ijÆû³µ¹©¸øÉ̵ÄϵͳÔÚÁ½ÖÜÄÚ±»HiveµÈÈý¸öÀÕË÷ÍŻ﹥»÷
°ä²¼¹¦·ò 2022-08-12
8ÔÂ10ÈÕ£¬Sophosй©ijÆû³µ¹©¸øÉ̵ÄϵͳÔÚÁ½ÖÜÄÚ±»Èý¸öÀÕË÷ÍÅ»ïLockBit¡¢HiveºÍBlackCat¹¥»÷¡£ÕâÈý¸ö¹¥»÷ÍŻﶼÀûÓÃÁËÒ»ÑùµÄÃýÎóÅäÖ㬼´ÔÚÖÎÀí·þÎñÆ÷É϶³öÁËÔ¶³Ì×ÀÃæºÍ̸µÄ·À»ðǽ¹æ¶¨¡£5ÔÂ1ÈÕ£¬Lockbit´´½¨ÁËÁ½¸öÅú´¦Öþ籾£¨1.batºÍ2.bat£©£¬Í¨¹ýPsExecÉÏ·Ö·¢ÁËÁ½¸öÀÕË÷Èí¼þµÄ¶þ½øÔìÎļþ£¬¼ÓÃÜÁË19̨Ö÷»úÉϵÄÎļþ£»Á½¸öÓ×ʱ֮ºó£¬HiveʹÓÃÒÑ×°ÖÃÔÚϵͳÉϵĵĺϷ¨Èí¼þPDQ DeployÀ´·Ö·¢ÆäÀÕË÷Èí¼þ¶þ½øÔìÎļþ£¬¼ÓÃÜÁË16̨Ö÷»úµÄÎļþ£»5ÔÂ15ÈÕ£¬BlackCatÀûÓñ»Ï°È¾Óû§µÄÍ´´¦ÔÚ6̨Ö÷»úÉÏͶ·ÅÁËÁ½¸öÀÕË÷Èí¼þµÄ¶þ½øÔìÎļþ¡£
https://www.bleepingcomputer.com/news/security/automotive-supplier-breached-by-3-ransomware-gangs-in-2-weeks/
2¡¢Cloudflareй©¶àÃûÔ±¹¤Ôâµ½ÓëTwilioÀàËÆµÄ´¹µö¹¥»÷
¾ÝýÌå8ÔÂ10Èճƣ¬CloudflareÅû¶ÆäÖÁÉÙÓÐ76ÃûÔ±¹¤¼°Æä¾ìÊôÔâµ½ÁËÀàËÆÓÚÕë¶ÔTwilioµÄ¸´ÔÓ´¹µö¹¥»÷¡£Õâ´Î¹¥»÷ԼĪÓëÕë¶ÔTwilioµÄ¹¥»÷ͬʱ²úÉú£¬À´×Ô4¸öÓëT-Mobile¿¯ÐеÄSIM¿¨Óйصĵ绰ºÅÂ룬ÕâЩ¶ÌÐÅÖ¸ÏòÒ»¸ö¿´ËƺϷ¨µÄÓò£¬ÆäÖÐÔ̺¬¹Ø¼ü×ÖCloudflareºÍOkta£¬ÊÔͼÓÕʹԱ¹¤½»³öÍ´´¦¡£Cloudflare°µÊ¾£¬ÓÐÈýÃûÔ±¹¤ÒÑÊÜÆÊÜÆ£¬µ«ÓÉÓÚʹÓýӼûÆäÀûÓ÷¨Ê½ËùÐèµÄÇкÏFIDO2³ß¶ÈµÄÎïÀí°²È«ÃÜÔ¿£¬ÆäÄÚ²¿ÏµÍ³²¢Î´±»¹¥ÆÆ¡£
https://thehackernews.com/2022/08/hackers-behind-twilio-breach-also_10.html
3¡¢Volexity³ÆZimbraÖзì϶±»ÓÃÀ´¹¥»÷ÉÏǧ̨ZCS·þÎñÆ÷
VolexityÔÚ8ÔÂ10ÈÕ±¨Â·£¬ZimbraÉíÖеķì϶Òѱ»ÀûÓÃÀ´ÈëÇÖ³¬¹ý1000̨Zimbra Collaboration Suite(ZCS)Óʼþ·þÎñÆ÷¡£¾ÝϤ£¬¹¥»÷ÕßÔçÔÚ6ÔÂµ×¾ÍÆðÍ·ÔÚÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶£¨CVE-2022-37042£©µÄÔ®ÊÖÏ£¬À´ÀûÓÃZCSÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2022-27925£©¡£VolexityÒÔΪ£¬¸Ã·ì϶µÄÀûÓ÷½Ê½Óë2021ËêÊ×·¢ÏÖµÄMicrosoft Exchange 0dayµÄÀûÓ÷½Ê½Ò»Ö¡£ZimbraÔÚ²¼¸æÖв¢Î´Ð¹Â©·ì϶ÀûÓÃÇé¿ö£¬ µ«Ò»ÃûÔ±¹¤ÔÚ¹«Ë¾ÂÛ̳ÉϽ¨ÒéÓû§µ±¼´×°Öò¹¶¡£¬³Æ·ì϶µÄÈ·ÒÑÔÚ¹¥»÷Öб»ÀûÓá£
