Ò½ÁÆ»ú¹¹CHSÒòFortra·ì϶й¶100Íò»¼ÕßµÄÓ×ÎÒÐÅÏ¢
°ä²¼¹¦·ò 2023-02-16
¾Ý2ÔÂ14ÈÕ±¨Â·£¬ÃÀ¹úÒ½ÁÆ»ú¹¹Community Health Systems(CHS)³ÆÆäÊܵ½ÁËÕë¶ÔFortraµÄGoAnywhere MFTƽ̨ÖÐÁãÈÕ·ì϶µÄ¹¥»÷µÄÓ°Ïì¡£Õâ¼ÒÒ½ÁÆ·þÎñ¹«Ë¾ÖÜÒ»°µÊ¾£¬Fortra·¢³ö¾¯±¨³Æ¾ÀúÁËÒ»´Î°²È«ÊÂÎñ£¬µ¼ÖÂCHSµÄ²¿ÃÅÊý¾Ýй¶¡£ËæºóµÄµ÷²éÏÔʾ£¬Õâ´Îй¶ӰÏìÁ˶à´ï100ÍòÃû»¼ÕßµÄÓ×ÎҺͽ¡È«ÐÅÏ¢¡£ClopÍÅ»ïÐû³ÆÊÇÕâ´Î¹¥»÷µÄÄ»ºóºÚÊÖ£¬»¹³ÆÒÑÇÔÈ¡130¶à¸ö×éÖ¯µÄÊý¾Ý¡£
https://www.bleepingcomputer.com/news/security/healthcare-giant-chs-reports-first-data-breach-in-goanywhere-hacks/
2¡¢Citrix½¨¸´Workspace AppsµÈ²úÆ·ÖеĶà¸ö·ì϶
¾ÝýÌå2ÔÂ15ÈÕ±¨Â·£¬Citrix Systems°ä²¼°²È«¸üУ¬½¨¸´ÆäVirtual Apps and DesktopsºÍWorkspace Apps²úÆ·Öеķì϶¡£ÆäÖÐ×îÑϳÁµÄÊÇȨÏÞÖÎÀí²»µ±·ì϶£¨CVE-2023-24483£©£¬¿É½«È¨ÏÞÌáÉýµ½NT AUTHORITY\SYSTEM¡£´Ë±í£¬»¹Óпɽ«ÈÕÖ¾ÎļþдÈëͨ³£Óû§ÎÞȨдÈëµÄĿ¼µÄ½Ó¼û½ÚÔì²»µ±·ì϶£¨CVE-2023-24484£©£¬ÒÔ¼°µ¼ÖÂȨÏÞÌáÉýµÄ½Ó¼û½ÚÔì²»µ±·ì϶£¨CVE-2023-24485£©ºÍµ¼Ö»ỰÊÕÊܵĽӼû½ÚÔì²»µ±·ì϶£¨CVE-2023-24486£©¡£CISA°ä²¼Á˹ØÓÚ¾¡¿ìÀûÓÃCitrix°²È«¸üеľ¯±¨¡£
https://www.bleepingcomputer.com/news/security/citrix-fixes-severe-flaws-in-workspace-virtual-apps-and-desktops/
3¡¢CiscoÅû¶·Ö·¢MortalKombatºÍLaplas ClipperµÄ»î¶¯
Cisco TalosÔÚ2ÔÂ14ÈÕÅû¶ÁËһ··Ö·¢ÀÕË÷Èí¼þMortalKombatºÍ¶ñÒâÈí¼þLaplas ClipperµÄ»î¶¯¡£×êÑÐÈËÔ±×Ô2022Äê12ÔÂÆðÍ·¹Û²ìµ½Á˸û£¬ÖØÒªÕë¶ÔÃÀ¹ú¡¢Ó¢¹ú¡¢ÍÁ¶úÆäºÍ·ÆÂɱöµÈµØÓò¡£¹¥»÷»î¶¯Ê¼ÓÚ´¹µöµç×ÓÓʼþ£¬²¢Æô¶¯¶à½×¶Î¹¥»÷Á´£¬»á·Ö·¢¶ñÒâÈí¼þ»òÀÕË÷Èí¼þ£¬¶øºóɾ³ý¶ñÒâÎļþµÄÖ¤¾Ý£¬¸²¸ÇÆä×ÙÓ°²¢Èƹý¶ÈÎö¡£MortalKombatÊÇXoristµÄÒ»ÖÖ±äÌ壬ÓÚ2023Äê1Ô³õ´Î±»·¢ÏÖ¡£Laplas ClipperÊÇÏà¶Ô½ÏеļôÌù°åÇÔÈ¡·¨Ê½£¬ÓÃÓÚÇÔȡָ±êµÄ¼ÓÃÜÇ®±Ò¡£
https://blog.talosintelligence.com/new-mortalkombat-ransomware-and-laplas-clipper-malware-threats/
