VulnCheckÅû¶ӰÏì90¶àÍǫ̀MikroTikÉ豸µÄÌáȨ©¶´
Ðû²¼Ê±¼ä 2023-07-271¡¢VulnCheckÅû¶ӰÏì90¶àÍǫ̀MikroTikÉ豸µÄÌáȨ©¶´
VulnCheckÔÚ7ÔÂ25ÈÕÅû¶ÁËMikroTik RouterOS·ÓÉÆ÷µÄÖеÄÌáȨ©¶´£¨CVE-2023-30799£©¡£¸Ã©¶´¿É±»ÓµÓйÜÀíÔ±ÕÊ»§µÄÔ¶³Ì¹¥»÷Õßͨ¹ýÉ豸µÄWinbox»òHTTP½Ó¿Ú£¬½«È¨ÏÞÌáÉýΪ³¬¼¶¹ÜÀíÔ±¡£ÕâÊÇÒòΪMikrotik RouterOS²Ù×÷ϵͳÎÞ·¨·ÀÖ¹ÃÜÂëµÄ±©Á¦¹¥»÷£¬¶øÇÒ»¹×Ô´øÄ¬ÈÏ"admin"Óû§¡£Ô¤¼ÆÔ¼ÓÐ50ÍòºÍ90Íò¸öRouterOSÏµÍ³ÃæÁÙͨ¹ýWebºÍWinbox½Ó¿Ú±»ÀûÓõķçÏÕ¡£Ñо¿ÈËÔ±½¨ÒéÓû§¾¡¿ìÓ¦ÓÃ×îиüÐÂÀ´ÐÞ¸´¸Ã©¶´¡£
https://vulncheck.com/blog/mikrotik-foisted-revisited
2¡¢ºÚ¿ÍÔÚ°µÍø³öÊÛÉù³Æ´Ó°£¼°ÎÀÉú²¿ÇÔÈ¡µÄ200ÍòÌõ¼Ç¼
ýÌå7ÔÂ25ÈÕ±¨µÀ³Æ£¬Ä³ºÚ¿ÍÍÅ»ïÉù³Æ´Ó°£¼°ÎÀÉúºÍÈ˿ڲ¿ÃÅÇÔÈ¡ÁËÁ½°ÙÍòÌõ¼Ç¼¡£Ñо¿ÈËÔ±ÓÚ7ÔÂ25ÈÕÔÚºÚ¿ÍÂÛ̳Pop¨¹rlerÉÏ·¢ÏÖÁËÕâÒ»Ìû×Ó¡£¾Ý³Æ£¬¸ÃÊý¾Ý¿â°üÂÞ»¼ÕߵĸöÈËÐÅÏ¢£¬Éæ¼°ÐÕÃû¡¢ID¡¢µç»°¡¢µØÖ·¡¢ÊÖÊõ·ÖÀàÏêÇé¡¢Õï¶ÏºÍÖÎÁÆÏêϸÐÅÏ¢µÈ¡£´ËÍ⣬ºÚ¿Í»¹ÌṩÁË1000È˵ÄÊý¾Ý×÷ΪÑù±¾£¬À´Ö§³ÖÕâһ˵·¨¡£ÕâÃûºÚ¿Í»¹ÔÚÉÏÖܳöÊÛÁËÊôÓÚÓ¡¶ÈÄáÎ÷ÑÇʵÌåµÄÊý¾Ý¿â¡£
https://www.infosecurity-magazine.com/news/hacker-stolen-medical-records/
3¡¢SentinelOne·¢ÏÖMac¶ñÒâÈí¼þRealstµÄ´ó¹æÄ£¹¥»÷»î¶¯
7ÔÂ25ÈÕ£¬SentinelOne³ÆÆä·¢ÏÖÁËMac¶ñÒâÈí¼þRealstµÄ´ó¹æÄ£¹¥»÷»î¶¯¡£Ñо¿ÈËÔ±·ÖÎöÁË59¸ö RealstÑù±¾£¬·¢ÏÖһЩÑù±¾ÒѾÕë¶ÔApple¼´½«Ðû²¼µÄ²Ù×÷ϵͳ°æ±¾macOS 14 Sonoma¡£¶ñÒâÈí¼þͨ¹ýαÔìµÄÓÎÏ·ÍøÕ¾·Ö·¢£¬ÒÔPKG°²×°·¨Ê½»òDMG´ÅÅÌÎļþµÄÐÎʽÕë¶ÔMacÉ豸£¬ÆäÖаüÂÞ¶ñÒâMach-OÎļþ£¬µ«Ã»ÓÐÕæÕýµÄÓÎÏ·»òÆäËüÓÕ¶üÈí¼þ¡£´ËÍ⣬ÓÉÓÚÕâЩÓÎÏ·Õë¶ÔµÄÊǼÓÃÜ»õ±ÒÓû§£¬Òò´ËÆäÖ÷ҪĿµÄ¿ÉÄÜÊÇÇÔÈ¡¼ÓÃÜÇ®°ü¼°ÆäÄÚµÄ×ʽð¡£
https://www.sentinelone.com/blog/apple-crimeware-massive-rust-infostealer-campaign-aiming-for-macos-sonoma-ahead-of-public-release/
