TruthFinderºÍInstant Checkmateй¶2000¶àÍòÕË»§ÐÅÏ¢
Ðû²¼Ê±¼ä 2023-02-06
¾ÝýÌå2ÔÂ5ÈÕ±¨µÀ£¬PeopleConnectµÄÅä¾°ÊÓ²ì·þÎñTruthFinderºÍInstant Checkmate·¢ÉúÊý¾Ýй¶¡£1ÔÂ21ÈÕ£¬ºÚ¿ÍÂÛ̳BreachedµÄÒ»Ãû³ÉԱй¶Á˽ØÖÁ2019Äê4ÔÂ16ÈÕʹÓ÷þÎñµÄ2022ÍòTruthFinderºÍInstant Checkmate¿Í»§µÄÊý¾Ý¡£±»µÁÊý¾Ý×÷ΪÁ½¸ö½ö°üÂÞ¿Í»§ÐÅÏ¢µÄ2.9 GB CSVÎļþ¹²Ïí£¬ÌáÈ¡ºóÕû¸öÊý¾Ý¼¯¸ß´ï7 GB£¬°üÂÞÐÕÃû¡¢µç»°ºÅÂë¡¢ÓʼþµØÖ·¡¢ÃÜÂëhashºÍÃÜÂëÖØÖÃÁîÅÆµÈ¡£PeopleConnectÒѶԴËÊÂÕ¹¿ªÊӲ죬²¢È·ÈϸÃÃûµ¥ÊǼ¸Äêǰ´´½¨µÄ£¬Ëƺõ°üÂÞÁË2011ÄêÖÁ2019ÄêÆÚ¼ä´´½¨µÄËùÓÐÕË»§¡£
https://www.hackread.com/instant-checkmate-truthfinder-data-breach/
2¡¢ÐµÄAndroidľÂíPixPirateÖ÷ÒªÕë¶Ô°ÍÎ÷µÄ½ðÈÚ»ú¹¹
2ÔÂ3ÈÕ£¬Cleafy³ÂË߯äÔÚ2022Äêµ×ÖÁ2023Äê³õ·¢ÏÖÁËÒ»ÖÖÕë¶Ô°ÍÎ÷½ðÈÚ»ú¹¹µÄ¶ñÒâÈí¼þPixPirate¡£PixPirateÊôÓÚ×îÐÂÒ»´úµÄAndroidÒøÐÐľÂí£¬ÒòΪËü¿ÉÒÔÖ´ÐÐATS£¨×Ô¶¯×ªÕËϵͳ£©£¬¹¥»÷ÕßÄܹ»Í¨¹ý¶à¼Ò°ÍÎ÷ÒøÐнÓÄɵļ´Ê±Ö§¸¶Æ½Ì¨Pix×Ô¶¯½øÐжñÒâ»ã¿î¡£³ýÁËÇÔÈ¡Óû§ÔÚÒøÐÐÓ¦ÓÃÉÏÊäÈëµÄÃÜÂëÍ⣬¹¥»÷Õß»¹ÀûÓÃAuto.js¿ò¼Ü½øÐдúÂë»ìÏýºÍ¼ÓÃÜÀ´ÈƹýÄæÏò¹¤³ÌµÄ·ÖÎö¡£
https://www.cleafy.com/cleafy-labs/pixpirate-a-new-brazilian-banking-trojan
3¡¢Ó¡¶È×î´ó»õÔ˹«Ë¾FR8·þÎñÆ÷ÅäÖôíÎóй¶140GBÊý¾Ý
ýÌå2ÔÂ4ÈÕ͸¶£¬Ó¡¶È×î´óµÄ¿¨³µÔËÊä·þÎñ¹«Ë¾FR8Òò·þÎñÆ÷ÅäÖôíÎóй¶ÁË140 GBµÄÊý¾Ý¡£1ÔÂ30ÈÕ£¬Ñо¿ÈËÔ±ÔÚShodanÉÏËÑË÷ÅäÖôíÎóµÄÔÆÊý¾Ý¿âʱ·¢ÏÖÁ˸÷þÎñÆ÷¡£Ð¹Â¶ÐÅÏ¢Éæ¼°¿Í»§ºÍÔ±¹¤µÄÐÕÃû¡¢µç»°¡¢·¢Æ±ºÍ¸¶¿îÃ÷ϸµÈÃô¸ÐÐÅÏ¢¡£Ä¿Ç°£¬¸ÃÅäÖôíÎóµÄ·þÎñÆ÷ÈÔ´¦ÓÚ̻¶״̬£¬FR8Ò²²¢Î´»ØÓ¦¸Ãʼþ¡£ÓÉÓÚ·þÎñÆ÷ÊÇʵʱµÄÇҸù«Ë¾Ò»Ö±Ã»ÓлØÓ¦£¬Èç¹ûÊý¾ÝÂäÈë¶ñÒâµÄµÚÈý·½ÊÖÖУ¬±»ÎóÓúÍÀÄÓõĿÉÄÜÐԺܴó¡£
https://www.hackread.com/india-truck-brokerage-company-data-leak/
4¡¢Ñо¿ÍŶӷ¢ÏÖÕë¶ÔESXi·þÎñÆ÷µÄ´ó¹æÄ£ESXiArgsÀÕË÷¹¥»÷
