zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - October 18, 2023

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - October 18, 2023

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Israeli Cyber Experts Start “War Room” to Track Missing Persons
  • Widespread Kwik Trip Disruption Attributed to “Network Incident”
  • Critical Vulnerabilities Uncovered in Open Source CasaOS Cloud Software
  • Data broker / initial-access broker / hacktivist group: Ransomed
  • Vulnerabilities: CVE-2023-22032 and CVE-2023-5450
  • Exploits: CVE-2023-1454 and CVE-2023-33246
  • Data Breach: Combolist: '100k_Hotmail.txt' and Combolist: 'CRUNCHYROLL X 11000.txt'

Israeli Cyber Experts Start “War Room” to Track Missing Persons

Hundreds of Israeli high-tech experts have temporarily left their private sector jobs to help locate missing persons after the recent Hamas attack. The volunteers, operating from Tel Aviv, are analyzing various footage sources to identify more than 1,000 people through clothing and recognizable features, while also employing artificial intelligence, facial recognition, and voice recognition in their efforts. Pictures of the missing Israelis line the walls, reminding the volunteers of their mission. Their work is crucial in locating hostages, while Hamas seeks to exchange captured Israelis for Palestinian prisoners. Hamas has reportedly begun removing footage of the attacks, suggesting that the group is aware that it is being analyzed for clues.

Widespread Kwik Trip Disruption Attributed to “Network Incident”

A "network incident" disrupted services at over 800 U.S. convenience stores of Kwik Trip in the past week. The outages affected Kwik Trip's phone service, rewards system, and mobile app. The company has not confirmed whether this was due to a ransomware attack but is actively working on restoring its Reward Program, addressing customer concerns. Employees have reported widespread issues, including impacts on payroll systems, printers, and inventory counts.

Critical Vulnerabilities Uncovered in Open Source CasaOS Cloud Software

Two critical security vulnerabilities, CVE-2023-37265 and CVE-2023-37266, have been discovered in the open-source CasaOS personal cloud software. The flaws, both rated 9.8 out of 10 on the CVSS scale, allow attackers to bypass authentication requirements and gain full access to the CasaOS dashboard. Further, CasaOS's support for third-party applications can be exploited to execute arbitrary commands, potentially leading to persistent access and internal network compromise. Responsible disclosure led to the flaws being addressed in version 0.4.4 released on July 14, 2023.

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

  • Ransomed:: Offered Pentesting Services on any target website

VULNERABILITIES

  • CVE-2023-22032:: Lack of TLS certificate verification in log transmission within LINE Client for iOS prior to 13.16.0.
  • CVE-2023-5450:: Insufficient verification of data in BIG-IP Edge Client Installer on macOS

EXPLOITS

BREACHES

Tags: DIB, tlp:green