΢ÈíÐû²¼8Ô·ÝÖܶþ²¹¶¡ £¬×ܼÆÐÞ¸´121¸öÄþ¾²Â©¶´

Ðû²¼Ê±¼ä 2022-08-10
1¡¢Î¢ÈíÐû²¼8Ô·ÝÖܶþ²¹¶¡ £¬×ܼÆÐÞ¸´121¸öÄþ¾²Â©¶´

      

8ÔÂ9ÈÕ £¬ ΢ÈíÐû²¼Á˱¾ÔµÄÖܶþ²¹¶¡ £¬×ܼÆÐÞ¸´ÁË121¸ö©¶´ ¡£´Ë´Î¸üÐÂÐÞ¸´ÁËÁ½¸ö0 day £¬·Ö±ðΪMicrosoft WindowsÖ§³ÖÕï¶Ï¹¤¾ß(MSDT)ÖеÄÔ¶³Ì´úÂëÖ´ÐЩ¶´¡°DogWalk¡±£¨CVE-2022-34713£©ºÍMicrosoft ExchangeÖеÄÐÅϢй¶©¶´£¨CVE-2022-30134£© £¬ÆäÖÐDogWalkÒÑÔÚ¹¥»÷Öб»»ý¼«ÀûÓà ¡£´ËÍâ £¬»¹ÐÞ¸´ÁËActive DirectoryÓò·þÎñÌáȨ©¶´£¨CVE-2022-34691£©ºÍWindows Hyper-VÔ¶³ÌÖ´ÐдúÂë©¶´£¨CVE-2022-34696£©µÈ½ÏΪÑÏÖØµÄ©¶´ ¡£


https://www.bleepingcomputer.com/news/microsoft/microsoft-august-2022-patch-tuesday-fixes-exploited-zero-day-121-flaws/


2¡¢µ¤Âó7-11µÄÖ§¸¶ÏµÍ³Ôâµ½¹¥»÷ £¬È«¹úÃŵêÔÝʱ¹Ø±Õ

      

¾ÝýÌå8ÔÂ8ÈÕ±¨µÀ £¬µ¤Âó7-11µÄÖ§¸¶ÏµÍ³Ôâµ½¹¥»÷ºó £¬È«¹ú·¶Î§ÄÚµÄËùÓÐÃŵêÔÝʱ¹Ø±Õ ¡£¹¥»÷·¢ÉúÔÚ8ÔÂ8ÈÕÔçÉÏ £¬¸Ã¹«Ë¾ÔÚFacebookÉÏ·¢Ìû³ÆËûÃÇ¿ÉÄÜÔâµ½Á˺ڿ͹¥»÷ £¬Ö§¸¶ºÍ½áÕËϵͳÎÞ·¨Ê¹Óà ¡£7-11Ô±¹¤ÔÚRedditÉÏ͸¶³Æ £¬ÒòΪȫ¹úµÄ7-11¶¼Ê¹ÓÃÁËÏàͬµÄϵͳ £¬ËùÒÔµ¤ÂóËùÓÐ7-11ÃŵêÏÖÔÚ¶¼ÒÑ¹Ø±Õ ¡£Ä¿Ç° £¬»¹Ã»ÓйØÓÚÕâ´Î¹¥»÷µÄ½øÒ»²½Ï¸½Ú £¬ÀýÈç¹¥»÷ÊÇ·ñÉæ¼°ÀÕË÷Èí¼þ ¡£


https://www.bleepingcomputer.com/news/security/7-eleven-stores-in-denmark-closed-due-to-a-cyberattack/


3¡¢Twilio͸¶ÆäÔ±¹¤Ôâµ½µöÓã¹¥»÷ £¬µ¼Ö¿ͻ§Êý¾Ýй¶

     

ýÌå8ÔÂ8ÈÕ³Æ £¬ÔÆÍ¨ÐŹ«Ë¾Twilio²¿Ãſͻ§µÄÊý¾ÝÒѾ­Ð¹Â¶ ¡£TwilioÌåÏÖ £¬ËûÃÇÔÚ8ÔÂ4ÈÕ·¢ÏÖÆäÔ±¹¤Ôâµ½ÁËÅÓ´óµÄµöÓã¹¥»÷ºóƾ¾Ýй¶ £¬È»ºó¹¥»÷ÕßÀûÓÃÇÔÈ¡µÄƾ¾Ý·ÃÎÊÁ˹«Ë¾µÄÄÚ²¿ÏµÍ³ £¬ÒÔ¼°²¿Ãſͻ§µÄÊý¾Ý ¡£¹¥»÷Õßð³äTwilioµÄIT²¿ÃÅ £¬ÒªÇóÄ¿±êµã»÷°üÂÞTwilio¡¢OktaºÍSSOÒªº¦×ÖµÄURL £¬²¢½«ËûÃÇÖØ¶¨Ïòµ½Î±ÔìµÄTwilioµÇÂ¼Ò³Ãæ ¡£TwilioÒÑÈ¡ÏûÁ˹¥»÷ÆÚ¼ä±»µÁµÄÔ±¹¤ÕË»§ £¬µ«ÉÐδȷ¶¨¹¥»÷ÕßÉí·Ý £¬Ä¿Ç°ÕýÔÚÓëÖ´·¨²¿ÃźÏ×÷¶Ô´ËÊÂÕ¹¿ªÊÓ²ì ¡£


https://securityaffairs.co/wordpress/134147/data-breach/twilio-discloses-data-breach.html


