ÃϼÓÀ­¹úijµ±¾ÖÍøÕ¾ÅäÖÃÃýÎóй¶Êý°ÙÍò¹«ÃñµÄÐÅÏ¢

°ä²¼¹¦·ò 2023-07-10

1¡¢ÃϼÓÀ­¹úijµ±¾ÖÍøÕ¾ÅäÖÃÃýÎóй¶Êý°ÙÍò¹«ÃñµÄÐÅÏ¢


¾ÝýÌå7ÔÂ7ÈÕ±¨Â· £¬ÃϼÓÀ­¹úijµ±¾ÖÍøÕ¾Ð¹Â¶ÁËÊý°ÙÍò¹«ÃñµÄÓ×ÎÒÐÅÏ¢ £¬Éæ¼°ÐÕÃû¡¢µç»°ºÅÂë¡¢µç×ÓÓʼþµØÖ·ºÍÉí·ÝÖ¤ºÅÂëµÈ ¡£×êÑÐÈËÔ±ÓÚ6ÔÂ27ÈÕ³õ´Î·¢ÏÖÁ˸ÃÎÊÌâ £¬²¢ÁªÏµÁËÃϼÓÀ­¹úµç×ÓÕþÎñÍÆËã»úÊÂÎñÏìÓ¦Ó××é(CERT) ¡£¾ÝϤ £¬Ð¹Â¶µÄÊý¾Ý³Ê´Ë¿ÌÓëSQLÃýÎóÓйصÄGoogle²éÎÊÁ˾ÖÖÐ ¡£×êÑÐÈËÔ±²¢Î´Ð¹Â©Ó¦¸Ã¾ÖÍøÕ¾µÄ¾ßÌåÃû³Æ £¬ÓÉÓÚÕâЩÊý¾ÝÈÔ¿ÉÔÚÏß»ñÈ¡ ¡£Ä¿Ç° £¬Ã»ÓÐÈκÎÃϼÓÀ­¹úµ±¾Ö×éÖ¯¶Ô´ËÊÂ×ö³ö»ØÓ¦ ¡£


https://techcrunch.com/2023/07/07/bangladesh-government-website-leaks-citizens-personal-data/


2¡¢TA453ͨ¹ýÐÂϰȾÁ´×°ÖÃPowerShellºóÃÅGorjolEcho 


ProofpointÓÚ7ÔÂ6ÈÕÅû¶ÁËÒÁÀʺڿÍÍÅ»ïTA453Õë¶ÔWindowsºÍmacOSµÄ¶ñÒâÈí¼þ»î¶¯ ¡£TA453ÓÚ5ÔÂ·ÝÆðͷʹÓÃLNKϰȾÁ´ £¬¶ø²»ÊÇ´øÓкêµÄMicrosoft WordÎĵµ ¡£Õâ´Î»î¶¯ÖÐ £¬¹¥»÷Õß¼Ù×°³É»Ê¼Ò½áºÏ±øÖÖ×êÑÐËù(RUSI)µÄ¸ß¼¶×êÑÐÔ± £¬Õë¶ÔÒ»¼ÒרһÓÚ±í½»ÊÂÎñµÄÃÀ¹úÖÇ¿âµÄºË°²È«×¨¼Ò ¡£¹¥»÷ÕßʹÓø÷ÀàÔÆÍйÜÌṩÉÌÀ´ÌṩеÄϰȾÁ´ £¬Ö¼ÔÚ×°ÖÃÐÂÐÍPowerShellºóÃÅGorjolEcho ¡£´Ë±í £¬TA453»¹ÒÆÖ²ÁËÆä¶ñÒâÈí¼þ £¬²¢ÊÔͼÆô¶¯Ò»¸öÃûΪNokNokµÄÕë¶ÔmacOSµÄϰȾÁ´ ¡£


https://www.proofpoint.com/us/blog/threat-insight/welcome-new-york-exploring-ta453s-foray-lnks-and-mac-malware


3¡¢Mastodon½¨¸´¿Éµ¼Ö·þÎñÆ÷½Ù³ÖµÄ·ì϶TootRoot


¾Ý7ÔÂ7ÈÕ±¨Â· £¬¿ªÔ´µÄÈ¥ÖÐÐÄ»¯Éç½»ÍøÂçÆ½Ì¨Mastodon½¨¸´ÁË4¸ö°²È«·ì϶ ¡£ÆäÖÐ×îÑϳÁµÄÊÇMastodonýÌå´¦ÖôúÂëÖеķì϶TootRoot£¨CVE-2023-36460£© £¬¿Éµ¼ÖÂDoSºÍËÁÒâÔ¶³Ì´úÂëÖ´ÐеÈÎÊÌâ £¬¿ÉÓÃÓÚÔÚ·þÎñÆ÷ÖÐÖ²ÈëºóÃÅ ¡£¹¥»÷ÕßÀûÓø÷ì϶ £¬¿ÉÄÜÎÞÏ޶ȵؽÚÔì·þÎñÆ÷¼°ÆäÍйܺÍÖÎÀíµÄÊý¾Ý ¡£µÚ¶þ¸öÊÇXSS·ì϶£¨CVE-2023-36459£© £¬¿ÉÈÆ¹ýÖ¸±êä¯ÀÀÆ÷ÉϵÄHTMLËãÕÊ ¡£Áí±íÁ½¸ö·ì϶ÊÇCVE-2023-36461ºÍCVE-2023-36462 ¡£


https://www.bleepingcomputer.com/news/security/critical-tootroot-bug-lets-attackers-hijack-mastodon-servers/


