Ò½ÁÆ»ú¹¹CHSÒòFortra·ì϶й¶100Íò»¼ÕßµÄÓ×ÎÒÐÅÏ¢

°ä²¼¹¦·ò 2023-02-16
1¡¢Ò½ÁÆ»ú¹¹CHSÒòFortra·ì϶й¶100Íò»¼ÕßµÄÓ×ÎÒÐÅÏ¢

      

¾Ý2ÔÂ14ÈÕ±¨Â· £¬ÃÀ¹úÒ½ÁÆ»ú¹¹Community Health Systems(CHS)³ÆÆäÊܵ½ÁËÕë¶ÔFortraµÄGoAnywhere MFTƽ̨ÖÐÁãÈÕ·ì϶µÄ¹¥»÷µÄÓ°Ïì¡£Õâ¼ÒÒ½ÁÆ·þÎñ¹«Ë¾ÖÜÒ»°µÊ¾ £¬Fortra·¢³ö¾¯±¨³Æ¾­ÀúÁËÒ»´Î°²È«ÊÂÎñ £¬µ¼ÖÂCHSµÄ²¿ÃÅÊý¾Ýй¶¡£ËæºóµÄµ÷²éÏÔʾ £¬Õâ´Îй¶ӰÏìÁ˶à´ï100ÍòÃû»¼ÕßµÄÓ×ÎҺͽ¡È«ÐÅÏ¢¡£ClopÍÅ»ïÐû³ÆÊÇÕâ´Î¹¥»÷µÄÄ»ºóºÚÊÖ £¬»¹³ÆÒÑÇÔÈ¡130¶à¸ö×éÖ¯µÄÊý¾Ý¡£


https://www.bleepingcomputer.com/news/security/healthcare-giant-chs-reports-first-data-breach-in-goanywhere-hacks/


2¡¢Citrix½¨¸´Workspace AppsµÈ²úÆ·ÖеĶà¸ö·ì϶

      

¾ÝýÌå2ÔÂ15ÈÕ±¨Â· £¬Citrix Systems°ä²¼°²È«¸üР£¬½¨¸´ÆäVirtual Apps and DesktopsºÍWorkspace Apps²úÆ·Öеķì϶¡£ÆäÖÐ×îÑϳÁµÄÊÇȨÏÞÖÎÀí²»µ±·ì϶£¨CVE-2023-24483£© £¬¿É½«È¨ÏÞÌáÉýµ½NT AUTHORITY\SYSTEM¡£´Ë±í £¬»¹Óпɽ«ÈÕÖ¾ÎļþдÈëͨ³£Óû§ÎÞȨдÈëµÄĿ¼µÄ½Ó¼û½ÚÔì²»µ±·ì϶£¨CVE-2023-24484£© £¬ÒÔ¼°µ¼ÖÂȨÏÞÌáÉýµÄ½Ó¼û½ÚÔì²»µ±·ì϶£¨CVE-2023-24485£©ºÍµ¼Ö»ỰÊÕÊܵĽӼû½ÚÔì²»µ±·ì϶£¨CVE-2023-24486£©¡£CISA°ä²¼Á˹ØÓÚ¾¡¿ìÀûÓÃCitrix°²È«¸üеľ¯±¨¡£


https://www.bleepingcomputer.com/news/security/citrix-fixes-severe-flaws-in-workspace-virtual-apps-and-desktops/


3¡¢CiscoÅû¶·Ö·¢MortalKombatºÍLaplas ClipperµÄ»î¶¯

      

Cisco TalosÔÚ2ÔÂ14ÈÕÅû¶ÁËһ··Ö·¢ÀÕË÷Èí¼þMortalKombatºÍ¶ñÒâÈí¼þLaplas ClipperµÄ»î¶¯¡£×êÑÐÈËÔ±×Ô2022Äê12ÔÂÆðÍ·¹Û²ìµ½Á˸û £¬ÖØÒªÕë¶ÔÃÀ¹ú¡¢Ó¢¹ú¡¢ÍÁ¶úÆäºÍ·ÆÂɱöµÈµØÓò¡£¹¥»÷»î¶¯Ê¼ÓÚ´¹µöµç×ÓÓʼþ £¬²¢Æô¶¯¶à½×¶Î¹¥»÷Á´ £¬»á·Ö·¢¶ñÒâÈí¼þ»òÀÕË÷Èí¼þ £¬¶øºóɾ³ý¶ñÒâÎļþµÄÖ¤¾Ý £¬¸²¸ÇÆä×ÙÓ°²¢Èƹý¶ÈÎö¡£MortalKombatÊÇXoristµÄÒ»ÖÖ±äÌå £¬ÓÚ2023Äê1Ô³õ´Î±»·¢ÏÖ¡£Laplas ClipperÊÇÏà¶Ô½ÏеļôÌù°åÇÔÈ¡·¨Ê½ £¬ÓÃÓÚÇÔȡָ±êµÄ¼ÓÃÜÇ®±Ò¡£


https://blog.talosintelligence.com/new-mortalkombat-ransomware-and-laplas-clipper-malware-threats/


4¡¢16¸ö¶ñÒâNPM°ü¼Ù×°³ÉÍø¿ì²âÊÔÆ÷Ö¼ÔÚÍÚ¾ò¼ÓÃÜÇ®±Ò

      

