Ð嵀 SSH-Snake ¶ñÒâÈí¼þÇÔÈ¡ SSH ÃÜÔ¿¿ÉÔÚÄÚÍøºáÏòÒƶ¯
Ðû²¼Ê±¼ä 2024-02-231. Ð嵀 SSH-Snake ¶ñÒâÈí¼þÇÔÈ¡ SSH ÃÜÔ¿¿ÉÔÚÄÚÍøºáÏòÒƶ¯
2ÔÂ21ÈÕ£¬ÍþвÐÐΪÕßÕýÔÚʹÓÃÃûΪ SSH-Snake µÄ¿ªÔ´ÍøÂçÓ³É乤¾ßÀ´Ñ°ÕÒδ±»¼ì²âµ½µÄ˽Կ£¬²¢ÔÚÊܺ¦Õß»ù´¡ÉèÊ©ÉϺáÏòÒƶ¯¡£SSH-Snake ÊÇÓÉ Sysdig ÍþвÑо¿ÍÅ¶Ó (TRT) ·¢Ïֵģ¬ËûÃǽ«ÆäÃèÊöΪһÖÖ¡°×ÔÎÒÐÞ¸ÄÈä³æ¡±£¬Ëüͨ¹ýÖÆֹͨ³£Óë½Å±¾¹¥»÷Ïà¹ØµÄģʽ¶ø´Ó´«Í³ SSH Èä³æÖÐÍÑÓ±¶ø³ö¡£¸ÃÈä³æÔÚ¸÷¸öλÖ㨰üÂÞ shell ÀúÊ·Îļþ£©ËÑË÷˽Կ£¬²¢ÔÚÓ³ÉäÍøÂçºóʹÓÃËüÃÇÃØÃÜÁ÷´«µ½ÐÂϵͳ¡£SSH-Snake¿É×÷ΪһÖÖ¿ªÔ´×ʲú£¬ÓÃÓÚ»ùÓÚ SSH µÄ×Ô¶¯»¯ÍøÂç±éÀú£¬Ëü¿ÉÒÔ´ÓÒ»¸öϵͳ¿ªÊ¼£¬²¢ÏÔʾÓëͨ¹ý SSH Á¬½ÓµÄÆäËûÖ÷»úµÄ¹Øϵ¡£SSH-Snake µÄÒ»¸öÌØÊâÐÔÊÇÄܹ»ÔÚµÚÒ»´ÎÔËÐÐʱ½øÐÐ×ÔÎÒÐ޸IJ¢Ê¹×ÔÉí±äС¡£Ëüͨ¹ý´Ó´úÂëÖÐɾ³ý×¢ÊÍ¡¢²»ÐëÒªµÄº¯ÊýºÍ¿Õ¸ñÀ´ÊµÏÖÕâÒ»µã¡£SSH-Snake רΪ¶à¹¦Ð§ÐÔ¶øÉè¼Æ£¬¼´²å¼´Ó㬵«ÔÊÐíƾ¾ÝÌض¨²Ù×÷ÐèÇó½øÐж¨ÖÆ£¬°üÂÞµ÷Õû¼ÆıÀ´·¢ÏÖ˽Կ²¢Ê¶±ðÆäDZÔÚÓÃ;¡£
https://www.bleepingcomputer.com/news/security/new-ssh-snake-malware-steals-ssh-keys-to-spread-across-the-network/
2. Ð嵀 Wi-Fi ©¶´Ê¹ Android ºÍ Linux É豸ÃæÁÙ¹¥»÷
2ÔÂ21ÈÕ£¬ÍøÂçÄþ¾²Ñо¿ÈËÔ±ÔÚ Android¡¢Linux ºÍ ChromeOS É豸Öз¢ÏֵĿªÔ´ Wi-Fi Èí¼þÖз¢ÏÖÁËÁ½¸öÉí·ÝÑéÖ¤ÈƹýȱÏÝ£¬ÕâЩȱÏÝ¿ÉÄÜ»áÓÕÆÓû§¼ÓÈëºÏ·¨ÍøÂçµÄ¶ñÒâ¿Ë¡£¬»òÔÊÐí¹¥»÷ÕßÎÞÐèÃÜÂë¼´¿É¼ÓÈëÊÜÐÅÈεÄÍøÂç¡£ÕâЩ©¶´·Ö±ð±àºÅΪ CVE-2023-52160 ºÍ CVE-2023-52161£¬ÊÇÔÚ¶Ôwpa_supplicantºÍÓ¢Ìضû iNet Wireless Daemon ( IWD ) ½øÐÐÄþ¾²ÆÀ¹Àºó·¢Ïֵġ£ÌرðÊÇ£¬CVE-2023-52161 ÔÊÐí¹¥»÷Õßδ¾ÊÚȨ·ÃÎÊÊܱ£»¤µÄ Wi-Fi ÍøÂ磬ʹÏÖÓÐÓû§ºÍÉ豸ÃæÁÙ¶ñÒâÈí¼þѬȾ¡¢Êý¾Ý͵ÇÔºÍÉÌÒµµç×ÓÓʼþй¶ (BEC) µÈDZÔÚ¹¥»÷¡£ËüÓ°Ïì IWD 2.12 ¼°¸üµÍ°æ±¾¡£ÁíÒ»·½Ã棬CVE-2023-52160 Ó°Ïì wpa_supplicant °æ±¾ 2.10 ¼°¸üÔç°æ±¾¡£ÕâÒ²ÊÇÕâÁ½¸öȱÏÝÖиü½ôÆȵÄÒ»¸ö£¬ÒòΪËüÊÇ Android É豸ÖÐÓÃÓÚ´¦ÖÃÎÞÏßÍøÂçµÇ¼ÇëÇóµÄĬÈÏÈí¼þ¡£
https://thehackernews.com/2024/02/new-wi-fi-vulnerabilities-expose.html
3. IBM X-Force Ðû²¼ 2024 ÄêÍþвÇ鱨ָÊý³ÂËß
2ÔÂ21ÈÕ£¬IBM µÄ X-Force ÍþвÇ鱨ÍŶÓÌåÏÖ£¬ÍøÂç·¸×ï·Ö×ÓÔ½À´Ô½¶àµØÀûÓñ»µÁÉí·ÝÀ´ÆÆ»µÆóҵϵͳ£¬¶ø²»ÊÇÊÔͼÇÖÈëÆóҵϵͳ£¬ÕâÖÖÇ÷ÊÆÓÐÍûÔÚδÀ´¼¸ÄêÄÚÔö¼Ó¡£Íþв×é֯Ϊ»ñÈ¡µÇ¼ϵͳËùÐèµÄÐÅÏ¢¶ø½ÓÄɵÄÐж¯ÌåÏÖÔÚÐí¶àÁìÓò£¬´Ó°µÍøÉÏÌṩµÄ´óÁ¿Æ¾Ö¤ºÍÆäËû¸öÈËÐÅÏ¢µ½ 2023 Äêͬ±ÈÔö³¤ 266%¡£¾Ý IBM ³Æ£¬¸Ã¶ñÒâÈí¼þÖ¼ÔÚÇÔÈ¡µç×ÓÓʼþ¡¢É罻ýÌåºÍÏûÏ¢Ó¦Ó÷¨Ê½Æ¾¾Ý¡¢ÒøÐÐÏêϸÐÅÏ¢ºÍ¼ÓÃÜ»õ±ÒÇ®°üÊý¾ÝµÈ¸öÈËÉí·ÝÐÅÏ¢¡£·ÀÓùÕßÒ²¸üÄѼì²âµ½´ËÀ๥»÷£¬´Ó¶øʹ×éÖ¯Ó¦¶ÔÕâЩ¹¥»÷µÄʱ¼ä¸ü³¤¡¢³É±¾¸ü¸ß¡£³ÂËߵļ¸¸öÁÁµãÖ®Ò»ÊÇÁ¬ÐøתÏòÉí·Ýʶ±ð¶ø²»ÊǺڿ͹¥»÷¡£ÆäËû°üÂÞÆóÒµÀÕË÷Èí¼þʼþÊýÁ¿¼õÉÙÁË 11.5%£¬¾¡¹ÜÊý¾Ý͵ÇÔºÍй¶°¸¼þÕ¼ËùÓй¥»÷µÄ 32%£¬Ê¹Æä³ÉΪ¡°¶Ô×éÖ¯×î³£¼ûµÄÓ°Ï죬±íÃ÷¸ü¶àÍÅÌåÇãÏòÓÚÕâÖÖÒªÁìÀ´»ñÈ¡¾¼ÃÊÕÒæ¡£
