Microsoft 365ÒòECS²¿Êð´íÎóÈ«Çò·¶Î§ÄÚÖжÏ5Сʱ
Ðû²¼Ê±¼ä 2022-07-25
¾Ý7ÔÂ23ÈÕ±¨µÀ £¬Î¢Èí͸¶ÉÏÖܳ¤´ï5СʱµÄMicrosoft 365È«Çò·¶Î§ÄÚÖжÏÊÇÓÉÆóÒµÅäÖ÷þÎñ(ECS)²¿Êð´íÎóµ¼Öµġ£ECS·þÎñµÄ²¿Êð´æÔÚ´úÂëȱÏÝ£¬Ó°ÏìÁËÆäÏòºó¼æÈÝÐÔ£¬µ¼ÖÂÀûÓÃECSµÄ·þÎñ£¬½«ÏòÆäËùÓеĺÏ×÷»ï°é·µ»Ø²»ÕýÈ·µÄÅäÖá£Ò£²â±íÃ÷£¬Ô¼ÄªÓÐ30Íò¸öºô½ÐÊܵ½Ó°Ï죬ÓÉÓÚÒµÎñʱ¼äÓëÓ°Ïì´°¿ÚÏàÎǺϣ¬ÑÇÌ«µØÓòÊܵ½µÄÓ°Ïì×î´ó¡£´ËÍ⣬ֱ½Ó·ÓɺÍSkype MFAÊÇÊÜÓ°Ïì×î´óµÄ·þÎñ¡£ÖжϿªÊ¼ÓÚ7ÔÂ21ÈÕÁ賿1:05 UTC¿ªÊ¼£¬µ±ÈÕÔçÉÏ6:00 UTC֮ǰ´ó²¿ÃÅÒѱ»ÐÞ¸´¡£
https://www.bleepingcomputer.com/news/microsoft/massive-microsoft-365-outage-caused-by-faulty-ecs-deployment/
2¡¢¹¥»÷ÕßÔÚ°µÍøÒÔ3ÍòÃÀÔª³öÊÛ540ÍòTwitterÓû§µÄÐÅÏ¢
¾ÝýÌå7ÔÂ24ÈÕ±¨µÀ£¬ÃûΪdevilµÄºÚ¿Í³ÆÆäÀûÓé¶´·ÃÎÊÁË5485636ÃûTwitterÓû§µÄÐÅÏ¢£¬²¢ÒÔÖÁÉÙ30000ÃÀÔªµÄ¼Û¸ñ½øÐгöÊÛ¡£ÓÃÓÚÊÕ¼¯Êý¾ÝµÄ©¶´ÓÚ1ÔÂ1±»Åû¶²¢ÓÚ1ÔÂ13ÈÕÐÞ¸´£¬¿É±»Î´¾Éí·ÝÑéÖ¤¹¥»÷ÕßÓÃÀ´Í¨¹ýµç»°ºÅÂëºÍÓʼþÀ´»ñÈ¡ÈÎÒâÓû§µÄTwitter ID¡£¹¥»÷ÕßÌåÏÖËûÃÇÔÚ2021Äê12Ô¾ͿªÊ¼ÀûÓé¶´ÊÕ¼¯Êý¾Ý£¬ÏÖÔÚÒÑÓиÐÐËȤµÄÂò¼ÒÓëËûÃǽøÐнÓÇ¢¡£Ä¿Ç°£¬TwitterÉÐδȷÈÏ´Ë´Îй¶Ê¼þ£¬¶øÂô¼ÒÒÑɾ³ý¸Ã¹ã¸æ¡£
https://securityaffairs.co/wordpress/133593/data-breach/twitter-leaked-data.html
3¡¢Securonix·¢ÏÖAPT37ÀûÓÃKonni¹¥»÷Å·ÖÞ¶à¹úµÄ»î¶¯
7ÔÂ20ÈÕ£¬Securonix³ÆÆä·¢ÏÖÁ˳¯Ïʹ¥»÷ÕßAPT37ÀûÓÃKonniÕë¶Ô½Ý¿ËºÍ²¨À¼µÈÅ·ÖÞ¹ú¼ÒµÄ¹¥»÷¡£Ôڴ˻ÖУ¬¹¥»÷ÕßʹÓÃÁËÔ¶³Ì·ÃÎÊľÂíKonni£¬¹¥»÷ʼÓÚÒ»·â°üÂÞWordÎĵµ(missile.docx)ºÍWindows¿ì½Ý·½Ê½Îļþ(weapons.doc.lnk.lnk)¸½¼þµÄµöÓãÓʼþ¡£´ò¿ªLNKºó»áÖ´ÐдúÂëÀ´ÔÚDOCXÎļþÖвéÕÒbase64±àÂëµÄPowerShell½Å±¾£¬È»ºó½¨Á¢C2ͨÐŲ¢ÏÂÔØÁ½¸öÎļþ¡°weapons.doc¡±ºÍ¡°wp.vbs¡±¡£ÕâЩÎļþÖ»ÊÇÓÕ¶ü£¬Í¬Ê±£¬ºǫ́»á¾²Ä¬µØÔËÐÐVBSÎļþ£¬×îÖÕÏÂÔØKonni¡£
https://www.securonix.com/blog/stiffbizon-detection-new-attack-campaign-observed/
