ijÆû³µ¹©Ó¦É̵ÄϵͳÔÚÁ½ÖÜÄÚ±»HiveµÈÈý¸öÀÕË÷ÍŻ﹥»÷
Ðû²¼Ê±¼ä 2022-08-12
8ÔÂ10ÈÕ£¬Sophos͸¶ijÆû³µ¹©Ó¦É̵ÄϵͳÔÚÁ½ÖÜÄÚ±»Èý¸öÀÕË÷ÍÅ»ïLockBit¡¢HiveºÍBlackCat¹¥»÷¡£ÕâÈý¸ö¹¥»÷ÍŻﶼÀûÓÃÁËÏàͬµÄ´íÎóÅäÖ㬼´ÔÚ¹ÜÀí·þÎñÆ÷ÉÏ̻¶ÁËÔ¶³Ì×ÀÃæÐÒéµÄ·À»ðǽ¹æÔò¡£5ÔÂ1ÈÕ£¬Lockbit´´½¨ÁËÁ½¸öÅú´¦Öýű¾£¨1.batºÍ2.bat£©£¬Í¨¹ýPsExecÉÏ·Ö·¢ÁËÁ½¸öÀÕË÷Èí¼þµÄ¶þ½øÖÆÎļþ£¬¼ÓÃÜÁË19̨Ö÷»úÉϵÄÎļþ£»Á½¸öСʱ֮ºó£¬HiveʹÓÃÒѰ²×°ÔÚϵͳÉϵĵĺϷ¨Èí¼þPDQ DeployÀ´·Ö·¢ÆäÀÕË÷Èí¼þ¶þ½øÖÆÎļþ£¬¼ÓÃÜÁË16̨Ö÷»úµÄÎļþ£»5ÔÂ15ÈÕ£¬BlackCatÀûÓñ»Ñ¬È¾Óû§µÄƾ¾ÝÔÚ6̨Ö÷»úÉÏͶ·ÅÁËÁ½¸öÀÕË÷Èí¼þµÄ¶þ½øÖÆÎļþ¡£
https://www.bleepingcomputer.com/news/security/automotive-supplier-breached-by-3-ransomware-gangs-in-2-weeks/
2¡¢Cloudflare͸¶¶àÃûÔ±¹¤Ôâµ½ÓëTwilioÀàËÆµÄµöÓã¹¥»÷
¾ÝýÌå8ÔÂ10Èճƣ¬CloudflareÅû¶ÆäÖÁÉÙÓÐ76ÃûÔ±¹¤¼°Æä¼ÒÊôÔâµ½ÁËÀàËÆÓÚÕë¶ÔTwilioµÄÅÓ´óµöÓã¹¥»÷¡£Õâ´Î¹¥»÷ԼĪÓëÕë¶ÔTwilioµÄ¹¥»÷ͬʱ·¢Éú£¬À´×Ô4¸öÓëT-Mobile¿¯ÐеÄSIM¿¨Ïà¹ØµÄµç»°ºÅÂ룬ÕâЩ¶ÌÐÅÖ¸ÏòÒ»¸ö¿´ËƺϷ¨µÄÓò£¬ÆäÖаüÂÞÒªº¦×ÖCloudflareºÍOkta£¬ÊÔͼÓÕʹԱ¹¤½»³öƾ¾Ý¡£CloudflareÌåÏÖ£¬ÓÐÈýÃûÔ±¹¤ÒÑÉϵ±ÊÜÆ£¬µ«ÒòΪʹÓ÷ÃÎÊÆäÓ¦Ó÷¨Ê½ËùÐèµÄÇкÏFIDO2³ß¶ÈµÄÎïÀíÄþ¾²ÃÜÔ¿£¬ÆäÄÚ²¿ÏµÍ³²¢Î´±»¹¥ÆÆ¡£
https://thehackernews.com/2022/08/hackers-behind-twilio-breach-also_10.html
3¡¢Volexity³ÆZimbraÖЩ¶´±»ÓÃÀ´¹¥»÷ÉÏǧ̨ZCS·þÎñÆ÷
VolexityÔÚ8ÔÂ10ÈÕ±¨µÀ£¬ZimbraÉíÖеÄ©¶´Òѱ»ÀûÓÃÀ´ÈëÇÖÁè¼Ý1000̨Zimbra Collaboration Suite(ZCS)Óʼþ·þÎñÆ÷¡£¾ÝϤ£¬¹¥»÷ÕßÔçÔÚ6Ôµ׾ͿªÊ¼ÔÚÉí·ÝÑéÖ¤ÈÆ¹ý©¶´£¨CVE-2022-37042£©µÄ×ÊÖúÏ£¬À´ÀûÓÃZCSÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2022-27925£©¡£VolexityÈÏΪ£¬¸Ã©¶´µÄÀûÓ÷½Ê½Óë2021Äê³õ·¢ÏÖµÄMicrosoft Exchange 0dayµÄÀûÓ÷½Ê½Ò»Ö¡£ZimbraÔÚͨ¸æÖв¢Î´Í¸Â¶Â©¶´ÀûÓÃÇé¿ö£¬ µ«Ò»ÃûÔ±¹¤ÔÚ¹«Ë¾ÂÛ̳ÉϽ¨ÒéÓû§Á¢¼´°²×°²¹¶¡£¬³ÆÂ©¶´È·ÊµÒÑÔÚ¹¥»÷Öб»ÀûÓá£