https://www.bleepingcomputer.com/news/security/zimbra-auth-bypass-bug-exploited-to-breach-over-1-000-servers/
4¡¢Cisco Meraki·À»ðǽÎ󱨵¼ÖÂMicrosoft 365·þÎñÖжÏ
ýÌå8ÔÂ10ÈÕ±¨Â·£¬³ÖÐøµÄÖжÏÓ°ÏìÁ˶à¸öMicrosoft 365·þÎñ£¬Óû§ÎÞ·¨Ïνӵ½Exchange Online¡¢Microsoft Teams¡¢Outlook×ÀÃæ¿Í»§¶ËºÍOneDrive for Business¡£¹ÌȻ΢Èí°µÊ¾´ËÊÂÎñ½öÓ°ÏìÁËEMEA£¨Å·ÖÞ¡¢Öж«ºÍ·ÇÖÞ£©µØÓòµÄ¿Í»§£¬µ«È«ÇòÓû§¶¼Ôڻ㱨·þÎñÆ÷ÏνӺ͵Ǽʧ°ÜÎÊÌâ¡£³õ´ëÊ©²é·¢ÏÖ£¬³ÖÐøÖжϿÉÄÜÓëCisco Meraki·À»ðǽÈëÇÖ¼ì²âºÍÔ¤·À(IDR)Îó±¨×èÖ¹Microsoft 365ÏνӲ¢·¢³öMicrosoft Windows IIS»Ø¾ø·þÎñ³¢ÊÔ¾¯±¨Óйء£Î¢Èí×îÖÕÈ·ÈÏÖжÏÊÇSnort¹æ¶¨1-60381µ¼Öµģ¬²¢°µÊ¾Cisco MerakiÒѽûÓÃÁËÊÜÓ°ÏìµÄ¹æ¶¨¡£
https://www.bleepingcomputer.com/news/microsoft/microsoft-365-outage-triggered-by-meraki-firewall-false-positive/
5¡¢Unit 42·¢ÏÖÐÂÀÕË÷Èí¼þBlueSkyÀûÓöàÏ̼߳±¾ç¼ÓÃÜ
Unit 42ÔÚ8ÔÂ10ÈÕ¹«¿ªÁËÐÂÀÕË÷Èí¼þ¼Ò×åBlueSkyµÄ¼¼Êõϸ½Ú¡£BlueSkyÀÕË÷Èí¼þÖØÒªÕë¶ÔWindowsÖ÷»ú£¬²¢ÀûÓöàÏ̼߳ÓÃÜÖ÷»úÉϵÄÎļþÀ´¼Ó¿ì¼ÓÃÜ¿ìÂÊ¡£·ÖÎö¹ý³ÌÖÐ×êÑÐÈËÔ±´ÓBlueSkyµÄÑù±¾Öз¢ÏÖÁËÄܹ»ÓëContiÁªÏµÆðÀ´µÄ´úÂëÖ¸ÎÆ£¬³ö¸ñÊÇBlueSkyµÄ¶àÏ̼ܹ߳¹ÓëConti v3µÄ´úÂëÀàËÆ£¬ÍøÂçËÑË÷Ä£¿éÒ²ÊÇËüµÄÆëÈ«·°æ¡£ÁíÒ»·½Ã棬BlueSkyÓëBabuk¸üΪÀàËÆ£¬Á½Õß¶¼Ê¹ÓÃChaCha20£¬Í¬Ê±Ê¹ÓÃCurve25519À´ÌìÉúÃÜÔ¿¡£
https://unit42.paloaltonetworks.com/bluesky-ransomware/
6¡¢Kaspersky°ä²¼¹ØÓÚ¶ñÒâÈí¼þVileRATµÄ·ÖÎö»ã±¨
8ÔÂ10ÈÕ£¬Kaspersky°ä²¼»ã±¨³ÆDeathStalkerÔÚ2022Äê³ÖÐøÊ¹ÓÃVileRAT¹¥»÷È«ÇòµÄ¼ÓÃÜÇ®±ÒÂòÂô·þÎñ¡£VileRATÊÇÒ»¸ö¾¹ý»ìºÏºÍ´ò°üµÄPython3 RAT£¬ÓµÓÐÖ´ÐÐËÁÒâÔ¶³ÌºÅÁî¡¢¼üÅ̼ͼºÍ´ÓC2·þÎñÆ÷×ÔÎÒ¸üеÈÖ°ÄÜ£¬ÔÚ2020ÄêQ2³õ´Î±»·¢ÏÖ¡£ÖµÍ×ÌùÐĵÄÊÇ£¬Æù½ñΪֹ£¬×êÑÐÈËÔ±ÒѾȷ¶¨ÁËÊý°Ù¸öÓëVileRATϰȾÁ´ÓйصÄÓò¡£2021Äê8ÔÂÖÁ½ñ£¬ÔÚ±£¼ÓÀûÑÇ¡¢ÈûÆÖ·˹¡¢µÂ¹ú¡¢¸ñÁÖÄɶ¡Ë¹¡¢¿ÆÍþÌØ¡¢Âí¶úËû¡¢°¢À²®½áºÏÇõ³¤¹úºÍ¶íÂÞ˹Áª¹ú·¢ÏÖÁË10¸ö±»Ï°È¾Ö¸±ê¡£
https://securelist.com/vilerat-deathstalkers-continuous-strike/107075/


¾©¹«Íø°²±¸11010802024551ºÅ