Winter Vivern ͨ¹ý Roundcube ȱÏÝÃé×¼ 80 ¶à¸ö×éÖ¯
Ðû²¼Ê±¼ä 2024-02-202ÔÂ19ÈÕ£¬Óë°×¶íÂÞ˹ºÍ¶íÂÞ˹ÀûÒæÒ»ÖµÄÍþвÐÐΪÕßÓëÒ»ÏîеÄÍøÂç¼äµý»î¶¯Óйأ¬¸Ã»î¶¯¿ÉÄÜÀûÓà Roundcube ÍøÂçÓʼþ·þÎñÆ÷ÖеĿçÕ¾½Å±¾ (XSS) ©¶´À´Õë¶Ô 80 ¶à¸ö×éÖ¯¡£¾Ý Recorded Future ³Æ£¬ÕâЩʵÌåÖ÷ҪλÓÚ¸ñ³¼ªÑÇ¡¢²¨À¼ºÍÎÚ¿ËÀ¼£¬¸Ã¹«Ë¾½«Õâ´ÎÈëÇÖ¹éÒòÓÚÃûΪ Winter Vivern µÄÍþвÐÐΪÕߣ¬¸ÃÍþвÕßÒ²±»³ÆΪ TA473 ºÍ UAC0114¡£¸ÃÍøÂçÄþ¾²¹«Ë¾ÕýÔÚ×·×ÙÃûΪ¡°Íþв»î¶¯×éÖ¯ 70¡±(TAG-70) µÄºÚ¿Í×éÖ¯¡£Recorded Future ·¢ÏÖµÄÕⳡ»î¶¯´Ó 2023 Äê 10 Ô¿ªÊ¼Ò»Ö±Á¬Ðøµ½±¾ÔÂÖÐÑ®£¬Ä¿µÄÊÇÊÕ¼¯ÓйØÅ·ÖÞÕþÖκ;üÊ»µÄÇ鱨¡£ÕâЩ¹¥»÷Óë 2023 Äê 3 Ô¼ì²âµ½µÄÕë¶ÔÎÚ×ȱð¿Ë˹̹Õþ¸®Óʼþ·þÎñÆ÷µÄÆäËû TAG-70 »î¶¯Öصþ¡£Recorded FutureÌåÏÖ£¬»¹·¢ÏÖÁËTAG-70Õë¶ÔÒÁÀÊפ¶íÂÞ˹ºÍºÉÀ¼´óʹ¹ÝÒÔ¼°¸ñ³¼ªÑÇפÈðµä´óʹ¹ÝµÄÖ¤¾Ý¡£
https://thehackernews.com/2024/02/russian-linked-hackers-breach-80.html
2.ÒÁÀʺڿÍÀûÓÃÐ嵀 BASICSTAR ºóÃÅÃé×¼Öж«Õþ²ßר¼Ò
2ÔÂ19ÈÕ£¬ÃûΪ Charming Kitten µÄÒÁÀÊÒáÍþвÐÐΪÕßͨ¹ý´´½¨Ò»¸öÐé¼ÙµÄÍøÂçÑÐÌÖ»áÃÅ»§£¬Í¨¹ýÃûΪBASICSTARµÄкóÃÅ£¬ÓëһϵÁÐÕë¶ÔÖж«Õþ²ßר¼ÒµÄй¥»÷Óйء£Charming Kitten£¬Ò²³ÆΪ APT35¡¢CharmingCypress¡¢Mint Sandstorm¡¢TA453 ºÍ Yellow Garuda£¬ÓÐ×ųïıÖÖÖÖÉç»á¹¤³Ì»î¶¯µÄÀúÊ·£¬ÕâЩ»î¶¯ÔÚÆäÄ¿±êÉÏÈöÏÂÁ˹㷺µÄÍøÂ磬ͨ³£×¨ÃÅÕë¶ÔÖÇ¿â¡¢·ÇÕþ¸®×éÖ¯ºÍ¼ÇÕß¡£¸Ã×éÖ¯±»ÆÀ¹ÀΪÁ¥ÊôÓÚÒÁÀÊÒÁ˹À¼¸ïÃüÎÀ¶Ó (IRGC)£¬ÔÚ¹ýÈ¥Ò»ÄêÖл¹·Ö·¢ÁËÆäËû¼¸¸öºóÃÅ£¬ÀýÈçPowerLess¡¢BellaCiao¡¢POWERSTAR£¨ÓÖÃû GorjolEcho£©ºÍNokNok £¬Ç¿µ÷Æä¼ÌÐø½øÐÐÍøÂç¹¥»÷µÄ¾öÐľ¡¹Ü¹ûÈ»Æع⣬µ«ÈÔµ÷ÕûÆä¼ÆıºÍÒªÁì¡£2023 Äê 9 ÔÂÖÁ 10 ÔÂÆÚ¼äÊӲ쵽µÄÍøÂçµöÓã¹¥»÷Éæ¼° Charming Kitten ÔËÓªÉÌð³ä Rasanah ¹ú¼ÊÒÁÀÊÑо¿Ëù (IIIS) Ìᳫ¹¥»÷²¢ÓëÄ¿±ê½¨Á¢ÐÅÈΡ£¹¥»÷Á´Í¨³£Ê¹ÓðüÂÞ LNK ÎļþµÄ RAR ´æµµ×÷Ϊ·Ö·¢¶ñÒâÈí¼þµÄÆðµã£¬²¢Í¨¹ýÏûÏ¢¶Ø´ÙDZÔÚÄ¿±ê¼ÓÈëÓйØËûÃǸÐÐËȤµÄÖ÷ÌâµÄÐé¼ÙÍøÂçÑÐÌֻᡣÒÑÊӲ쵽²¿Êð BASICSTAR ºÍ KORKULOADER£¨Ò»ÖÖ PowerShell ÏÂÔØÆ÷½Å±¾£©µÄ´ËÀà¶à½×¶ÎѬȾÐòÁС£
https://thehackernews.com/2024/02/iranian-hackers-target-middle-east.html
3.ºÚ¿ÍÉù³ÆÈËÁ¦×ÊÔ´¾ÞÍ· Robert Half Êý¾Ýй¶²¢³öÊÛÃô¸ÐÊý¾Ý
2ÔÂ18ÈÕ£¬ÕâЩÎÛÃûÕÑÖøµÄºÚ¿Í·Ö±ðÊÇ IntelBroker ºÍ Sanggiero£¬ËûÃÇÉù³ÆÓµÓÐ Robert Half µÄ´óÁ¿Êý¾Ý£¬ÕâЩÊý¾ÝÕýÔÚÒÔÃÅÂÞ±Ò (XMR) ¼ÓÃÜ»õ±ÒµÄ¼Û¸ñ³öÊÛ£¬ÊÛ¼ÛΪ 20,000 ÃÀÔª¡£2022 Äê 6 Ô£¬È«ÇòÈËÁ¦×ÊÔ´ºÍÉÌÒµ×Éѯ·þÎñ¹«Ë¾ Robert Half International Inc. ÏòÃåÒòÖÝ×ܼì²ì³¤°ì¹«ÊÒÌá½»ÁËÊý¾Ýй¶֪ͨ¡£Í¨Öª³Æ£¬¸Ã¹«Ë¾ÔâÓöÊý¾Ýй¶£¬ºÚ¿ÍÕë¶Ô 1000 ¶àÃû¿Í»§£¬ÀֳɻñÈ¡ÁËËûÃǵÄÐÕÃû¡¢µØÖ·¡¢Éç»áÄþ¾²ºÅÂëºÍË°ÎñÐÅÏ¢¡£ºÚ¿Í»¹·ÖÏíÁ˾ݳÆÏÔʾ±»µÁÊý¾Ý¡¢Git ´æ´¢¿âºÍ AWS Ïà¹ØϵͳÉèÖõÄÆÁÄ»½Øͼ¡£Ò»ÕÅÆÁÄ»½ØͼËƺõÏÔʾÁËÒ»·Ý¿Í»§ÁÐ±í£¬¡°ÕÊ»§Ãû³Æ¡±ÏÂÁгöÁ˹«Ë¾£¬²¢¸½ÓÐÈ«Ãû¡¢Ö÷ÒªÖ°ÄܽÇÉ«¡¢Í·Ïκ͵绰ºÅÂë¡£
https://www.hackread.com/hackers-claim-robert-half-data-breach/
4.Turla APT ʹÓÃTinyTurla-NGÖ¼ÔÚÇÔÈ¡µÇ¼ƾ¾Ý
https://gbhackers.com/turla-aptc-new-tool/
5.ESET ÐÞ¸´ WINDOWS ²úÎïÖеÄÑÏÖØÐÔµ±µØȨÏÞÉý¼¶Â©¶´
