Ó¢¹úÕþ¸®³Ð°üÉÌMPD FMÊý¾Ý¿âÅäÖôíÎóй¶Ա¹¤ÐÅÏ¢
Ðû²¼Ê±¼ä 2023-08-141¡¢Ó¢¹úÕþ¸®³Ð°üÉÌMPD FMÊý¾Ý¿âÅäÖôíÎóй¶Ա¹¤ÐÅÏ¢
¾ÝýÌå8ÔÂ12ÈÕ±¨µÀ£¬Ñо¿ÈËÔ±·¢ÏÖÁËÒ»¸ö¹ûÈ»µÄAmazon S3´æ´¢¿â£¬Ì»Â¶ÁË16000¶à¸öÃô¸ÐµÄÎĵµ¡£¾ÝÍƶϣ¬ÕâЩÐÅÏ¢ÊôÓÚMDP FM£¬ËüÊÇÒ»¼ÒΪӢ¹úNHSºÍË°Îñº£¹Ø×ÜÊðµÈ¶à¸öÕþ¸®»ú¹¹Ìṩ·þÎñµÄÉèÊ©¹ÜÀíºÍÄþ¾²¹«Ë¾¡£Ð¹Â¶µÄÎļþÉæ¼°´óÁ¿Ô±¹¤ÐÅÏ¢£¬°üÂÞ»¤ÕÕ¡¢Ç©Ö¤¡¢Éí·ÝÖ¤¡¢¼ÝʻִÕÕ¡¢ÊÂÇéºÏͬ¡¢µØÖ·Ö¤Ã÷ºÍÒøÐжÔÕ˵¥µÈ¡£Ä¿Ç°£¬ÕâЩÊý¾ÝÒѱ»±£»¤ÆðÀ´£¬µ«ÊÇMPD FMÉÐδ¶Ô´Ëʼþ×ö³ö»Ø¸´¡£
https://securityaffairs.com/149440/security/mpd-fm-data-leak.html
2¡¢¸£ÌغÍÁÖ¿ÏÆû³µÊ¹ÓõÄSYNC3ϵͳ´æÔÚ»º³åÇøÒç³ö©¶´
¾Ý8ÔÂ12ÈÕ±¨µÀ£¬¸£ÌØ͸¶£¬¸£ÌغÍÁֿϲ¿ÃųµÐÍʹÓõÄSYNC3ϵͳ´æÔÚ»º³åÇøÒç³ö©¶´£¬¿ÉÄܵ¼ÖÂÔ¶³ÌÖ´ÐдúÂ룬µ«²»»áÓ°Ïì¼ÝÊ»Äþ¾²¡£SYNC3ÊÇÒ»¿îÏÖ´úÐÅÏ¢ÓéÀÖϵͳ£¬Ö§³Ö³µÔØWiFiÈȵ㡢µç»°Á¬½Ó¡¢ÓïÒôÃüÁîºÍµÚÈý·½Ó¦Ó÷¨Ê½µÈ¡£¸Ã©¶´£¨CVE-2023-29468£©Î»ÓÚÆû³µÐÅÏ¢ÓéÀÖϵͳÖм¯³ÉµÄWiFi×ÓϵͳµÄWL18xx MCPÇý¶¯·¨Ê½ÖУ¬ÔÚWiFi·¶Î§ÄڵĹ¥»÷Õß¿ÉʹÓÃÌØÖÆÖ¡´¥·¢»º³åÇøÒç³ö¡£¸£ÌØÔÊÐí½«ºÜ¿ìÍƳö²¹¶¡£¬¹©Óû§Í¨¹ýUSBÏÂÔغͰ²×°¡£
https://www.bleepingcomputer.com/news/security/ford-says-cars-with-wifi-vulnerability-still-safe-to-drive/
3¡¢ÄÏ·ÇijµçÁ¦¹«Ë¾Ôâµ½ÀûÓÃSystemBC±äÌåDroxiDatµÄ¹¥»÷
KasperskyÔÚ8ÔÂ10ÈÕ³ÆÆä·¢ÏÖÁËÀûÓÃDroxiDatÕë¶ÔÄÏ·ÇijµçÁ¦¹«Ë¾µÄ¹¥»÷»î¶¯¡£¹¥»÷·¢ÉúÔÚ3ÔÂÖÐÑ®£¬DroxiDatÊÇSystemBCµÄÒ»¸öÔ¼8kbµÄ¾«¼ò°æ±äÌ壬¿É×÷Ϊϵͳ·ÖÎöÆ÷ºÍ¼òµ¥µÄÖ§³ÖSOCKS5µÄ»úÆ÷ÈË¡£ÖµµÃ×¢ÒâµÄÊÇ£¬Cobalt Strike beaconºÍDroxiDatÒ»Æð±»²¿Êð£¬Òò´ËÑо¿ÈËÔ±ÍƲâ¸Ãʼþ´¦ÓÚÀÕË÷¹¥»÷µÄ³õʼ½×¶Î¡£´Ë´Î¹¥»÷ÖÐC2»ù´¡ÉèÊ©µÄÒ»¸öÉæ¼°ÄÜÔ´µÄÓòÃûËù½âÎö³öµÄIP£¬ÔÚ¼¸ÄêÇ°Ôø±»ÓÃ×÷APT»î¶¯£¬Õâ±íÃ÷¸Ãʼþ¿ÉÄÜÊÇAPT¹¥»÷»î¶¯¡£
