VeeamÐû²¼¸üÐÂÐÞ¸´Veeam ONE¼à¿ØÆ½Ì¨Öжà¸ö©¶´

Ðû²¼Ê±¼ä 2023-11-08

1¡¢VeeamÐû²¼¸üÐÂÐÞ¸´Veeam ONE¼à¿ØÆ½Ì¨Öжà¸ö©¶´


11ÔÂ6ÈÕ£¬VeeamÐû²¼ÁËÄþ¾²¸üÐÂÒÔÐÞ¸´Veeam ONE IT»ù´¡ÉèÊ©¼à¿ØºÍ·ÖÎöƽ̨ÖеÄ4¸ö©¶´¡£ÆäÖнÏΪÑÏÖØµÄÊÇCVE-2023-38547(CVSSÆÀ·Ö9.9)£¬¿ÉÓÃÀ´»ñÈ¡ÓйØVeeam ONEÓÃÓÚ·ÃÎÊÆäÅäÖÃÊý¾Ý¿âµÄSQL·þÎñÆ÷Á¬½ÓµÄÐÅÏ¢£¬¿ÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐУ»ÒÔ¼°CVE-2023-38548£¨CVSSÆÀ·Ö9.8£©£¬¿É»ñÈ¡Veeam ONE Reporting ServiceËùʹÓÃÕÊ»§µÄNTLM¹þÏ£¡£ÁíÍâÁ½¸öÊÇ¿Éͨ¹ýXSS¹¥»÷ÇÔÈ¡¹ÜÀíÔ±ÁîÅÆµÄ©¶´£¨CVE-2023-38549£©ºÍ¿É·ÃÎÊDashboard ScheduleµÄ©¶´£¨CVE-2023-41723£©¡£


https://www.bleepingcomputer.com/news/security/veeam-warns-of-critical-bugs-in-veeam-one-monitoring-platform/


2¡¢ÈÕ±¾º½¿Õµç×Ó¹«Ë¾Ôâµ½AlphVµÄ¹¥»÷ÔËÓªÊܵ½Ó°Ïì


¾Ý11ÔÂ8ÈÕ±¨µÀ£¬ÈÕ±¾º½¿Õµç×Ó¹«Ë¾Í¸Â¶£¬ÆäϵͳÔâµ½ÍøÂç¹¥»÷£¬ÍøÕ¾±»ÆÈ¹Ø±Õ¡£ÖÜÒ»ÍíÉÏ£¬¸Ã¹«Ë¾µÄÍøÕ¾ÏÔʾÁËÒ»ÌõÏûÏ¢£¬±íÃ÷Æä²¿ÃÅ·þÎñÆ÷ÔÚÉÏÖÜËı»ºÚ¡£Õâ¼Ò¹«Ë¾ÌåÏÖ£¬ËûÃÇĿǰÕýÔÚÊÓ²ìÈëÇÖÇé¿ö²¢»Ö¸´ÔËÓª£¬µ«Ò»Ð©ÏµÍ³ÒѾ­ÖжÏ£¬ÊÕ·¢µç×ÓÓʼþÒ²·ºÆðÁËһЩÑÓÎó£¬ÉÐδ·¢ÏÖÐÅϢй¶¡£AlphVÔÚ±¾ÖÜÒ»½«ÈÕ±¾º½¿Õµç×Ó¹«Ë¾¼ÓÈëÆäÍøÕ¾£¬µ«¸Ã¹«Ë¾ÉÐδ͸¶ÊÇ·ñÕýÔÚÓ¦¶ÔÀÕË÷¹¥»÷¡£


https://therecord.media/japan-aviation-electronics-says-servers-accessed-during-cyberattack


3¡¢Unit 42·¢ÏÖAgriusÕë¶ÔÒÔÉ«ÁнÌÓýºÍ¿Æ¼¼ÐÐÒµµÄ¹¥»÷


Unit 42ÔÚ11ÔÂ6ÈÕ³ÆÆä·¢ÏÖÁËAgriusÕë¶ÔÒÔÉ«ÁнÌÓýºÍ¿Æ¼¼ÐÐÒµµÄ¹¥»÷¡£ÕâЩ¹¥»÷´Ó1ÔÂÒ»Ö±Á¬Ðøµ½10Ô£¬Ö¼ÔÚÇÔÈ¡PIIºÍ֪ʶ²úȨµÈÃô¸ÐÐÅÏ¢¡£Ò»µ©ÇÔÈ¡ÁËÐÅÏ¢£¬¹¥»÷Õ߾ͻᰲװÖÖÖÖ²Á³ý·¨Ê½£¬À´ÑÚ¸ÇÆä×Ù¼£²¢Ê¹±»Ñ¬È¾µÄÖÕ¶ËÎÞ·¨Ê¹Óá£×î½üµÄ¹¥»÷»¹Ê¹ÓõÄ3ÖÖеIJÁ³ý·¨Ê½£¬MultiLayer Wiper¡¢PartialWasherºÍBFG Agonizer Wiper£¬ÒÔ¼°Ò»¸ö´ÓÊý¾Ý¿â·þÎñÆ÷ÌáÈ¡ÐÅÏ¢µÄ×Ô½ç˵¹¤¾ßSqlextractor¡£


https://unit42.paloaltonetworks.com/agonizing-serpens-targets-israeli-tech-higher-ed-sectors/


