Ñо¿ÈËÔ±Åû¶SolarWinds ARM²úÎïÖжà¸ö©¶´µÄÏêÇé

Ðû²¼Ê±¼ä 2023-10-24

1¡¢Ñо¿ÈËÔ±Åû¶SolarWinds ARM²úÎïÖжà¸ö©¶´µÄÏêÇé


¾ÝýÌå10ÔÂ20ÈÕ±¨µÀ£¬Ñо¿ÈËÔ±³ÆÆäÔÚSolarWinds Access Rights Manager(ARM)²úÎïÖз¢ÏÖÁË3¸öÔ¶³Ì´úÂëÖ´ÐЩ¶´ ¡£ÕâЩ©¶´·Ö±ðÊÇcreateGlobalServerChannelInternalÖв»ÐÐÐÅÊý¾ÝµÄ·´ÐòÁл¯Â©¶´£¨CVE-2023-35182£©¡¢ OpenFileÖжÔÓû§Ìṩ·¾¶Ñé֤ȱ·¦µÄ©¶´£¨CVE-2023-35185£©ÒÔ¼°OpenClientUpdateFileÖжÔÓû§Ìṩ·¾¶Ñé֤ȱ·¦µÄ©¶´£¨CVE-2023-35187£© ¡£ËüÃǵÄCVSSÆÀ·Ö¾ùΪ9.8£¬ÒÑÓÚ10ÔÂ18ÈÕÐÞ¸´ ¡£


https://www.bleepingcomputer.com/news/security/critical-rce-flaws-found-in-solarwinds-access-audit-solution/


2¡¢ÃÀ¹úÃÜЪ¸ù´óѧÔâµ½¹¥»÷ѧÉúºÍÊÂÇéÈËÔ±µÄÐÅϢй¶


¾Ý10ÔÂ23ÈÕ±¨µÀ£¬ÃÜЪ¸ù´óѧ͸¶£¬ºÚ¿ÍÔÚ8Ô·ÝÈëÇÖÆäϵͳ²¢·ÃÎÊÁ˰üÂÞѧÉú¡¢ÉêÇëÈË¡¢Ð£ÓÑ¡¢¾è¿îÈË¡¢Ô±¹¤¡¢»¼ÕߺÍÑо¿¼ÓÈëÕßµÄÐÅÏ¢ ¡£Î´¾­ÊÚȨµÄ·ÃÎÊ·¢ÉúÓÚ8ÔÂ23ÈÕÖÁ27ÈÕ£¬ÔÚ¼ì²âµ½¿ÉÒɻºó£¬¸ÃѧУÁ¢¼´ÇжÏÁËÕû¸öУ԰µÄÍøÂ磬ÒÔ¾¡Á¿¼õÇáÓ°Ïì ¡£´Ë´Îʼþ²»½öй¶Á˸öÈËÐÅÏ¢£¬»¹Ð¹Â¶Á˲ÆÕþºÍÒ½ÁÆÏêϸÐÅÏ¢ ¡£Ä¿Ç°£¬ÃÜЪ¸ù´óѧÒÑ֪ͨËùÓÐÊÜÓ°ÏìµÄ¸öÈË£¬²¢½«ÎªËûÃÇÌṩÃâ·ÑÐÅÓÃ¼à¿Ø·þÎñ ¡£


https://www.bleepingcomputer.com/news/security/university-of-michigan-employee-student-data-stolen-in-cyberattack/


3¡¢FacebookºÍInstagramÓëÖ´·¨²¿ÃÅÁª¶¯µÄÕ˺ű»³öÊÛ


ýÌå10ÔÂ21Èճƣ¬ºÚ¿ÍÕýÔÚ°µÍø³öÊÛFacebookºÍInstagramµÄPolice PortalµÄ·ÃÎÊȨÏÞ ¡£¸ÃÃÅ»§¿É±»Ö´·¨»ú¹¹ÓÃÓÚÇëÇóÓëÓû§Ïà¹ØµÄÊý¾Ý£¨IP¡¢µç»°¡¢Ë½ÐźÍÉ豸ÐÅÏ¢£©»òÇëÇóɾ³ýÌû×ӺͽûÓÃÕÊ»§ ¡£¹¥»÷ÕßÒÔ700ÃÀÔªµÄ¼Û¸ñÌṩ·ÃÎÊȨÏÞ£¬¶øÇÒËÆºõÓµÓв»Ö¹Ò»¸öÃÅ»§µÄÕË»§ ¡£Ñо¿ÈËÔ±ÍÆ²â£¬ÒªÃ´ÊÇMetaÔâµ½ÁËÉ繤¹¥»÷µ¼Ö·ÃÎÊȨÏÞй¶£¬ÒªÃ´¾ÍÊǹ¥»÷ÕßÓµÓкϷ¨µÄÖ´·¨ÕÊ»§µÄƾ¾Ý ¡£


https://securityaffairs.com/152811/cyber-crime/facebook-and-instagrams-police-portal-access.html


