ZyxelÐÞ¸´NASÖеÄRCE©¶´CVE-2022-34747
Ðû²¼Ê±¼ä 2022-09-08
9ÔÂ6ÈÕ£¬ÍøÂçÉè±¸ÖÆÔìÉÌZyxel³ÆÒ»¸öеÄRCE©¶´»áÓ°ÏìÆä²úÎïNAS326¡¢NAS540ºÍNAS542¡£Í¨¸æÖ¸³ö£¬ÕâÊÇÔÚZyxel NAS²úÎïµÄÌØ¶¨¶þ½øÖÆÎļþÖз¢ÏÖµÄÒ»¸ö¸ñʽ×Ö·û´®Â©¶´£¬¿É±»ÓÃÀ´Í¨¹ýÌØÖÆµÄUDPÊý¾Ý°üʵÏÖδ¾ÊÚȨµÄÔ¶³Ì´úÂëÖ´ÐС£¸Ã©¶´×·×ÙΪCVE-2022-34747£¬CVSSÆÀ·ÖΪ9.8¡£¸Ã©¶´¿ÉÓÃÓÚÇÔÈ¡Êý¾Ý¡¢É¾³ýÊý¾Ý»òÔÚ̻¶ÓÚ»¥ÁªÍøÉϵÄNASÉ豸Öа²×°ÀÕË÷Èí¼þ£¬¹©Ó¦ÉÌÒѾÒԹ̼þ¸üеÄÐÎʽÐû²¼ÁËÊÜÓ°ÏìÉ豸µÄÄþ¾²¸üС£
https://www.bleepingcomputer.com/news/security/zyxel-releases-new-nas-firmware-to-fix-critical-rce-vulnerability/
2¡¢North FaceÔâµ½´ó¹æÄ£µÄײ¿â¹¥»÷Ó°ÏìÔ¼20Íò¸öÕË»§
¾ÝýÌå9ÔÂ7Èճƣ¬»§Íâ·þ×°Æ·ÅÆThe North FaceÔâµ½ÁË´ó¹æÄ£×²¿â¹¥»÷£¬µ¼ÖÂthenorthface.comÍøÕ¾ÉϵÄ194905¸öÕË»§±»ºÚ¡£´Ë´Î¹¥»÷»î¶¯¿ªÊ¼ÓÚ2022Äê7ÔÂ26ÈÕ£¬µ«ÍøÕ¾µÄ¹ÜÀíÔ±ÔÚ8ÔÂ11Èղżì²âµ½Òì³£»î¶¯£¬²¢ÓÚ8ÔÂ19ÈÕ×èÖ¹Á˹¥»÷¡£Ä¿Ç°£¬¸Ã¹«Ë¾ÕýÔÚÏòÊÜÓ°ÏìµÄ¿Í»§·¢ËÍÊý¾Ýй¶֪ͨ£¬²¢ÖØÖÃÁËËùÓÐÓû§ÃÜÂë¡£ÖµµÃ×¢ÒâµÄÊÇ£¬ÕâÊÇThe North FaceµÚ¶þ´ÎÔ⵽ײ¿â¹¥»÷ºóÖØÖÃÃÜÂ룬ÉÏÒ»´Î·¢ÉúÔÚ2020Äê11Ô¡£
https://www.bleepingcomputer.com/news/security/200-000-north-face-accounts-hacked-in-credential-stuffing-attack/
3¡¢AT&TÅû¶ͨ¹ý¶à½×¶ÎѬȾÁ´·Ö·¢Èƹý¼ì²âµÄShikitega
AT&T Alien LabsÓÚ9ÔÂ6ÈÕÅû¶ÁËеÄLinux¶ñÒâÈí¼þShikitega¡£¸Ã¶ñÒâÈí¼þÀûÓÃϵͳ©¶´»ñÈ¡×î¸ßȨÏÞ£¬Í¨¹ýcrontabÔÚÖ÷»úÉϱ£³Ö³Ö¾ÃÐÔ£¬²¢×îÖÕÔÚÄ¿±êÉ豸ÉÏÖ´ÐмÓÃܿ󹤡£Shikitega·Ç³£Òþ±Î£¬ÀûÓöà̬±àÂëÆ÷ÈÆ¹ýɱ¶¾ÒýÇæµÄ¼ì²â£¬ÕâʹµÃ¾²Ì¬¡¢»ùÓÚÇ©ÃûµÄ¼ì²âʧЧ¡£Ä¿Ç°Éв»Çå³þ¿ª¶ËѬȾҪÁ죬µ«Ñо¿ÈËÔ±ÌåÏÖ£¬¸Ã¶ñÒâÈí¼þʹÓöà½×¶ÎѬȾÁ´£¬ÆäÖÐÿһ²ã½öͨ±¨¼¸°Ù×Ö½Ú£¬¼¤»îÒ»¸ö¼òµ¥Ä£¿é£¬È»ºóÒÆ¶¯µ½ÏÂÒ»¸öÄ£¿é¡£
https://cybersecurity.att.com/blogs/labs-research/shikitega-new-stealthy-malware-targeting-linux
4¡¢ESET½üÆÚ·¢ÏÖÖ÷ÒªÕë¶ÔÑÇÖÞÕþ¸®»ú¹¹ºÍ´óÐ͹«Ë¾µÄWorok
