NCC³Æ½ü2000̨Citrix NetScaler·þÎñÆ÷Òѱ»Ö²ÈëºóÃÅ
Ðû²¼Ê±¼ä 2023-08-171¡¢NCC³Æ½ü2000̨Citrix NetScaler·þÎñÆ÷Òѱ»Ö²ÈëºóÃÅ
¾Ý8ÔÂ16ÈÕ±¨µÀ£¬NCC Group·¢ÏÖÁËCitrix NetScaler©¶´µÄ´ó¹æÄ£ÀûÓû¡£¹¥»÷ÕßÒÔ×Ô¶¯»¯·½Ê½ÀûÓÃÁË©¶´£¨CVE-2023-3519£©£¬ÔÚNetscaler·þÎñÆ÷ÖÐÖ²ÈëÁËWebshell¡£¼´Ê¹NetScalerÒÑ´ò²¹¶¡»òÖØÆô£¬¹¥»÷ÕßÒ²¿ÉÒÔʹÓôËWebshellÖ´ÐÐÈÎÒâÃüÁî¡£Ñо¿ÈËÔ±×ܹ²ÔÚ1952¸ö²îÒìµÄNetScalerÖз¢ÏÖÁË2491¸öWebshell£¬´ó¶àÊýλÓڵ¹ú¡¢·¨¹ú¡¢ÈðÊ¿¡¢ÈÕ±¾ºÍÒâ´óÀûµÈ¹ú¡£½ØÖÁ8ÔÂ14ÈÕ£¬ÈÔÓÐ1828¸öNetScaler´æÔÚºóÃÅ£¬ÆäÖÐÔ¼1248̨ÒѾÕë¶Ô¸Ã©¶´½øÐÐÁËÐÞ¸´¡£
https://thehackernews.com/2023/08/nearly-2000-citrix-netscaler-instances.html
2¡¢´óÁ¿LinkedInÓû§³ÆÆäÕË»§±»½Ù³Ö»òËø¶¨²¿ÃÅÒª½»Êê½ð
¾ÝýÌå8ÔÂ15ÈÕ±¨µÀ£¬CyberintÔÚ×î½ü¼¸ÖÜ·¢ÏÖÁËÒ»³¡Á¬ÐøµÄ¹¥»÷»î¶¯Ö÷ÒªÕë¶ÔLinkedInÕÊ»§¡£¸Ã»î¶¯µÄÓ°Ï췶ΧÁýÕÖÈ«Çò£¬µ¼Ö´óÁ¿Óû§ÎÞ·¨·ÃÎÊÆäÕÊ»§¡£Ðí¶àLinkedInÓû§Ëß¿àÆäÕË»§±»½Ó¹Ü»òËø¶¨£¬¶øÇÒÎÞ·¨Í¨¹ýLinkedInµÄÖ§³Ö·þÎñ½â¾ö¡£ÓÐЩÈËÉõÖÁ±»ÆÈ½»Êê½ð²ÅÆøÖØÐ»ñµÃ¿ØÖÆÈ¨£¬»òÕßÃæÁÙÕË»§±»ÓÀ¾Ãɾ³ýµÄÇé¿ö¡£ËäÈ»LinkedInÉÐδÐû²¼Õýʽͨ¸æ£¬µ«ËûÃǵÄÖ§³ÖÏìӦʱ¼äËÆºõÒѾÑÓ³¤£¬Óб¨µÀ³ÆÖ§³ÖÇëÇóµÄÊýÁ¿ºÜ´ó¡£
https://www.bleepingcomputer.com/news/security/linkedin-accounts-hacked-in-widespread-hijacking-campaign/
3¡¢ÃÀ¹ú¸ßÀÖÊÏ(Clorox)Ôâµ½¹¥»÷µ¼ÖÂÔËÓªÔÝʱÖжÏ
8ÔÂ16ÈÕ±¨µÀ³Æ£¬ÃÀ¹úÈÕÓÃÆ·Éú²úÉ̸ßÀÖÊÏ(Clorox)Ôâµ½¹¥»÷£¬µ¼ÖÂÔËÓªÔÝʱÖжϡ£¸Ã¹«Ë¾ÔÚ2022ÄêµÄÊÕÈëÁè¼Ý70ÒÚÃÀÔª¡£´Ë´Î¹¥»÷ÓÚ8ÔÂ14ÈÕ±»¼ì²âµ½£¬CloroxÁ¢¼´½ÓÄÉÐж¯£¬¹Ø±ÕÁËÊÜÓ°ÏìµÄϵͳ¡£¸ÃʼþµÄÊÓ²ìÈÔÔÚÔçÆÚ½×¶Î£¬Éв»Çå³þÊÇÄÄÖÖÀàÐ͵Ĺ¥»÷¡£È»¶øÏÖÓÐÐÅÏ¢±íÃ÷£¬Õâ¿ÉÄÜÊÇÀÕË÷¹¥»÷¡£´Ë´Î¹¥»÷Ó°ÏìÁËCloroxµÄÖÆÔìºÍÏúÊÛÁ÷³Ì£¬ÒÔ¼°ÆäÂÄÐж©µ¥ºÍά³ÖÕý³£ÔËÓªµÄÄÜÁ¦¡£
