Symantec³ÆBillbug¹¥»÷ÑÇÖÞµØÓòµÄÊý×ÖÖ¤ÊéÐû¸æ»ú¹¹

°ä²¼¹¦·ò 2022-11-17
1¡¢Symantec³ÆBillbug¹¥»÷ÑÇÖÞµØÓòµÄÊý×ÖÖ¤ÊéÐû¸æ»ú¹¹

SymantecÔÚ11ÔÂ15ÈÕ³ÆÆä·¢ÏÖBillbug¹¥»÷ÁËÑÇÖ޵Ķà¸öµ±¾Ö»ú¹¹£¬ÆäÖÐÔ̺¬Ò»¸öÊý×ÖÖ¤ÊéÐû¸æ»ú¹¹¡£¸ÃÍÅ»ï×Ô2009ÄêÒÔÀ´Ò»Ïò»îÔ¾£¬Symantec 2019Äê¼Í¼µÄ»î¶¯ÖоßÌå½éÉÜÁ˸ÃÍÅ»ïÈôºÎʹÓúóÃÅHannotogºÍSagerunexµÄ£¬ÕâЩ¹¤¾ßÔÚ×î½üµÄ»î¶¯ÖÐÒ²ÓгöÏÖ¡£Õâ´Î»î¶¯ÖÁÉÙ´Ó3Ô¾ÍÒÑÆðÍ·£¬Óм£ÏóÅú×¢¹¥»÷ÕßÔÚÀûÓÃÃæÏò¹«¼ÒµÄÀûÓ÷¨Ê½À´»ñµÃ¶ÔÖ¸±êÍøÂçµÄ³õʼ½Ó¼ûȨÏÞ¡£Óë֮ǰµÄ»î¶¯Ò»Ñù£¬¹¥»÷ÕßҲʹÓÃÁ˶àÖÖÁ½Óù¤¾ß¼°×Ô½ç˵¶ñÒâÈí¼þ£¬ÈçAdFind¡¢Directory¡¢Winmail¡¢WinRAR¡¢PingºÍTracertµÈ¡£

https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/espionage-asia-governments-cert-authority

2¡¢VaronisÅû¶Zendesk ExploreÖÐSQL×¢ÈëµÈ·ì϶µÄϸ½Ú

VaronisÔÚ11ÔÂ15ÈÕÅû¶ÁËZendesk ExploreÖÐÁ½¸ö·ì϶µÄϸ½Ú¡£ÆäÖÐÒ»¸öÊÇSQL×¢Èë·ì϶£¬¸Ã·ìÏ¶Éæ¼°ÆäGraphQL APIÖеÄSQL×¢È룬¿É±»ÓÃÀ´Ð¹Â¶×÷ΪÖÎÀíÔ±´æ´¢ÔÚÊý¾Ý¿âÖеÄËùÓÐÐÅÏ¢£¬Ô̺¬ÓʼþµØÖ·¡¢¹¤µ¥ÒÔ¼°ÓëʵʱÆÚÀíµÄ¶Ô»°µÈ¡£ÁíÒ»¸ö·ì϶ÊÇÉæ¼°Óë²éÎÊÖ´ÐÐAPIÓйصÄÂß¼­½Ó¼ûÎÊÌ⣬¸ÃAPI±»ÅäÖÃΪÔËÐвéÎÊ£¬¶ø²»²é³­½øÐÐŲÓõÄÓû§ÊÇ·ñÓÐ×ã¹»µÄȨÏÞÕâÑù×ö¡£Ä¿Ç°£¬ÕâЩ·ì϶Òѱ»½¨¸´¡£

https://securityaffairs.co/wordpress/138579/hacking/zendesk-explore-critical-flaws.html

3¡¢LazarusÀûÓúóÃÅDTrack¹¥»÷Å·ÖÞºÍÀ­¶¡ÃÀÖÞµÄ×éÖ¯

¾Ý11ÔÂ15ÈÕ±¨Â·£¬³¯ÏʺڿÍÍÅ»ïLazarusÔÚʹÓÃа汾µÄDTrackºóÃÅÀ´¹¥»÷Å·ÖÞºÍÀ­¶¡ÃÀÖÞµÄ×éÖ¯¡£Ö¸±êÐÐÒµÔ̺¬×êÑÐÖÐÐÄ¡¢Õþ²ß»ú¹¹¡¢»¯Ñ§Æ·Ôì×÷ÉÌ¡¢IT·þÎñÌṩÉÌ¡¢µçÐÅÌṩÉÌ¡¢¹«ÓÃÊÂÒµ·þÎñÌṩÉ̺ͽÌÓý¡£ÔÚеĻÖУ¬DTrackͨ³£Ê¹ÓÃÓëºÏ·¨ÎļþÓйصÄÎļþÃû½øÐзַ¢£¬ÈçÒ»¸öÑù±¾ÒÔ¡°NvContainer.exe¡±ÎªÃû·Ö·¢£¬ËüÓëºÏ·¨µÄNVIDIAÎļþͬÃû¡£´Ë±í£¬DTrackÈÔ³ÖÐøÍ¨¹ýÇÔÈ¡µÄƾ֤ÈëÇÖÍøÂç»òÀûÓÃÍøÉ϶³öµÄ·þÎñÆ÷À´½øÐзַ¢¡£

