Symantec³ÆBillbug¹¥»÷ÑÇÖÞµØÇøµÄÊý×ÖÖ¤Êé½ÒÏþ»ú¹¹

Ðû²¼Ê±¼ä 2022-11-17
1¡¢Symantec³ÆBillbug¹¥»÷ÑÇÖÞµØÇøµÄÊý×ÖÖ¤Êé½ÒÏþ»ú¹¹

SymantecÔÚ11ÔÂ15ÈÕ³ÆÆä·¢Ã÷Billbug¹¥»÷ÁËÑÇÖ޵Ķà¸öÕþ¸®»ú¹¹£¬£¬£¬£¬£¬ÆäÖаüÀ¨Ò»¸öÊý×ÖÖ¤Êé½ÒÏþ»ú¹¹¡£¡£¸ÃÍÅ»ï×Ô2009ÄêÒÔÀ´Ò»Ö±»îÔ¾£¬£¬£¬£¬£¬Symantec 2019ÄêË꼵ĻÖÐÏêϸÏÈÈÝÁ˸ÃÍÅ»ïÔõÑùʹÓúóÃÅHannotogºÍSagerunexµÄ£¬£¬£¬£¬£¬ÕâЩ¹¤¾ßÔÚ×î½üµÄ»î¶¯ÖÐÒ²ÓзºÆð¡£¡£´Ë´Î»î¶¯ÖÁÉÙ´Ó3Ô¾ÍÒÑ×îÏÈ£¬£¬£¬£¬£¬Óм£ÏóÅú×¢¹¥»÷ÕßÕýÔÚʹÓÃÃæÏò¹«ÖÚµÄÓ¦ÓóÌÐòÀ´»ñµÃ¶ÔÄ¿µÄÍøÂçµÄ³õʼ»á¼ûȨÏÞ¡£¡£Óë֮ǰµÄ»î¶¯Ò»Ñù£¬£¬£¬£¬£¬¹¥»÷ÕßҲʹÓÃÁ˶àÖÖÁ½Óù¤¾ß¼°×Ô½ç˵¶ñÒâÈí¼þ£¬£¬£¬£¬£¬ÈçAdFind¡¢Directory¡¢Winmail¡¢WinRAR¡¢PingºÍTracertµÈ¡£¡£

https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/espionage-asia-governments-cert-authority

2¡¢VaronisÅû¶Zendesk ExploreÖÐSQL×¢ÈëµÈÎó²îµÄϸ½Ú

VaronisÔÚ11ÔÂ15ÈÕÅû¶ÁËZendesk ExploreÖÐÁ½¸öÎó²îµÄϸ½Ú¡£¡£ÆäÖÐÒ»¸öÊÇSQL×¢ÈëÎó²î£¬£¬£¬£¬£¬¸ÃÎó²îÉæ¼°ÆäGraphQL APIÖеÄSQL×¢È룬£¬£¬£¬£¬¿É±»ÓÃÀ´Ð¹Â¶×÷ΪÖÎÀíÔ±´æ´¢ÔÚÊý¾Ý¿âÖеÄËùÓÐÐÅÏ¢£¬£¬£¬£¬£¬°üÀ¨ÓʼþµØµã¡¢¹¤µ¥ÒÔ¼°ÓëʵʱÊðÀíµÄ¶Ô»°µÈ¡£¡£ÁíÒ»¸öÎó²îÊÇÉæ¼°ÓëÅÌÎÊÖ´ÐÐAPIÏà¹ØµÄÂß¼­»á¼ûÎÊÌ⣬£¬£¬£¬£¬¸ÃAPI±»ÉèÖÃΪÔËÐÐÅÌÎÊ£¬£¬£¬£¬£¬¶ø²»¼ì²é¾ÙÐÐŲÓõÄÓû§ÊÇ·ñÓÐ×ã¹»µÄȨÏÞÕâÑù×ö¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬ÕâЩÎó²îÒѱ»ÐÞ¸´¡£¡£

https://securityaffairs.co/wordpress/138579/hacking/zendesk-explore-critical-flaws.html

