̨»ýµç͸¶Æ乩ӦÉÌÔâµ½¹¥»÷±»LockBitÀÕË÷7000ÍòÃÀÔª

Ðû²¼Ê±¼ä 2023-07-03

1¡¢Ì¨»ýµç͸¶Æ乩ӦÉÌÔâµ½¹¥»÷±»LockBitÀÕË÷7000ÍòÃÀÔª


¾ÝýÌå7ÔÂ1ÈÕ±¨µÀ£¬LockBitÉù³ÆÒÑÈëÇÖÖйų́ÍåоƬÖÆÔìÉĮ̀»ýµç(TSMC)£¬²¢ÀÕË÷7000ÍòÃÀÔªÊê½ð ¡£Ì¨»ýµçÊÇÈ«Çò×î´óµÄоƬºÏÔ¼ÖÆÔìÉÌ£¬ÎªÆ»¹ûºÍ¸ßͨµÈ¿Æ¼¼¾ÞÍ·ÌṩоƬ ¡£Ì¨»ýµç·ñÈÏÆäÔâµ½ºÚ¿Í¹¥»÷£¬²¢ÌåÏÖÊÇËûÃǵÄITÓ²¼þ¹©Ó¦ÉÌÖ®Ò»Kinmax TechnologyµÄϵͳÔâµ½¹¥»÷ ¡£Kinmax͸¶ËüÓÚ6ÔÂ29ÈÕÒâʶµ½¹¥»÷»î¶¯£¬²¿ÃÅÐÅϢй¶£¬Ö÷ÒªÉæ¼°¿Í»§µÄϵͳ°²×°ºÍÅäÖÃÖ¸µ¼ ¡£ÒòΪKinmax²¢²»ÊÇ̨»ýµçÄÇÑùµÄ¾ÞÍ·£¬Òò´ËLockBit 7000ÍòÃÀÔªÊê½ðµÄÒªÇó¿ÉÄܻᱻºöÂÔ ¡£


https://www.bleepingcomputer.com/news/security/tsmc-denies-lockbit-hack-as-ransomware-gang-demands-70-million/


2¡¢AvastÐû²¼Windows°æ±¾µÄAkiraÀÕË÷Èí¼þÃâ·Ñ½âÃÜÆ÷


¾Ý7ÔÂ1ÈÕ±¨µÀ£¬Äþ¾²¹«Ë¾AvastÐû²¼ÁËAkiraÀÕË÷Èí¼þµÄÃâ·Ñ½âÃÜÆ÷£¬ÎÞÐèÖ§¸¶Êê½ð¼´¿É»Ö¸´Êý¾Ý ¡£AkiraÓÚ3ÔÂÊ״ηºÆ𠣬²¢ÒòÕë¶ÔÈ«Çò¸÷¸öÁìÓòµÄ×éÖ¯¶øÃûÉù´óÔë ¡£6Ô£¬Akira¿ªÊ¼·Ö·¢ÆäÕë¶ÔVMware ESXiÐéÄâ»úµÄLinux±äÌå ¡£AvastÐû²¼ÁËÁ½¸ö°æ±¾µÄAkira½âÃÜÆ÷£¬Ò»ÖÖÊÊÓÃÓÚ64λWindows¼Ü¹¹£¬ÁíÒ»¸öÊÊÓÃÓÚ32λ ¡£Ëü½¨ÒéʹÓÃ64λ°æ±¾£¬ÒòΪÆƽâÃÜÂëÐèÒª´óÁ¿µÄϵͳÄÚ´æ ¡£¸ÃÄþ¾²¹«Ë¾Ã»ÓнâÊÍËüÊÇÈçºÎÆƽâAkiraµÄ£¬µ«¿ÉÄÜÀûÓÃÁËÀÕË÷Èí¼þµÄ²¿ÃÅÎļþ¼ÓÃÜÒªÁì ¡£


https://securityaffairs.com/148007/cyber-crime/akira-ransomware-decryptor.html


3¡¢Ñо¿ÈËÔ±·¢ÏÖÀûÓÃWP²å¼þUltimate Member©¶´µÄ¹¥»÷


ýÌå7ÔÂ2Èճƣ¬Ñо¿ÈËÔ±·¢ÏÖÀûÓÃWordPress²å¼þUltimate MemberÖеÄ©¶´µÄ¹¥»÷»î¶¯£¬¸Ã²å¼þÒѱ»°²×°Áè¼Ý200000´Î ¡£Â©¶´×·×ÙΪCVE-2023-3460£¬CVSSÆÀ·Ö9.8£¬Ó°ÏìÁË°üÂÞ×îа汾v2.6.6ÔÚÄÚµÄËùÓÐUltimate Member°æ±¾ ¡£¹¥»÷Õß¿ÉÒÔÀûÓôË©¶´´´½¨¾ßÓйÜÀíȨÏÞµÄÐÂÓû§ÕÊ»§£¬´Ó¶øÍêÈ«¿ØÖÆÍøÕ¾ ¡£ÓÉÓڸ鶴ÉÐδÐÞ¸´ÇÒºÜÈÝÒ×±»ÀûÓã¬Ñо¿ÈËÔ±½¨ÒéÁ¢¼´Ð¶ÔØUltimate Member²å¼þ ¡£


https://securityaffairs.com/148030/hacking/wordpress-ultimate-member-plugin-attacks.html