4¡¢¼ÓÃÜÇ®±Òƽ̨MultichainÔâµ½¹¥»÷Ëðʧ³¬¹ý1.25ÒÚÃÀÔª


ýÌå7ÔÂ8ÈÕ±¨Â·³Æ £¬¼ÓÃÜÇ®±Òƽ̨MultichainÒÑÔÝÍ£Æä·þÎñ £¬ÓÉÓÚËüÔÚµ÷²éÉæ¼°³¬¹ý1.25ÒÚÃÀÔªµÄ¼ÓÃÜÇ®±Ò±»µÁÊÂÎñ ¡£ÉÏÖÜËÄÍí¼ä £¬¸Ã¹«Ë¾°µÊ¾ £¬Æ½Ì¨²¿ÃÅ×ʲú¡°ÒÑÒì³£×ªÒÆÖÁδ֪µØÖ·¡± £¬²¢ÔÚ¼¸Ó×ʱºóÔÝÍ£ÁËËùÓзþÎñÒÔ½øÐе÷²é ¡£ÖÜÎåÔçÉÏ £¬¸Ã¹«Ë¾°ä²¼ÉêÃ÷È·ÈÏËûÃÇÔâµ½Á˺ڿ͹¥»÷ £¬²¢°µÊ¾½«»áÍË¿î¸ø¸÷ÈË ¡£Óд«ÑÔ³ÆÕâ´Î¹¥»÷Êǰ×ñºÚ¿ÍËùΪ £¬µ«Éв»Ã÷ÏÔÕâЩ˵·¨ÊÇ·ñÕýÈ· ¡£


https://therecord.media/millions-stolen-from-multichain-crypto


5¡¢Google PlayÖеÄÁ½¿î¼äµýÈí¼þÇÔÈ¡150ÍòÓû§µÄÐÅÏ¢


7ÔÂ8ÈÕ±¨Â·³Æ £¬PradeoÔÚGoogle PlayÉ̵êÖз¢ÏÖÁËÁ½¿î¶ñÒâÀûÓà £¬°µ²Ø×żäµýÈí¼þ²¢¼à¶½¶à´ï150ÍòÓû§ ¡£ÕâÁ½¸öÀûÓ÷¨Ê½¶¼ÊÇÀ´×Ôͳһ¿ª·¢É̵ÄÎļþÖÎÀíµ±Óà £¬±ðÀëÊÇ×°ÖÃÁ¿³¬¹ý100ÍòµÄÎļþ¸´Ô­ºÍÊý¾Ý¸´Ô­ÀûÓúÍ×°ÖÃÁ¿³¬¹ý50ÍòµÄÎļþÖÎÀíÆ÷ ¡£Á½¿îÀûÓûáÇÔÈ¡ÁªÏµÈËÁÐ±í¡¢Ã½ÌåÎļþ¡¢ÊµÊ±µØÎ»ºÍÒÆ¶¯¹ú¶È´úÂëµÈÐÅÏ¢ ¡£×êÑÐÈËÔ±°ÑÎȵ½ £¬ÕâЩÀûÓöÔÍøÂçµ½µÄÊý¾ÝÖ´ÐÐÁËÒ»°ÙÂŴδ«Êä £¬Õâ¶ÔÓÚ¼äµýÈí¼þÀ´ËµÊDz»Ñ°³£µÄ ¡£


https://thehackernews.com/2023/07/two-spyware-apps-on-google-play-with-15.html


6¡¢Î¢Èí°ä²¼¹ØÓÚÀÕË÷Èí¼þBlackByteµÄ¹¥»÷Á´µÄµ÷²é»ã±¨


7ÔÂ6ÈÕ £¬Î¢Èí°ä²¼¹ØÓÚÀÕË÷Èí¼þBlackByteµÄ·ÖÎö»ã±¨ ¡£×êÑÐÈËÔ±×î½ü¶ÔÒ»´ÎÈëÇֵĵ÷²éÖÐ £¬·¢ÏÖ¹¥»÷ÕßÔÚ²»µ½ÎåÌìµÄ¹¦·òÀïʵÏÖÁË´Ó³õʼ½Ó¼ûµ½Ö´ÐÐÕû¸ö¹¥»÷Á´ ¡£ÔÚÕâÎåÌìÄÚ £¬¹¥»÷ÕßʹÓÃÁËһϵÁй¤¾ßºÍ¼¼Êõ £¬×îÖÕ×°ÖÃÁËBlackByte 2.0À´ÊµÏÔìäÖ¸±ê ¡£ÕâЩ¼¼ÊõÔ̺¬£ºÀûÓÃδ´ò²¹¶¡µÄExchange·þÎñÆ÷¡¢Ê¹ÓÃliving-off-the-land¹¤¾ß½øÐÐÓÆ¾ÃÐԺͿúËÅ¡¢²¿ÊðÓÃÓÚC2µÄCobalt StrikeÐűêÒÔ¼°²¿Êð¶¨ÔìµÄÊý¾ÝÍøÂçºÍÉøÈ빤¾ßµÈ ¡£


https://www.microsoft.com/en-us/security/blog/2023/07/06/the-five-day-job-a-blackbyte-ransomware-intrusion-case-study/