https://securityboulevard.com/2024/02/identity-based-attacks-grow-while-ransomware-declines-ibm-x-force/
4. WordPress ²å¼þȱÏÝ£¨CVE-2024-1317£©¿Éµ¼ÖÂÊý¾Ýй¶
2ÔÂ21ÈÕ£¬Ò»¸öÑÏÖصÄ©¶´»áΣ¼°Ê¹Óà Feedzy ²å¼þÌṩµÄÁ÷ÐÐ RSS ¾ÛºÏÆ÷µÄ WordPress ÍøÕ¾µÄÄþ¾²¡£WordPress µÄ»îÔ¾°²×°Á¿Áè¼Ý 50,000 ¸ö£¬Òò´ËÓû§±ØÐëÁ˽â·çÏÕ²¢Á¢¼´½ÓÄÉÐж¯¡£¸Ã²å¼þ 4.4.2 ֮ǰµÄ°æ±¾°üÂÞÒ»¸öÑÏÖØµÄ SQL ×¢ÈëȱÏÝ£¬Ê¹ÄúµÄÃô¸ÐÐÅÏ¢Êܵ½ÍøÂç·¸×ï·Ö×ӵĿØÖÆ¡£¸ÃȱÏݱ»×·×ÙΪCVE-2024-1317 ( CVSS 8.8 )£¬ÔÚ Feedzy ²å¼þ 4.4.2 ¼°Ö®Ç°µÄËùÓа汾ÖоùÒÑ·¢ÏÖ¡£¡° search_key ¡±²ÎÊýÊÇÒ»¸öÍø¹Ø£¬SQL ²éѯͨ¹ý¸ÃÍø¹ØÏòÊý¾Ý¿â͸¶ÃØÃÜ£¬µ«Ã»Óеõ½³äʵµÄ±£»¤¡£¶ÔÓû§ÌṩµÄ²ÎÊýµÄתÒå²»³äʵÒÔ¼° SQL ²éѯ×Ô¼ºÈ±·¦×¼±¸£¬Îª¾ßÓÐТ¾´Õß¼¶±ð»ò¸ü¸ßȨÏ޵ľ¹ýÉí·ÝÑéÖ¤µÄ¹¥»÷Õß×¢Èë¶ñÒâ SQL ³¨¿ªÁË´óÃÅ£¬´Ó¶øÇÔÈ¡ÁË°üÂÞÃÜÂë¹þÏ£ÔÚÄÚµÄÊý¾Ý¡£2 Ô 9 ÈÕÐû²¼Á˲¹¶¡¡£°æ±¾4.4.3ÐÞ¸´Á˸鶴¡£
https://securityonline.info/cve-2024-1317-critical-wordpress-plugin-flaw-leaves-your-data-exposed/
5. µÂ¹ú PSI Software SE È·ÈÏÆäÔâµ½ÀÕË÷Èí¼þµÄ¹¥»÷
2ÔÂ22ÈÕ£¬µÂ¹úÅÓ´óÖÆÔìºÍÎïÁ÷Á÷³ÌÈí¼þ¿ª·¢ÉÌ PSI Software SE ֤ʵ£¬¸Ã¹«Ë¾³ÉΪÉæ¼°ÀÕË÷Èí¼þµÄÍøÂç¹¥»÷µÄÊܺ¦Õߣ¬¸Ã¹¥»÷Ëðº¦ÁËÆäÄÚ²¿»ù´¡ÉèÊ©¡£¸Ã¹«Ë¾ÔÚÈ«ÇòÔËÓª£¬ÓµÓÐÁè¼Ý 2,000 