¾Ý2ÔÂ3ÈÕ±¨µÀ£¬Ñо¿ÍŶӷ¢ÏÖÁËÀûÓÃVMware ESXi·þÎñÆ÷ÖÐδÐÞ¸´µÄÔ¶³Ì´úÂëÖ´ÐЩ¶´°²×°ÐÂÀÕË÷Èí¼þESXiArgsµÄ»î¶¯¡£Â©¶´×·×ÙΪCVE-2021-21974£¬ÓÉOpenSLP·þÎñÖеĶÑÒç³öÒýÆð£¬¿É±»ÓÃÀ´Ö´ÐеÍÅÓ´ó¶È¹¥»÷¡£OVHcloud͸¶£¬¸Ã»î¶¯Í¨¹ýOpenSLP¶Ë¿Ú(427)Õë¶Ô7.0 U3i֮ǰ°æ±¾µÄESXi·þÎñÆ÷¡£Æ¾¾ÝShodanËÑË÷µÄÊý¾Ý£¬È«ÇòÖÁÉÙÓÐ120̨VMware ESXi·þÎñÆ÷ÒÑÔâµ½¹¥»÷¡£Õë¶Ô¸Ã»î¶¯µÄÊÓ²ìÈÔÔÚ½øÐÐÖС£
https://www.bleepingcomputer.com/news/security/massive-esxiargs-ransomware-attack-targets-vmware-esxi-servers-worldwide/
5¡¢ÒÁÀʺڿÍÍÅ»ïOilRigÀûÓÃкóÃŹ¥»÷Öж«µÄÕþ¸®»ú¹¹
Trend MicroÔÚ2ÔÂ2ÈÕÅû¶ÁËÒÁÀÊOilRigÕë¶ÔÖж«Õþ¸®»ú¹¹µÄ¹¥»÷»î¶¯¡£2022Äê12Ô£¬Ñо¿ÈËÔ±·¢ÏÖÁËÒ»¸ö¿ÉÖ´ÐÐÎļþ£¨¼ì²âΪTrojan.MSIL.REDCAP.AD£©ÒÑÔÚ¶ą̀¼ÆËã»úÉÏ·Ö·¢²¢Ö´ÐС£·ÖÎö·¢ÏָûÓëAPT×éÖ¯OilRig£¨APT34£©Óйأ¬Ö÷ҪĿµÄÊÇÇÔÈ¡Óû§µÄƾ¾Ý¡£¸Ã»î¶¯Ê¼ÓÚÒ»¸ö»ùÓÚ.NETµÄÖ²È뷨ʽ£¬ÆäÈÎÎñÊÇ·Ö·¢Ëĸö²îÒìµÄÎļþ¡£µÚ¶þ½×¶Î»¹Ê¹ÓÃÁËÒ»¸öDLLÎļþ£¬ÄÜ´ÓÓòÓû§ºÍµ±µØÕÊ»§Öлñȡƾ¾Ý¡£´ËÍ⣬´Ë´Î»î¶¯ÖеĺóÃÅ¿ÉÀûÓñ»Ñ¬È¾µÄÓÊÏäÕÊ»§½«ÇÔÈ¡µÄÊý¾Ý´ÓÄÚ²¿ÓÊÏä·¢Ë͵½¹¥»÷ÕßµÄÓʼþÕÊ»§¡£
https://www.trendmicro.com/en_us/research/23/b/new-apt34-malware-targets-the-middle-east.html
6¡¢CiscoÐÞ¸´IOxÓ¦ÓÃÖеÄÃüÁî×¢Èë©¶´CVE-2023-20076
2ÔÂ3ÈÕ£¬CiscoÐû²¼Äþ¾²¸üУ¬ÐÞ¸´ÁËIOxÓ¦Ó÷¨Ê½Íйܻ·¾³ÖеÄÃüÁî×¢Èë©¶´£¨CVE-2023-20076£©¡£¸Ã©¶´ÊÇÓÉÓÚ¼¤»îÓ¦Ó÷¨Ê½Ê±´«ÈëµÄ²ÎÊýδµÃµ½ÍêÈ«µÄ¾»»¯µ¼Öµģ¬¹¥»÷Õß¿ÉÒÔʹÓÃÌØÖÆµÄ¼¤»îpayloadÎļþÔÚCisco IOxÓ¦Ó÷¨Ê½Íйܻ·¾³Öа²×°ºÍ¼¤»îÓ¦Ó÷¨Ê½À´ÀûÓôË©¶´¡£ÀÖ³ÉÀûÓøÃ©¶´ºó£¬¿ÉÒÔÔڵײãÖ÷»ú²Ù×÷ϵͳÉÏÒÔrootÉí·ÝÖ´ÐÐÈÎÒâÃüÁî¡£¸Ã©¶´Ó°ÏìÁËÆôÓÃCisco IOx¹¦Ð§¶øÇÒ²»Ö§³Ö±¾»ú dockerµÄÉ豸¡£
https://securityaffairs.com/141743/security/cisco-bug-iox-application-hosting-environment.html