ShuckwormÍÅ»ïͨ¹ýUSB·Ö·¢Æä×Ô½ç˵ºóÃÅPterodo

°ä²¼¹¦·ò 2023-06-20

1¡¢ShuckwormÍÅ»ïͨ¹ýUSB·Ö·¢Æä×Ô½ç˵ºóÃÅPterodo


6ÔÂ15ÈÕ£¬SymantecÅû¶Á˶íÂÞ˹ÓйغڿÍÍÅ»ïShuckworm¸üÐµĹ¤¾ß¼¯ºÍϰȾսÊõ¡£Shuckworm³ÖÐø¶ÔÎÚ¿ËÀ¼ÌáÒéÁËÂŴι¥»÷£¬×î½üµÄÖ¸±êÔ̺¬°²È«ÊýÃÅ¡¢¾ü¶ÓºÍµ±¾Ö×éÖ¯¡£ShuckwormʹÓõç×ÓÓʼþ×÷Ϊ³õÊ¼Ï°È¾ÔØÌåÀ´·Ö·¢¶ñÒâÈí¼þ£¬¶øºóʹÓÃÁËÒ»¸öеÄPowerShell¾ç±¾£¬Í¨¹ýUSB·Ö·¢Æä×Ô½ç˵ºóÃŶñÒâÈí¼þPterodo¡£ÔÚ×î½üµÄ»î¶¯ÖУ¬¸ÃÍŻﻹÀûÓúϷ¨·þÎñ³äÈÎC&C·þÎñÆ÷£¬Ô̺¬Telegram£¬ÒÔ¼°TelegramµÄ΢²©Æ½Ì¨£¬¼´Telegraph£¬À´´æ´¢C&CµØÖ·¡£


https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/shuckworm-russia-ukraine-military


2¡¢ÃÀ¹ú·Ò×˹°²ÄÇÖݺͶíÀÕ¸ÔÖÝÊý°ÙÍò¾ÓÃñµÄÐÅϢй¶


6ÔÂ16ÈÕ±¨Â·³Æ£¬Â·Ò×˹°²ÄÇÖݺͶíÀÕ¸ÔÖݵÄMOVEit Transfer°²È«Îļþ´«ÊäϵͳÔâµ½¹¥»÷£¬Êý°ÙÍò¾ÓÃñµÄÐÅϢй¶¡£Â·Ò×˹°²ÄÇÖÝ»ú¶¯³µÁ¾°ì¹«ÊÒ(OMV)й©£¬¿ÉÄÜËùÓÐÕ¼ÓиÃÖݵ±¾ÖÐû¸æµÄ¼ÝÊ»ÅÆÕÕ¡¢Éí·ÝÖ¤»òÆû³µµÇ¼ÇÖ¤µÄ¾ÓÃñ¶¼Êܵ½ÁËÓ°Ïì¡£¶íÀÕ¸ÔDMVÒ²°ä²¼ÁËÀàËÆµÄÉêÃ÷£¬³ÆÕâ´ÎÊý¾Ýй¶ÊÂÎñÓ°ÏìÁËԼĪ3500000Ãû¶íÀÕ¸ÔÈË¡£¶íÀÕ¸ÔÖݵ±¾Ö°µÊ¾£¬ËûÃÇÎÞ·¨È·¶¨¾ßÌåµÄÊÜÓ°ÏìÓ×ÎÒ£¬Òò¶ø½¨ÒéËùÓй«Ãñ²ÉȡԤ·À´ëÊ©¡£


https://www.bleepingcomputer.com/news/security/millions-of-oregon-louisiana-state-ids-stolen-in-moveit-breach/


3¡¢»ªË¶°ä²¼´¹Î£¹Ì¼þ¸üУ¬½¨¸´Æä¶à¿î·ÓÉÆ÷Öеķì϶


ýÌå6ÔÂ19Èճƣ¬»ªË¶°ä²¼ÁË´¹Î£¹Ì¼þ¸üУ¬½¨¸´Æä¶à¸ö·ÓÉÆ÷ÐͺÅÖеÄ9¸ö·ì϶¡£ÆäÖÐÔ̺¬Á½¸öCVSSÆÀ·ÖΪ9.8µÄ·ì϶£¬±ðÀëÊÇNetatalk 3.1.12֮ǰµÄÔ½½çдÈë·ì϶£¨CVE-2018-1160£©£¬¿Éµ¼ÖÂËÁÒâ´úÂëÖ´ÐС£ÒÔ¼°Asuswrt¹Ì¼þÖеÄÄÚ´æ°Ü»µ·ì϶£¨CVE-2022-26376£©£¬¿ÉÄܵ¼Ö»ؾø·þÎñ״̬»òËÁÒâ´úÂëÖ´ÐС£¸Ã¹«Ë¾½¨ÒéÊÜÓ°Ïì·ÓÉÆ÷ÐͺŵÄÓû§¾¡¿ì½«É豸¸üе½×îй̼þ£¬²¢ÎªÎÞÏßÍøÂçºÍ·ÓÉÆ÷ÖÎÀíÒ³ÃæÉèÖõ¥¶ÀµÄ¸´ÔÓµÄÃÜÂë¡£


