ÃϼÓÀ­¹úijÕþ¸®ÍøÕ¾ÅäÖôíÎóй¶Êý°ÙÍò¹«ÃñµÄÐÅÏ¢

Ðû²¼Ê±¼ä 2023-07-10

1¡¢ÃϼÓÀ­¹úijÕþ¸®ÍøÕ¾ÅäÖôíÎóй¶Êý°ÙÍò¹«ÃñµÄÐÅÏ¢


¾ÝýÌå7ÔÂ7ÈÕ±¨µÀ£¬ÃϼÓÀ­¹úijÕþ¸®ÍøÕ¾Ð¹Â¶ÁËÊý°ÙÍò¹«ÃñµÄ¸öÈËÐÅÏ¢£¬Éæ¼°ÐÕÃû¡¢µç»°ºÅÂë¡¢µç×ÓÓʼþµØÖ·ºÍÉí·ÝÖ¤ºÅÂëµÈ¡£Ñо¿ÈËÔ±ÓÚ6ÔÂ27ÈÕÊ״η¢ÏÖÁ˸ÃÎÊÌ⣬²¢ÁªÏµÁËÃϼÓÀ­¹úµç×ÓÕþÎñ¼ÆËã»úʼþÏìӦС×é(CERT)¡£¾ÝϤ£¬Ð¹Â¶µÄÊý¾Ý·ºÆðÔÚÓëSQL´íÎóÏà¹ØµÄGoogle²éѯ½á¹ûÖС£Ñо¿ÈËÔ±²¢Î´Í¸Â¶¸ÃÕþ¸®ÍøÕ¾µÄ¾ßÌåÃû³Æ£¬ÒòΪÕâЩÊý¾ÝÈÔ¿ÉÔÚÏß»ñÈ¡¡£Ä¿Ç°£¬Ã»ÓÐÈκÎÃϼÓÀ­¹úÕþ¸®×éÖ¯¶Ô´ËÊÂ×ö³ö»ØÓ¦¡£


https://techcrunch.com/2023/07/07/bangladesh-government-website-leaks-citizens-personal-data/


2¡¢TA453ͨ¹ýÐÂѬȾÁ´°²×°PowerShellºóÃÅGorjolEcho 


ProofpointÓÚ7ÔÂ6ÈÕÅû¶ÁËÒÁÀʺڿÍÍÅ»ïTA453Õë¶ÔWindowsºÍmacOSµÄ¶ñÒâÈí¼þ»î¶¯¡£TA453ÓÚ5Ô·ݿªÊ¼Ê¹ÓÃLNKѬȾÁ´£¬¶ø²»ÊÇ´øÓкêµÄMicrosoft WordÎĵµ¡£´Ë´Î»î¶¯ÖУ¬¹¥»÷Õßαװ³É»Ê¼ÒÁªºÏ¾üÖÖÑо¿Ëù(RUSI)µÄ¸ß¼¶Ñо¿Ô±£¬Õë¶ÔÒ»¼ÒרעÓÚÍâ½»ÊÂÎñµÄÃÀ¹úÖÇ¿âµÄºËÄþ¾²×¨¼Ò¡£¹¥»÷ÕßʹÓÃÖÖÖÖÔÆÍйÜÌṩÉÌÀ´ÌṩеÄѬȾÁ´£¬Ö¼ÔÚ°²×°ÐÂÐÍPowerShellºóÃÅGorjolEcho¡£´ËÍ⣬TA453»¹ÒÆÖ²ÁËÆä¶ñÒâÈí¼þ£¬²¢ÊÔͼÆô¶¯Ò»¸öÃûΪNokNokµÄÕë¶ÔmacOSµÄѬȾÁ´¡£


https://www.proofpoint.com/us/blog/threat-insight/welcome-new-york-exploring-ta453s-foray-lnks-and-mac-malware


3¡¢MastodonÐÞ¸´¿Éµ¼Ö·þÎñÆ÷½Ù³ÖµÄ©¶´TootRoot


¾Ý7ÔÂ7ÈÕ±¨µÀ£¬¿ªÔ´µÄÈ¥ÖÐÐÄ»¯Éç½»ÍøÂçÆ½Ì¨MastodonÐÞ¸´ÁË4¸öÄþ¾²Â©¶´¡£ÆäÖÐ×îÑÏÖØµÄÊÇMastodonýÌå´¦ÖôúÂëÖеÄ©¶´TootRoot£¨CVE-2023-36460£©£¬¿Éµ¼ÖÂDoSºÍÈÎÒâÔ¶³Ì´úÂëÖ´ÐеÈÎÊÌ⣬¿ÉÓÃÓÚÔÚ·þÎñÆ÷ÖÐÖ²ÈëºóÃÅ¡£¹¥»÷ÕßÀûÓøÃ©¶´£¬Äܹ»ÎÞÏÞÖÆµØ¿ØÖÆ·þÎñÆ÷¼°ÆäÍйܺ͹ÜÀíµÄÊý¾Ý¡£µÚ¶þ¸öÊÇXSS©¶´£¨CVE-2023-36459£©£¬¿ÉÈÆ¹ýÄ¿±êä¯ÀÀÆ÷ÉϵÄHTMLÇåÀí¡£ÁíÍâÁ½¸ö©¶´ÊÇCVE-2023-36461ºÍCVE-2023-36462¡£


https://www.bleepingcomputer.com/news/security/critical-tootroot-bug-lets-attackers-hijack-mastodon-servers/


