RedTailÍÚ¿óÀûÓà Palo Alto Networks ·À»ðǽµÄ©¶´
Ðû²¼Ê±¼ä 2024-06-035ÔÂ31ÈÕ£¬RedTail¼ÓÃÜ»õ±ÒÍÚ¾ò¶ñÒâÈí¼þ±³ºóµÄÍþвÐÐΪÕß½«×î½üÅû¶µÄÓ°Ïì Palo Alto Networks ·À»ðǽµÄÄþ¾²Â©¶´Ìí¼Óµ½Æ䩶´ÀûÓÿâÖС£Æ¾¾ÝÍøÂç»ù´¡ÉèÊ©ºÍÄþ¾²¹«Ë¾ Akamai µÄÑо¿½á¹û£¬¸Ã¶ñÒâÈí¼þ²»½öÔÚÆ乤¾ß°üÖÐÔö¼ÓÁË PAN-OS ©¶´£¬»¹¶ÔÆä½øÐÐÁ˸üУ¬Ä¿Ç°ÒѽÓÄÉÁËеķ´·ÖÎö¼¼Êõ¡£Akamai ·¢ÏÖµÄѬȾÐòÁÐÀûÓÃÁË PAN-OS ÖÐÏÖÒÑÐÞ²¹µÄ©¶´CVE-2024-3400£¨CVSS ÆÀ·Ö£º10.0£©£¬¸Ã©¶´¿ÉÄÜÔÊÐíδ¾Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÔÚ·À»ðǽÉÏÒÔ root ȨÏÞÖ´ÐÐÈÎÒâ´úÂë¡£ÀÖ³ÉÀûÓÃÖ®ºó£¬½«Ö´ÐÐÖ¼ÔÚ´ÓÍⲿÓò¼ìË÷ºÍÔËÐÐ bash shell ½Å±¾µÄÃüÁ¸Ã½Å±¾·´¹ýÀ´ÂôÁ¦Æ¾¾Ý CPU ¼Ü¹¹ÏÂÔØ RedTail ÓÐЧ¸ºÔØ¡£RedTail µÄÆäËûÁ÷´«»úÖÆÉæ¼°ÀûÓà TP-Link ·ÓÉÆ÷£¨CVE-2023-1389£©¡¢ThinkPHP£¨CVE-2018-20062£©¡¢Ivanti Connect Secure£¨CVE-2023-46805 ºÍ CVE-2024-21887£©ÒÔ¼° VMWare Workspace ONE Access ºÍ Identity Manager£¨CVE-2022-22954£©ÖÐÒÑÖªµÄÄþ¾²Â©¶´¡£RedTailÓÚ 2024 Äê 1 ÔÂÊ×´ÎÓÉÄþ¾²Ñо¿Ô± Patryk Machowiak ¼Ç¼£¬Éæ¼°ÀûÓà Log4Shell ©¶´ (CVE-2021-44228) ÔÚ»ùÓÚ Unix µÄϵͳÉϲ¿Êð¶ñÒâÈí¼þµÄ»î¶¯¡£
https://thehackernews.com/2024/05/redtail-crypto-mining-malware.html
2. Cooler Master È·ÈÏÊý¾Ýй¶Ê¼þÖпͻ§ÐÅÏ¢±»µÁ