https://www.infosecurity-magazine.com/news/clorox-disrupted-cyber-attack/
4¡¢¹ýÈ¥°ëÄêCloudflare R2ÍйܵĵöÓãÍøÒ³Á÷Á¿Ôö³¤61±¶
NetskopeÔÚ8ÔÂ14Èճƣ¬´Ó½ñÄê2Ôµ½7Ô£¬Cloudflare R2ÖÐÍйܵĵöÓãÒ³ÃæÁ÷Á¿Ôö³¤ÁË61±¶¡£´ó¶àÊýµöÓã»î¶¯¶¼Õë¶ÔMicrosoftµÇ¼ƾ¾Ý£¬µ«Ò²ÓÐһЩÕë¶ÔAdobe¡¢DropboxºÍÆäËüÔÆÓ¦Ó÷¨Ê½¡£ÕâЩ¹¥»÷Ö÷ÒªÕë¶Ô±±ÃÀºÍÑÇÖÞ£¬Éæ¼°ÖÖÖÖÁìÓò£¬ÒÔ¼¼Êõ¡¢½ðÈÚ·þÎñºÍÒøÐÐҵΪÊס£ÕâЩµöÓã»î¶¯²»½öÀûÓÃCloudflare R2·Ö·¢¾²Ì¬µöÓãÒ³Ãæ£¬»¹ÀûÓøù«Ë¾µÄTurnstile²úÎïÀ´Èƹý¼ì²â¡£
https://www.netskope.com/blog/evasive-phishing-campaign-steals-cloud-credentials-using-cloudflare-r2-and-turnstile
5¡¢AhnLab·¢ÏÖHakuna MatataÕë¶Ôº«¹úÆóÒµµÄ¹¥»÷»î¶¯
8ÔÂ16ÈÕ£¬AhnLab͸¶ÀÕË÷Èí¼þHakuna MatataÕý±»ÓÃÀ´¹¥»÷º«¹úµÄÆóÒµ¡£Hakuna MatataÊǽüÆÚ¿ª·¢µÄÀÕË÷Èí¼þ£¬ÓÚ7ÔÂ6ÈÕÊ״α»Åû¶¡£Hakuna MatataÓëÆäËü´«Í³ÀÕË÷Èí¼þµÄ²îÒìÖ®´¦ÔÚÓÚ£¬Ëü¾ßÓÐClipBanker¹¦Ð§¡£¼´Ê¹ÔÚ¼ÓÃÜÖ®ºó£¬ËüÈÔÈ»±£ÁôÔÚϵͳÖУ¬½«±ÈÌØ±ÒÇ®°üµØÖ·¸ü¸ÄΪ¹¥»÷ÕߵĵØÖ·¡£¼ÓÃÜϵͳºó£¬¹¥»÷Õß»áɾ³ý¹¥»÷ÖÐʹÓõÄʼþÈÕÖ¾ºÍ¶ñÒâÈí¼þ£¬Òò´ËºÜÄÑ»ñµÃÈ·ÇеÄÐÅÏ¢¡£µ«ÊÇ£¬Æ¾¾ÝÖÖÖÖÇé¿ö£¬ÍƲâÔ¶³Ì×ÀÃæÐÒ飨RDP£©±»×÷Ϊ³õʼ¹¥»÷ÔØÌå¡£
https://asec.ahnlab.com/en/56010/
6¡¢Group-IBÐû²¼¹ØÓÚ¶ñÒâÈí¼þGigabudµÄ·ÖÎö³ÂËß
8ÔÂ14ÈÕ£¬Group-IBÐû²¼Á˹ØÓÚ¶ñÒâÈí¼þGigabudµÄ·ÖÎö³ÂËß¡£ËüÖ÷ÒªÕë¶ÔÌ©¹ú¡¢Ó¡¶ÈÄáÎ÷ÑÇ¡¢Ô½ÄÏ¡¢·ÆÂɱöºÍÃØÂ³µÄ½ðÈÚ»ú¹¹¡£Gigabud RATÔÚÓû§±»ÊÚȨ½øÈë¶ñÒâÓ¦ÓÃ֮ǰ²»»áÖ´ÐÐÈκζñÒâ»î¶¯£¬Õâ¼Ó´óÁ˼ì²âµÄÄѶȡ£ËüÖ÷Ҫͨ¹ýÆÁÄ»Â¼ÖÆÀ´ÊÕ¼¯Ãô¸ÐÐÅÏ¢£¬¶ø²»ÊÇHTMLÁýÕÖ¹¥»÷¡£¼ÌÐøÊӲ췢ÏÖÁËÁíÒ»¸ö²»¾ß±¸RAT¹¦Ð§µÄÑù±¾£¬´úºÅΪGigabud.Loan£¬ÕâÊÇÒ»¸öαÔìµÄ´û¿îÓ¦Ó㬻áÇÔÈ¡Óû§ÊäÈëµÄÊý¾Ý¡£
https://www.group-ib.com/blog/gigabud-banking-malware/