3¡¢LazarusʹÓúóÃÅDTrack¹¥»÷Å·ÖÞºÍÀ­¶¡ÃÀÖÞµÄ×éÖ¯

¾Ý11ÔÂ15ÈÕ±¨µÀ£¬£¬£¬£¬£¬³¯ÏʺڿÍÍÅ»ïLazarusÕýÔÚʹÓÃа汾µÄDTrackºóÃÅÀ´¹¥»÷Å·ÖÞºÍÀ­¶¡ÃÀÖÞµÄ×éÖ¯¡£¡£Ä¿µÄÐÐÒµ°üÀ¨Ñо¿ÖÐÐÄ¡¢Õþ²ß»ú¹¹¡¢»¯Ñ§Æ·ÖÆÔìÉÌ¡¢ITЧÀÍÌṩÉÌ¡¢µçÐÅÌṩÉÌ¡¢¹«ÓÃÊÂҵЧÀÍÌṩÉ̺ͽÌÓý¡£¡£ÔÚеĻÖУ¬£¬£¬£¬£¬DTrackͨ³£Ê¹ÓÃÓëÕýµ±ÎļþÏà¹ØµÄÎļþÃû¾ÙÐзַ¢£¬£¬£¬£¬£¬ÈçÒ»¸öÑù±¾ÒÔ¡°NvContainer.exe¡±ÎªÃû·Ö·¢£¬£¬£¬£¬£¬ËüÓëÕýµ±µÄNVIDIAÎļþͬÃû¡£¡£±ðµÄ£¬£¬£¬£¬£¬DTrackÈÔ¼ÌÐøÍ¨¹ýÇÔÈ¡µÄƾ֤ÈëÇÖÍøÂç»òʹÓÃÍøÉÏ̻¶µÄЧÀÍÆ÷À´¾ÙÐзַ¢¡£¡£

https://securelist.com/dtrack-targeting-europe-latin-america/107798/

4¡¢Ñо¿ÍŶӷ¢Ã÷¿ÉÓ°Ï캽ÌìÆ÷ºÍ·É»úµÄ¹¥»÷·½·¨PCspooF

ýÌå11ÔÂ15ÈÕ±¨µÀ£¬£¬£¬£¬£¬Ñо¿ÍŶӷ¢Ã÷ÁËÒ»ÖÖÕë¶Ôʱ¼ä´¥·¢ÒÔÌ«Íø(TTE)µÄÐÂÐ͹¥»÷ÒªÁì¡£¡£TTEÊôÓÚ»ìÏýÒªº¦ÐÔÍøÂçµÄÍøÂçÊÖÒÕÖ®Ò»£¬£¬£¬£¬£¬ÆäÖоßÓвî±ðʱÐòºÍÈÝ´íÒªÇóµÄÁ÷Á¿¹²´æÓÚͳһÎïÀíÍøÂçÖС£¡£¸ÃÊÖÒÕÓÃÓÚÇå¾²»ù´¡ÉèÊ©£¬£¬£¬£¬£¬¿Éµ¼ÖÂΪº½ÌìÆ÷ºÍ·É»úÌṩ¶¯Á¦µÄϵͳ·ºÆð¹ÊÕÏ¡£¡£ÕâÊÇʹÓöñÒâ×°±¸Í¨¹ýÒÔÌ«ÍøµçÀ½«µç´Å×ÌÈÅ(EMI)×¢ÈëTTE½»Á÷»úÀ´ÊµÏֵ쬣¬£¬£¬£¬¿ÉÓÐÓõØÓÕʹ½»Á÷»ú·¢ËÍ¿´ËÆÕæÊµµÄͬ²½ÐÂÎŲ¢ÈÃËüÃDZ»ÆäËûTTE×°±¸½ÓÊÜ¡£¡£×÷Ϊ»º½â²½·¥£¬£¬£¬£¬£¬Ñо¿Ö°Ô±½¨ÒéʹÓùâñîºÏÆ÷»òÀËÓ¿±£»£»¤Æ÷À´×èÖ¹µç´Å×ÌÈÅ¡£¡£