https://securelist.com/focus-on-droxidat-systembc/110302/
4¡¢¼ÓÄôóADSC¹«Ë¾µÄϵͳ±»ºÚ½ü150ÍòÈ˵ÄÐÅϢй¶
8ÔÂ11ÈÕ±¨µÀ³Æ£¬°¬²®ËþÊ¡ÑÀ¿Æ·þÎñ¹«Ë¾£¨ADSC£©Ð¹Â¶ÁË147Íò¹«ÃñµÄ¸öÈËÐÅÏ¢¡£ADSCÓë°¬²®ËþÊ¡Õþ¸®ºÏ×÷£¬Îª¹«ÃñÌṩÑÀ¿Æ·þÎñ¡£7ÔÂ9ÈÕ£¬ADSC·¢ÏÖ¹¥»÷Õß»ñµÃÁ˲¿ÃÅ»ù´¡ÉèÊ©µÄ·ÃÎÊȨÏÞ£¬°²×°¶ñÒâÈí¼þ£¬²¢¼ÓÃÜÁ˲¿ÃÅͳºÍÊý¾Ý¡£ÊÓ²ìÈ·¶¨¹¥»÷·¢ÉúÓÚ5ÔÂ7ÈÕÖÁ7ÔÂ9ÈÕ£¬¹¥»÷ÕßÔÚ²¿Êð¶ñÒâÈí¼þ֮ǰ·ÃÎʲ¢ÇÔÈ¡ÁËÍøÂçÖеIJ¿ÃÅÊý¾Ý¡£Ð¹Â¶ÐÅÏ¢°üÂÞÐÕÃû¡¢µØÖ·ÒÔ¼°²¿ÃÅ¿Í»§µÄÒøÐÐÐÅÏ¢¡£
https://www.databreaches.net/nearly-1-5-million-affected-by-data-breach-at-alberta-dental-service-corporation/
5¡¢Ö´·¨»ú¹¹²é·âLolek HostedµÄ·þÎñÆ÷²¢´þ²¶5ÃûÏÓÒÉÈË
ýÌå8ÔÂ12Èճƣ¬Å·ÃÀÖ´·¨»ú¹¹Òѵ·»Ùbulletproof hosting·þÎñÌṩÉÌLolek Hosted¡£Å·ÖÞÐ̾¯×é֯͸¶£¬5Ãû¹ÜÀíÈËÔ±±»²¶£¬ËùÓзþÎñÆ÷±»²é·â£¬LolekHosted.netÒѲ»ÔÙ¿ÉÓᣲ¨À¼¾¯·½³Æ£¬ËûÃDzé»ñÁËÊý°Ų̀ÔØÓÐÊýTBÊý¾ÝµÄ·þÎñÆ÷¡¢¼ÆËã»úÉ豸ºÍÊÖ»ú¡£Lolek±»Ðû´«Îª¡°100%Òþ˽Íйܡ±·þÎñ£¬±»ÖÖÖÖÍøÂç¹¥»÷ÕßʹÓ᣾ݳƣ¬Lolek Hosted»¹ÐÖúÁËԼĪ50ÆðNetWalkerÀÕË÷¹¥»÷¡£
https://thehackernews.com/2023/08/lolek-bulletproof-hosting-servers.html
6¡¢ESETÅû¶Õë¶Ôפ°×¶íÂÞ˹´óʹ¹Ý³¤´ïÊýÄêµÄ¼äµý»î¶¯
8ÔÂ10ÈÕ£¬ESETÅû¶ÁËMoustachedBouncerÕë¶Ôפ°×¶íÂÞ˹´óʹ¹Ý³¤´ïÊýÄêµÄ¼äµý»î¶¯¡£MoustchedBouncerÖÁÉÙ´Ó2014Ä꿪ʼÔËÓª¡£¹¥»÷Õß¿ÉÄÜʹÓÃÁËSORMµÈºÏ·¨À¹½ØϵͳÀ´Ö´ÐÐAitM¹¥»÷£¬²¢·Ö·¢¶ñÒâÈí¼þNightClubºÍDiscoµÈ¡£ÕâÁ½¸ö¶ñÒâÈí¼þ¶¼Ö§³ÖÆäËü¼äµý²å¼þ£¬°üÂÞÆÁÄ»½Øͼ·¨Ê½¡¢Â¼Òô»úºÍÎļþÇÔÈ¡·¨Ê½¡£ESETÒÑÈ·¶¨ÓÐ4¸ö¹ú¼ÒµÄ´óʹ¹ÝÊܵ½´Ë´Î»î¶¯µÄÓ°Ï죬ÆäÖÐÁ½¸öÀ´×ÔÅ·ÖÞ£¬Ò»¸öÀ´×ÔÄÏÑÇ£¬Ò»¸öÀ´×Ô·ÇÖÞ¡£
https://www.welivesecurity.com/en/eset-research/moustachedbouncer-espionage-against-foreign-diplomats-in-belarus/