2ÔÂ18ÈÕ£¬ESET ½â¾öÁËÆä Windows ²úÎïÖеÄÒ»¸ö¸ßÑÏÖØÐÔ©¶´£¬±àºÅΪ CVE-2024-0353£¨CVSS ÆÀ·Ö 7.8£©¡£¸Ã©¶´ÊÇÒ»¸öµ±µØȨÏÞÉý¼¶ÎÊÌ⣬ÓÉÁãÈռƻ® (ZDI) Ìá½»¸ø¸Ã¹«Ë¾¡£Æ¾¾Ý¸Ãͨ±¨£¬¹¥»÷Õß¿ÉÒÔÀÄÓà ESET µÄÎļþ²Ù×÷£¨ÓÉʵʱÎļþϵͳ±£»¤Ö´ÐУ©£¬ÔÚûÓÐÊʵ±È¨ÏÞµÄÇé¿öÏÂɾ³ýÎļþ¡£ÓÉ Windows ²Ù×÷ϵͳÉϵÄʵʱÎļþϵͳ±£»¤¹¦Ð§Ö´ÐеÄÎļþ²Ù×÷´¦ÖÃÖеÄ©¶´£¬¿ÉÄÜÔÊÐíÄܹ»ÔÚÄ¿±êϵͳÉÏÖ´ÐеÍÌØȨ´úÂëµÄ¹¥»÷Õßɾ³ý NT AUTHORITY\SYSTEM ϵÄÈÎÒâÎļþ£¬ÌáÉýËûÃǵÄÌØȨ¡£ESET ÉÐδ·¢ÏÖÀûÓôË©¶´½øÐеÄÒ°Íâ¹¥»÷»î¶¯¡£
https://securityaffairs.com/159280/breaking-news/eset-local-privilege-escalation-windows.html
6. SOLARWINDS ÐÞ¸´ ACCESS RIGHTS MANAGER ÖеÄÒªº¦ RCE
2ÔÂ19ÈÕ£¬SolarWinds ½â¾öÁËÆä·ÃÎÊȨÏÞ¹ÜÀíÆ÷ (ARM) ½â¾ö·½°¸ÖеÄÈý¸öÒªº¦Â©¶´£¬ÆäÖаüÂÞÁ½¸ö RCE ´íÎó¡£·ÃÎÊȨÏÞ¹ÜÀíÆ÷ (ARM) ÊÇÒ»¿îÈí¼þ½â¾ö·½°¸£¬Ö¼ÔÚ×ÊÖú×éÖ¯¹ÜÀíºÍ¼à¿ØÆä IT »ù´¡ÉèÊ©ÄڵķÃÎÊȨÏÞºÍȨÏÞ¡£´ËÀ๤¾ß¶ÔÓÚά»¤Óû§¶ÔÖÖÖÖ×ÊÔ´¡¢ÏµÍ³ºÍÊý¾ÝµÄ·ÃÎʵÄÄþ¾²ÐÔ¡¢ºÏ¹æÐԺ͸ßЧ¹ÜÀíÖÁ¹ØÖØÒª¡£Èý¸öÑÏÖصÄÔ¶³Ì´úÂëÖ´ÐÐȱÏÝÊÇ£ºCVE-2023-40057£¨CVSS ÆÀ·Ö 9.0£©£º²»ÊÜÐÅÈÎÊý¾ÝµÄ·´ÐòÁл¯ÎÊÌâ¡£¾¹ýÉí·ÝÑéÖ¤µÄÓû§¿ÉÒÔÀûÓôË©¶´ÀÄÓà SolarWinds ·þÎñ£¬´Ó¶øµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£CVE-2024-23479£¨CVSS ÆÀ·Ö 9.6£©£ºÄ¿Â¼±éÀúÔ¶³Ì´úÂëÖ´ÐЩ¶´¡£Î´¾Éí·ÝÑéÖ¤µÄÓû§¿ÉÒÔÀûÓôËÎÊÌâʵÏÖÔ¶³Ì´úÂëÖ´ÐС£CVE-2024-23476£¨CVSS ÆÀ·Ö 9.6£©Ä¿Â¼±éÀúÔ¶³Ì´úÂëÖ´ÐЩ¶´¡£Èç¹û±»ÀûÓã¬Î´¾Éí·ÝÑéÖ¤µÄÓû§¿ÉÒÔʵÏÖÔ¶³ÌÖ´ÐдúÂë¡£
https://securityaffairs.com/159294/security/solarwinds-access-rights-manager-flaws.html