https://thehackernews.com/2022/11/pcspoof-new-vulnerability-affects.html

5¡¢ÒÁÀÊÏà¹ØºÚ¿ÍʹÓÃLog4ShellÎó²îÈëÇÖÃÀ¹úÕþ¸®»ú¹¹

11ÔÂ16ÈÕ£¬£¬£¬£¬£¬FBIºÍCISAÁªºÏÐû²¼ÁËÒ»·Ýͨ¸æ£¬£¬£¬£¬£¬³ÆÓëÒÁÀÊÏà¹ØµÄºÚ¿ÍÈëÇÖÁËÒ»¸öÕþ¸®»ú¹¹²¢×°ÖÃÁËXMRig¿ó¹¤¶ñÒâÈí¼þ¡£¡£Í¨¸æ³Æ£¬£¬£¬£¬£¬´Ó2022Äê6ÔÂÖÐÑ®µ½7Ô£¬£¬£¬£¬£¬CISAÔÚÁª°îÃñÓÃÐÐÕþ²¿·Ö(FCEB)×éÖ¯ÖÐÊӲ쵽ÁË¿ÉÒɵÄAPT»î¶¯¡£¡£¹¥»÷ÕßʹÓÃδÐÞ¸´µÄVMware HorizonЧÀÍÆ÷ÖеÄLog4ShellÎó²î£¬£¬£¬£¬£¬×°ÖÃXMRig¿ó¹¤Èí¼þ£¬£¬£¬£¬£¬ºáÏòÒÆ¶¯µ½Óò¿ØÖÆÆ÷(DC)£¬£¬£¬£¬£¬ÇÔȡƾ֤£¬£¬£¬£¬£¬È»ºóÖ²ÈëNgrok·´ÏòÊðÀíÀ´ÔÚ¶à¸ö×°±¸Éϼá³Ö³¤ÆÚÐÔ¡£¡£CISA ºÍ FBI Ðû²¼´ËCSAÌṩºÚ¿ÍµÄTTPºÍIOC£¬£¬£¬£¬£¬ÒÔ×ÊÖú×éÖ¯¼ì²âºÍ·ÀÓùÏà¹ØµÄ¹¥»÷¡£¡£

https://www.cisa.gov/uscert/ncas/alerts/aa22-320a

6¡¢KasperskyÐû²¼¹ØÓÚ2023ÄêAPT¹¥»÷»î¶¯µÄÕ¹Íû±¨¸æ

KasperskyÔÚ11ÔÂ14ÈÕÐû²¼Á˹ØÓÚ2023ÄêAPT¹¥»÷»î¶¯µÄÕ¹Íû±¨¸æ¡£¡£±¨¸æÕ¹ÍûÔÚ2023Ä꣬£¬£¬£¬£¬½«·ºÆð´ó×򵀮ÆËðÐÔÍøÂç¹¥»÷£¬£¬£¬£¬£¬Ó°ÏìÕþ¸®²¿·ÖºÍÒªº¦ÐÐÒµ£»£»ÓʼþЧÀÍÆ÷½«³ÉΪÖ÷ҪĿµÄ£¬£¬£¬£¬£¬ºÜ¿ÉÄÜËùÓÐÖ÷Òªµç×ÓÓʼþÈí¼þ¶¼·ºÆð0-day£»£»Ò»Ð©¾ßÓÐÓ°ÏìÁ¦µÄ²¡¶¾Ã¿6-7Ä걬·¢Ò»´Î£¬£¬£¬£¬£¬¿ÉÄÜ·ºÆðÏÂÒ»¸öWannaCry£»£»APT¹¥»÷ÍŻォĿµÄתÏòÎÀÐÇÊÖÒÕ¡¢Éú²úÉ̺ÍÔËÓªÉÌ£»£»¸ü¶àAPT×éÖ¯½«´ÓCobaltStrike×ªÒÆµ½ÆäËüÌæ»»¼Æ»®µÈ¡£¡£

https://securelist.com/advanced-threat-predictions-for-2023/107939/