LATRODECTUS²»Í£¸üв¢·Ö·¢ICEDIDºÍÆäËû¶ñÒâÈí¼þ
Ðû²¼Ê±¼ä 2024-05-225ÔÂ21ÈÕ£¬LATRODECTUSÓÚ 2023 Äê 10 ÔÂÓÉÎÖ¶ûÂêÑо¿ÈËÔ±Ê״η¢ÏÖ£¬ÊÇÒ»ÖÖÔÚÍøÂç·¸×ï·Ö×ÓÖÐÔ½À´Ô½Á÷ÐеĶñÒâÈí¼þ¼ÓÔØ·¨Ê½¡£ËäÈ»Õâ±»ÈÏΪÊÇÒ»¸öеļÒ×壬µ«ÓÉÓÚÐÐΪºÍÉú³¤ÏàËÆÐÔ£¬LATRODECTUS ºÍICEDIDÖ®¼ä´æÔÚ½ôÃÜÁªÏµ£¬°üÂÞÏÂÔغÍÖ´ÐмÓÃܸºÔØ£¨Èç ICEDID£©µÄÃüÁî´¦Ö÷¨Ê½¡£Proofpoint ºÍ Team Cymru »ùÓÚÕâÖÖÁªÏµ£¬·¢ÏÖÁËICEDID ºÍ LATRODECTUS ÔËÓªÉÌʹÓõÄÍøÂç»ù´¡ÉèÊ©Ö®¼ä´æÔÚ½ôÃÜÁªÏµ¡£LATRODECTUS ÌṩÁËһϵÁÐÈ«ÃæµÄ³ß¶È¹¦Ð§£¬ÍþвÐÐΪÕß¿ÉÒÔÀûÓÃÕâЩ¹¦Ð§À´²¿Êð¸ü¶àµÄÓÐЧ¸ºÔØ£¬ÔÚ¿ª¶ËÈëÇÖºóÖ´ÐÐÖÖÖֻ¡£´úÂë¿âδ¾¹ý»ìÏý£¬½ö°üÂÞ 11 ¸öרעÓÚö¾ÙºÍÖ´ÐеÄÃüÁî´¦Ö÷¨Ê½¡£ÕâÖÖÀàÐ͵ļÓÔØÆ÷´ú±íÁËÎÒÃÇÍŶÓ×î½üÊӲ쵽µÄÀ˳±£¬ÀýÈçPIKABOT£¬ÆäÖдúÂëÔ½·¢ÇáÁ¿¼¶ºÍÖ±½Ó£¬´¦Ö÷¨Ê½ÊýÁ¿ÓÐÏÞ¡£
https://www.elastic.co/security-labs/spring-cleaning-with-latrodectus?&web_view=true
2. Kinsing¹¥»÷Apache Tomcat²¿ÊðÍÚ¿ó·¨Ê½
5ÔÂ20ÈÕ£¬Kinsing ¶ñÒâÈí¼þÒÔÀûÓà Linux ÔÆ·þÎñÆ÷ÉϵÄ©¶´²¿ÊðºóÃźͼÓÃÜ»õ±ÒÍÚ¿ó·¨Ê½¶øÎÅÃû£¬×î½ü½«ÆäÄ¿±êÀ©Õ¹µ½°üÂÞ Apache Tomcat ·þÎñÆ÷¡£¸Ã¶ñÒâÈí¼þÀûÓÃÐÂÓ±µÄ¼¼ÊõÀ´Ìӱܼì²â£¬½«×ÔÉíÒþ²ØÔÚ¿´ËÆÎÞº¦µÄϵͳÎļþÖУ¬Ê¹ÆäÔÚÊÜѬȾµÄϵͳÉϳ־ôæÔÚ£¬Í»³öÁË Kinsing ²»Í£Éú³¤µÄ¼Æı£¬²¢Ç¿µ÷ϵͳ¹ÜÀíÔ±ÐèÒª¶ÔÕâЩÐÂÐËÍþв±£³Ö¾¯Ìè¡£Kinsing