5ÔÂ31ÈÕ£¬¼ÆËã»úÓ²¼þÖÆÔìÉÌ Cooler Master È·ÈÏÆäÓÚ 5 Ô 19 ÈÕÔâÓöÊý¾Ýй¶£¬ÍþвÐÐΪÕßÇÔÈ¡ÁË¿Í»§Êý¾Ý¡£Cooler Master ÊÇÒ»¼ÒÖªÃûµÄ¼ÆËã»úÓ²¼þÖÆÔìÉÌ£¬ÒÔÆäÀäÈ´É豸¡¢¼ÆËã»ú»úÏä¡¢µçÔ´ºÍÆäËûÍâΧÉ豸¶øÎÅÃû¡£BleepingComputer×òÌ챨µÀ³Æ£¬Ò»¸öÃûΪ¡°Ghostr¡±µÄÍþвÐÐΪÕ߸æËßÎÒÃÇ£¬ËûÃÇÓÚ 5 Ô 18 ÈÕÈëÇÖÁ˸ù«Ë¾µÄ Fanzone ÍøÕ¾²¢ÏÂÔØÁËÆäÁ´½ÓµÄÊý¾Ý¿â¡£Cooler Master µÄ Fanzone ÍøÕ¾ÓÃÓÚ×¢²á²úÎï±£ÐÞ¡¢ÉêÇë RMA »ò¿ªÁ¢Ö§³ÖƱ£¬ÒªÇó¿Í»§Ìîд¸öÈËÊý¾Ý£¬ÀýÈçÐÕÃû¡¢µç×ÓÓʼþµØÖ·¡¢µØÖ·¡¢µç»°ºÅÂë¡¢³öÉúÈÕÆÚºÍʵ¼ÊµØÖ·¡£Ghostr ÌåÏÖ£¬ÔÚ Fanzone ©¶´·¢ÉúÆڼ䣬ËûÃÇÏÂÔØÁË 103 GB µÄÊý¾Ý£¬ÆäÖаüÂÞÁè¼Ý 500,000 Ãû¿Í»§µÄ¿Í»§ÐÅÏ¢¡£ÍþвÐÐΪÕß»¹¹²ÏíÁËÊý¾ÝÑù±¾£¬Ê¹ BleepingComputer Äܹ»ÓëÎ¥¹æÐÐΪÖÐÁгöµÄÖÚ¶à¿Í»§È·ÈÏËûÃǵÄÊý¾ÝÊÇ׼ȷµÄ£¬¶øÇÒËûÃÇ×î½üÏò Cooler Master ÇëÇóÁËÖ§³Ö»ò RMA¡£Ñù±¾ÖеÄÆäËûÊý¾Ý°üÂÞ²úÎïÐÅÏ¢¡¢Ô±¹¤ÐÅÏ¢ÒÔ¼°Ó빩ӦÉ̵ĵç×ÓÓʼþÐÅÏ¢¡£ÍþвÕßÉù³ÆÓµÓв¿ÃÅÐÅÓÿ¨ÐÅÏ¢£¬µ« BleepingComputer ÔÚÊý¾ÝÑù±¾ÖÐÕÒ²»µ½ÕâЩÊý¾Ý¡£
https://www.bleepingcomputer.com/news/security/cooler-master-confirms-customer-info-stolen-in-data-breach/
3. BBC Åû¶ÁËÓ°ÏìÆäÑøÀϽð¼Æ»®³ÉÔ±µÄÊý¾Ýй¶Ê¼þ
