wild

Cisco has detected an active exploitation of an undisclosed zero-day vulnerability (CVE-2023-20198) in the web UI feature of Cisco IOS XE Software when exposed to the internet or untrusted networks. The flaw could allow a remote, unauthenticated attacker to create an account with privilege level 15 access, potentially gaining control over the entire system. To address this, customers are strongly advised to disable the HTTP Server feature on internet-facing systems using the "no ip http server" or "no ip http secure-server" commands. Additional workarounds were provided based on the system's configuration, along with indicators of compromise.

EPA Withdraws Cyber Audit Requirement for Water Systems

The U.S. Environmental Protection Agency (EPA) has withdrawn its auditory requirements to strengthen cybersecurity in the water system infrastructure. The move comes after litigation between Missouri, Arkansas, Iowa, and the EPA, which halted the guidance's enforcement. The states cited lack of resources, expertise and funding to evaluate and address cybersecurity issues. Further, the states cited that existing laws do not protect sensitive information collected through sanitary surveys, and if publicly shared, it could expose water system vulnerabilities. Despite this change, the EPA emphasized regulations as a top priority due to persistent threats to water system operations and aims to assist regions in adopting best practices, aligning with the Biden administration's focus on securing infrastructure.

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

VULNERABILITIES

  • CVE-2023-5556:: Lack of TLS certificate verification in log transmission within LINE Client for iOS prior to 13.16.0.
  • CVE-2023-4750:: Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1969.

EXPLOITS

  • CVE-2023-27163: Maltrail v0.53 - Unauthenticated Remote Code Execution (RCE)
  • CVE-2023-1671: Sophos Web Appliance 4.3.10.4 - Pre-auth command injection

BREACHES

Tags: DIB, tlp:green