2ÔÂ14ÈÕ £¬Check Point³ÆÆäÔÚNPMÉϼì²âµ½16¸ö¶ñÒâ°ü¡£ËüÃǼÙ×°³ÉÍø¿ì²âÊÔÆ÷ £¬Ö¼ÔÚ½Ù³ÖÖ¸±êµÄÍÆËã»ú×ÊÔ´ÒÔÍÚ¾ò¼ÓÃÜÇ®±Ò¡£ËùÓаü¾ùÓÉÓû§trendavaÉÏ´«µ½NPM £¬Ö»¹ÜËüÃÇÓµÓÐÒ»ÑùµÄÖ¸±ê £¬µ«×êÑÐÈËÔ±·¢ÏÖÿ¸ö°ü¶¼Ñ¡È¡·ÖÆçµÄ±àÂëºÍ²½ÖèÀ´ÊµÏ֯乤×÷¡£Äܹ»ÒÔΪÕâЩ²î¾à´ú±íÁ˹¥»÷ÕßËù×öµÄÊÔÑé £¬ËûÊÂÏȲ»ÖªÂ·Äĸö°æ±¾»á±»°²È«¹¤¾ß¼ì²âµ½ £¬Òò¶ø³¢ÊÔÓÃ·ÖÆçµÄ·½Ê½À´°µ²Ø¶ñÒâÒâͼ¡£×êÑÐÈËÔ±ÓÚ1ÔÂ17ÈÕ·¢ÏÖÁËÕâЩ°ü £¬NPMÓÚ´ÎÈÕɾ³ýÁËËüÃÇ¡£


https://blog.checkpoint.com/2023/02/14/check-point-cloudguard-spectral-detects-malicious-crypto-mining-packages-on-npm-the-leading-registry-for-javascript-open-source-packages/


5¡¢BlackCat³ÆÒÑÇÔÈ¡°®¶ûÀ¼Ã÷Ë¹ÌØ¿Æ¼¼´óѧ6GBµÄÊý¾Ý

      

ýÌå2ÔÂ14ÈÕ³Æ £¬BlackCat£¨Ò²³ÆALPHV£©ÔÚÆäÍøÕ¾ÁгöÁË´Ó°®¶ûÀ¼Ã÷Ë¹ÌØ¿Æ¼¼´óѧ(MTU)ÇÔÈ¡µÄ³¬¹ý6 GBµÄÊý¾Ý¡£¸ÃÍÅ»ïÔÚ.onionÍøÕ¾ÉÏÐû³ÆÐ¹Â¶ÐÅÏ¢Ô̺¬Ô±¹¤¼Í¼ºÍ¹¤×ʵ¥¾ßÌåÐÅÏ¢ £¬ÕâÁ½¸öÊý¾Ý¼¯¶¼¿ÉÄܵ¼ÖÂڲƭºÍɧÈŻ¡£MTUÔøÓÚ2ÔÂ6ÈÕ³Æ £¬ÓÉÓÚ³Á´óITÎÊÌâºÍµç»°ÖжÏ £¬ÆäλÓڿƿ˵ÄÐ£Çø¹Ø¹ØÇҿγÌÈ¡µÞ £¬µ«²¢Î´½«Õâ´Î¹¥»÷¹é×ïÓÚÌØ¶¨µÄ¹¥»÷ÍŻ


https://therecord.media/alphv-blackcat-posted-data-ireland-munster-technical-university/


6¡¢Minerva°ä²¼ÇÔÊØÐÅÏ¢µÄ¶ñÒâÈí¼þBeepµÄ·ÖÎö»ã±¨

      

2ÔÂ13ÈÕ £¬Minerva°ä²¼Á˹ØÓÚÇÔÊØÐÅÏ¢µÄ¶ñÒâÈí¼þBeepµÄ·ÖÎö»ã±¨¡£BeepʹÓÃÈý¸ö¶ÀÁ¢µÄ×é¼þ£ºÖ²È뷨ʽ¡¢×¢È뷨ʽºÍpayload¡£¸Ã¶ñÒâÈí¼þËÆºõÈÔÔÚ¿ª·¢ÖÐ £¬×êÑÐÈËÔ±ÔÚÑù±¾Öз¢ÏÖÁ˺öàÓÉC2ºÅÁî´¥·¢µÄÖ°ÄÜÉÐδִÐС£BeepÖ®ËùÒÔÍÑÓ±¶ø³ö £¬ÊÇÓÉÓÚÔÚÕû¸öÖ´ÐÐÁ÷³ÌÖÐʹÓÃÁ˶àÖÖ¼¼ÊõÀ´Èƹý°²È«Èí¼þºÍ×êÑÐÈËÔ±µÄ¼ì²âºÍ·ÖÎö £¬Ô̺¬¶¯Ì¬×Ö·û´®È¥»ìºÏ¡¢ÏµÍ³Ëµ»°²é³­¡¢IsDebuggerPresent APIº¯ÊýµÄ·¨Ê½¼¯ºÍNtGlobalFlag×ֶη´µ÷ÊԵȡ£


https://www.bleepingcomputer.com/news/security/new-stealthy-beep-malware-focuses-heavily-on-evading-detection/