https://www.securityweek.com/asus-patches-highly-critical-wifi-router-flaws/


4¡¢FTCÖ¸¿Ø»ùÒò¼ì²â¹«Ë¾1health.ioй¶Óû§µÄ½¡È«ÐÅÏ¢


ýÌå6ÔÂ16Èճƣ¬ÃÀ¹úFTCÖ¸¿Ø»ùÒò½¡È«¼ì²â¹«Ë¾1health.ioδÄܱ£»¤Ãô¸ÐµÄ»ùÒòºÍ½¡È«ÐÅÏ¢¡£FTC³Æ£¬1healthÒÔǰ³ÆÎªVitagene£¬ÔÚÆäÒþÖÔÕþ²ß·½ÃæºýŪÁ˿ͻ§£¬×·ÒäÐԵظü¸ÄÁ˸ÃÕþ²ß£¬²¢ÔÚÆäɾ³ýÊý¾ÝµÄ¹ý³ÌÖÐÎóµ¼Á˿ͻ§¡£¸Ã¹«Ë¾±»ÒªÇóÏòFTCÖ§¸¶75000ÃÀÔªÓÃÓÚÏû·ÑÕßÍ˿²¢±»²»ÈÝÔÚδ»ñµÃ¿Í»§Ã÷È·Ô޳ɵÄÇé¿öÏÂÓëµÚÈý·½¹²Ïí½¡È«Êý¾Ý£¬»¹±ØÐëÖ´ÐÐÐµİ²È«´òËã¡£1healthµÄÊ×ϯִÐйٳÆFTCµÄµ÷²éÊÇ¡°µ±¾Ö¹ý¶È¹ýÎʵݸÀý¡±¡£


https://cyberscoop.com/ftc-1healthio-health-data-privacy/


5¡¢×êÑÐÈËÔ±ÑÝʾÐÂÐͲàÐÅ·¹¥»÷·½Ê½Freaky Leaky SMS


¾Ý6ÔÂ17ÈÕ±¨Â·£¬Ò»×é×êÑÐÈËÔ±Éè¼ÆÁËÃûΪFreaky Leaky SMSµÄÐÂÐͲàÐÅ·¹¥»÷·½Ê½£¬ËüÒÀÀµÓÚSMS·¢Ëͻ㱨µÄ¹¦·òÀ´´§¶ÈÊÕ¼þÈ˵ĵØÎ»¡£¹¥»÷ÕßÊ×ÏȱØÒªÍøÂçһЩÕÉÁ¿Êý¾Ý£¬ÒÔ±ãÔÚSMS·¢Ëͻ㱨ºÍÖ¸±êµÄµØÎ»Ö®¼ä³ÉÁ¢¾ßÌåµÄ¹ØÁª¡£¹¥»÷Õß°ÑÎÕµÄÖ¸±êÐÐ×ÙÊý¾ÝÔ½¾«È·£¬¹¥»÷½×¶ÎMLÄ£ÐÍÔ¤²âÖеĵØÎ»·ÖÀàÁ˾־ÍÔ½ÕýÈ·¡£´Ë±í£¬Í³Ò»×é×êÑÐÈËÔ±ÔÚÈ¥Ä꿪·¢ÁËÀàËÆµÄ°´Ê±¹¥»÷£¬¿ÉʹÓÃÐÂÎŽӹܻ㱨´óÌ嶨λSignal¡¢ThreemaºÍWhatsAppµÈ¼´Ê±Í¨Ñ¶¹¤¾ßµÄÓû§¡£


https://www.bleepingcomputer.com/news/security/sms-delivery-reports-can-be-used-to-infer-recipients-location/


6¡¢MandiantÅû¶UNC4841ÀûÓÃBarracuda ESG·ì϶µÄ¹¥»÷ÏêÇé


MandiantÔÚ6ÔÂ15ÈÕÅû¶ÁËUNC4841ÀûÓÃBarracuda ESG·ì϶µÄ¹¥»÷ÏêÇ顣ԼĪ´Ó2022Äê10ÔÂ10ÈÕÆðÍ·£¬UNC4841ÆðÍ·ÀûÓÃÔ¶³ÌºÅÁî×¢Èë·ì϶£¨CVE-2023-2868£©¡£¹¥»÷ʼÓÚÔ̺¬¶ñÒ⸽¼þµÄµç×ÓÓʼþ£¬µ±Barracuda ESG³¢ÊÔɨÃèÎļþʱ£¬¸½¼þ»áÀûÓø÷ì϶ÔÚÉ豸ÉÏÔ¶³ÌÖ´ÐдúÂë¡£Ò»µ©»ñÈ¡½Ó¼ûȨÏÞ£¬¾Í»áʹÓöñÒâÈí¼þϵÁÐSaltwater¡¢SeaspyºÍSeasideϰȾËü£¬À´´ÓÉ豸ÖÐÇÔÈ¡µç×ÓÓʼþÊý¾Ý¡£Mandiant»¹³ÆBarracudaÉÏÖÜÒªÇóÓû§¸ü»»É豸ÊdzöÓÚÉóÉ÷µÄÖ÷ÕÅ£¬ÓÉÓÚËüÎÞ·¨È·±£ÒÑÆëȫɾ³ý¶ñÒâÈí¼þ¡£


https://www.mandiant.com/resources/blog/barracuda-esg-exploited-globally