ResecurityÅû¶ͨ¹ýÎäÆ÷»¯OfficeÎĵµ·Ö·¢µÄEscanor

Ðû²¼Ê±¼ä 2022-08-23

1¡¢ResecurityÅû¶ͨ¹ýÎäÆ÷»¯OfficeÎĵµ·Ö·¢µÄEscanor

      

8ÔÂ21ÈÕ£¬Resecurity³ÆÔÚ°µÍøºÍTelegramÖз¢ÏÖÁËÒ»ÖÖÃûΪEscanorµÄÐÂRAT¡£¸Ã¹¤¾ßÓÚ½ñÄê1ÔÂ26ÈÕÐû²¼£¬×î³õÊÇ×÷Ϊ½ô´ÕÐÍHVNCÖ²È뷨ʽ£¬¿ÉÓÃÀ´½¨Á¢ÓëÄ¿±ê¼ÆËã»úµÄÔ¶³Ì¾²Ä¬Á¬½Ó£¬ºóÀ´×ª±äΪ¾ßÓжàÖÖ¹¦Ð§¼¯µÄÉÌÒµRAT¡£×î½ü¼ì²âµ½µÄ´ó¶àÊýÑù±¾¶¼ÊÇʹÓÃEscanor Exploit Builder·Ö·¢µÄ£¬¹¥»÷ÕßʹÓÃÁËÓÕ¶üÎÄ£¬Ä£·ÂÁ÷ÐÐÔÚÏß·þÎñµÄ·¢Æ±ºÍ֪ͨ¡£´ËÍ⣬ÓòÃûescanor[.]live´ËǰÒѱ»È·ÈÏÓëAridViperµÄ»ù´¡ÉèÊ©Óйء£     


https://resecurity.com/blog/article/escanor-malware-delivered-in-weaponized-microsoft-office-documents


2¡¢ÃÀ¹úNovant HealthµÄ130Íò»¼ÕߵĸöÈËÐÅϢй¶

      

¾Ý8ÔÂ22ÈÕ±¨µÀ£¬ÃÀ¹úÒ½ÁƱ£½¡ÌṩÉÌNovant HealthÅû¶ÁËÒ»ÆðÊý¾Ýй¶Ê¼þ£¬Ó°ÏìÁË1362296¸ö»¼Õß¡£¸ÃʼþʼÓÚ2020Äê5Ô£¬ÆäʱNovant¿ªÕ¹ÁËÉæ¼°Facebook¹ã¸æµÄCOVID-19ÒßÃç½ÓÖÖÐû´«»î¶¯¡£ÎªÁ˸ú×ÙÕâЩ¹ã¸æ£¬¸Ã¹«Ë¾ÔÚÍøÕ¾ÉÏÌí¼ÓÁËMeta Pixel´úÂ룬À´ÅÐ¶Ï¹ã¸æµÄЧ¹û¡£µ«ÊÇ£¬Novant HealthµÄÍøÕ¾ºÍMyChartÃÅ»§ÉϵÄMeta PixelÅäÖôíÎ󣬵¼Ö»¼ÕßµÄÐÅÏ¢»á±»·¢Ë͸øMeta¼°Æä¹ã¸æºÏ×÷»ï°é¡£NovantÔÚ2022Äê5ÔÂ´ÓÆäÍøÕ¾ºÍÃÅ»§ÖÐɾ³ýÁËMeta Pixel¡£


https://www.bleepingcomputer.com/news/security/misconfigured-meta-pixel-exposed-healthcare-data-of-13m-patients/


3¡¢Donot TeamΪÆä¶ñÒâÈí¼þ¿ò¼ÜJacaÌí¼ÓÐµĹ¦Ð§

      

ýÌå8ÔÂ22ÈÕ±¨µÀ£¬Donot Team£¨ÓÖÃûAPT-C-35£©ÒÑΪÆäWindows¶ñÒâÈí¼þ¿ò¼ÜJacaÌí¼ÓÁËÐµĹ¦Ð§¡£¸ÃÍÅ»ï×Ô2016Ä꿪ʼ»îÔ¾£¬Ö÷ÒªÕë¶ÔÓ¡¶È¡¢°Í»ù˹̹¡¢Ë¹ÀïÀ¼¿¨¡¢ÃϼÓÀ­¹úµÈÄÏÑǹú¼ÒµÄÕþ¸®»ú¹¹¡¢¾üÊÂ×éÖ¯¡¢Íâ½»²¿ºÍ´óʹ¹Ý¡£Ð°汾ÔöÇ¿ÁËä¯ÀÀÆ÷ÇÔȡģ¿é£¬Ê¹ÓÃǰһ½×¶ÎÏÂÔØµÄ4¸ö¸½¼Ó¿ÉÖ´ÐÐÎļþ(WavemsMp.dll)ʵÏÖÇÔÈ¡¹¦Ð§£¬¶ø²»ÊÇÔÚDLLÖУ¬Ã¿¸ö¸½¼ÓµÄ¿ÉÖ´ÐÐÎļþ¶¼¿ÉÒÔ´ÓChrome»òFirefoxÖÐÇÔÈ¡ÐÅÏ¢¡£


https://securityaffairs.co/wordpress/134674/apt/donot-team-improves-jaca-framework.html