4¡¢16¸ö¶ñÒâNPM°ü¼Ù×°³ÉÍø¿ì²âÊÔÆ÷Ö¼ÔÚÍÚ¾ò¼ÓÃÜÇ®±Ò
2ÔÂ14ÈÕ£¬Check Point³ÆÆäÔÚNPMÉϼì²âµ½16¸ö¶ñÒâ°ü¡£ËüÃǼÙ×°³ÉÍø¿ì²âÊÔÆ÷£¬Ö¼ÔÚ½Ù³ÖÖ¸±êµÄÍÆËã»ú×ÊÔ´ÒÔÍÚ¾ò¼ÓÃÜÇ®±Ò¡£ËùÓаü¾ùÓÉÓû§trendavaÉÏ´«µ½NPM£¬Ö»¹ÜËüÃÇÓµÓÐÒ»ÑùµÄÖ¸±ê£¬µ«×êÑÐÈËÔ±·¢ÏÖÿ¸ö°ü¶¼Ñ¡È¡·ÖÆçµÄ±àÂëºÍ²½ÖèÀ´ÊµÏ֯乤×÷¡£Äܹ»ÒÔΪÕâЩ²î¾à´ú±íÁ˹¥»÷ÕßËù×öµÄÊÔÑ飬ËûÊÂÏȲ»ÖªÂ·Äĸö°æ±¾»á±»°²È«¹¤¾ß¼ì²âµ½£¬Òò¶ø³¢ÊÔÓÃ·ÖÆçµÄ·½Ê½À´°µ²Ø¶ñÒâÒâͼ¡£×êÑÐÈËÔ±ÓÚ1ÔÂ17ÈÕ·¢ÏÖÁËÕâЩ°ü£¬NPMÓÚ´ÎÈÕɾ³ýÁËËüÃÇ¡£
https://blog.checkpoint.com/2023/02/14/check-point-cloudguard-spectral-detects-malicious-crypto-mining-packages-on-npm-the-leading-registry-for-javascript-open-source-packages/
5¡¢BlackCat³ÆÒÑÇÔÈ¡°®¶ûÀ¼Ã÷Ë¹ÌØ¿Æ¼¼´óѧ6GBµÄÊý¾Ý
ýÌå2ÔÂ14Èճƣ¬BlackCat£¨Ò²³ÆALPHV£©ÔÚÆäÍøÕ¾ÁгöÁË´Ó°®¶ûÀ¼Ã÷Ë¹ÌØ¿Æ¼¼´óѧ(MTU)ÇÔÈ¡µÄ³¬¹ý6 GBµÄÊý¾Ý¡£¸ÃÍÅ»ïÔÚ.onionÍøÕ¾ÉÏÐû³ÆÐ¹Â¶ÐÅÏ¢Ô̺¬Ô±¹¤¼Í¼ºÍ¹¤×ʵ¥¾ßÌåÐÅÏ¢£¬ÕâÁ½¸öÊý¾Ý¼¯¶¼¿ÉÄܵ¼ÖÂڲƺÍɧÈŻ¡£MTUÔøÓÚ2ÔÂ6Èճƣ¬ÓÉÓÚ³Á´óITÎÊÌâºÍµç»°Öжϣ¬ÆäλÓڿƿ˵ÄÐ£Çø¹Ø¹ØÇҿγÌÈ¡µÞ£¬µ«²¢Î´½«Õâ´Î¹¥»÷¹é×ïÓÚÌØ¶¨µÄ¹¥»÷ÍŻ
https://therecord.media/alphv-blackcat-posted-data-ireland-munster-technical-university/
6¡¢Minerva°ä²¼ÇÔÊØÐÅÏ¢µÄ¶ñÒâÈí¼þBeepµÄ·ÖÎö»ã±¨
2ÔÂ13ÈÕ£¬Minerva°ä²¼Á˹ØÓÚÇÔÊØÐÅÏ¢µÄ¶ñÒâÈí¼þBeepµÄ·ÖÎö»ã±¨¡£BeepʹÓÃÈý¸ö¶ÀÁ¢µÄ×é¼þ£ºÖ²È뷨ʽ¡¢×¢È뷨ʽºÍpayload¡£¸Ã¶ñÒâÈí¼þËÆºõÈÔÔÚ¿ª·¢ÖУ¬×êÑÐÈËÔ±ÔÚÑù±¾Öз¢ÏÖÁ˺öàÓÉC2ºÅÁî´¥·¢µÄÖ°ÄÜÉÐδִÐС£BeepÖ®ËùÒÔÍÑÓ±¶ø³ö£¬ÊÇÓÉÓÚÔÚÕû¸öÖ´ÐÐÁ÷³ÌÖÐʹÓÃÁ˶àÖÖ¼¼ÊõÀ´Èƹý°²È«Èí¼þºÍ×êÑÐÈËÔ±µÄ¼ì²âºÍ·ÖÎö£¬Ô̺¬¶¯Ì¬×Ö·û´®È¥»ìºÏ¡¢ÏµÍ³Ëµ»°²é³¡¢IsDebuggerPresent APIº¯ÊýµÄ·¨Ê½¼¯ºÍNtGlobalFlag×ֶη´µ÷ÊԵȡ£
https://www.bleepingcomputer.com/news/security/new-stealthy-beep-malware-focuses-heavily-on-evading-detection/


¾©¹«Íø°²±¸11010802024551ºÅ