4¡¢FortinetÔÚMicrosoftÏûÏ¢ÐÐÁзþÎñÖз¢ÏÖ¶à¸ö©¶´
FortinetÓÚ7ÔÂ24ÈÕ³ÆÆäÔÚMicrosoftÏûÏ¢ÐÐÁÐ(MSMQ)·þÎñÖз¢ÏÖÁ˶à¸ö©¶´£¬¿ÉÄܻᵼÖÂÔ¶³Ì´úÂëÖ´ÐкÍDoS¹¥»÷¡£ÆäÖаüÂÞÔÚÏûϢͷ½âÎö·¨Ê½ÖзÃÎÊijЩҪº¦º¯Êý֮ǰδÑéÖ¤µ¼ÖµÄÔ½½ç¶Áȡ©¶´£¬Î´ÑéÖ¤ÈÎÒâ¾ÞϸµÄÏûϢͷµ¼ÖµÄÔ½½çдÈë©¶´£¬ÒÔ¼°CompoundMessageͷδÄÜ¶ÔÆäÊý¾Ý½á¹¹½øÐÐÕýÈ·ÐÔ¼ì²éµ¼ÖµÄÔ½½çдÈë©¶´¡£Ä¿Ç°£¬Î¢ÈíÒÑÔÚ4ÔºÍ7ÔµÄÄþ¾²¸üÐÂÐÞ¸´ÁËÕâЩ©¶´¡£
https://www.fortinet.com/blog/threat-research/microsoft-message-queuing-service-vulnerabilities
5¡¢Èí¼þ¹«Ë¾OrtivusÔâµ½¹¥»÷Ó°ÏìÓ¢¹ú¾È»¤³µ·þÎñ»ú¹¹
¾Ý7ÔÂ26ÈÕ±¨µÀ£¬ÈðµäÈí¼þ¹«Ë¾OrtivusÔâµ½ÍøÂç¹¥»÷£¬µ¼ÖÂÖÁÉÙÁ½¼ÒÓ¢¹ú¾È»¤³µ·þÎñ»ú¹¹ÎÞ·¨·ÃÎʵç×Ó²¡Àú¡£¹¥»÷·¢ÉúÓÚ7ÔÂ18ÈÕÍíÉÏ£¬Ó°ÏìÁËÆäÍйÜÊý¾ÝÖÐÐÄ»·¾³ÖеÄÓ¢¹ú¿Í»§ÏµÍ³£¬µ¼Öµç×Ó²¡ÀúÎÞ·¨Ê¹Óã¬Ä¿Ç°±»ÆÈʹÓÃÊÖ¶¯ÏµÍ³½øÐд¦Öá£Ortivus³Æ£¬Ìæ´úϵͳÔÚ¹¥»÷·¢Éúºó24СʱÄÚ¾Í×¼±¸ºÃÁË£¬Ã»Óпͻ§ÐÅϢй¶¡£¸Ã¹«Ë¾Ã»ÓÐ͸¶ÊÜÓ°Ïì¾È»¤³µ·þÎñµÄÃû³Æ£¬µ«¾Ý͸¶£¬·Ö±ðÊÇSouth Western Ambulance Service TrustºÍSouth Central Ambulance Service Trust£¬ËüÃÇΪԼ1200Íò³£×¡ÈË¿ÚÌṩ·þÎñ¡£
https://securityaffairs.com/148847/cyber-crime/ambulance-services-cyberattack.html
6¡¢SygniaÏêÊöCasbaneiroÖ÷ÒªÕë¶ÔÄÏÃÀºÍ±±ÃÀµÄ¹¥»÷»î¶¯
7ÔÂ25ÈÕ£¬Sygnia¹ûÈ»ÁËÒøÐÐľÂíCasbaneiro¹¥»÷»î¶¯µÄÏêÇé¡£CasbaneiroÓÚ2018Ê״α»·¢ÏÖ£¬Ö÷ÒªÓÃÓÚ¹¥»÷À¶¡ÃÀÖÞ½ðÈÚÐÐÒµµÄ×éÖ¯¡£ÔÚ×î½üÊӲ쵽µÄ¹¥»÷ÖУ¬¹¥»÷ÊÇÓÉǶÈëHTMLÎļþÁ´½ÓµÄÓã²æÊ½µöÓãÓʼþÆô¶¯µÄ£¬»áÖØ¶¨ÏòÄ¿±ê²¢ÏÂÔØRARÎļþ¡£ÁíÒ»¸ö±ä»¯É漰ʹÓÃfodhelper.exeÀ´ÊµÏÖUACÈÆ¹ý£¬²¢»ñµÃÍêÕûµÄ¼ÆËã»ú¹ÜÀíȨÏÞ¡£¶ÔÉÏ´«µ½VirusTotalµÄÑù±¾½øÐзÖÎö£¬·¢ÏÖËüÃÇÕýÔÚÏòÄÏÃÀºÍ±±ÃÀ¼¯ÖС£
https://blog.sygnia.co/breaking-down-casbaneiro-infection-chain-part2