4¡¢Ð½©Ê¬ÍøÂçOrchardÀûÓÃÖб¾´ÏµÄÕË»§ÐÅÏ¢À´Éú³ÉDGAÓò

      

¾Ý8ÔÂ8ÈÕ±¨µÀ £¬Ñо¿ÍŶӷ¢ÏÖÁËÒ»¸öÃûΪOrchardµÄн©Ê¬ÍøÂç £¬Ê¹ÓñÈÌØ±Ò´´½¨ÕßSatoshi NakamotoµÄÕË»§½»Ò×ÐÅÏ¢Éú³ÉDGAÓòÀ´Òþ²ØÆäC2»ù´¡ÉèÊ© ¡£×Ô2021Äê2ÔÂÒÔÀ´ £¬Orchard¾­ÀúÁËÈý´Î¸üР¡£¸Ã½©Ê¬ÍøÂç½ÓÄÉÁËÓ²±àÂëÓò+DGAµÄÈßÓàC2»úÖÆ £¬Ñо¿ÈËÔ±·¢ÏÖÿ¸ö°æ±¾¶¼°üÂÞÒ»¸öΨһµÄÓ²±àÂëDuckDNS¶¯Ì¬ÓòÃû×÷ΪC2 ¡£ËüµÄÈý¸ö°æ±¾»ù±¾Ö§³ÖÏàͬµÄ¹¦Ð§ £¬°üÂÞÉÏ´«É豸ºÍÓû§ÐÅÏ¢¡¢ÏìÓ¦ÃüÁî»òÏÂÔØÖ´ÐÐÄ£¿éµÄÏÂÒ»¸ö½×¶ÎÒÔ¼°Ñ¬È¾USB´æ´¢É豸 ¡£


https://thehackernews.com/2022/08/new-orchard-botnet-uses-bitcoin.html


5¡¢KasperskyÅû¶TA428Õë¶Ô¾ü¹¤ÆóÒµºÍÕþ¸®»ú¹¹µÄ¹¥»÷

      

¾ÝKaspersky 8ÔÂ8ÈÕ±¨µÀ £¬ÆäÔÚ1Ô·ݼì²âµ½Ò»²¨Õë¶Ô¶«Å·¶à¸ö¹ú¼ÒµÄ¾ü¹¤ÆóÒµºÍ¹«¹²»ú¹¹µÄ¶¨Ïò¹¥»÷ ¡£¹¥»÷ÕßÒÑÀÖ³ÉÈëÇÖÁËÊýÊ®¸öÄ¿±ê £¬Ö÷ҪΪ°×¶íÂÞ˹¡¢¶íÂÞ˹ÎÚ¿ËÀ¼ºÍ°¢¸»º¹µÈ¹ú¼ÒµÄ¹¤Òµ¹¤³§¡¢Éè¼Æ¾Ö¡¢Ñо¿»ú¹¹ºÍÕþ¸®»ú¹¹µÈ ¡£¹¥»÷»î¶¯ÀûÓÃÁËMicrosoft Office©¶´£¨CVE-2017-11882£©À´°²×°¶ñÒâÈí¼þPortDoor £¬²¢ÔÚ½ÓÏÂÀ´µÄ¹¥»÷½×¶Î°²×°ÁË5¸öÌØ±ðµÄºóÃÅnccTrojan¡¢Logtu¡¢Cotx¡¢DNSepºÍCotSam £¬Ö¼ÔÚÇÔȡϵͳÐÅÏ¢ºÍÎļþ ¡£Ñо¿·¢ÏÖ £¬¸Ã»î¶¯ÓëAPT TA428»î¶¯µÄTTP´æÔÚÃ÷ÏÔÖØµþ ¡£


https://securelist.com/targeted-attack-on-industrial-enterprises-and-public-institutions/107054/


6¡¢Group-IBÐû²¼¹ØÓÚÕ©Æ­»î¶¯ClassiscamµÄ·ÖÎö³ÂËß

      

8ÔÂ8ÈÕ £¬Group-IBÐû²¼Á˹ØÓÚÕ©Æ­»î¶¯ClassiscamµÄ·ÖÎö³ÂËß ¡£ClassiscamÊÇÒ»ÖÖÅÓ´óµÄÕ©Æ­¼´·þÎñÒµÎñ£¨scam-as-a-service£© £¬ÒÑÓÚ2022Äê3ÔÂÉøÍ¸µ½ÐÂ¼ÓÆÂ ¡£¸Ã»î¶¯×î³õÓÚ2020Äê±»·¢ÏÖ £¬¹¥»÷Õßð³äºÏ·¨Âò¼Ò½Ó½üÂô¼Ò £¬ÒªÇó´ÓËûÃǵÄÇåµ¥ÖйºÖÃÉÌÆ· £¬À´ÇÔȡ֧¸¶Êý¾Ý ¡£¸ÃÕ©Æ­»î¶¯ÒѾ­±é¼°Å·ÖÞ¡¢CISºÍÖж«µÄ64¸ö¹ú¼Ò £¬2020Äê4Ôµ½2022Äê2ÔÂÒÑΪ¹¥»÷ÕßIJÀûÖÁÉÙ2950ÍòÃÀÔª ¡£


https://www.group-ib.com/media/classiscam-singapore-global-scam-operation/