ÃûÔ±¹¤£¬ÒÔΪÖ÷ÒªÄÜÔ´¹©Ó¦ÉÌ´òÔìÈí¼þ½â¾ö·½°¸¶øÎÅÃû¡£Ëü»¹ÌṩһÕûÌ×·þÎñ£¬ÓÃÓÚ¹ÜÀíºÍά»¤ÏÖÓÐÄÜÔ´»ù´¡ÉèÊ©¡¢Í¶×Ê×éºÏ¹ÜÀíÒÔ¼°ÄÜÔ´×ÊÔ´µÄÓªÏúºÍ·ÖÅä¡£2ÔÂ15ÈÕ£¬PSI SoftwareÐû²¼´Ë´ÎÍøÂç¹¥»÷ÔÚÆäÍøÕ¾Ö÷Ò³µÄÏÔ×ÅλÖÃÏÔʾ£¬ÔÝʱÒþ²ØÁËÆäÓàÄÚÈÝ¡£´Ë´Î¹¥»÷µ¼Ö¶à¸ö IT ϵͳ£¨°üÂÞµç×ÓÓʼþ£©¹Ø±Õ£¬ÒÔ½µµÍÊý¾Ý¶ªÊ§µÄ·çÏÕ¡£ÔÚËæºóµÄ¸üÐÂÖУ¬PSI Software È·ÈÏ´Ë´ÎÖжÏÊÇÓÉÍøÂç·¸×ï·Ö×ÓʹÓÃÀÕË÷Èí¼þÔì³ÉµÄ¡£¸Ã¹«Ë¾ÉÐδȷ¶¨ÕØÊÂÕß½øÈë¼òÖ±Çз½Ê½¡£¸Ã¹«Ë¾ÉÐδÌṩÓйؿͻ§¶Ëϵͳµ±Ç°ÔËÐÐ״̬µÄÐÅÏ¢¡£
https://meterpreter.org/psi-software-se-confirms-ransomware-disruption/
6. ΢Èí¿ªÊ¼Ç¿ÖƸüÐÂWindows 11 23H2
2ÔÂ22ÈÕ£¬Î¢ÈíÔÚÈ¥ÄêÐû²¼ÁËWindows 11µÄÖØ´ó¸üУ¬°æ±¾23H2£¬ÒýÈëÁËÈ˹¤ÖÇÄÜÖúÊÖCopilot£¬Ê¹Windows 11³ÉΪµÚÒ»¸öÏòÓû§Ìṩ¼¯ÖÐʽÈ˹¤ÖÇÄÜ×ÊÖúµÄPCƽ̨¡£È»¶ø£¬ÓÉÓÚ·½±ãµÄ¡°¿ÉÑ¡¡±¿ª¹Ø£¬Ðí¶àÓû§Ñ¡Ôñ²»Éý¼¶µ½Windows 11 23H2¡£¶ÔÓÚ΢ÈíÀ´Ëµ£¬ÕâÖÖÇ÷ÊƲ¢²»ÀíÏ룬΢Èí×î½üÌåÏÖÔÚÆäÖ§³ÖÎĵµÖÐÌåÏÖ£¬Ëü½«×Ô¶¯½«¡°ÇкÏÌõ¼þµÄ¡±É豸¸üе½ Windows 11 23H2¡£´Ë¼ÆıÖ÷ÒªÕë¶ÔÒѵ½´ï»ò½Ó½üʹÓÃÊÙÃüµÄ Windows 11 É豸£¬ÌرðÊÇ Windows 11 21H2 / 22H1 °æ±¾¡£Windows 11 21H2 ÓÚ 2023 Äê 10 Ô 10 ÈÕµ½´ïÉúÃüÖÜÆÚÖÕÖ¹ (EOL)£¬¶ø Windows 11 22H2 Ò²½«ÓÚ 2024 Äê 10 Ô 8 ÈÕÖÕÖ¹¡£ÔÚÕâЩÈÕÆÚÖ®ºó£¬Microsoft ½«Í£Ö¹ÎªÕâЩ°æ±¾ÌṩÄþ¾²¸üкÍÆäËû¸ïС£
https://meterpreter.org/microsoft-begins-mandatory-update-to-windows-11-23h2/