Veeam°ä²¼¸üн¨¸´Veeam ONE¼à¿ØÆ½Ì¨Öжà¸ö·ì϶

°ä²¼¹¦·ò 2023-11-08

1¡¢Veeam°ä²¼¸üн¨¸´Veeam ONE¼à¿ØÆ½Ì¨Öжà¸ö·ì϶


11ÔÂ6ÈÕ £¬Veeam°ä²¼Á˰²È«¸üÐÂÒÔ½¨¸´Veeam ONE IT»ù´¡ÉèÊ©¼à¿ØºÍ·ÖÎöƽ̨ÖеÄ4¸ö·ì϶¡£ÆäÖнÏΪÑϳÁµÄÊÇCVE-2023-38547(CVSSÆÀ·Ö9.9) £¬¿ÉÓÃÀ´»ñÈ¡ÓйØVeeam ONEÓÃÓÚ½Ó¼ûÆäÅäÖÃÊý¾Ý¿âµÄSQL·þÎñÆ÷ÏνӵÄÐÅÏ¢ £¬¿ÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐÐ £»ÒÔ¼°CVE-2023-38548£¨CVSSÆÀ·Ö9.8£© £¬¿É»ñÈ¡Veeam ONE Reporting ServiceËùʹÓÃÕÊ»§µÄNTLM¹þÏ£¡£Áí±íÁ½¸öÊÇ¿Éͨ¹ýXSS¹¥»÷ÇÔÈ¡ÖÎÀíÔ±ÁîÅÆµÄ·ì϶£¨CVE-2023-38549£©ºÍ¿É½Ó¼ûDashboard ScheduleµÄ·ì϶£¨CVE-2023-41723£©¡£


https://www.bleepingcomputer.com/news/security/veeam-warns-of-critical-bugs-in-veeam-one-monitoring-platform/


2¡¢ÈÕ±¾º½¿Õµç×Ó¹«Ë¾Ôâµ½AlphVµÄ¹¥»÷ÔËÓªÊܵ½Ó°Ïì


¾Ý11ÔÂ8ÈÕ±¨Â· £¬ÈÕ±¾º½¿Õµç×Ó¹«Ë¾Ð¹Â© £¬ÆäϵͳÔâµ½ÍøÂç¹¥»÷ £¬ÍøÕ¾±»ÆÈ¹Ø¹Ø¡£ÖÜÒ»ÍíÉÏ £¬¸Ã¹«Ë¾µÄÍøÕ¾ÏÔʾÁËÒ»ÌõÐÂÎÅ £¬Åú×¢Æä²¿ÃÅ·þÎñÆ÷ÔÚÉÏÖÜËı»ºÚ¡£Õâ¼Ò¹«Ë¾°µÊ¾ £¬ËûÃÇĿǰÔÚµ÷²éÈëÇÖÇé¿ö²¢¸´Ô­ÔËÓª £¬µ«Ò»Ð©ÏµÍ³ÒѾ­ÖжÏ £¬ÊÕ·¢µç×ÓÓʼþÒ²³öÏÖÁËһЩÑÓÎó £¬ÉÐδ·¢ÏÖÐÅϢй¶¡£AlphVÔÚ±¾ÖÜÒ»½«ÈÕ±¾º½¿Õµç×Ó¹«Ë¾²ÎÓëÆäÍøÕ¾ £¬µ«¸Ã¹«Ë¾ÉÐδй©ÊÇ·ñÔÚÓ¦¶ÔÀÕË÷¹¥»÷¡£


https://therecord.media/japan-aviation-electronics-says-servers-accessed-during-cyberattack


3¡¢Unit 42·¢ÏÖAgriusÕë¶ÔÒÔÉ«ÁнÌÓýºÍ¿Æ¼¼ÐÐÒµµÄ¹¥»÷


Unit 42ÔÚ11ÔÂ6ÈÕ³ÆÆä·¢ÏÖÁËAgriusÕë¶ÔÒÔÉ«ÁнÌÓýºÍ¿Æ¼¼ÐÐÒµµÄ¹¥»÷¡£ÕâЩ¹¥»÷´Ó1ÔÂÒ»Ïò³ÖÐøµ½10Ô £¬Ö¼ÔÚÇÔÈ¡PIIºÍ֪ʶ²úȨµÈÃô¸ÐÐÅÏ¢¡£Ò»µ©ÇÔÈ¡ÁËÐÅÏ¢ £¬¹¥»÷Õ߾ͻá×°Öø÷Àà²Á³ý·¨Ê½ £¬À´¸²¸ÇÆä×ÙÓ°²¢Ê¹±»Ï°È¾µÄÖÕ¶ËÎÞ·¨Ê¹Óá£×î½üµÄ¹¥»÷»¹Ê¹ÓõÄ3ÖÖеIJÁ³ý·¨Ê½ £¬MultiLayer Wiper¡¢PartialWasherºÍBFG Agonizer Wiper £¬ÒÔ¼°Ò»¸ö´ÓÊý¾Ý¿â·þÎñÆ÷ÌáÊØÐÅÏ¢µÄ×Ô½ç˵¹¤¾ßSqlextractor¡£


https://unit42.paloaltonetworks.com/agonizing-serpens-targets-israeli-tech-higher-ed-sectors/


