Symantec³ÆBillbug¹¥»÷ÑÇÖÞµØÓòµÄÊý×ÖÖ¤Êé·¢±í»ú¹¹

Ðû²¼Ê±¼ä 2022-11-17
1¡¢Symantec³ÆBillbug¹¥»÷ÑÇÖÞµØÓòµÄÊý×ÖÖ¤Êé·¢±í»ú¹¹

SymantecÔÚ11ÔÂ15ÈÕ³ÆÆä·¢ÏÖBillbug¹¥»÷ÁËÑÇÖ޵Ķà¸öÕþ¸®»ú¹¹£¬ÆäÖаüÂÞÒ»¸öÊý×ÖÖ¤Êé·¢±í»ú¹¹¡£¸ÃÍÅ»ï×Ô2009ÄêÒÔÀ´Ò»Ö±»îÔ¾£¬Symantec 2019Äê¼Ç¼µÄ»î¶¯ÖÐÏêϸ½éÉÜÁ˸ÃÍÅ»ïÈçºÎʹÓúóÃÅHannotogºÍSagerunexµÄ£¬ÕâЩ¹¤¾ßÔÚ×î½üµÄ»î¶¯ÖÐÒ²ÓзºÆð¡£´Ë´Î»î¶¯ÖÁÉÙ´Ó3Ô¾ÍÒÑ¿ªÊ¼£¬Óм£Ïó±íÃ÷¹¥»÷ÕßÕýÔÚÀûÓÃÃæÏò¹«ÖÚµÄÓ¦Ó÷¨Ê½À´»ñµÃ¶ÔÄ¿±êÍøÂçµÄ³õʼ·ÃÎÊȨÏÞ¡£Óë֮ǰµÄ»î¶¯Ò»Ñù£¬¹¥»÷ÕßҲʹÓÃÁ˶àÖÖÁ½Óù¤¾ß¼°×Ô½ç˵¶ñÒâÈí¼þ£¬ÈçAdFind¡¢Directory¡¢Winmail¡¢WinRAR¡¢PingºÍTracertµÈ¡£

https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/espionage-asia-governments-cert-authority

2¡¢VaronisÅû¶Zendesk ExploreÖÐSQL×¢ÈëµÈ©¶´µÄϸ½Ú

VaronisÔÚ11ÔÂ15ÈÕÅû¶ÁËZendesk ExploreÖÐÁ½¸ö©¶´µÄϸ½Ú¡£ÆäÖÐÒ»¸öÊÇSQL×¢Èë©¶´£¬¸Ã©¶´Éæ¼°ÆäGraphQL APIÖеÄSQL×¢È룬¿É±»ÓÃÀ´Ð¹Â¶×÷Ϊ¹ÜÀíÔ±´æ´¢ÔÚÊý¾Ý¿âÖеÄËùÓÐÐÅÏ¢£¬°üÂÞÓʼþµØÖ·¡¢¹¤µ¥ÒÔ¼°ÓëʵʱÊðÀíµÄ¶Ô»°µÈ¡£ÁíÒ»¸ö©¶´ÊÇÉæ¼°Óë²éѯִÐÐAPIÏà¹ØµÄÂß¼­·ÃÎÊÎÊÌ⣬¸ÃAPI±»ÅäÖÃΪÔËÐвéѯ£¬¶ø²»¼ì²é½øÐе÷ÓõÄÓû§ÊÇ·ñÓÐ×ã¹»µÄȨÏÞÕâÑù×ö¡£Ä¿Ç°£¬ÕâЩ©¶´Òѱ»ÐÞ¸´¡£

https://securityaffairs.co/wordpress/138579/hacking/zendesk-explore-critical-flaws.html

3¡¢LazarusÀûÓúóÃÅDTrack¹¥»÷Å·ÖÞºÍÀ­¶¡ÃÀÖÞµÄ×éÖ¯

¾Ý11ÔÂ15ÈÕ±¨µÀ£¬³¯ÏʺڿÍÍÅ»ïLazarusÕýÔÚʹÓÃа汾µÄDTrackºóÃÅÀ´¹¥»÷Å·ÖÞºÍÀ­¶¡ÃÀÖÞµÄ×éÖ¯¡£Ä¿±êÐÐÒµ°üÂÞÑо¿ÖÐÐÄ¡¢Õþ²ß»ú¹¹¡¢»¯Ñ§Æ·ÖÆÔìÉÌ¡¢IT·þÎñÌṩÉÌ¡¢µçÐÅÌṩÉÌ¡¢¹«ÓÃÊÂÒµ·þÎñÌṩÉ̺ͽÌÓý¡£ÔÚеĻÖУ¬DTrackͨ³£Ê¹ÓÃÓëºÏ·¨ÎļþÏà¹ØµÄÎļþÃû½øÐзַ¢£¬ÈçÒ»¸öÑù±¾ÒÔ¡°NvContainer.exe¡±ÎªÃû·Ö·¢£¬ËüÓëºÏ·¨µÄNVIDIAÎļþͬÃû¡£´ËÍ⣬DTrackÈÔ¼ÌÐøÍ¨¹ýÇÔÈ¡µÄƾ֤ÈëÇÖÍøÂç»òÀûÓÃÍøÉÏ̻¶µÄ·þÎñÆ÷À´½øÐзַ¢¡£