6ÔÂ1ÈÕ£¬BBC µÄÐÅÏ¢Äþ¾²ÍŶÓÒÑÏòÎÒÃÇͨ±¨ÁËÒ»ÆðÊý¾ÝÄþ¾²Ê¼þ£¬ÆäÖв¿ÃÅ°üÂÞ BBC ÑøÀϽð¼Æ»®³ÉÔ±¸öÈËÐÅÏ¢µÄÎļþ±»´ÓÔÆ´æ´¢·þÎñÖи´ÖÆ¡£ÕâЩÎļþ°üÂÞһЩÑøÀϽð¼Æ»®³ÉÔ±µÄ¸öÈËÐÅÏ¢£¬°üÂÞÐÕÃû¡¢¹úÃñ±£Ïպš¢³öÉúÈÕÆںͼÒͥסַµÈÏêϸÐÅÏ¢¡£¡±Í¨¸æдµÀ¡£¡°ËùÉæ¼°µÄÊý¾ÝÎļþÊǸ±±¾£¬Òò´Ë¶Ô¼Æ»®µÄÕý³£ÔË×÷ûÓÐÓ°Ïì¡£¸ÃʼþδӰÏìÑøÀϽð¼Æ»®ÃÅ»§ÍøÕ¾µÄÔËÐУ¬Óû§¿ÉÒÔ¼ÌÐøʹÓ᣸Ãʼþй¶ÁËÔ¼ 25,000 Ãû BBC ÑøÀϽð¼Æ»®³ÉÔ±µÄ¸öÈËÐÅÏ¢£¬ÆäÖаüÂÞÏÖÈκÍÇ°ÈÎÔ±¹¤¡£Ð¹Â¶µÄÊý¾Ý°üÂÞÈ«Ãû¡¢¹úÃñ±£Ïպš¢³öÉúÈÕÆÚ¡¢ÐÔ±ðºÍ¼Òͥסַ¡£Õâ¼ÒÓ¢¹ú¹«¹²·þÎñ¹ã²¥¹«Ë¾ÔÚÍⲿר¼ÒµÄ×ÊÖúÏÂÊÓ²ìÁËÕâһʼþ£¬²¢ÒѽÓÄÉÁËÌرðµÄÄþ¾²´ëÊ©¡£×¨¼ÒÃÇÒѾȷ¶¨ÁËÄþ¾²Â©¶´µÄÔÒò²¢½ÓÄÉÁËÄþ¾²´ëÊ©¡£¸Ã¹«Ë¾ÕýÔÚͨ¹ýµç×ÓÓʼþ»òÓʼķ½Ê½ÁªÏµËùÓÐÊÜÓ°ÏìµÄ»áÔ±¡£Ä¿Ç°£¬¸Ã¹«Ë¾Ã»ÓÐÖ¤¾Ý±íÃ÷ÊÜËðÎļþÒѱ»ÀÄÓá£
https://securityaffairs.com/163908/data-breach/bbc-disclosed-data-breach.html
4. FlyingYetiÀûÓÃWinRAR©¶´½øÐÐÓÐÕë¶ÔÐԵĹ¥»÷»î¶¯
6ÔÂ2ÈÕ£¬×Ô 2022 Äê 2 Ô 24 ÈÕ¶íÂÞ˹ÈëÇÖÎÚ¿ËÀ¼ÒÔÀ´£¬¸÷¹úÖ®¼äÒÔ¼°È«ÊÀ½çÖ®¼äµÄ½ôÕžÖÊÆÒ»Ö±ºÜÑÏÖØ¡£´Ë´Îʼþºó£¬ÎÚ¿ËÀ¼¶Ôδ³¥Õ®ÎñµÄס»§ÊµÊ©ÁËÇýÖðºÍÖÕÖ¹¹«ÓÃÊÂÒµ·þÎñµÄ½ûÁ¸Ã½ûÁÓÚ2024Äê1Ô½áÊø¡£È»¶ø£¬ÕâÒ»Ìض¨Ê±ÆÚÈ´±»Ò»ÃûÃûΪFlyingYetiµÄÍþвÐÐΪÕßËùÀûÓ᣸ÃÍþвÐÐΪÕßÀûÓÃÎÚ¿ËÀ¼¹«Ãñ¶Ôδ¹é»¹Õ®ÎñºÍ¿ÉÄÜʧȥס·¿µÄ½¹ÂÇ£¬¿ªÕ¹ÁËÒÔÕ®ÎñΪÖ÷ÌâµÄÍøÂçµöÓã»î¶¯£¬ÓÕÆÊܺ¦Õß½«¶ñÒâÈí¼þÎļþÏÂÔص½ËûÃǵÄϵͳÖС£¸Ã¶ñÒâÈí¼þÊÇÒ»ÖÖ³ÆΪ¡°COOKBOX¡±µÄ PowerShell ¶ñÒâÈí¼þ£¬ËüʹÕâЩÍþвÐÐΪÕßÄܹ»°²×°ÌرðµÄÓÐЧÔغɲ¢¿ØÖÆÊܺ¦ÕßµÄϵͳ¡£´ËÍ⣬ÍøÂçµöÓã»î¶¯»¹ÀûÓÃÁË