9ÔÂ6ÈÕ£¬ESETÑо¿ÈËÔ±³ÆÆä×î½ü·¢ÏÖÁËÖ÷ÒªÕë¶ÔÑÇÖ޵ĴóÐ͹«Ë¾ºÍµØ·½Õþ¸®µÄÕë¶ÔÐÔ¹¥»÷»î¶¯¡£ÕâЩ¹¥»÷ÓëÒ»¸öеļäµý×éÖ¯WorokÓйأ¬¸ÃÍÅ»ïÖÁÉÙ×Ô2020ÄêÒÔÀ´Ò»Ö±´¦Óڻ״̬¡£WorokµÄ¹¤¾ß¼¯°üÂÞÒ»¸öC++¼ÓÔØ·¨Ê½CLRLoad¡¢Ò»¸öPowerShellºóÃÅPowHeartBeatºÍÒ»¸öC#¼ÓÔØ·¨Ê½PNGLoad£¬ËüʹÓÃÒþдÊõ´ÓPNGÎļþÖÐÌáÈ¡Òþ²ØµÄ¶ñÒâpayload¡£´ËÍ⣬WorokÓë±»×·×ÙΪTA428µÄÍÅ»ïÔÚ¹¤¾ß¡¢»î¶¯Ê±¼äºÍÄ¿±êÐÐÒµ·½Ãæ´æÔÚÖØµþ¡£
https://www.welivesecurity.com/2022/09/06/worok-big-picture/
5¡¢TA505ÍÅ»ïʹÓÃTeslaGunÃæ°åÀ´¹ÜÀíÆäServHelperºóÃÅ
PRODAFTÔÚ9ÔÂ6ÈÕÐû²¼Á˹ØÓÚTA505ÍÅ»ïTeslaGunµÄÉî¶È·ÖÎö³ÂËß¡£TA505ÓÖÃûEvil Corp£¬×Ô2014ÄêÒÔÀ´Ò»Ö±»îÔ¾£¬Ö÷ÒªÕë¶ÔÁãÊÛÐÐÒµºÍÒøÐеȡ£³ÂËßÖ¸³ö£¬¹¥»÷ÕßʹÓÃTeslaGun¿ØÖÆÃæ°åÀ´¹ÜÀíServHelperÖ²È뷨ʽ£¬×÷ΪC2¿ò¼ÜÀ´¿ØÖƱ»Ñ¬È¾µÄÉ豸¡£³ýÁËʹÓÃÃæ°åÍ⣬¹¥»÷Õß»¹Ê¹ÓÃÔ¶³Ì×ÀÃæÐÒ鹤¾ßͨ¹ýRDPËíµÀÊÖ¶¯Á¬½Óµ½Ä¿±êϵͳ¡£PRODAFTµÄ·ÖÎöÏÔʾ£¬×Ô2020Äê7ÔÂÒÔÀ´£¬¸ÃÍÅ»ïÒѹ¥»÷ÁËÖÁÉÙ8160¸öÄ¿±ê£¬ÆäÖдó¶àÊýÄ¿±êλÓÚÃÀ¹ú£¨3667¸ö£©¡£
https://www.prodaft.com/resource/detail/ta505-ta505-groups-tesla-gun-depth-analysis
6¡¢Check PointÐû²¼Õë¶Ô·ÇÖÞ´óÐͽðÈÚ»ú¹¹µÄ¹¥»÷µÄ³ÂËß
9ÔÂ6ÈÕ£¬Check Point Research½ÒʾÁËÕë¶Ô·ÇÖ޵Ĺ¥»÷»î¶¯DangerousSavanna¡£¸Ã»î¶¯ÔÚ¹ýÈ¥µÄÁ½ÄêÖÐÒ»Ö±Õë¶Ô·ÇÖÞ·¨ÓïÇøµÄ¶à¸öÖ÷ÒªµÄ½ðÈÚ·þÎñ¹«Ë¾¡£¹¥»÷ÕßʹÓÃÓã²æÊ½µöÓã¹¥»÷×÷Ϊ³õʼѬȾҪÁ죬Ïò¿ÆÌصÏÍß¡¢Ä¦Âå¸ç¡¢¿¦Âó¡¡¢ÈûÄÚ¼Ó¶ûºÍ¶à¸çµÄÔ±¹¤·¢ËͶñÒâÓʼþ¡£ÕâЩÓʼþµÄ¸½¼þҪôÊÇ´øÓкêµÄWordÎĵµ£¬ÒªÃ´ÊÇ´øÓÐÔ¶³ÌÄ£°åµÄÎĵµ£¬»òÕßÊÇÓÕʹĿ±êÏÂÔØ²¢ÊÖ¶¯Ö´ÐÐÏÂÒ»½×¶ÎµÄPDFÎĵµ¡£ËùÓÐÎĵµ£¬ÎÞÂÛÊÇMS Office»¹ÊÇPDF£¬¶¼ÊÇÓ÷¨ÓïдµÄ£¬¶øÇÒʹÓÃÀàËÆµÄÔªÊý¾Ý¡£
https://blog.checkpoint.com/2022/09/06/in-the-mighty-savana-check-point-research-reveals-a-2-year-campaign-targeting-large-financial-institutions-in-french-speaking-african-countries/