https://securelist.com/dtrack-targeting-europe-latin-america/107798/

4¡¢Ñо¿ÍŶӷ¢ÏÖ¿ÉÓ°Ï캽ÌìÆ÷ºÍ·É»úµÄ¹¥»÷·½Ê½PCspooF

ýÌå11ÔÂ15ÈÕ±¨µÀ£¬Ñо¿ÍŶӷ¢ÏÖÁËÒ»ÖÖÕë¶Ôʱ¼ä´¥·¢ÒÔÌ«Íø(TTE)µÄÐÂÐ͹¥»÷ÒªÁì¡£TTEÊôÓÚ»ìºÏÒªº¦ÐÔÍøÂçµÄÍøÂç¼¼ÊõÖ®Ò»£¬ÆäÖоßÓвîÒìʱÐòºÍÈÝ´íÒªÇóµÄÁ÷Á¿¹²´æÓÚͬһÎïÀíÍøÂçÖС£¸Ã¼¼ÊõÓÃÓÚÄþ¾²»ù´¡ÉèÊ©£¬¿Éµ¼ÖÂΪº½ÌìÆ÷ºÍ·É»úÌṩ¶¯Á¦µÄϵͳ·ºÆð¹ÊÕÏ¡£ÕâÊÇʹÓöñÒâÉ豸ͨ¹ýÒÔÌ«ÍøµçÀ½«µç´Å×ÌÈÅ(EMI)×¢ÈëTTE½»»»»úÀ´ÊµÏֵģ¬¿ÉÓÐЧµØÓÕʹ½»»»»ú·¢ËÍ¿´ËÆÕæÊµµÄͬ²½ÏûÏ¢²¢ÈÃËüÃDZ»ÆäËûTTEÉ豸½ÓÊÜ¡£×÷Ϊ»º½â´ëÊ©£¬Ñо¿ÈËÔ±½¨ÒéʹÓùâñîºÏÆ÷»òÀËÓ¿±£»¤Æ÷À´×èÖ¹µç´Å×ÌÈÅ¡£

https://thehackernews.com/2022/11/pcspoof-new-vulnerability-affects.html

5¡¢ÒÁÀÊÏà¹ØºÚ¿ÍÀûÓÃLog4Shell©¶´ÈëÇÖÃÀ¹úÕþ¸®»ú¹¹

11ÔÂ16ÈÕ£¬FBIºÍCISAÁªºÏÐû²¼ÁËÒ»·Ýͨ¸æ£¬³ÆÓëÒÁÀÊÏà¹ØµÄºÚ¿ÍÈëÇÖÁËÒ»¸öÕþ¸®»ú¹¹²¢°²×°ÁËXMRig¿ó¹¤¶ñÒâÈí¼þ¡£Í¨¸æ³Æ£¬´Ó2022Äê6ÔÂÖÐÑ®µ½7Ô£¬CISAÔÚÁª°îÃñÓÃÐÐÕþ²¿ÃÅ(FCEB)×éÖ¯ÖÐÊӲ쵽ÁË¿ÉÒɵÄAPT»î¶¯¡£¹¥»÷ÕßÀûÓÃδÐÞ¸´µÄVMware Horizon·þÎñÆ÷ÖеÄLog4Shell©¶´£¬°²×°XMRig¿ó¹¤Èí¼þ£¬ºáÏòÒÆ¶¯µ½Óò¿ØÖÆÆ÷(DC)£¬ÇÔȡƾ¾Ý£¬È»ºóÖ²ÈëNgrok·´ÏòÊðÀíÀ´ÔÚ¶à¸öÉ豸Éϱ£³Ö³Ö¾ÃÐÔ¡£CISA ºÍ FBI Ðû²¼´ËCSAÌṩºÚ¿ÍµÄTTPºÍIOC£¬ÒÔ×ÊÖú×éÖ¯¼ì²âºÍ·ÀÓùÏà¹ØµÄ¹¥»÷¡£

https://www.cisa.gov/uscert/ncas/alerts/aa22-320a

6¡¢KasperskyÐû²¼¹ØÓÚ2023ÄêAPT¹¥»÷»î¶¯µÄÔ¤²â³ÂËß

KasperskyÔÚ11ÔÂ14ÈÕÐû²¼Á˹ØÓÚ2023ÄêAPT¹¥»÷»î¶¯µÄÔ¤²â³ÂËß¡£³ÂËßÔ¤²âÔÚ2023Ä꣬½«·ºÆð´óÁ¿µÄÆÆ»µÐÔÍøÂç¹¥»÷£¬Ó°ÏìÕþ¸®²¿ÃźÍÒªº¦ÐÐÒµ£»Óʼþ·þÎñÆ÷½«³ÉÎªÖØÒªÄ¿±ê£¬ºÜ¿ÉÄÜËùÓÐÖ÷Òªµç×ÓÓʼþÈí¼þ¶¼·ºÆð0-day£»Ò»Ð©¾ßÓÐÓ°ÏìÁ¦µÄ²¡¶¾Ã¿6-7Äê·¢ÉúÒ»´Î£¬¿ÉÄÜ·ºÆðÏÂÒ»¸öWannaCry£»APT¹¥»÷ÍŻォĿ±êתÏòÎÀÐǼ¼Êõ¡¢Éú²úÉ̺ÍÔËÓªÉÌ£»¸ü¶àAPT×éÖ¯½«´ÓCobaltStrike×ªÒÆµ½ÆäËüÌæ´ú·½°¸µÈ¡£

https://securelist.com/advanced-threat-predictions-for-2023/107939/