# Weekly Community Review - November 9, 2023

**URL:** <https://community.emergingthreats.net/t/weekly-community-review-november-9-2023/1259>\
**Category:** Announcements\
**Created:** [November 9, 2023, 6:00am UTC](https://community.emergingthreats.net/t/weekly-community-review-november-9-2023/1259 "2023-11-09T06:00:00Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![rgonzalez](https://avatars.discourse-cdn.com/v4/letter/r/bc79bd/32.png) [@rgonzalez](https://community.emergingthreats.net/u/rgonzalez)\
**Post date:** [November 9, 2023, 6:00am UTC](https://community.emergingthreats.net/t/weekly-community-review-november-9-2023/1259/1 "2023-11-09T06:00:00Z")

</div>

Greetings all! It’s Suricon week - where members of the Suricata IDS community get together to discuss and collaborate! In that spirit, we had 148 rule submissions to ET Open last week, and we’d like to discuss a few!

Lots of CVE coverage in there - it seems a new vulnerable target and exploit in the wild every day! As we said last week just a ton of intel and protections contributed by the community spraying to all fields. For Apache ActiveMQ CVE-2023-46604, SIDs 2049045 (RCE attempt alert) and 2049046 (XML Configuration downloaded - possible RCE) from the great shared work of @[X1r0z](https://twitter.com/X1r0z)!

> **[GitHub - X1r0z/ActiveMQ-RCE: ActiveMQ RCE (CVE-2023-46604) 漏洞利用工具](https://github.com/X1r0z/ActiveMQ-RCE)**
>
> ActiveMQ RCE (CVE-2023-46604) 漏洞利用工具

From F5 CVE-2023-46747 SIDs 2048925 (AJP request smuggling attempt), 2049057 (AJP smuggling request - sets flowbit), 2049058 (unauthenticated RCE for user creation) and 2049059 (unauthenticated RCE for user deletion) from this @[praetorian](https://twitter.com/praetorian) share…

> **[Refresh: Compromising F5 BIG-IP With Request Smuggling | CVE-2023-46747](https://www.praetorian.com/blog/refresh-compromising-f5-big-ip-with-request-smuggling-cve-2023-46747/)**
>
> Overview In an effort to safeguard our customers, we perform proactive vulnerability research with the goal of identifying zero-day vulnerabilities that are likely to impact the security of leading organizations.  We decided to focus on the F5...

And Atlassian Confluence #CVE-2023-22518 (auth bypass with ability of potential data destruction) - we’ve got coverage on possible (2049096) and successful (2049097) inbound exploit attempts as well as multiple SIDs (2049080-2049085) to detect presence of vulnerable versions of Confluence within your monitored networks!

> **[CVE-2023-22518 - Improper Authorization Vulnerability In Confluence Data...](https://confluence.atlassian.com/security/cve-2023-22518-improper-authorization-vulnerability-in-confluence-data-center-and-server-1311473907.html)**

Also continued help from so many great researchers on Cisco CVEs. Now CVE-2023-20273 - (separate from 20198) has ET coverage in SID 2049007 (inbound exploit attempt against the vulnerable webUI endpoint) thanks to so many intel sharing researchers! @[leak\_ix](https://twitter.com/leak_ix) @[joel\_land](https://twitter.com/joel_land)

> <https://x.com/leak_ix/status/1719500320940961814?s=20>

I mentioned suricon - big thanks to @[OISFoundation](https://twitter.com/OISFoundation) for their efforts putting on virtual Suricon this year!

> <https://x.com/OISFoundation/status/1722720767224295821?s=20>

Speaking of Suricata, we’re working hard to prepare our rule fork to fully support a new ruleset for Suricata 7. Come along on that journey with us as we investigate the changes that need to be made to current rules and talk about some of the challenges we have - like dichotomy of http/2 support between versions:

> [@Addressing HTTP/2 in Suri7](https://community.emergingthreats.net/t/addressing-http-2-in-suri7/1104):
>
> Updated 2024-02-21 There has been significant progress within Suricata 7.0 to allow a single rule to support both HTTP/1 and HTTP/2. However, there are many changes that must be made to rules in order to allow this behavior to occur. The below has been updated to reflect the state of Suricata 7.0 as of the 7.0.3 release. Within the Suricata 7.0 Emerging Threats ruleset, there will be many changes to support allowing the ruleset to function with both HTTP/1 and HTTP/2 traffic. These changes w…

Many new DNS and TLS SNI signatures last week thanks to work from our friends @[elasticseclabs](https://twitter.com/elasticseclabs) (h/t @[greglesnewich](https://twitter.com/greglesnewich)) - SIDs 2049013-2049037 cover SockRacket KANDYKORN domains found through their great work.

> **[Elastic catches DPRK passing out KANDYKORN — Elastic Security Labs](https://www.elastic.co/security-labs/elastic-catches-dprk-passing-out-kandykorn)**
>
> Elastic Security Labs exposes an attempt by the DPRK to infect blockchain engineers with novel macOS malware.

Thanks to @[_cpresearch_](https://twitter.com/_cpresearch_) (h/t @[adorais](https://twitter.com/adorais)) for the guidance for SIDs 2049010 Tunna webshell activity outbound) and FOXSHELL webshell activity (2049011-2049012) as well as APT34 Related SSD Backdoor alerts (2049047-2049048) all from their #ScarredManticore writeup!

> **[From Albania to the Middle East: The Scarred Manticore is Listening - Check...](https://research.checkpoint.com/2023/from-albania-to-the-middle-east-the-scarred-manticore-is-listening/)**
>
> Key Findings Introduction Check Point Research, in collaboration with Sygnia’s Incident Response Team, has been tracking and responding to the activities of Scarred Manticore, an Iranian nation-state threat actor that primarily targets...

That’s it for us - thanks all, be well!
