6ÔÂWindows¸üпÉÄܵ¼Ö²¿ÃÅÓ¦ÓÃÎÞ·¨Ê¹ÓÃVSS±¸·Ý

Ðû²¼Ê±¼ä 2022-06-17
1¡¢6Ô·ÝWindows¸üпÉÄܵ¼Ö²¿ÃÅÓ¦ÓÃÎÞ·¨Ê¹ÓÃVSS±¸·Ý

      

¾Ý6ÔÂ15ÈÕ±¨µÀ£¬Î¢ÈíÌåÏÖ£¬ÔÚ°²×°2022Äê6ÔµÄWindows¸üкó£¬Ä³Ð©Ó¦Ó÷¨Ê½¿ÉÄÜÎÞ·¨Ê¹ÓþíÓ°¸´ÖÆ·þÎñ(VSS)À´±¸·ÝÊý¾Ý¡£¸ÃÎÊÌâÊÇÐÞ¸´MicrosoftÎļþ·þÎñÆ÷¾íÓ°¸´ÖÆÊðÀí·þÎñ(RVSS)ÖеÄÌáȨ©¶´(CVE-2022-30154)µ¼ÖµÄ¡£´æÔÚÎÊÌâµÄϵͳÖУ¬Windows±¸·ÝÓ¦Ó÷¨Ê½ÔÚ¾íÓ°¸´ÖÆ´´½¨¹ý³ÌÖпÉÄÜ»áÊÕµ½E_ACCESSDENIED´íÎó£¬ÇÒ»áÔÚÎļþ·þÎñÆ÷ÖмǼΪ"FileShareShadowCopyAgent Event 1013"¡£


https://www.bleepingcomputer.com/news/microsoft/microsoft-june-windows-server-updates-may-cause-backup-issues/


2¡¢F5 LabsÅû¶ÐÂAndroidľÂíMaliBotµÄϸ½ÚÐÅÏ¢

      

6ÔÂ15ÈÕ£¬F5 Labs×îгÂËßÅû¶ÁËAndroidľÂíMaliBotµÄϸ½ÚÐÅÏ¢¡£MaliBotרעÓÚÇÔÈ¡½ðÈÚÐÅÏ¢£¬ÀýÈçµç×ÓÒøÐзþÎñƾ֤¡¢¼ÓÃÜÇ®°üÃÜÂëºÍ¸öÈËÏêϸÐÅÏ¢£¬»¹¿ÉÒÔÇÔÈ¡ºÍÈÆ¹ý¶àÒòËØ(2FA/MFA)´úÂ룬Ö÷ÒªÕë¶ÔÒâ´óÀûºÍÎ÷°àÑÀµÄ½ðÈÚ»ú¹¹¡£¸Ã¶ñÒâÈí¼þ»áαװ³É¼ÓÃÜ»õ±ÒÍÚ¾òÓ¦Ó÷¨Ê½¡°Mining X¡±ºÍ¡°The CryptoApp¡±£¬ÓÐʱҲαװ³É¡°MySocialSecurity¡±ºÍ¡°Chrome¡±¡£´ËÍ⣬Ñо¿ÈËÔ±ÌåÏÖÆäC2·þÎñÆ÷λÓÚ¶íÂÞ˹£¬ËƺõÓë·Ö·¢SalityµÄ»î¶¯Ê¹ÓõÄÊÇͬһ¸ö·þÎñÆ÷£¬×Ô2020Äê6ÔÂÒÔÀ´£¬Ðí¶à»î¶¯¶¼Ô´×Ô´ËIP¡£


https://www.f5.com/labs/articles/threat-intelligence/f5-labs-investigates-malibot


3¡¢Citrix ADM¿ÉÖØÖùÜÀíÔ±ÃÜÂëµÄ©¶´CVE-2022-27511

      

¾ÝýÌå6ÔÂ15ÈÕ±¨µÀ£¬CitrixÓ¦Óý»¸¶¹ÜÀí(ADM)´æÔÚ¿ÉÖØÖùÜÀíÔ±ÃÜÂëµÄ©¶´¡£¸Ã©¶´×·×ÙΪCVE-2022-27511£¬ÊÇÓɲ»ÕýÈ·µÄ·ÃÎÊ¿ØÖƵ¼ÖµÄ£¬Ó°ÏìËùÓÐÊÜÖ§³ÖµÄCitrix ADM·þÎñÆ÷ºÍCitrix ADMÊðÀí°æ±¾¡£Citrix½âÊ͵À£¬ÀûÓøÃ©¶´¿ÉÄÜÔÚÏ´ÎÉè±¸ÖØÆôÊ±ÖØÖùÜÀíÔ±ÃÜÂ룬¾ßÓÐssh·ÃÎÊȨÏ޵Ĺ¥»÷ÕßÔÚÉè±¸ÖØÆôºó¿ÉÒÔʹÓÃĬÈϹÜÀíԱƾ¾Ý½øÐÐÁ¬½Ó¡£Ä¿Ç°£¬Â©¶´Òѱ»ÐÞ¸´£¬¸Ã¹«Ë¾½¨Òé¹ÜÀíÔ±Á¢¼´°²×°²¹¶¡¡£


https://www.bleepingcomputer.com/news/security/citrix-warns-critical-bug-can-let-attackers-reset-admin-passwords/


