ÃϼÓÀ­¹úijÕþ¸®ÍøÕ¾ÅäÖôíÎóй¶Êý°ÙÍò¹«ÃñµÄÐÅÏ¢

Ðû²¼Ê±¼ä 2023-07-10

1¡¢ÃϼÓÀ­¹úijÕþ¸®ÍøÕ¾ÅäÖôíÎóй¶Êý°ÙÍò¹«ÃñµÄÐÅÏ¢


¾ÝýÌå7ÔÂ7ÈÕ±¨µÀ £¬ÃϼÓÀ­¹úijÕþ¸®ÍøÕ¾Ð¹Â¶ÁËÊý°ÙÍò¹«ÃñµÄ¸öÈËÐÅÏ¢ £¬Éæ¼°ÐÕÃû¡¢µç»°ºÅÂë¡¢µç×ÓÓʼþµØÖ·ºÍÉí·ÝÖ¤ºÅÂëµÈ ¡£Ñо¿ÈËÔ±ÓÚ6ÔÂ27ÈÕÊ״η¢ÏÖÁ˸ÃÎÊÌâ £¬²¢ÁªÏµÁËÃϼÓÀ­¹úµç×ÓÕþÎñ¼ÆËã»úʼþÏìӦС×é(CERT) ¡£¾ÝϤ £¬Ð¹Â¶µÄÊý¾Ý·ºÆðÔÚÓëSQL´íÎóÏà¹ØµÄGoogle²éѯ½á¹ûÖÐ ¡£Ñо¿ÈËÔ±²¢Î´Í¸Â¶¸ÃÕþ¸®ÍøÕ¾µÄ¾ßÌåÃû³Æ £¬ÒòΪÕâЩÊý¾ÝÈÔ¿ÉÔÚÏß»ñÈ¡ ¡£Ä¿Ç° £¬Ã»ÓÐÈκÎÃϼÓÀ­¹úÕþ¸®×éÖ¯¶Ô´ËÊÂ×ö³ö»ØÓ¦ ¡£


https://techcrunch.com/2023/07/07/bangladesh-government-website-leaks-citizens-personal-data/


2¡¢TA453ͨ¹ýÐÂѬȾÁ´°²×°PowerShellºóÃÅGorjolEcho 


ProofpointÓÚ7ÔÂ6ÈÕÅû¶ÁËÒÁÀʺڿÍÍÅ»ïTA453Õë¶ÔWindowsºÍmacOSµÄ¶ñÒâÈí¼þ»î¶¯ ¡£TA453ÓÚ5Ô·ݿªÊ¼Ê¹ÓÃLNKѬȾÁ´ £¬¶ø²»ÊÇ´øÓкêµÄMicrosoft WordÎĵµ ¡£´Ë´Î»î¶¯ÖÐ £¬¹¥»÷Õßαװ³É»Ê¼ÒÁªºÏ¾üÖÖÑо¿Ëù(RUSI)µÄ¸ß¼¶Ñо¿Ô± £¬Õë¶ÔÒ»¼ÒרעÓÚÍâ½»ÊÂÎñµÄÃÀ¹úÖÇ¿âµÄºËÄþ¾²×¨¼Ò ¡£¹¥»÷ÕßʹÓÃÖÖÖÖÔÆÍйÜÌṩÉÌÀ´ÌṩеÄѬȾÁ´ £¬Ö¼ÔÚ°²×°ÐÂÐÍPowerShellºóÃÅGorjolEcho ¡£´ËÍâ £¬TA453»¹ÒÆÖ²ÁËÆä¶ñÒâÈí¼þ £¬²¢ÊÔͼÆô¶¯Ò»¸öÃûΪNokNokµÄÕë¶ÔmacOSµÄѬȾÁ´ ¡£


https://www.proofpoint.com/us/blog/threat-insight/welcome-new-york-exploring-ta453s-foray-lnks-and-mac-malware


3¡¢MastodonÐÞ¸´¿Éµ¼Ö·þÎñÆ÷½Ù³ÖµÄ©¶´TootRoot


¾Ý7ÔÂ7ÈÕ±¨µÀ £¬¿ªÔ´µÄÈ¥ÖÐÐÄ»¯Éç½»ÍøÂçÆ½Ì¨MastodonÐÞ¸´ÁË4¸öÄþ¾²Â©¶´ ¡£ÆäÖÐ×îÑÏÖØµÄÊÇMastodonýÌå´¦ÖôúÂëÖеÄ©¶´TootRoot£¨CVE-2023-36460£© £¬¿Éµ¼ÖÂDoSºÍÈÎÒâÔ¶³Ì´úÂëÖ´ÐеÈÎÊÌâ £¬¿ÉÓÃÓÚÔÚ·þÎñÆ÷ÖÐÖ²ÈëºóÃÅ ¡£¹¥»÷ÕßÀûÓøÃ©¶´ £¬Äܹ»ÎÞÏÞÖÆµØ¿ØÖÆ·þÎñÆ÷¼°ÆäÍйܺ͹ÜÀíµÄÊý¾Ý ¡£µÚ¶þ¸öÊÇXSS©¶´£¨CVE-2023-36459£© £¬¿ÉÈÆ¹ýÄ¿±êä¯ÀÀÆ÷ÉϵÄHTMLÇåÀí ¡£ÁíÍâÁ½¸ö©¶´ÊÇCVE-2023-36461ºÍCVE-2023-36462 ¡£


https://www.bleepingcomputer.com/news/security/critical-tootroot-bug-lets-attackers-hijack-mastodon-servers/


