Ó¢¹úµ±¾Ö³Ð°üÉÌMPD FMÊý¾Ý¿âÅäÖÃÃýÎóй¶Ա¹¤ÐÅÏ¢

°ä²¼¹¦·ò 2023-08-14

1¡¢Ó¢¹úµ±¾Ö³Ð°üÉÌMPD FMÊý¾Ý¿âÅäÖÃÃýÎóй¶Ա¹¤ÐÅÏ¢


¾ÝýÌå8ÔÂ12ÈÕ±¨Â· £¬×êÑÐÈËÔ±·¢ÏÖÁËÒ»¸ö¹«¿ªµÄAmazon S3´æ´¢¿â £¬Â¶³öÁË16000¶à¸öÃô¸ÐµÄÎĵµ¡£¾Ý´§¶È £¬ÕâЩÐÅÏ¢ÊôÓÚMDP FM £¬ËüÊÇÒ»¼ÒΪӢ¹úNHSºÍ˰Îñº£¹Ø×ÜÊðµÈ¶à¸öµ±¾Ö»ú¹¹Ìṩ·þÎñµÄÉèÊ©ÖÎÀíºÍ°²È«¹«Ë¾¡£Ð¹Â¶µÄÎļþÉæ¼°´óÁ¿Ô±¹¤ÐÅÏ¢ £¬Ô̺¬»¤ÕÕ¡¢Ç©Ö¤¡¢Éí·ÝÖ¤¡¢¼ÝÊ»ÅÆÕÕ¡¢¹¤×÷ºÏͬ¡¢µØÖ·Ö¤Ã÷ºÍÒøÐжÔÕ˵¥µÈ¡£Ä¿Ç° £¬ÕâЩÊý¾ÝÒѱ»±£»¤ÆðÀ´ £¬µ«ÊÇMPD FMÉÐδ¶Ô´ËÊÂÎñ×ö³ö»Ø¸´¡£


https://securityaffairs.com/149440/security/mpd-fm-data-leak.html


2¡¢¸£ÌغÍÁÖ¿ÏÆû³µÊ¹ÓõÄSYNC3ϵͳ´æÔÚ»º³åÇøÒç¶Âí½Å


¾Ý8ÔÂ12ÈÕ±¨Â· £¬¸£ÌØÐ¹Â© £¬¸£ÌغÍÁֿϲ¿ÃųµÐÍʹÓõÄSYNC3ϵͳ´æÔÚ»º³åÇøÒç¶Âí½Å £¬¿ÉÄܵ¼ÖÂÔ¶³ÌÖ´ÐдúÂë £¬µ«²»»áÓ°Ïì¼ÝÊ»°²È«¡£SYNC3ÊÇÒ»¿îÏÖ´úÐÅÏ¢ÓéÀÖϵͳ £¬Ö§³Ö³µÔØWiFiÈȵ㡢µç»°Ïνӡ¢ÓïÒôºÅÁîºÍµÚÈý·½ÀûÓ÷¨Ê½µÈ¡£¸Ã·ì϶£¨CVE-2023-29468£©Î»ÓÚÆû³µÐÅÏ¢ÓéÀÖϵͳÖм¯³ÉµÄWiFi×ÓϵͳµÄWL18xx MCPÇý¶¯·¨Ê½ÖÐ £¬ÔÚWiFiÁìÓòÄڵĹ¥»÷Õß¿ÉʹÓÃÌØÔìÖ¡´¥·¢»º³åÇøÒç³ö¡£¸£ÌسÐŵ½«ºÜ¿ìÍÆ³ö²¹¶¡ £¬¹©Óû§Í¨¹ýUSBÏÂÔØºÍ×°Öá£


https://www.bleepingcomputer.com/news/security/ford-says-cars-with-wifi-vulnerability-still-safe-to-drive/


3¡¢ÄÏ·ÇijµçÁ¦¹«Ë¾Ôâµ½ÀûÓÃSystemBC±äÌåDroxiDatµÄ¹¥»÷


KasperskyÔÚ8ÔÂ10ÈÕ³ÆÆä·¢ÏÖÁËÀûÓÃDroxiDatÕë¶ÔÄÏ·ÇijµçÁ¦¹«Ë¾µÄ¹¥»÷»î¶¯¡£¹¥»÷²úÉúÔÚ3ÔÂÖÐÑ® £¬DroxiDatÊÇSystemBCµÄÒ»¸öÔ¼8kbµÄ¾«¼ò°æ±äÌå £¬¿É×÷Ϊϵͳ·ÖÎöÆ÷ºÍµ¥Ò»µÄÖ§³ÖSOCKS5µÄ»úеÈË¡£ÖµÍ×ÌùÐĵÄÊÇ £¬Cobalt Strike beaconºÍDroxiDatһ·±»²¿Ê𠣬Òò¶ø×êÑÐÈËÔ±´§Ä¦¸ÃÊÂÎñ´¦ÓÚÀÕË÷¹¥»÷µÄ³õʼ½×¶Î¡£Õâ´Î¹¥»÷ÖÐC2»ù´¡ÉèÊ©µÄÒ»¸öÉæ¼°ÄÜÔ´µÄÓòÃûËù½âÎö³öµÄIP £¬ÔÚ¼¸ÄêÇ°Ôø±»ÓÃ×÷APT»î¶¯ £¬ÕâÅú×¢¸ÃÊÂÎñ¿ÉÄÜÊÇAPT¹¥»÷»î¶¯¡£