4¡¢APT29ÔÚÕë¶Ô±±Ô¼µÄ¹¥»÷»î¶¯ÖÐʹÓÃеÄTTPÈÆ¹ý¼ì²â

      

8ÔÂ18ÈÕ£¬MandiantÅû¶Á˶íÂÞ˹APT29£¨Cozy Bear£©Õë¶Ô±±Ô¼¹ú¼ÒµÄÐÂÒ»ÂÖ¹¥»÷»î¶¯¡£ÔÚ¹¥»÷ÖУ¬APT29ʹÓÃÁËеÄÕ½Êõ¡¢¼¼ÊõºÍ·¨Ê½£¨TTP£©À´Èƹý¼ì²â£¬°üÂÞÔÚÔÚѬȾµÄÄ¿±êÕÊ»§ÉϽûÓÃPurview Audit¹¦Ð§£¬È»ºóÊÕ¼¯ÊÕ¼þÏäÖеĵç×ÓÓʼþ £»ÀûÓÃAzure Active DirectoryºÍÆäËüƽ̨ÖеÄMFA×ÔÎÒ×¢²á¹ý³Ì£¬¸ÃÍÅ»ï¿É±©Á¦ÆÆ½â´ÓδµÇ¼¹ýµÄÓòµÄÕÊ»§²¢½«ÆäÉ豸ע²áµ½MFA £»Ñо¿ÈËԱǿµ÷APT29½ÓÄÉÁ˵ÄÌØÊâµÄÔËÓªÄþ¾²ºÍÈÆ¹ý¼ÆÄ±£¬ËüʹÓÃÁËAzureÐéÄâ»ú¡£


https://www.mandiant.com/resources/blog/apt29-continues-targeting-microsoft


5¡¢AppleÐÞ¸´SafariÖÐÒѱ»ÀûÓõÄ©¶´CVE-2022-32893

      

8ÔÂ18ÈÕ£¬AppleΪmacOS Big SurºÍCatalinaÐû²¼ÁËSafari 15.6.1£¬ÒÔÐÞ¸´Ò»¸ö±»ÓÃÀ´ÈëÇÖMacµÄ©¶´¡£ÕâÊÇWebKitÖеÄÒ»¸öÔ½½çдÈë©¶´(CVE-2022-32893)£¬¿ÉÓÃÀ´ÔÚÄ¿±êÉ豸ÉÏÔ¶³ÌÖ´ÐдúÂë¡£¸Ã©¶´ÓëApple֮ǰÐÞ¸´µÄmacOS MontereyºÍiPhone/iPadÖеÄ©¶´Ïàͬ£¬¸Ã¹«Ë¾²¢Î´ÌṩÓйØÈçºÎ±»ÀûÓõÄÏêϸÐÅÏ¢£¬Ö»ÊÇ˵Ëü¿ÉÄÜÒѱ»»ý¼«ÀûÓá£ÕâÊÇAppleÔÚ2022ÄêÐÞ¸´µÄµÚ7¸ö0 day¡£


https://www.bleepingcomputer.com/news/security/apple-releases-safari-1561-to-fix-zero-day-bug-used-in-attacks/


6¡¢Unit42Ðû²¼2022Äê2ÔÂÖÁ4ÔÂÍøÂçÄþ¾²Ì¬ÊƵķÖÎö³ÂËß

      

Unit42ÔÚ8ÔÂ19ÈÕÐû²¼ÁË2022Äê2ÔÂÖÁ4ÔÂÍøÂçÄþ¾²Ì¬ÊƵķÖÎö³ÂËß¡£´Ó½ñÄê2ÔÂÖÁ4Ô£¬Unit42¹²¼Ç¼ÁË5962¸öеÄCVE£¬ÆäÖÐ26.4%±»¹éÀàΪµ±µØÂ©¶´£¬Ê£ÓàµÄ73.6%ÊÇ¿Éͨ¹ýÍøÂçÀûÓõÄÔ¶³Ì©¶´¡£XSS©¶´ÈÔÊdzÂËß×î¶àµÄ©¶´£¬Æä´ÎÊÇÔ½½çдÈë¡¢ÐÅϢй¶ºÍSQL×¢Èë©¶´¡£¶ÔÍøÂç¹¥»÷½øÐзÖÀ࣬×î¶àµÄÊÇÔ¶³Ì´úÂëÖ´Ðй¥»÷£¬Æä´ÎÊDZéÀú¹¥»÷¡¢ÐÅϢй¶¹¥»÷¡¢¿çÕ¾½Å±¾¹¥»÷ºÍSQL×¢Èë¹¥»÷¡£´ó¶àÊý¹¥»÷ËÆºõÀ´×ÔÃÀ¹ú£¬Æä´ÎÊǵ¹úºÍ¶íÂÞ˹¡£


https://unit42.paloaltonetworks.com/recent-exploits-network-security-trends/