¼ÓÄôóÍøÂçÔËÓªÉÌRogers´ó¹æÄ£Öжϲ¨¼°¶à¸öÁìÓò
Ðû²¼Ê±¼ä 2022-07-111¡¢¼ÓÄôóÍøÂçÔËÓªÉÌRogers´ó¹æÄ£Öжϲ¨¼°¶à¸öÁìÓò
¾ÝýÌå7ÔÂ8ÈÕ±¨µÀ£¬¼ÓÄôóÍøÂçÔËÓªÉÌÂÞ½Ü˹£¨Rogers£©·¢ÉúÁË´ó¹æÄ£·þÎñÖжϡ£DownDetector³Æ£¬ÖжϿªÊ¼×ÔÃÀ¹ú¶«²¿Ê±¼äÔçÉÏ5µã×óÓÒ£¬¿Í»§·´Ó³Í»È»ÎÞ·¨²¦´òµç»°»òÁ¬½Óµ½»¥ÁªÍø¡£ÁªÍø¼à¿Ø×éÖ¯NetBlocksÌåÏÖ£¬¸Ãʼþµ¼Ö¼ÓÄôóµÄÍøÂçÁ¬½Ó¼õÉÙÁË25%¡£ÖжÏÓ°ÏìÁ˼ÓÄôóµÄÒøÐкͽðÈÚ½»Ò×£¬×Ô¶¯¹ñÔ±»úºÍÐÅÓÿ¨½»Ò×ÎÞ·¨Õý³£ÊÂÇ飬¶ø²¿ÃŵØÓòµÄ911·þÎñÒ²Êܵ½Ó°Ïì¡£½ØÖÁ7ÔÂ9ÈÕÉÏÎç8:00£¬RogerÐû²¼ÉùÃ÷³Æ£¬ÒÑΪ¾ø´ó¶àÊý¿Í»§»Ö¸´ÁË·þÎñ£¬µ«ÈÔȻûÓнâÊ͵¼ÖÂÖжϵÄÔÒò¡£
https://www.bleepingcomputer.com/news/technology/massive-rogers-outage-disrupts-mobile-service-payments-in-canada/
2¡¢MangatoonÊý¾Ý¿âÅäÖôíÎóй¶2300ÍòÓû§µÄÐÅÏ¢
¾Ý7ÔÂ9ÈÕ±¨µÀ£¬Êý¾Ýй¶֪ͨ·þÎñHave I Been Pwned(HIBP)ÔÚÆäƽ̨ÉÏ͸¶2300Íò¸öMangatoonÕÊ»§Ð¹Â¶¡£MangatoonÊÇÒ»¿îÊÜ»¶ÓµÄÔÚÏßÂþ»Ó¦Ó㬴˴Îй¶ÁËÓû§µÄÐÕÃû¡¢ÓʼþµØÖ·¡¢É罻ýÌåÕË»§¡¢Éí·ÝÑéÖ¤ÁîÅƺÍÃÜÂë¡£¾ÝºÚ¿Ípompompurin³Æ£¬ËûÃÇ´ÓʹÓÃÁËÈõÃÜÂë"password"µÄElasticsearch·þÎñÆ÷ÉÏÇÔÈ¡ÁËÊý¾Ý¡£¸ÃºÚ¿Í»¹ÌåÏÖ£¬¹«Ë¾ÔÚÊÕµ½Ð¹Â¶Í¨Öªºó¸ü¸ÄÁËÃÜÂ룬µ«²¢Î´Í¨Öª¿Í»§£¬Ò²Î´¶Ô´ËÊÂ×÷³ö»ØÓ¦¡£
https://www.bleepingcomputer.com/news/security/mangatoon-data-breach-exposes-data-from-23-million-accounts/
3¡¢Fortinet·¢ÏÖÀûÓÃDiscord·Ö·¢ºóÃÅRozenaµÄ»î¶¯
7ÔÂ6ÈÕ£¬FortinetÅû¶ÁË·Ö·¢¶ñÒâÈí¼þRozenaµÄ¹¥»÷»î¶¯µÄ¼¼Êõϸ½Ú¡£RozenaÊÇÒ»¸öеĺóÃÅ£¬¿ÉÒÔ½«Ô¶³ÌshellÁ¬½Ó×¢Èë¹¥»÷ÕߵļÆËã»ú¡£´Ë´Î»î¶¯ÀûÓÃÁËMSDTÔ¶³Ì´úÂëÖ´ÐЩ¶´Follina£¨CVE-2022-30190£©£¬Ê¼ÓÚÒ»¸öÎäÆ÷»¯µÄOfficeÎĵµ£¬¸ÃÎĵµÔÚ´ò¿ªÊ±»áÁ¬½Óµ½Discord CDN URLÒÔ¼ìË÷HTMLÎļþ£¨¡°index.htm¡±£©¡£¸ÃÎļþʹÓÃPowerShellÃüÁîµ÷ÓÃÕï¶Ï¹¤¾ß£¬´Óͬһ¸öCDN¸½¼þ¿Õ¼äÏÂÔØÏÂÒ»½×¶ÎµÄpayload£¬Õâ°üÂÞRozenaÖ²È뷨ʽ£¨¡°Word.exe¡±£©ºÍÒ»¸öÅú´¦ÖÃÎļþ£¨¡°cd.bat¡±£©¡£