4¡¢VolexityÅû¶APT35ºóÃÅPOWERSTARµÄ¸üа汾µÄϸ½Ú


VolexityÔÚ6ÔÂ28ÈÕÅû¶ÁËAPT35£¨ÓÖÃûCharming Kitten£©ºóÃÅPOWERSTARµÄ¸üа汾 ¡£¹¥»÷ÕßÔöÇ¿ÁËPOWERSTARµÄ·´·ÖÎö´ëÊ© ¡£2021Äê¼ì²âµ½µÄµÍ¼¶°æ±¾Ê¹ÓÃDOCMÎļþÖÐǶÈëµÄ¶ñÒâºê·Ö·¢£¬¶øÔÚ½ñÄê5ÔµĹ¥»÷»î¶¯ÖÐÀûÓÃÁËÊÜÃÜÂë± £»¤µÄRARÎļþÄÚµÄLNKÎļþ£¬´ÓBackblazeÏÂÔغóÃÅ ¡£´ËÍ⣬½ü¼¸¸öÔÂÀ´£¬¸ÃÍŻﻹÓÃ˽ÓÐÍйܻù´¡ÉèÊ©BackblazeºÍIPFSÈ¡´úÁËËûÃÇ֮ǰµÄÔÆÍйÜÌṩÉÌ£¨OneDrive¡¢AWS S3ºÍDropbox£© ¡£


https://www.volexity.com/blog/2023/06/28/charming-kitten-updates-powerstar-with-an-interplanetary-twist/


5¡¢MITRE¹ûÈ»2023ÄêCWE 25¸ö×îΣÏÕµÄÈí¼þ©¶´µÄÇåµ¥


6ÔÂ29ÈÕ£¬MITRE¹ûÈ»ÁË2023ÄêCWE 25¸ö×îΣÏÕµÄÈí¼þ©¶´µÄÇåµ¥ ¡£MITRE·ÖÎöÁËNIST¹ú¼Ò©¶´Êý¾Ý¿â£¨NVD£©ÖеÄ43996¸öCVE£¬¼´2021ÄêºÍ2022ÄêÆڼ䷢ÏֺͳÂËߵĩ¶´£¬Æ¾¾ÝÆäÑÏÖØÐÔºÍÆÕ±éÐÔ¶Ôÿ¸ö©¶´½øÐÐÁËÆÀ·Ö£¬´Ó¶ø´´½¨Á˸ÃÁбí ¡£ÆäÖÐ×îΪÑÏÖصÄÊÇÔ½½çдÈë¡¢ÍøÒ³Éú³ÉÆÚ¼äÊäÈëµÄ²»ÕýÈ·Öкͣ¨¿çÕ¾½Å±¾£©¡¢SQLÃüÁîÖÐʹÓõÄÌØÊâÔªËصIJ»ÕýÈ·Öкͣ¨SQL×¢È룩ºÍÊͷźóʹÓ鶴µÈ ¡£


https://cwe.mitre.org/top25/


6¡¢ElasticÐû²¼Õë¶ÔmacOSµÄRustBucketбäÌåµÄ·ÖÎö³ÂËß


6ÔÂ29ÈÕ£¬ElasticÐû²¼³ÂËߣ¬Åû¶ÁËÕë¶ÔmacOSµÄRustBucketбäÌå ¡£Ñо¿ÈËÔ±·¢ÏÖÁËRustBucketϵÁÐÖÐÒÔǰûÓеij־ÃÐÔ¹¦Ð§£¬²¢ÈÏΪ¸ÃϵÁÐÕýÔÚ»ý¼«¿ª·¢ÖÐ ¡£´ËÍ⣬½ØÖÁÄ¿Ç°£¬¸ÃбäÖÖÔÚVirusTotalÉϵļì²âÂÊΪÁ㣬²¢ÀûÓö¯Ì¬ÍøÂç»ù´¡ÉèÊ©µÄÒªÁì½øÐÐC2 ¡£¹¥»÷µÄµÚÒ»½×¶Î£¬»áÖ´ÐÐÒ»¸öAppleScript£¬Æô¶¯Ê¹ÓÃcURL´ÓC2ÏÂÔصڶþ½×¶ÎpayloadµÄ¶þ½øÖÆÎļþ ¡£µÚ¶þ½×¶Î¶þ½øÖÆÎļþ(.pd)ÓÃSwift±àÒ룬´ÓC2ÏÂÔØÖ÷Òª¶ñÒâÈí¼þ ¡£µÚÈý½×¶ÎµÄ¶ñÒâÈí¼þÊÇÒ»¸öFAT macOS¶þ½øÖÆÎļþ ¡£


https://www.elastic.co/cn/security-labs/DPRK-strikes-using-a-new-variant-of-rustbucket