Kaspersky·¢ÏÖAPT41ÀûÓÃMoonBounceµÄ¹¥»÷»î¶¯
°ä²¼¹¦·ò 2022-01-24Kaspersky·¢ÏÖAPT41ÀûÓÃMoonBounceµÄ¹¥»÷»î¶¯
1ÔÂ20ÈÕ£¬Kaspersky°ä²¼Á˹ØÓÚ¶ñÒâÈí¼þMoonBounceµÄ·ÖÎö»ã±¨¡£×êÑÐÈËÔ±³Æ£¬MoonBounceÊÇÆù½ñΪֹÔÚÒ°±í·¢ÏÖµÄ×îÏȽøµÄUEFI¹Ì¼þ¶ñÒâÈí¼þ£¬ÓëºÚ¿Í×éÖ¯APT41£¨Ò²³ÆÎªWinnti£©Óйء£MoonBounceÖ²ÈëÔÚÖ÷°åµÄSPIÉÁ´æÉÏ£¬Òò¶ø¼´±ã¸ü»»Ó²ÅÌÒ²ÎÞ·¨½«Æä¸ù³ý¡£ÕâÊǽüÆÚ·¢ÏֵĵÚÈý¸öUEFI¶ñÒâÈí¼þ£¬Ö®Ç°Á½¸öΪFinFisherºÍESPecter¡£Kaspersky°µÊ¾Õâ´Î¹¥»÷ÓµÓи߶ÈÕë¶ÔÐÔ£¬Ä³¸ö½ÚÔì׿¸¼ÒÔËÊä¼¼ÊõÓÐ¹ØÆóÒµµÄ×éÖ¯ÒѳÉΪ¹¥»÷Ö¸±ê¡£
https://securelist.com/moonbounce-the-dark-side-of-uefi-firmware/105468/
ContiÍÅ»ïÐû³Æ¶ÔÓ¡¶ÈÄáÎ÷ÑÇÑëÐеÄÀÕË÷¹¥»÷ÕÆ¹Ü
¾ÝýÌå1ÔÂ20ÈÕ±¨Â·£¬Ó¡¶ÈÄáÎ÷ÑÇÒøÐУ¨BI£©ÈÏ¿ÉÆäÔâµ½ÀÕË÷¹¥»÷¡£¸ÃÐн²»°È˰µÊ¾£¬¹¥»÷²úÉúÔÚÉϸöÔ£¬¹¥»÷ÕßÇÔÈ¡Á˲¿ÃÅÔ±¹¤µÄÐÅÏ¢£¬²¢ÔÚÊ®¼¸¸öϵͳÉÏ×°ÖÃÁËÀÕË÷Èí¼þ£¬µ«ÆäÔËÓª²¢Î´Êܵ½Ó°Ïì¡£ContiÍÅ»ïÐû³Æ¶Ô´ËÊÂÕÆ¹Ü£¬ÈôÊÇÓ¡ÄáÒøÐв»Ö§¸¶Êê½ð£¬ËûÃǽ«¹«¿ª¸ÃÒøÐÐ13.88 GBµÄÎļþ¡£Ç°²»¾Ã£¬Conti»¹¹¥»÷Á˰®¶ûÀ¼DoH¡¢HSE£¬ºÍÓªÏú¹«Ë¾RR Donnelly¡£
https://www.bleepingcomputer.com/news/security/indonesias-central-bank-confirms-ransomware-attack-conti-leaks-data/
×êÑÐÈËÔ±³ÆÊýÊ®¸öWordPressÖ÷ÌâºÍ²å¼þÒѱ»Ö²ÈëºóÃÅ
JetPackÔÚ1ÔÂ18ÈÕ°ä²¼»ã±¨£¬³ÆÒÑÔÚÊýÊ®¸öWordPressÖ÷ÌâºÍ²å¼þÖз¢ÏÖºóÃÅ¡£×êÑÐÈËÔ±³Æ£¬¹¥»÷ÕßÒÑÔÚAccessPress ThemesµÄ40¸öÖ÷ÌâºÍ53¸ö²å¼þÖÐÖ²ÈëºóÃÅ¡£¾¹ýµ÷²éµÃÖª£¬AccessPress ThemesÓÚ2021Äê9ÔÂÉϰëÔÂÔâµ½¹¥»÷£¬ÆäÊ±ÍøÕ¾ÉϵÄÀ©´ó·¨Ê½±»×¢ÈëÁ˺óÃÅ¡£ÊÜϰȾµÄÀ©´ó·¨Ê½Ô̺¬Ò»¸öwebshell dropper£¬Ê¹¹¥»÷ÕßÄܹ»ÆëÈ«½Ó¼ûÖ¸±êÍøÕ¾£¬¸Ã·ì϶׷×ÙΪCVE-2021-24867¡£
https://thehackernews.com/2022/01/hackers-planted-secret-backdoor-in.html
ÀûÓÃCWPµÄÎļþÔ̺¬ºÍËÁÒâдÈë·ì϶¿ÉʵÏÖÔ¶³Ì´úÂëÖ´ÐÐ
ýÌå1ÔÂ22ÈÕ±¨Â·£¬Control Web PanelÖдæÔÚ2¸öÑϳÁµÄ·ì϶¡£Control Web Panel£¨ÒÔǰµÄCentOS Web Panel£©ÊÇÒ»¸ö¿ªÔ´µÄLinux½ÚÔìÃæ°åÈí¼þ£¬ÓÃÓÚ²¿ÊðWebÍйܻ·¾³¡£µÚÒ»¸öÊÇÎļþÔ̺¬·ì϶£¨CVE-2021-45467£©£¬¹¥»÷ÕßÖ»ÐèÅú¸ÄincludeÓï¾ä¾ÍÄܹ»Ô¶³Ì×¢Èë¶ñÒâ´úÂë»òʵÏÖ´úÂëÖ´ÐС£µÚ¶þ¸öΪËÁÒâÎļþдÈë·ì϶£¨CVE-2021-45466£©£¬½áºÏÀûÓÃÕâÁ½¸ö·ì϶Äܹ»ÔÚÒ×Êܹ¥»÷µÄLinux·þÎñÆ÷ÉÏʵÏÖÔ¶³Ì´úÂëÖ´ÐС£