GitHub ·þÎñÆ÷ºÍ Cloudflare ÊÂÇéÆ÷ÒÔ¼° WinRAR ©¶´£¨CVE-2023-38831£©¡£lyingYeti ÍþвÐÐΪÕߵĻÓë֮ǰȷ¶¨µÄÍþвÐÐΪÕß UAC-0149 ÓÐÖصþ£¬ºóÕßÔøÔÚ 2023 ÄêÇ^ʹÓÃÏàͬµÄ¶ñÒâÈí¼þ¹¥»÷ÎÚ¿ËÀ¼¹ú·ÀʵÌå¡£2024 Äê 4 ÔÂÖÐÑ®ÖÁ 5 ÔÂÖÐÑ®Æڼ䣬¾ÝÊӲ죬FlyingYeti ÍþвÐÐΪÕßÕýÔÚ¶ÔÊܺ¦Õß½øÐÐÕì²ì»î¶¯£¬ÕâЩ»î¶¯ºÜ¿ÉÄÜÓÃÓÚÔ¶¨ÓÚ¸´Éú½ÚÆÚ¼äÌᳫµÄ»î¶¯¡£
https://gbhackers.com/flyingyeti-winrar-vulnerability-malware-attacks/
5. LilacSquid ºÚ¿Í¹¥»÷ IT ÐÐÒµÒÔ»ñÈ¡»úÃÜÊý¾Ý
6ÔÂ1ÈÕ£¬ºÚ¿ÍÃé×¼ IT ÐÐÒµ£¬ÒòΪÕâЩÐÐÒµÕÆÎÕ×ÅÃû¹óµÄÊý¾Ý¡¢Òªº¦µÄ»ù´¡ÉèÊ©£¬¶øÇÒͨ³£¿ÉÒÔ·ÃÎʸ÷¸öÁìÓòµÄÃô¸ÐÐÅÏ¢¡£ÈëÇÖ IT ¹«Ë¾¿ÉÒÔΪºÚ¿ÍÌṩ½øÐмäµý»î¶¯¡¢»ñÈ¡¾¼ÃÀûÒæÒÔ¼°ÆÆ»µ»ù±¾·þÎñµÄ¾Þ´ó»ú»á¡£½üÈÕ£¬Ë¼¿ÆTalosÍøÂçÄþ¾²Ñо¿ÈËÔ±·¢ÏÖ£¬LilacSquidºÚ¿ÍÒ»Ö±ÔÚ»ý¼«¹¥»÷ITÐÐÒµ£¬ÒÔ»ñÈ¡»úÃÜÊý¾Ý¡£Talos È·ÐÅ¡°LilacSquid¡± APT ×éÖ¯ÖÁÉÙ´Ó 2021 Ä꿪ʼ¾ÍÒ»Ö±ÔÚ½øÐÐÊý¾ÝÇÔÈ¡»î¶¯£¬ÀÖ³ÉÈëÇÖÁËÑÇÖÞ¡¢Å·ÖÞºÍÃÀ¹úµÄÖÆÒ©¡¢Ê¯ÓÍ¡¢ÌìÈ»ÆøºÍ¼¼ÊõÐÐÒµµÄÄ¿±ê ³õʼ·ÃÎÊÀûÓÃÁË©¶´ºÍ±»µÁµÄ RDP ƾ¾Ý¡£ÈëÇÖºó£¬LilacSquid ²¿ÊðÁË MeshAgent Ô¶³Ì·ÃÎʹ¤¾ß¡¢QuasarRAT µÄ¶¨ÖÆ¡°PurpleInk¡±±äÌåÒÔ¼° SSF µÈ¿ªÔ´ÊðÀí¹¤¾ß£¬Óë Lazarus ºÍ Andariel µÈ³¯ÏÊ×éÖ¯µÄ TTP Öصþ¡£¸Ã»î¶¯½¨Á¢ÁËÊý¾Ýй¶µÄºã¾Ã·ÃÎÊȨÏÞ£¬ÏÈÇ°µÄ¹©Ó¦Á´Â©¶´Í¹ÏÔÁËÕâÖÖÁ¬Ðø¡¢¸ß¼¶ÍþвµÄ·çÏÕ¡£ÈëÇÖºó£¬ËûÃÇʹÓà MeshAgent µÈ·¨Ê½½øÐÐÔ¶³Ì·ÃÎÊ¡¢Ê¹Óà SSF ½øÐÐÄþ¾²ËíµÀÒÔ¼°Ê¹Óö¨ÖƶñÒâÈí¼þ InkLoader¡¢PurpleInk RAT µÈ¡£