https://www.bleepingcomputer.com/news/security/zimbra-auth-bypass-bug-exploited-to-breach-over-1-000-servers/
4¡¢Cisco Meraki·À»ðǽÎ󱨵¼ÖÂMicrosoft 365·þÎñÖжÏ
ýÌå8ÔÂ10ÈÕ±¨µÀ£¬Á¬ÐøµÄÖжÏÓ°ÏìÁ˶à¸öMicrosoft 365·þÎñ£¬Óû§ÎÞ·¨Á¬½Óµ½Exchange Online¡¢Microsoft Teams¡¢Outlook×ÀÃæ¿Í»§¶ËºÍOneDrive for Business¡£ËäȻ΢ÈíÌåÏÖ´Ëʼþ½öÓ°ÏìÁËEMEA£¨Å·ÖÞ¡¢Öж«ºÍ·ÇÖÞ£©µØÓòµÄ¿Í»§£¬µ«È«ÇòÓû§¶¼ÔÚ³ÂËß·þÎñÆ÷Á¬½ÓºÍµÇ¼ʧ°ÜÎÊÌâ¡£³õ·¨Ê½²é·¢ÏÖ£¬Á¬ÐøÖжϿÉÄÜÓëCisco Meraki·À»ðǽÈëÇÖ¼ì²âºÍÔ¤·À(IDR)Îó±¨×èÖ¹Microsoft 365Á¬½Ó²¢·¢³öMicrosoft Windows IIS¾Ü¾ø·þÎñʵÑ龯±¨Óйء£Î¢Èí×îÖÕÈ·ÈÏÖжÏÊÇSnort¹æÔò1-60381µ¼Öµģ¬²¢ÌåÏÖCisco MerakiÒѽûÓÃÁËÊÜÓ°ÏìµÄ¹æÔò¡£
https://www.bleepingcomputer.com/news/microsoft/microsoft-365-outage-triggered-by-meraki-firewall-false-positive/
5¡¢Unit 42·¢ÏÖÐÂÀÕË÷Èí¼þBlueSkyÀûÓöàÏ߳̿ìËÙ¼ÓÃÜ
Unit 42ÔÚ8ÔÂ10ÈÕ¹ûÈ»ÁËÐÂÀÕË÷Èí¼þ¼Ò×åBlueSkyµÄ¼¼Êõϸ½Ú¡£BlueSkyÀÕË÷Èí¼þÖ÷ÒªÕë¶ÔWindowsÖ÷»ú£¬²¢ÀûÓöàÏ̼߳ÓÃÜÖ÷»úÉϵÄÎļþÀ´¼Ó¿ì¼ÓÃÜËÙ¶È¡£·ÖÎö¹ý³ÌÖÐÑо¿ÈËÔ±´ÓBlueSkyµÄÑù±¾Öз¢ÏÖÁË¿ÉÒÔÓëContiÁªÏµÆðÀ´µÄ´úÂëÖ¸ÎÆ£¬ÌرðÊÇBlueSkyµÄ¶àÏ̼ܹ߳¹ÓëConti v3µÄ´úÂëÏàËÆ£¬ÍøÂçËÑË÷Ä£¿éÒ²ÊÇËüµÄÍêÈ«·°æ¡£ÁíÒ»·½Ã棬BlueSkyÓëBabuk¸üΪÏàËÆ£¬Á½Õß¶¼Ê¹ÓÃChaCha20£¬Í¬Ê±Ê¹ÓÃCurve25519À´Éú³ÉÃÜÔ¿¡£
https://unit42.paloaltonetworks.com/bluesky-ransomware/
6¡¢KasperskyÐû²¼¹ØÓÚ¶ñÒâÈí¼þVileRATµÄ·ÖÎö³ÂËß
8ÔÂ10ÈÕ£¬KasperskyÐû²¼³ÂËß³ÆDeathStalkerÔÚ2022Äê¼ÌÐøÊ¹ÓÃVileRAT¹¥»÷È«ÇòµÄ¼ÓÃÜ»õ±Ò½»Ò×·þÎñ¡£VileRATÊÇÒ»¸ö¾¹ý»ìÏýºÍ´ò°üµÄPython3 RAT£¬¾ßÓÐÖ´ÐÐÈÎÒâÔ¶³ÌÃüÁî¡¢¼üÅ̼ǼºÍ´ÓC2·þÎñÆ÷×ÔÎÒ¸üеȹ¦Ð§£¬ÔÚ2020ÄêQ2Ê״α»·¢ÏÖ¡£ÖµµÃ×¢ÒâµÄÊÇ£¬Æù½ñΪֹ£¬Ñо¿ÈËÔ±ÒѾȷ¶¨ÁËÊý°Ù¸öÓëVileRATѬȾÁ´Ïà¹ØµÄÓò¡£2021Äê8ÔÂÖÁ½ñ£¬ÔÚ±£¼ÓÀûÑÇ¡¢ÈûÆÖ·˹¡¢µÂ¹ú¡¢¸ñÁÖÄɶ¡Ë¹¡¢¿ÆÍþÌØ¡¢Âí¶úËû¡¢°¢À²®ÁªºÏÇõ³¤¹úºÍ¶íÂÞ˹Áª°î·¢ÏÖÁË10¸ö±»Ñ¬È¾Ä¿±ê¡£
https://securelist.com/vilerat-deathstalkers-continuous-strike/107075/