4¡¢Google³Æ¶à¸öÍÅ»ïÊÔͼ½«ÆäÈÕÀú·þÎñÓÃ×÷C2»ù´¡ÉèÊ©


¾ÝýÌå11ÔÂ6ÈÕ±¨Â· £¬GoogleÌáÐѶà¸ö¹¥»÷ÍÅ»ïÔÚ¹²ÏíÒ»¸öÃûΪGoogle Calendar RAT(GCR)µÄPoC £¬ËüÀûÓÃÈÕÀú·þÎñÀ´ÍйܺÅÁîºÍ½ÚÔ죨C2£©»ù´¡ÉèÊ©¡£Æä¿ª·¢Õß°µÊ¾ £¬¸Ã¾ç±¾Í¨¹ýÀûÓÃGoogleÈÕÀúÖеÄÊÂÎñÃèÊö´´½¨ÁËÒ»¸ö¡°Òñ±Îͨ·¡± £¬Ö¸±ê½«Ö±½ÓÏνӵ½Google¡£Google³ÆÉÐδ·¢ÏÖGCRÔÚÒ°±íµÄʹÓÃÇé¿ö £¬µ«Mandiant°ÑÎȵ½¶à¸öÍÅ»ïÔÚºÚ¿ÍÂÛ̳ÉÏ·ÖÏíÁËPoC £¬Õâ˵ÁËÈ»ËûÃǶÔÀÄÓÃÔÆ·þÎñ¸ÐÐËÖ¡£


https://securityaffairs.com/153700/hacking/google-calendar-rat-attacks.html


5¡¢VMwareÅû¶JupyterбäÌåÔÚ½üÆÚ¼¤ÔöµÄ¹¥»÷»î¶¯


VMwareÔÚ11ÔÂ6ÈÕÅû¶ÁËJupyter Infostealer±äÌåÐÂÒ»ÂֵĹ¥»÷»î¶¯¡£¸Ã¶ñÒâÈí¼þÓÚ2020Äêµ×³õ´Î±»·¢ÏÖ £¬ÖØÒªÕë¶Ô½ÌÓýºÍÎÀÉú²¿ÃÅ¡£´ÓǰÁ½ÖÜ £¬×êÑÐÈËÔ±¹Û²ìµ½µÄJupyter InfostealerϰȾÊýÁ¿Öð²½ÉÏÉý £¬Ä¿Ç°Ï°È¾×ÜÊýΪ26Àý¡£ËüÕë¶ÔChrome¡¢EdgeºÍFirefoxä¯ÀÀÆ÷ £¬ÀûÓÃSEOÖж¾ºÍËÑË÷ÒýÇæ³Á¶¨ÀúÀ´´«²¼¡£ÐÂÒ»ÂֵĹ¥»÷ÀûÓÃÁËPowerShellºÅÁîÀ´Åú¸ÄºÍÊðÃû˽Կ £¬ÊÔͼ½«¶ñÒâÈí¼þ¼ÙÒâΪºÏ·¨ÊðÃûµÄÎļþ¡£


https://blogs.vmware.com/security/2023/11/jupyter-rising-an-update-on-jupyter-infostealer.html


6¡¢Kaspersky°ä²¼2023ÄêÓëÓÎÏ·ÓйصÄÍøÂçÍþвµÄ»ã±¨


11ÔÂ6ÈÕ £¬Kaspersky°ä²¼ÁË2023ÄêÓëÓÎÏ·ÓйصÄÍøÂçÍþвµÄ·ÖÎö»ã±¨¡£¸Ã»ã±¨·ÖÎöÁË2022Äê7ÔÂ1ÈÕÖÁ2023Äê7ÔÂ1ÈÕÆÚ¼äÍøÂçµÄÊý¾Ý¡£»ã±¨Ö¸³ö £¬Kaspersky×ܹ²¼ì²âµ½4076530´ÎÓëÓÎÏ·ÓйصÄ×ÀÃæÏ°È¾³¢ÊÔ £¬Ó°ÏìÁËÈ«Çò192456ÃûÓÎÏ·Íæ¼Ò¡£×î³£¼ûµÄÍþвÊÇÏÂÔØ·¨Ê½£¨89.70%£© £¬Æä´ÎÊǸæ°×Èí¼þ£¨5.25%£©ºÍľÂí£¨2.39%£©¡£×î³£±»ÓÃ×÷µö¶üµÄÊÇÎÒµÄÊÀ½ç£¨70.29%£© £¬Æä´ÎÊÇRoblox£¨20.37%£©¡¢·´¿Ö¾«Ó¢£ºÈ«Çò¹¥ÊÆ£¨4.78%£©ºÍ¾øµØÇóÉú£¨2.85%£©¡£


https://securelist.com/game-related-threat-report-2023/110960/