4¡¢¼ÓÃÜ»õ±Òƽ̨MultichainÔâµ½¹¥»÷ËðʧÁè¼Ý1.25ÒÚÃÀÔª


ýÌå7ÔÂ8ÈÕ±¨µÀ³Æ £¬¼ÓÃÜ»õ±Òƽ̨MultichainÒÑÔÝÍ£Æä·þÎñ £¬ÒòΪËüÕýÔÚÊÓ²ìÉæ¼°Áè¼Ý1.25ÒÚÃÀÔªµÄ¼ÓÃÜ»õ±Ò±»µÁʼþ ¡£ÉÏÖÜËÄÍí¼ä £¬¸Ã¹«Ë¾ÌåÏÖ £¬Æ½Ì¨²¿ÃÅ×ʲú¡°ÒÑÒì³£×ªÒÆÖÁδ֪µØÖ·¡± £¬²¢ÔÚ¼¸Ð¡Ê±ºóÔÝÍ£ÁËËùÓзþÎñÒÔ½øÐÐÊÓ²ì ¡£ÖÜÎåÔçÉÏ £¬¸Ã¹«Ë¾Ðû²¼ÉùÃ÷È·ÈÏËûÃÇÔâµ½Á˺ڿ͹¥»÷ £¬²¢ÌåÏÖ½«»áÍË¿î¸ø¸÷ÈË ¡£Óд«ÑԳƴ˴ι¥»÷Êǰ×ñºÚ¿ÍËùΪ £¬µ«Éв»Çå³þÕâЩ˵·¨ÊÇ·ñ׼ȷ ¡£


https://therecord.media/millions-stolen-from-multichain-crypto


5¡¢Google PlayÖеÄÁ½¿î¼äµýÈí¼þÇÔÈ¡150ÍòÓû§µÄÐÅÏ¢


7ÔÂ8ÈÕ±¨µÀ³Æ £¬PradeoÔÚGoogle PlayÉ̵êÖз¢ÏÖÁËÁ½¿î¶ñÒâÓ¦Óà £¬Òþ²Ø×żäµýÈí¼þ²¢¼àÊÓ¶à´ï150ÍòÓû§ ¡£ÕâÁ½¸öÓ¦Ó÷¨Ê½¶¼ÊÇÀ´×Ôͬһ¿ª·¢É̵ÄÎļþ¹ÜÀíÓ¦Óà £¬·Ö±ðÊǰ²×°Á¿Áè¼Ý100ÍòµÄÎļþ»Ö¸´ºÍÊý¾Ý»Ö¸´Ó¦ÓúͰ²×°Á¿Áè¼Ý50ÍòµÄÎļþ¹ÜÀíÆ÷ ¡£Á½¿îÓ¦ÓûáÇÔÈ¡ÁªÏµÈËÁÐ±í¡¢Ã½ÌåÎļþ¡¢ÊµÊ±Î»ÖúÍÒÆ¶¯¹ú¼Ò´úÂëµÈÐÅÏ¢ ¡£Ñо¿ÈËÔ±×¢Òâµ½ £¬ÕâЩӦÓöÔÊÕ¼¯µ½µÄÊý¾ÝÖ´ÐÐÁËÒ»°Ù¶à´Î´«Êä £¬Õâ¶ÔÓÚ¼äµýÈí¼þÀ´ËµÊDz»Ñ°³£µÄ ¡£


https://thehackernews.com/2023/07/two-spyware-apps-on-google-play-with-15.html


6¡¢Î¢ÈíÐû²¼¹ØÓÚÀÕË÷Èí¼þBlackByteµÄ¹¥»÷Á´µÄÊÓ²ì³ÂËß


7ÔÂ6ÈÕ £¬Î¢ÈíÐû²¼¹ØÓÚÀÕË÷Èí¼þBlackByteµÄ·ÖÎö³ÂËß ¡£Ñо¿ÈËÔ±×î½ü¶ÔÒ»´ÎÈëÇÖµÄÊÓ²ìÖÐ £¬·¢ÏÖ¹¥»÷ÕßÔÚ²»µ½ÎåÌìµÄʱ¼äÀïÍê³ÉÁË´Ó³õʼ·ÃÎʵ½ÊµÊ©Õû¸ö¹¥»÷Á´ ¡£ÔÚÕâÎåÌìÄÚ £¬¹¥»÷ÕßʹÓÃÁËһϵÁй¤¾ßºÍ¼¼Êõ £¬×îÖÕ°²×°ÁËBlackByte 2.0À´ÊµÏÖÆäÄ¿±ê ¡£ÕâЩ¼¼Êõ°üÂÞ£ºÀûÓÃδ´ò²¹¶¡µÄExchange·þÎñÆ÷¡¢Ê¹ÓÃliving-off-the-land¹¤¾ß½øÐг־ÃÐÔºÍÕì²ì¡¢²¿ÊðÓÃÓÚC2µÄCobalt StrikeÐűêÒÔ¼°²¿Êð¶¨ÖƵÄÊý¾ÝÊÕ¼¯ºÍÉøÍ¸¹¤¾ßµÈ ¡£


https://www.microsoft.com/en-us/security/blog/2023/07/06/the-five-day-job-a-blackbyte-ransomware-intrusion-case-study/