ÀûÓÃÈÝÆ÷ºÍ·þÎñÆ÷ÖеÄ©¶´À´²¿ÊðºóÃźͼÓÃÜÍÚ¿ó·¨Ê½£¬ÊÓ²ì½á¹ûÏÔʾ¶à¸ö·þÎñÆ÷Êܵ½Ñ¬È¾£¬ÆäÖаüÂÞ¾ßÓÐÑÏÖØȱÏÝµÄ Apache Tomcat¡£Tomcat ÊÇÒ»¿î¿É¹ûÈ»·ÃÎʵľ²Ì¬ÄÚÈÝ¿ªÔ´·þÎñÆ÷£¬ÓÉÓÚÆäÔÚ»¥ÁªÍøÉϵÄ̻¶¶ø³ÉΪÖ÷Òª¹¥»÷Ä¿±ê£¬ÕâʹµÃ Kinsing ¿ÉÒÔÉø͸µ½ÏµÍ³Öв¢½¨Á¢Òþ²ØµÄºóÃÅÒÔʵÏÖ³Ö¾ÃÐÔ£¬Í¬Ê±²¿Êð¼ÓÃÜ¿ó¹¤À´ÇÔÈ¡¼ÆËã×ÊÔ´ÒÔ½øÐмÓÃÜ»õ±ÒÍÚ¾ò¡£
https://gbhackers.com/kinsing-malware-apache-tomcat-servers/
3. SECÒªÇó½ðÈÚ×éÖ¯ÐèÒªÔÚ 30 ÌìÄÚÅû¶Êý¾Ýй¶Ê¼þ
5ÔÂ21ÈÕ£¬ÃÀ¹ú֤ȯ½»Ò×ίԱ»á£¨SEC£©¶Ô SP ¹æÔò½øÐÐÁËÐ޸ģ¬ÒªÇó½ðÈÚ¹«Ë¾ÔÚ 30 ÌìÄÚ³ÂËßÊý¾Ýй¶Çé¿ö¡£ÕâÊDZ£»¤Ïû·ÑÕßµÄÒ»´ó½ø²½¡£ÕâÏîй涨½«ÓÚ 2024 Äê 5 Ô 15 ÈÕÉúЧ£¬Ö¼ÔÚ¼ÓÇ¿ºÍ¸üжÔÏû·ÑÕß½ðÈÚÐÅÏ¢µÄ±£»¤¡£×Ô 2000 ÄêÍƳöÒÔÀ´£¬SEC ¼à¹Ü SPÒªÇó¾¼Í½»Ò×ÉÌ¡¢Í¶×ʹ«Ë¾ºÍ³ÖÅÆͶ×ÊÕÕÁÏͨ¹ýÊéÃæÕþ²ßºÍ·¨Ê½±£»¤¿Í»§¼Ç¼ºÍÐÅÏ¢¡£¸Ã¹æÔò»¹½âÊÍÁËÈçºÎÕýȷɾ³ýÏû·ÑÕß³ÂËßÐÅÏ¢£¬²¢ÒªÇóÒþ˽Õþ²ß֪ͨºÍÑ¡ÔñÍ˳öÑ¡Ïî¡£¶àÄêÀ´£¬¼¼ÊõµÄ½ø²½Ê¹µÃÊý¾Ýй¶µÄ¿ÉÄÜÐÔ¸ü´ó£¬Õâ¾ÍÊÇÐèÒªÕâЩ¸Ä±äµÄÔÒò¡£
https://gbhackers.com/financial-organizations-data-breach/
4. Git Ô¶³Ì´úÂëÖ´ÐЩ¶´CVE-2024-32002