https://securelist.com/focus-on-droxidat-systembc/110302/


4¡¢¼ÓÄôóADSC¹«Ë¾µÄϵͳ±»ºÚ½ü150ÍòÈ˵ÄÐÅϢй¶


8ÔÂ11ÈÕ±¨Â·³Æ £¬°¬²®ËþÊ¡ÑÀ¿Æ·þÎñ¹«Ë¾£¨ADSC£©Ð¹Â¶ÁË147Íò¹«ÃñµÄÓ×ÎÒÐÅÏ¢¡£ADSCÓë°¬²®ËþÊ¡µ±¾ÖºÏ×÷ £¬Îª¹«ÃñÌṩÑÀ¿Æ·þÎñ¡£7ÔÂ9ÈÕ £¬ADSC·¢ÏÖ¹¥»÷Õß»ñµÃÁ˲¿ÃÅ»ù´¡ÉèÊ©µÄ½Ó¼ûȨÏÞ £¬×°ÖöñÒâÈí¼þ £¬²¢¼ÓÃÜÁ˲¿ÃÅͳºÍÊý¾Ý¡£µ÷²éÈ·¶¨¹¥»÷²úÉúÓÚ5ÔÂ7ÈÕÖÁ7ÔÂ9ÈÕ £¬¹¥»÷ÕßÔÚ²¿Êð¶ñÒâÈí¼þ֮ǰ½Ó¼û²¢ÇÔÈ¡ÁËÍøÂçÖеIJ¿ÃÅÊý¾Ý¡£Ð¹Â¶ÐÅÏ¢Ô̺¬ÐÕÃû¡¢µØÖ·ÒÔ¼°²¿Ãſͻ§µÄÒøÐÐÐÅÏ¢¡£


https://www.databreaches.net/nearly-1-5-million-affected-by-data-breach-at-alberta-dental-service-corporation/


5¡¢·¨ÂÉ»ú¹¹²é·âLolek HostedµÄ·þÎñÆ÷²¢¿ÛÁô5ÃûÏÓÒÉÈË


ýÌå8ÔÂ12ÈÕ³Æ £¬Å·ÃÀ·¨ÂÉ»ú¹¹Òѵ·»Ùbulletproof hosting·þÎñÌṩÉÌLolek Hosted¡£Å·ÖÞÐ̾¯×é֯й© £¬5ÃûÖÎÀíÈËÔ±±»²¶ £¬ËùÓзþÎñÆ÷±»²é·â £¬LolekHosted.netÒѲ»ÔÙ¿ÉÓᣲ¨À¼¾¯·½³Æ £¬ËûÃDzé»ñÁËÊý°ÙÌ¨ÔØº±¼ûTBÊý¾ÝµÄ·þÎñÆ÷¡¢ÍÆËã»úÉ豸ºÍÊÖ»ú¡£Lolek±»Ðû´«Îª¡°100%ÒþÖÔÍйܡ±·þÎñ £¬±»¸÷ÀàÍøÂç¹¥»÷ÕßʹÓá£¾Ý³Æ £¬Lolek Hosted»¹Ð­ÖúÁËԼĪ50ÆðNetWalkerÀÕË÷¹¥»÷¡£


https://thehackernews.com/2023/08/lolek-bulletproof-hosting-servers.html


6¡¢ESETÅû¶Õë¶Ôפ°×¶íÂÞ˹´óʹ¹Ý³¤´ïÊýÄêµÄ¼äµý»î¶¯


8ÔÂ10ÈÕ £¬ESETÅû¶ÁËMoustachedBouncerÕë¶Ôפ°×¶íÂÞ˹´óʹ¹Ý³¤´ïÊýÄêµÄ¼äµý»î¶¯¡£MoustchedBouncerÖÁÉÙ´Ó2014ÄêÆðÍ·ÔËÓª¡£¹¥»÷Õß¿ÉÄÜʹÓÃÁËSORMµÈºÏ·¨À¹½ØÏµÍ³À´Ö´ÐÐAitM¹¥»÷ £¬²¢·Ö·¢¶ñÒâÈí¼þNightClubºÍDiscoµÈ¡£ÕâÁ½¸ö¶ñÒâÈí¼þ¶¼Ö§³ÔìäËü¼äµý²å¼þ £¬Ô̺¬ÆÁÄ»½ØÍ¼·¨Ê½¡¢¹àÒô»úºÍÎļþÇÔÈ¡·¨Ê½¡£ESETÒÑÈ·¶¨ÓÐ4¸ö¹ú¶ÈµÄ´óʹ¹ÝÊܵ½Õâ´Î»î¶¯µÄÓ°Ïì £¬ÆäÖÐÁ½¸öÀ´×ÔÅ·ÖÞ £¬Ò»¸öÀ´×ÔÄÏÑÇ £¬Ò»¸öÀ´×Ô·ÇÖÞ¡£


https://www.welivesecurity.com/en/eset-research/moustachedbouncer-espionage-against-foreign-diplomats-in-belarus/