4¡¢Ñо¿ÈËÔ±·¢ÏÖBeanVPN½ü20GBµÄÁ¬½ÓÈÕÖ¾¿É¹ûÈ»·ÃÎÊ

      

ýÌå6ÔÂ15Èճƣ¬CybernewsµÄÊӲ췢ÏÖÌṩÉÌBeanVPN 18.5 GBµÄÁ¬½ÓÈÕÖ¾¿É±»¹ûÈ»·ÃÎÊ¡£¸Ã»º´æÈÕÖ¾°üÂÞÁè¼Ý2500ÍòÌõ¼Ç¼£¬Éæ¼°Óû§É豸ºÍPlay·þÎñID¡¢Á¬½Óʱ¼ä´ÁºÍIPµØÖ·µÈ¡£Ñо¿ÈËÔ±ÌåÏÖ£¬Play·þÎñID¿ÉÓÃÓÚ²éÕÒÓû§µÇ¼É豸ʱʹÓõĵç×ÓÓʼþµØÖ·¡£´ËÍ⣬¸ÃÌṩÉÌÌåÏÖ²»ÊÕ¼¯Óû§IPµØÖ·¡¢´«³öIPµØÖ·¡¢Á¬½Óʱ¼ä´ÁºÍ»á»°Á¬ÐøÊ±¼äµÈÐÅÏ¢¡£µ«Õâһ˵·¨Óëй¶µÄÐÅÏ¢²¢·×ÆçÖ£¬ºóÕß¼¸ºõ°üÂÞÁËBeanVPNÉù³Æ²»»áÊÕ¼¯µÄËùÓÐÊý¾Ý¡£Ä¿Ç°£¬Ð¹Â¶µÄÊý¾ÝÒѱ»±£»¤ÆðÀ´¡£


https://www.infosecurity-magazine.com/news/beanvpn-leaks-user-records/


5¡¢ÃÀ¹úTransact CampusÅäÖôíÎóй¶3Íò¶àѧÉúµÄÐÅÏ¢

      

ýÌå6ÔÂ15ÈÕ±¨µÀ£¬SafetyDetectives·¢ÏÖÁËÒ»¸öÅäÖôíÎóµÄElasticsearch·þÎñÆ÷£¬ÆäÖаüÂÞTransact CampusµÄÓ¦Ó÷¨Ê½µÄÊý¾Ý¡£¸ÃÓ¦ÓÃÓÃÓڸߵȽÌÓý»ú¹¹µÄѧÉúµÄÖ§¸¶Á÷³Ì£¬´Ë´Îʼþй¶ÁËÔ¼100ÍòÌõ¼Ç¼£¬Éæ¼°3ÖÁ4ÍòÃûѧÉú¡£ÖµµÃ×¢ÒâµÄÊÇ£¬Óû§ÃûºÍÃÜÂëµÈµÇ¼Êý¾Ý¾ùÒÔ´¿Îı¾¸ñʽ´æ´¢£¬ÇÒй¶µÄÐÅÓÿ¨ÐÅÏ¢°üÂÞÒøÐÐʶ±ðºÅ¡¢ÐÅÓÿ¨ºÅµÄǰÁùλºÍºóËÄλºÍµ½ÆÚÈÕÆÚµÈ¡£Ä¿Ç°£¬Êý¾Ý¿âÒѱ»±£»¤ÆðÀ´£¬µ«¸Ã¹«Ë¾Éù³Æ·þÎñÆ÷²»ÔÚËûÃǵĿØÖÆÖ®ÏÂÇÒÊý¾ÝÊǼٵÄ¡£µ«Ñо¿ÈËÔ±ÌåÏÖ¾­¹ý¿ªÔ´¹¤¾ßµÄ¼ì²é£¬ÕâЩÊý¾ÝÊôÓÚÕæÊµµÄÓû§¡£


https://www.hackread.com/elasticsearch-database-expose-login-pii-data-students/


6¡¢Blue MockingbirdÍÅ»ïÀÄÓÃTelerik UIÖеÄ©¶´ÍÚ¿ó

      

6ÔÂ15ÈÕ£¬SophosÐû²¼ÁËBlue Mockingbird½üÆÚ¹¥»÷»î¶¯µÄ·ÖÎö³ÂËß¡£¸ÃÍÅ»ïÀûÓÃÁËTelerik UI WebÓ¦Ó÷¨Ê½¿ò¼ÜÖеÄ©¶´À´ÈëÇÖ·þÎñÆ÷£¬°²×°Cobalt Strike beacons£¬È»ºó½Ù³Öϵͳ×ÊÔ´À´ÍÚ¾òMonero¡£¹¥»÷ÕßÀûÓõÄÊÇÒÑ´æÔÚ3ÄêµÄ.NET·´ÐòÁл¯Â©¶´£¨CVE-2019-18935£¬CVSSÆÀ·Ö9.8£©£¬¿ÉÔÚTelerik UI¿âÖÐÔ¶³ÌÖ´ÐÐASP.NET AJAXµÄ´úÂë¡£´ËÍ⣬ÔÚ¹¥»÷¹ý³ÌÖУ¬¸ÃÍÅ»ïʹÓÃÁËÒ»ÖÖÏֳɵÄPoC£¬¿É´¦ÖüÓÃÜÂß¼­²¢×Ô¶¯Ö´ÐÐDLL±àÒë¡£


https://www.bleepingcomputer.com/news/security/hackers-exploit-three-year-old-telerik-flaws-to-deploy-cobalt-strike/