5ÔÂ21ÈÕ£¬Ñо¿ÍŶӷ¢ÏÖÁËÒ»¸öÑÏÖصÄÔ¶³Ì´úÂëÖ´ÐЩ¶´£¬¸Ã©¶´±»Ö¸¶¨Îª CVE-2024-32002£¬ÑÏÖØˮƽΪ 9.0£¨ÑÏÖØ£©¡£Õâ¸öÌØÊâµÄ©¶´´æÔÚÓڹ㷺ʹÓõÄcloneÃüÁîÖС£Git ÉÏÖÜÐû²¼ÁËÒ»·ÝÄþ¾²Í¨¸æ£¬ÆäÖÐÖ¸³öÁËÓйØÔ¶³Ì´úÂëÖ´ÐеÄÎÊÌâ¡£³ý´ËÖ®Í⣬¸Ã©¶´±»ÃèÊöΪÓÉÓÚ¿ÉÒÔÒÔÌض¨·½Ê½Æð²ÝµÄ×ÓÄ£¿é¶ø´æÔÚ£¬´Ó¶ø¿ÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£²»ÍâÕâ¸ö©¶´ÒѾ±»gitÐÞ¸´£¬¶øÇÒÐû²¼ÁËÐÞ²¹°æ±¾¡£Æ¾¾ÝÍøÂçÄþ¾²ÐÂÎÅ·ÖÏíµÄ³ÂËߣ¬git ʹÓÃ×ÓÄ£¿é£¬ÕâЩ×ÓÄ£¿éÊÇǶÌ×ÔÚÆäËû´æ´¢¿âÖеĴ洢¿â¡£Ã¿¸ö×ÓÄ£¿éÔÚÖ÷Ŀ¼Öж¼ÓÐÒ»¸öÖ¸¶¨µÄĿ¼·¾¶£¬¸ÃĿ¼·¾¶»á±»¸ú×ÙÒÔÈ·±£×¼È·¼Ç¼¸ü¸Ä¡£½øÒ»²½ÊӲ췢ÏÖ£¬Windows£¨A/modules/x£©ºÍmacOS£¨a/modules/x£©µÄĬÈÏÉèÖÃÖдæÔÚ²»Çø·Ö¾ÞϸдµÄÎļþϵͳ¡£ÕâÁ½¸ö·¾¶µÄ´¦Ö÷½Ê½Ïàͬ£¬ÕâÊÇÔ¶³Ì´úÂëÖ´Ðб³ºóµÄÖ÷ÒªÔÒò¡£
https://gbhackers.com/git-flaw-remote-code-execution/
5. Fluent Bit ÑÏÖØȱÏÝÓ°ÏìËùÓÐÖ÷ÒªÔÆÌṩÉÌ
5ÔÂ21ÈÕ£¬¿ÉÔھܾø·þÎñºÍÔ¶³Ì´úÂëÖ´Ðй¥»÷ÖÐÀûÓõÄÒªº¦ Fluent Bit ©¶´Ó°ÏìÁËËùÓÐÖ÷ÒªÔÆÌṩÉ̺ÍÐí¶à¼¼Êõ¾ÞÍ·¡£Fluent Bit ÊÇÒ»Öַdz£Á÷ÐеÄÈÕÖ¾¼Ç¼ºÍÖ¸±ê½â¾ö·½°¸£¬ÊÊÓÃÓÚ Windows¡¢Linux ºÍ macOS£¬Ç¶ÈëÔÚÖ÷Òª Kubernetes ¿¯ÐаæÖУ¬°üÂÞÀ´×Ô Amazon AWS¡¢Google GCP ºÍ Microsoft Azure µÄ¿¯Ðа档½ØÖÁ 2024 Äê 3 Ô£¬Fluent Bit µÄÏÂÔغͲ¿Êð´ÎÊýÁè¼Ý 130 ÒڴΣ¬½Ï 2022 Äê 10 Ô±¨µÀµÄ30 ÒÚ´ÎÏÂÔØÁ¿´ó·ùÔö³¤¡£Fluent Bit Ò²±» Crowdstrike ºÍ Trend Micro µÈÍøÂçÄþ¾²¹«Ë¾ÒÔ¼°Ë¼¿Æ¡¢VMware¡¢Ó¢Ìضû¡¢Adobe