https://securityaffairs.co/wordpress/127058/hacking/control-web-panel-flaws.html
MoleratsÍÅ»ïÀûÓöà¸öÔÆ·þÎñ¶ÔÖж«µØÓò½øÐмäµý¹¥»÷
¾ÝýÌå1ÔÂ22ÈÕ±¨Â·£¬°²È«¹«Ë¾Zscaler·¢ÏÖMoleratsÍÅ»ïÕë¶ÔÖж«µØÓòµÄ¼äµý»î¶¯¡£¾ÝϤ£¬¹¥»÷´Ó2021Äê7Ô¾ÍÒÑÆðÍ·£¬¹¥»÷ÕßÀûÓúϷ¨µÄÔÆ·þÎñ£¨ÈçGoogle DriveºÍDropbox£©ÍйܶñÒâÈí¼þpayload£¬´ÓÖж«µØÓòµÄÖ¸±êÖÐÇÔÈ¡Êý¾Ý¡£Õâ´Î»î¶¯ÀûÓÃÓëÒÔÉ«ÁкͰÍÀÕ˹̹ì¶ÜÓйصĵö¶ü£¬ÔÚÖ¸±êϵͳÉÏ×°ÖÃ.NETºóÃÅ£¬ÖØÒªÖ¸±êÔ̺¬°ÍÀÕË¹Ì¹ÒøÐÐÒµÔ±¹¤¡¢°ÍÀÕ˹̹Õþµ³³ÉÔ±£¬ÒÔ¼°ÍÁ¶úÆä¼ÇÕߵȡ£
https://thehackernews.com/2022/01/molerats-hackers-hiding-new-espionage.html
×ÖÄ»ÍøÕ¾OpenSubtitles½ü700ÍòÓû§µÄÐÅϢй¶
¾Ý1ÔÂ23ÈÕ±¨Â·£¬×ÖÄ»ÍøÕ¾OpenSubtitlesÔâµ½¹¥»÷£¬6783158¸öÓû§µÄÐÅÏ¢ÒѾй¶¡£2021Äê8Ô£¬ÍøÕ¾ÖÎÀíÔ±ÊÕµ½Êê½ð֪ͨºó²ÅÒâʶµ½ÆäÒÑÔâµ½¹¥»÷¡£¹¥»÷Õß»¹°µÊ¾»áÌṩ֧³ÖÒÔ½¨¸´ÍøÕ¾Öеķì϶£¬µ«ÔÚÖ§¸¶Êê½ðºó¹¥»÷Õß´ÓδԮÊÖËûÃǼӹÌÍøÕ¾£¬²¢ÔÚ1ÔÂ11ÈÕ¹«¿ªÁ˱»µÁÊý¾Ý¡£¾ÝϤ£¬ºÚ¿Íͨ¹ýSQL×¢Èë¹¥»÷½Ó¼ûÁËÍøÕ¾µÄÊý¾Ý¿â£¬ÇÔÈ¡ÁËÓû§Óʼþ¡¢IPµØÖ·¡¢Óû§Ãû¡¢µØµã¹ú¶ÈºÍÃÜÂëµÈÐÅÏ¢¡£
https://securityaffairs.co/wordpress/127092/data-breach/opensubtitles-data-breach.html
°²È«¹¤¾ß
Narthex
ÊÇÒ»¸öÄ£¿é»¯ºÍ×îÓ×µÄ×ÖµäÌìÉúÆ÷£¬ÓÃÓÚÓà C ºÍ Shell ±àдµÄ Unix ºÍÀà Unix ²Ù×÷ϵͳ¡£
https://github.com/MichaelDim02/Narthex
Iptable_Evil
IptablesµÄºóÃÅ£¬Ê¹¶ñÒâÊý¾Ý°üͨ¹ýiptables£¬ÎÞÂÛ·À»ðǽ¹æ¶¨ÈôºÎ¡£
https://github.com/FlamingSpork/iptable_evil
iMonitor
ÊÇÒ»¿î»ùÓÚiMonitorSDKµÄ¶ËµãÐÐΪ¼à¿Ø·ÖÎöÈí¼þ¡£
https://github.com/wecooperate/iMonitor/releases
°²È«·ÖÎö
΢Èí½¨¸´ÁË Windows 10 µÄ Outlook ËÑË÷ÎÊÌâ
΢Èí½¨¸´ÁË×°ÖÃ2021 Äê 11 Ô°䲼µÄ Windows 10 °²È«¸üкóµ¼Ö Outlook Óû§³öÏÖËÑË÷ÎÊÌâµÄÎÊÌâ¡£
https://www.bleepingcomputer.com/news/microsoft/microsoft-fixes-outlook-search-issues-for-windows-10-users/
WordPress²å¼þ´æÔÚ·ì϶
WP HTML MailÖдæÔÚÒ»¸öÑϳÁµÄ¿çÕ¾µã¾ç±¾(XSS)·ì϶£¬Ó°Ï쳬¹ý20,000¸öWordPressÍøÕ¾¡£
https://threatpost.com/wordpress-insecure-plugin-rest-api/177866/


¾©¹«Íø°²±¸11010802024551ºÅ