https://gbhackers.com/lilacsquid-hackers-attacking-it-industries/
6. Êý°ÙÃûÓ¢¹ú¡¢·¨¹úºÍÅ·ÃËÕþ¿ÍµÄÐÅÏ¢ÔÚÍøÉÏÐû²¼
5ÔÂ31ÈÕ£¬¾ÝרעÓÚÒþ˽µÄ½â¾ö·½°¸ÌṩÉÌ Proton ³Æ£¬Êý°ÙÃûÓ¢¹ú¡¢·¨¹úºÍÅ·ÖÞÒé»áÕþ¿ÍµÄµç×ÓÓʼþµØÖ·ºÍÆäËûÐÅÏ¢¿ÉÒÔÔÚ°µÍøÊг¡ÉÏÕÒµ½¡£×÷Ϊ Proton Óë Constella Intelligence ºÏ×÷¿ªÕ¹µÄÒ»ÏîÑо¿µÄÒ»²¿ÃÅ£¬Ñо¿ÈËÔ±ÔÚ°µÍøÉÏËÑË÷Á˽ü 2,300 ¸öÊôÓÚÓ¢¹ú¡¢·¨¹úºÍÅ·ÖÞÒé»áÒéÔ±µÄ¹Ù·½Õþ¸®µç×ÓÓʼþµØÖ·¡£×ܹ²ÓÐ 918 ¸öµç×ÓÓʼþµØÖ·±»Ð¹Â¶µ½ÍøÂç·¸×ïÊг¡£¬µ«Ã¿¸ö×éÖ¯ÊÜÓ°ÏìµÄÕþ¿Í±ÈÀýÓÐËù²îÒì¡£ÀýÈ磬Ӣ¹úÒéÔ±Êܵ½µÄÓ°Ïì×î´ó£¬68% µÄÄ¿±êµç×ÓÓʼþµØÖ··ºÆðÔÚ°µÍøÉÏ¡£¾ÍÅ·ÃËÒé»áÒéÔ±¶øÑÔ£¬44% µÄµç×ÓÓʼþµØÖ·±»Ðû²¼ÔÚºÚ¿ÍÂÛ̳ÉÏ¡£Ö»ÓÐ 18% µÄ·¨¹úÒéÔ±ºÍ²ÎÒéÔ±µÄÊý¾Ý±»Ð¹Â¶¡£¾ÍÓ¢¹úÕþ¿ÍµÄ°¸Àý¶øÑÔ£¬ÆäÖаüÂÞÕþ¸®¸ß²ãºÍ×èµ²ÅÉÈËÎËûÃǵĵç×ÓÓʼþµØÖ·ÔÚ°µÍøÉϱ»·¢ÏÖÁè¼Ý 2,100 ´Î¡£ÔÚÐí¶àÇé¿öÏ£¬µç×ÓÓʼþµØÖ·ÔÚÕþ¸®ÍøÕ¾ÉÏÊǹûÈ»µÄ¡£ÎÊÌâÔÚÓÚ£¬µç×ÓÓʼþµØÖ··ºÆðÔÚ°µÍøÊг¡ÉϱíÃ÷ÕâЩµØÖ·Ôø±»ÓÃÀ´ÔÚÖÖÖÖµÚÈý·½ÔÚÏß·þÎñÉϽ¨Á¢ÕË»§£¬¶øÕâЩ·þÎñÔÚij¸öʱºòÔâµ½Á˺ڿ͹¥»÷¡£
https://www.securityweek.com/information-of-hundreds-of-european-politicians-found-on-dark-web/