ºÍ´÷¶ûµÈÐí¶à¿Æ¼¼¹«Ë¾Ê¹Óá£Õâ¸öÑÏÖصÄÄÚ´æËð»µÂ©¶´±»¸ú×ÙΪCVE-2024-4323£¬²¢±»·¢Ïָ鶴µÄ Tenable Äþ¾²Ñо¿ÈËÔ±³ÆΪLinguistic Lumberjack£¬ËüÊÇÔÚ°æ±¾ 2.0.7 ÖÐÒýÈëµÄ£¬ÊÇÓÉ Fluent Bit µÄǶÈëʽ HTTP ·þÎñÆ÷½âÎö¸ú×ÙÇëÇóÖеĶѻº³åÇøÒç³ö©¶´ÒýÆðµÄ¡£¾¡¹Üδ¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔÇáËÉÀûÓøÃÄþ¾²Â©¶´À´´¥·¢¾Ü¾ø·þÎñ»òÔ¶³Ì²¶×½Ãô¸ÐÐÅÏ¢£¬µ«Èç¹ûÓÐÊʵ±µÄÌõ¼þºÍ×ã¹»µÄʱ¼äÀ´´´½¨¿É¿¿µÄ©¶´£¬ËûÃÇÒ²¿ÉÒÔʹÓÃËüÀ´»ñµÃÔ¶³Ì´úÂëÖ´ÐС£
https://www.bleepingcomputer.com/news/security/critical-fluent-bit-flaw-impacts-all-major-cloud-providers/
6. AntidotľÂíαװ³ÉGoogle Play¸üУ¬ÇÔÈ¡ÒøÐÐÊý¾Ý
5ÔÂ22ÈÕ£¬CybleµÄÑо¿ÈËÔ±·¢ÏÖÁËÒ»ÖÖÕë¶Ô Android É豸µÄÐÂÒøÐÐľÂí¡£ÕâÖÖÅÓ´óµÄ¶ñÒâÈí¼þ¾ßÓжàÖÖΣÏÕ¹¦Ð§£¬°üÂÞÁýÕÖ¹¥»÷¡¢¼üÅ̼ǼºÍ»ìÏý¼¼Êõ¡£¸ÃľÂíƾ¾ÝÆäÔ´´úÂëÖеÄ×Ö·û´®ÃüÃûΪ¡°Antidot¡±£¬ÒÔαװ³É¹Ù·½ Google Play ¸üв¢Ö§³Ö¶àÖÖÓïÑÔ¶øÎÅÃû£¬°üÂÞÓ¢Óï¡¢µÂÓï¡¢·¨Óï¡¢Î÷°àÑÀÓï¡¢ÆÏÌÑÑÀÓï¡¢ÂÞÂíÄáÑÇÓÉõÖÁ¶íÓï¡£¸Ã¶ñÒâÈí¼þ×÷Ϊ Google Play µÄ¸üнøÐзַ¢£¬²¢ÒÔ¡°Ð°汾¡±µÄÃû³Æ·ºÆðÔÚÊܺ¦ÕßµÄÉ豸ÉÏ¡£°²×°ºÍÊ×´ÎÆô¶¯ºó£¬Óû§»á¿´µ½Ò»¸ö¼ÙÒ³Ã棬¾Ý³ÆÀ´×Ô Google Play£¬ÆäÖаüÂÞÍê³É¸üÐÂËùÐè²Ù×÷µÄÏêϸ˵Ã÷¡£
https://meterpreter.org/new-antidot-trojan-masquerades-as-google-play-update-steals-banking-data/