4¡¢Google³Æ¶à¸öÍÅ»ïÊÔͼ½«ÆäÈÕÀú·þÎñÓÃ×÷C2»ù´¡ÉèÊ©


¾ÝýÌå11ÔÂ6ÈÕ±¨µÀ£¬GoogleÌáÐѶà¸ö¹¥»÷ÍÅ»ïÕýÔÚ¹²ÏíÒ»¸öÃûΪGoogle Calendar RAT(GCR)µÄPoC£¬ËüÀûÓÃÈÕÀú·þÎñÀ´ÍйÜÃüÁîºÍ¿ØÖÆ£¨C2£©»ù´¡ÉèÊ©¡£Æä¿ª·¢ÕßÌåÏÖ£¬¸Ã½Å±¾Í¨¹ýÀûÓÃGoogleÈÕÀúÖеÄʼþÃèÊö´´½¨ÁËÒ»¸ö¡°Òþ±ÎͨµÀ¡±£¬Ä¿±ê½«Ö±½ÓÁ¬½Óµ½Google¡£Google³ÆÉÐδ·¢ÏÖGCRÔÚÒ°ÍâµÄʹÓÃÇé¿ö£¬µ«Mandiant×¢Òâµ½¶à¸öÍÅ»ïÔÚºÚ¿ÍÂÛ̳ÉÏ·ÖÏíÁËPoC£¬Õâ˵Ã÷ÁËËûÃǶÔÀÄÓÃÔÆ·þÎñ¸ÐÐËȤ¡£


https://securityaffairs.com/153700/hacking/google-calendar-rat-attacks.html


5¡¢VMwareÅû¶JupyterбäÌåÔÚ½üÆÚ¼¤ÔöµÄ¹¥»÷»î¶¯


VMwareÔÚ11ÔÂ6ÈÕÅû¶ÁËJupyter Infostealer±äÌåÐÂÒ»ÂֵĹ¥»÷»î¶¯¡£¸Ã¶ñÒâÈí¼þÓÚ2020Äêµ×Ê״α»·¢ÏÖ£¬Ö÷ÒªÕë¶Ô½ÌÓýºÍÎÀÉú²¿ÃÅ¡£¹ýÈ¥Á½ÖÜ£¬Ñо¿ÈËÔ±ÊӲ쵽µÄJupyter InfostealerѬȾÊýÁ¿Öð²½ÉÏÉý£¬Ä¿Ç°Ñ¬È¾×ÜÊýΪ26Àý¡£ËüÕë¶ÔChrome¡¢EdgeºÍFirefoxä¯ÀÀÆ÷£¬ÀûÓÃSEOÖж¾ºÍËÑË÷ÒýÇæÖØ¶¨ÏòÀ´Á÷´«¡£ÐÂÒ»ÂֵĹ¥»÷ÀûÓÃÁËPowerShellÃüÁîÀ´Ð޸ĺÍÇ©Ãû˽Կ£¬ÊÔͼ½«¶ñÒâÈí¼þð³äΪºÏ·¨Ç©ÃûµÄÎļþ¡£


https://blogs.vmware.com/security/2023/11/jupyter-rising-an-update-on-jupyter-infostealer.html


6¡¢KasperskyÐû²¼2023ÄêÓëÓÎÏ·Ïà¹ØµÄÍøÂçÍþвµÄ³ÂËß


11ÔÂ6ÈÕ£¬KasperskyÐû²¼ÁË2023ÄêÓëÓÎÏ·Ïà¹ØµÄÍøÂçÍþвµÄ·ÖÎö³ÂËß¡£¸Ã³ÂËß·ÖÎöÁË2022Äê7ÔÂ1ÈÕÖÁ2023Äê7ÔÂ1ÈÕÆÚ¼äÊÕ¼¯µÄÊý¾Ý¡£³ÂËßÖ¸³ö£¬Kaspersky×ܹ²¼ì²âµ½4076530´ÎÓëÓÎÏ·Ïà¹ØµÄ×ÀÃæÑ¬È¾ÊµÑ飬ӰÏìÁËÈ«Çò192456ÃûÓÎÏ·Íæ¼Ò¡£×î³£¼ûµÄÍþвÊÇÏÂÔØ·¨Ê½£¨89.70%£©£¬Æä´ÎÊÇ¹ã¸æÈí¼þ£¨5.25%£©ºÍľÂí£¨2.39%£©¡£×î³£±»ÓÃ×÷ÓÕ¶üµÄÊÇÎÒµÄÊÀ½ç£¨70.29%£©£¬Æä´ÎÊÇRoblox£¨20.37%£©¡¢·´¿Ö¾«Ó¢£ºÈ«Çò¹¥ÊÆ£¨4.78%£©ºÍ¾øµØÇóÉú£¨2.85%£©¡£


https://securelist.com/game-related-threat-report-2023/110960/