https://securelist.com/dtrack-targeting-europe-latin-america/107798/

4¡¢×êÑÐÍŶӷ¢ÏÖ¿ÉÓ°Ï캽ÌìÆ÷ºÍ·É»úµÄ¹¥»÷·½Ê½PCspooF

ýÌå11ÔÂ15ÈÕ±¨Â·£¬×êÑÐÍŶӷ¢ÏÖÁËÒ»ÖÖÕë¶Ô¹¦·ò´¥·¢ÒÔÌ«Íø(TTE)µÄÐÂÐ͹¥»÷²½Öè¡£TTEÊôÓÚ»ìºÏ¹Ø¼üÐÔÍøÂçµÄÍøÂç¼¼ÊõÖ®Ò»£¬ÆäÖÐÓµÓÐ·ÖÆçʱÐòºÍÈÝ´íÒªÇóµÄÁ÷Á¿¹²´æÓÚͳһÎïÀíÍøÂçÖС£¸Ã¼¼ÊõÓÃÓÚ°²È«»ù´¡ÉèÊ©£¬¿Éµ¼ÖÂΪº½ÌìÆ÷ºÍ·É»úÌṩ¶¯Á¦µÄϵͳ³öÏÖ¹ÊÕÏ¡£ÕâÊÇʹÓöñÒâÉ豸ͨ¹ýÒÔÌ«ÍøµçÀ½«µç´Å×ÌÈÅ(EMI)×¢ÈëTTE»¥»»»úÀ´ÊµÏֵģ¬¿ÉÓÐЧµØÓÕʹ»¥»»»ú·¢ËÍ¿´ËÆÕæÊµµÄͬ²½ÐÂÎŲ¢ÈÃËüÃDZ»ÆäËûTTEÉ豸½ÓÊÜ¡£×÷Ϊ»º½â´ëÊ©£¬×êÑÐÈËÔ±½¨ÒéʹÓùâñîºÏÆ÷»òÀËÓ¿±£»¤Æ÷À´×èÖ¹µç´Å×ÌÈÅ¡£

https://thehackernews.com/2022/11/pcspoof-new-vulnerability-affects.html

5¡¢ÒÁÀÊÓйغڿÍÀûÓÃLog4Shell·ì϶ÈëÇÖÃÀ¹úµ±¾Ö»ú¹¹

11ÔÂ16ÈÕ£¬FBIºÍCISA½áºÏ°ä²¼ÁËÒ»·Ý¹«¸æ£¬³ÆÓëÒÁÀÊÓйصĺڿÍÈëÇÖÁËÒ»¸öµ±¾Ö»ú¹¹²¢×°ÖÃÁËXMRig¿ó¹¤¶ñÒâÈí¼þ¡£¹«¸æ³Æ£¬´Ó2022Äê6ÔÂÖÐÑ®µ½7Ô£¬CISAÔÚÁª¹úÃñÓÃÐÐÕþ²¿ÃÅ(FCEB)×éÖ¯Öй۲쵽ÁË¿ÉÒɵÄAPT»î¶¯¡£¹¥»÷ÕßÀûÓÃ佨¸´µÄVMware Horizon·þÎñÆ÷ÖеÄLog4Shell·ì϶£¬×°ÖÃXMRig¿ó¹¤Èí¼þ£¬ºáÏòÒÆ¶¯µ½Óò½ÚÔìÆ÷(DC)£¬ÇÔȡʹ´¦£¬¶øºóÖ²ÈëNgrok·´Ïò´úÀíÀ´ÔÚ¶à¸öÉ豸ÉÏά³ÖÓÆ¾ÃÐÔ¡£CISA ºÍ FBI °ä²¼´ËCSAÌṩºÚ¿ÍµÄTTPºÍIOC£¬ÒÔÔ®ÊÖ×éÖ¯¼ì²âºÍ·ÀÓùÓйصĹ¥»÷¡£

https://www.cisa.gov/uscert/ncas/alerts/aa22-320a

6¡¢Kaspersky°ä²¼¹ØÓÚ2023ÄêAPT¹¥»÷»î¶¯µÄÔ¤²â»ã±¨

KasperskyÔÚ11ÔÂ14ÈÕ°ä²¼Á˹ØÓÚ2023ÄêAPT¹¥»÷»î¶¯µÄÔ¤²â»ã±¨¡£»ã±¨Ô¤²âÔÚ2023Ä꣬½«³öÏÖ´óÁ¿µÄ·ÛËéÐÔÍøÂç¹¥»÷£¬Ó°Ïìµ±²¿ÃÅÃź͹ؼüÐÐÒµ£»Óʼþ·þÎñÆ÷½«³ÉΪ³ÁÒªÖ¸±ê£¬ºÜ¿ÉÄÜËùÓÐÖØÒªµç×ÓÓʼþÈí¼þ¶¼³öÏÖ0-day£»Ò»Ð©ÓµÓÐÓ°ÏìÁ¦µÄ²¡¶¾Ã¿6-7Äê²úÉúÒ»´Î£¬¿ÉÄܳöÏÖÏÂÒ»¸öWannaCry£»APT¹¥»÷ÍŻォָ±êתÏòÎÀÐǼ¼Êõ¡¢³ö²úÉ̺ÍÔËÓªÉÌ£»¸ü¶àAPT×éÖ¯½«´ÓCobaltStrike×ªÒÆµ½ÆäËü´úÌæ¹æ»®µÈ¡£

https://securelist.com/advanced-threat-predictions-for-2023/107939/