https://www.fortinet.com/blog/threat-research/follina-rozena-leveraging-discord-to-distribute-a-backdoor
4¡¢QNAPÌáÐѳÆÐÂÀÕË÷Èí¼þCheckmatÖ÷ÒªÕë¶ÔÆäNASÉ豸
QNAPÔÚ7ÔÂ7ÈÕÐû²¼Í¨¸æ³Æ£¬ÐÂÀÕË÷Èí¼þCheckmatÖ÷ÒªÕë¶ÔÆäNASÉ豸¡£³õ·¨Ê½²é±íÃ÷£¬Checkmate»áͨ¹ý̻¶ÔÚ»¥ÁªÍøÉϵÄSMB·þÎñ½øÐй¥»÷£¬²¢Ê¹ÓÃ×ֵ乥»÷À´ÆƽâÈõÃÜÂëµÄÕÊ»§¡£¹¥»÷ÕßÒ»µ©ÀֳɵǼÉ豸£¬¾Í»á¶Ô¹²ÏíÎļþ¼ÐÖеÄÊý¾Ý½øÐмÓÃÜ£¬²¢ÔÚÿ¸öÎļþ¼ÐÖÐÁôÏÂÒ»¸öÎļþ¡°£¡CHECKMATE_DECRYPTION_README¡±×÷ΪÀÕË÷¼Ç¼¡£CheckmateÓÚ5ÔÂ28ÈÕ×óÓÒÊ×´ÎÔÚ¹¥»÷Öб»Ê¹Óã¬QNAP½¨Òé¸æÓû§²»Òª½«SMB·þÎñ̻¶ÔÚ»¥ÁªÍøÉÏ£¬²¢Ê¹ÓÃVPN·ÃÎÊNASÀ´¼õÉÙ¹¥»÷Ãæ¡£
https://securityaffairs.co/wordpress/132989/malware/checkmate-ransomware-targets-qnap-nas.html
5¡¢IBM X-ForceÐû²¼¹ØÓÚTrickbotÕë¶ÔÎÚ¿ËÀ¼µÄ·ÖÎö³ÂËß
7ÔÂ7ÈÕ£¬IBM Security X-ForceÐû²¼Á˹ØÓÚTrickbotÍŻ↑ʼÕë¶ÔÎÚ¿ËÀ¼µÄ·ÖÎö³ÂËß¡£ÔÚ2022Äê4ÔÂÖÁ6Ô£¬Trickbot³ïıÁËÖÁÉÙ6´ÎÕë¶ÔÎÚ¿ËÀ¼µÄ¹¥»÷»î¶¯£¬²¢ÔÚÕâЩ»î¶¯Öа²×°Á˶ñÒâÈí¼þIcedID¡¢CobaltStrike¡¢AnchorMailºÍMeterpreter¡£ÔÚÊÓ²ìÕâЩ»î¶¯Ê±£¬X-Force»¹·¢ÏÖÁ˸ÃÍÅ»ïÕýÔÚʹÓõÄеĶñÒâÈí¼þºÍ¹¤¾ß£ºÓÃÓÚͨ±¨payloadµÄ¶ñÒâExcelÏÂÔØ·¨Ê½¡¢ÓÃÓÚͶ·ÅºÍ¹¹½¨payload£¨ÈçAnchorMail£©µÄ×Ô½âѹ´æµµ£¨SFX£©£¬ÒÔ¼°Ò»¸ö±»³ÆΪForestµÄ¶ñÒâÈí¼þ¼ÓÃÜ·¨Ê½¡£
https://securityintelligence.com/posts/trickbot-group-systematically-attacking-ukraine/
6¡¢Ñо¿ÈËÔ±ÑÝʾÈçºÎͨ¹ýRolling-PWN¹¥»÷½âËø±¾ÌïÆû³µ
ýÌå7ÔÂ10Èճƣ¬Star-VʵÑéÊÒµÄÒ»×éÑо¿ÈËÔ±³ÆÆä¿ÉÒÔͨ¹ýRolling-PWN¹¥»÷½âËø¶à¸ö±¾Ìï³µÐÍ¡£Ñо¿ÈËÔ±ÔÚ±¾ÌïÖз¢ÏÖÁËÒ»¸ö©¶´(CVE-2021-46145)£¬¿ÉÓÃÀ´½âËø³µÁ¾£¬ÉõÖÁÆô¶¯³µÁ¾·¢¶¯»ú¡£¾ÝϤ£¬¸ÃÎÊÌâÓ°ÏìÊг¡ÉÏ´Ó2012Äêµ½2022ÄêµÄËùÓб¾ÌïÆû³µ¡£¸Ã©¶´´æÔÚÓÚÓÃÀ´·ÀÖ¹ÖطŹ¥»÷µÄ¹ö¶¯´úÂë»úÖÆÖУ¬Ñо¿ÈËÔ±»¹Ðû²¼ÁËÒ»×éPoCÊÓƵ£¬À´ÑÝʾÀûÓø鶴¶Ô±¾ÌïCRVµÄ¹¥»÷¡£
https://securityaffairs.co/wordpress/133090/hacking/honda-rolling-pwn-attack.html