4¡¢¼ÓÃÜ»õ±Òƽ̨MultichainÔâµ½¹¥»÷ËðʧÁè¼Ý1.25ÒÚÃÀÔª


ýÌå7ÔÂ8ÈÕ±¨µÀ³Æ£¬¼ÓÃÜ»õ±Òƽ̨MultichainÒÑÔÝÍ£Æä·þÎñ£¬ÒòΪËüÕýÔÚÊÓ²ìÉæ¼°Áè¼Ý1.25ÒÚÃÀÔªµÄ¼ÓÃÜ»õ±Ò±»µÁʼþ¡£ÉÏÖÜËÄÍí¼ä£¬¸Ã¹«Ë¾ÌåÏÖ£¬Æ½Ì¨²¿ÃÅ×ʲú¡°ÒÑÒì³£×ªÒÆÖÁδ֪µØÖ·¡±£¬²¢ÔÚ¼¸Ð¡Ê±ºóÔÝÍ£ÁËËùÓзþÎñÒÔ½øÐÐÊӲ졣ÖÜÎåÔçÉÏ£¬¸Ã¹«Ë¾Ðû²¼ÉùÃ÷È·ÈÏËûÃÇÔâµ½Á˺ڿ͹¥»÷£¬²¢ÌåÏÖ½«»áÍË¿î¸ø¸÷ÈË¡£Óд«ÑԳƴ˴ι¥»÷Êǰ×ñºÚ¿ÍËùΪ£¬µ«Éв»Çå³þÕâЩ˵·¨ÊÇ·ñ׼ȷ¡£


https://therecord.media/millions-stolen-from-multichain-crypto


5¡¢Google PlayÖеÄÁ½¿î¼äµýÈí¼þÇÔÈ¡150ÍòÓû§µÄÐÅÏ¢


7ÔÂ8ÈÕ±¨µÀ³Æ£¬PradeoÔÚGoogle PlayÉ̵êÖз¢ÏÖÁËÁ½¿î¶ñÒâÓ¦Óã¬Òþ²Ø×żäµýÈí¼þ²¢¼àÊÓ¶à´ï150ÍòÓû§¡£ÕâÁ½¸öÓ¦Ó÷¨Ê½¶¼ÊÇÀ´×Ôͬһ¿ª·¢É̵ÄÎļþ¹ÜÀíÓ¦Ó㬷ֱðÊǰ²×°Á¿Áè¼Ý100ÍòµÄÎļþ»Ö¸´ºÍÊý¾Ý»Ö¸´Ó¦ÓúͰ²×°Á¿Áè¼Ý50ÍòµÄÎļþ¹ÜÀíÆ÷¡£Á½¿îÓ¦ÓûáÇÔÈ¡ÁªÏµÈËÁÐ±í¡¢Ã½ÌåÎļþ¡¢ÊµÊ±Î»ÖúÍÒÆ¶¯¹ú¼Ò´úÂëµÈÐÅÏ¢¡£Ñо¿ÈËÔ±×¢Òâµ½£¬ÕâЩӦÓöÔÊÕ¼¯µ½µÄÊý¾ÝÖ´ÐÐÁËÒ»°Ù¶à´Î´«Ê䣬Õâ¶ÔÓÚ¼äµýÈí¼þÀ´ËµÊDz»Ñ°³£µÄ¡£


https://thehackernews.com/2023/07/two-spyware-apps-on-google-play-with-15.html


6¡¢Î¢ÈíÐû²¼¹ØÓÚÀÕË÷Èí¼þBlackByteµÄ¹¥»÷Á´µÄÊÓ²ì³ÂËß


7ÔÂ6ÈÕ£¬Î¢ÈíÐû²¼¹ØÓÚÀÕË÷Èí¼þBlackByteµÄ·ÖÎö³ÂËß¡£Ñо¿ÈËÔ±×î½ü¶ÔÒ»´ÎÈëÇÖµÄÊÓ²ìÖУ¬·¢ÏÖ¹¥»÷ÕßÔÚ²»µ½ÎåÌìµÄʱ¼äÀïÍê³ÉÁË´Ó³õʼ·ÃÎʵ½ÊµÊ©Õû¸ö¹¥»÷Á´¡£ÔÚÕâÎåÌìÄÚ£¬¹¥»÷ÕßʹÓÃÁËһϵÁй¤¾ßºÍ¼¼Êõ£¬×îÖÕ°²×°ÁËBlackByte 2.0À´ÊµÏÖÆäÄ¿±ê¡£ÕâЩ¼¼Êõ°üÂÞ£ºÀûÓÃδ´ò²¹¶¡µÄExchange·þÎñÆ÷¡¢Ê¹ÓÃliving-off-the-land¹¤¾ß½øÐг־ÃÐÔºÍÕì²ì¡¢²¿ÊðÓÃÓÚC2µÄCobalt StrikeÐűêÒÔ¼°²¿Êð¶¨ÖƵÄÊý¾ÝÊÕ¼¯ºÍÉøÍ¸¹¤¾ßµÈ¡£


https://www.microsoft.com/en-us/security/blog/2023/07/06/the-five-day-job-a-blackbyte-ransomware-intrusion-case-study/