4¡¢Êý×ÖÄþ¾²¹«Ë¾EntrustÔâµ½¹¥»÷ºóÄÚ²¿ÏµÍ³Êý¾Ý±»µÁ
ýÌå7ÔÂ22ÈÕ±¨µÀ£¬Entrust³ÆÆäÔâµ½ÁËÍøÂç¹¥»÷£¬ÄÚ²¿ÏµÍ³ÖеÄÊý¾Ý±»µÁ¡£EntrustÊÇÒ»¼ÒרעÓÚÔÚÏßÐÅÈκÍÉí·Ý¹ÜÀíµÄÄþ¾²¹«Ë¾£¬Ìṩ°üÂÞ¼ÓÃÜͨÐÅ¡¢Äþ¾²Êý×ÖÖ§¸¶ºÍÉí·ÝÖ¤Ã÷½â¾ö·½°¸µÈ·þÎñ¡£¹¥»÷·¢ÉúÔÚ6ÔÂ18ÈÕ£¬¸Ã¹«Ë¾²¢Î´Ìṩ¹ØÓÚ¸ÃʼþµÄ¸ü¶àϸ½Ú£¬µ«Ñо¿ÈËÔ±Á˽⵽һ¸öÖøÃûµÄÀÕË÷ÍÅ»ïÊÇÄ»ºóºÚÊÖ¡£±»µÁÊý¾ÝÏÔʾ£¬´Ë´Îʼþ¿ÉÄÜ»áÓ°Ïì´óÁ¿Ê¹ÓÃEntrust½øÐÐÉí·Ý¹ÜÀíºÍÉí·ÝÑéÖ¤µÄ×éÖ¯£¬°üÂÞÃÀ¹úÕþ¸®»ú¹¹£¬ÈçÄÜÔ´²¿¡¢¹úÍÁÄþ¾²²¿¡¢²ÆÕþ²¿¡¢ÎÀÉúÓ빫ÖÚ·þÎñ²¿¡¢ÍËÎé¾üÈËÊÂÎñ²¿ºÍũҵ²¿µÈµÈ¡£
https://www.bleepingcomputer.com/news/security/digital-security-giant-entrust-breached-by-ransomware-gang/
5¡¢Cisco͸¶Õë¶ÔÎÚ¿ËÀ¼Ä³´óÐÍÈí¼þ¹«Ë¾µÄ¹¥»÷µÄϸ½Ú
CiscoÔÚ7ÔÂ21ÈÕÅû¶ÁËÕë¶ÔÎÚ¿ËÀ¼Ä³´óÐÍÈí¼þ¹«Ë¾µÄ¹¥»÷»î¶¯µÄϸ½Ú¡£Õâ¼ÒÈí¼þ¹«Ë¾Éú²úµÄÈí¼þ¹©ÎÚ¿ËÀ¼¶à¸ö¹ú¼Ò»ú¹¹ËùʹÓã¬Ñо¿ÈËÔ±ÈÏΪ£¬¸Ãʼþ¿ÉÄÜÓë¶íÂÞ˹Óйأ¬ÒԸù«Ë¾ÎªÄ¿±êÆóͼ·¢¶¯¹©Ó¦Á´¹¥»÷¡£¹¥»÷»î¶¯Ê¹ÓÃÁËÒ»¸öÃûΪGoMetµÄ¿ªÔ´ºóÃŵÄ×Ô½ç˵±äÌ壬ֻÓÐÁ½Æð¼Ç¼ÔÚ°¸µÄ»î¶¯ÀûÓùý¸ÃºóÃÅ£º2020Äê¹¥»÷ÕßÀûÓÃF5 BIG-IPÖЩ¶´£¨CVE-2020-5902£©ÈëÇÖϵͳ²¢°²×°Õâ¸öºóÃÅ£»½üÆÚ£¬¹¥»÷ÕßÔÚÀûÓÃSophos FirewallÖЩ¶´£¨CVE-2022-1040£©ºó°²×°ºóÃÅ¡£
https://blog.talosintelligence.com/2022/07/attackers-target-ukraine-using-gomet.html
6¡¢SonicWalÐû²¼SQL×¢Èë©¶´CVE-2022-22280µÄÄþ¾²Í¨¸æ
SonicWallÔÚ7ÔÂ22ÈÕÐû²¼Äþ¾²Í¨¸æ£¬ÌáÐÑÓ°ÏìGMS£¨È«Çò¹ÜÀíϵͳ£©ºÍAnalytics On-Prem²úÎïµÄSQL×¢Èë©¶´¡£¸Ã©¶´×·×ÙΪCVE-2022-22280£¬ÊǶÔSQLÃüÁîÖÐʹÓõÄÌØÊâÔªËØµÄ²»ÕýÈ·Öк͵¼Öµģ¬CVSSÆÀ·ÖΪ9.4£¬ÎÞÐèÉí·ÝÑéÖ¤»òÓû§½»»¥¼´¿ÉÀûÓá£SonicWallÌåÏÖ˵£¬¸Ã©¶´ÉÐδ±»ÔÚÒ°ÀûÓã¬Ò²Ã»ÓÐÕë¶Ô´Ë©¶´µÄ¿´·¨Ö¤Ã÷(PoC)¡£´Ë©¶´Ã»ÓпÉÓõĽâ¾öÒªÁ죬Òò´ËSonicWallÇ¿ÁÒ½¨ÒéʹÓÃÊÜÓ°Ïì²úÎïµÄ×éÖ¯Á¢¼´Éý¼¶µ½ÏàÓ¦µÄÐÞ¸´°æ±¾¡£
https://www.bleepingcomputer.com/news/security/sonicwall-patch-critical-sql-injection-bug-immediately/