4¡¢Cadre ServicesÔ¼100GBÊý¾Ýй¶²¢±»ÀÕË÷30ÍòÃÀÔª


10ÔÂ19ÈÕ±¨µÀ³Æ£¬AlphVÉù³Æ¹¥»÷Á˾ÍÒµºÍÈËÊ·þÎñCadre Services²¢ÒÑÇÔÈ¡100 GBµÄÎļþ ¡£¹¥»÷ÍÅ»ïÔÚ9ÔÂ19ÈÕÊ×´ÎÁªÏµÁËCadre£¬²¢ÓÚ9ÔÂ22ÈÕÊÕµ½»Ø¸´ ¡£Ì¸ÅеÄÁÄÌì½ØÍ¼ÏÔʾ£¬AlphVÒªÇó30ÍòÃÀÔªÊê½ð£¬¸Ã¹«Ë¾×î³õÌåÏÖÔ¸Òâ³ö¼Û25000ÃÀÔª£¬²¢³Æ×î¸ß±¨¼ÛΪ35000ÃÀÔª ¡£×î½ü¼¸ÈÕ£¬AlphVÔÙ´ÎÏò¸Ã¹«Ë¾£¬ÒÔ¼°¿Í»§ºÍDataBreaches·¢ËÍÓʼþ£¬ÌṩÁ˽«ÒªÐ¹Â¶µÄÊý¾ÝµÄÑù±¾£¬°üÂÞÔ±¹¤Êý¾ÝºÍÉêÇëÈËÊý¾Ý ¡£


https://www.databreaches.net/another-small-firm-suffers-a-serious-ransomware-attack-cadre-services-gets-mauled-by-alphv/


5¡¢WithSecure·¢ÏÖÕë¶ÔÓ¢ÃÀµÈ¹úµÄDarkGate¹¥»÷»î¶¯


10ÔÂ20ÈÕ£¬WithSecureÅû¶ÁËÕë¶ÔÓ¢¹ú¡¢ÃÀ¹úºÍÓ¡¶ÈµÄDarkGate¹¥»÷»î¶¯ ¡£¸Ã»î¶¯ÓëÈ¥ÄêÊ״η¢ÏÖµÄDucktail»î¶¯µÄÔ½ÄϹ¥»÷ÕßÓйØ£¬³õʼѬȾý½éÊÇLinkedInÏûÏ¢ºÍÓ²¼þÖÆÔìÉÌCorsairµÄFacebook¹ã¸æ×¨Ô±Ö°Î»£¬»á½«Ä¿±êÖØ¶¨Ïòµ½Google DriveÉÏÍйܵÄÎļþ ¡£ÏÂÔØµÄÎĵµ°üÂÞÒ»¸öVBS½Å±¾£¬¿ÉÄÜǶÈëÔÚDOCXÎļþÖУ¬»áÏÂÔØautoit3.exeºÍÒ»¸ö±àÒëºóµÄAutoit3½Å±¾ ¡£¿ÉÖ´ÐÐÎļþºó»áÀûÓýű¾ÖеÄ×Ö·û´®½á¹¹DarkGate£¬°²×°ÈýÊ®Ãëºó£¬¶ñÒâÈí¼þ»áʵÑé´ÓÄ¿±êϵͳÖÐÐ¶ÔØÄþ¾²²úÎï ¡£


https://labs.withsecure.com/publications/darkgate-malware-campaign


6¡¢FortinetÐû²¼¶ñÒâÈí¼þExelaStealerµÄ·ÖÎö³ÂËß


10ÔÂ19ÈÕ£¬FortinetÐû²¼Á˹ØÓÚ¶ñÒâÈí¼þExelaStealerµÄ·ÖÎö³ÂËß ¡£ExelaStealerÊÇÒ»¸ö»ù±¾ÉÏ¿ªÔ´µÄÐÅÏ¢ÇÔÈ¡·¨Ê½£¬¿ÉÒÔÌṩ¸¶·Ñ¶¨ÖÆ·þÎñ ¡£Æä¸¶·Ñ°æ±¾Ã¿ÔÂ20ÃÀÔª£¬Èý¸öÔÂ45ÃÀÔª£¬ÖÕÉí°æ±¾120ÃÀÔª ¡£ËüÓÉPython¿ª·¢²¢Ö§³ÖJavaScript£¬¾ßÓÐÇÔÈ¡ÃÜÂë¡¢DiscordÁîÅÆ¡¢ÐÅÓÿ¨¡¢cookieºÍ»á»°Êý¾Ý¡¢»÷¼ü¡¢ÆÁÄ»½ØÍ¼ºÍ¼ôÌù°åÄÚÈݵĹ¦Ð§ ¡£ExelaStealer¿ÉÄÜÊÇͨ¹ýαװ³ÉPDFÎĵµµÄ¿ÉÖ´ÐÐÎļþ½øÐзַ¢µÄ£¬Æô¶¯¶þ½øÖÆÎļþºó£¬»áÏÔʾһ·ÝÒýÓÕÎļþ£¬Í¬Ê±ÔÚºǫ́ÇÄÇÄÆô¶¯ÇÔÈ¡·¨Ê½ ¡£


https://www.fortinet.com/blog/threat-research/exelastealer-infostealer-enters-the-field