SonicWall´¹Î£¸üн¨¸´GMSºÍAnalyticsÖеÄ15¸ö·ì϶

°ä²¼¹¦·ò 2023-07-14

1¡¢SonicWall´¹Î£¸üн¨¸´GMSºÍAnalyticsÖеÄ15¸ö·ì϶


7ÔÂ12ÈÕ£¬SonicWall°ä²¼´¹Î£¸üУ¬½¨¸´ÁËGMS·À»ðǽÖÎÀíϵͳºÍAnalyticsÍøÂç»ã±¨ÒýÇæÈí¼þÖеÄ15¸ö·ì϶¡£ÆäÖнÏΪÑϳÁµÄÊÇWeb·þÎñÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶£¨CVE-2023-34124£©¡¢¶à¸öδ¾­Éí·ÝÑéÖ¤µÄSQLºÍ°²È«¹ýÂËÆ÷ÈÆ¹ý·ì϶£¨CVE-2023-34133£©¡¢Í¨¹ýWeb·þÎñ¶ÁÈ¡ÃÜÂëhash·ì϶£¨CVE-2023-34134£©ºÍCASÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶£¨CVE-2023-34137£©¡£ÕâЩ·ì϶ÉÐδ±»ÀûÓ㬸ù«Ë¾½¨ÒéʹÓÃÊÜÓ°Ïì²úÆ·µÄÓû§µ±¼´ÀûÓò¹¶¡¡£


https://www.bleepingcomputer.com/news/security/sonicwall-warns-admins-to-patch-critical-auth-bypass-bugs-immediately/


2¡¢BlackLotus UEFI BootkitÔ´´úÂëÔÚGitHubÉϹ«¿ª


¾Ý7ÔÂ13ÈÕ±¨Â·£¬BlackLotus UEFI BootkitÔ´´úÂëÔÚGitHubÉϹ«¿ª¡£¸ÃbootkitרΪWindowsÉè¼Æ£¬È¥Äê10Ô³ʴ˿̺ڿÍÂÛ̳£¬Ðû³ÆÓµÓÐAPT¼¶´ËÍâÖ°ÄÜ£¬ÀýÈçÈÆ¹ýUACÒÔ¼°½ûÓð²È«ÀûÓúͷÀÓù»úÔì¡£BlackLotus×î³õÔÚºÚ¿ÍÂÛ̳ÉϵÄÊÛ¼ÛΪ5000ÃÀÔª£¬´Ë¿Ì£¬ÆäÔ´´úÂë±»Óû§YukariÔÚ°ä²¼ÔÚGitHubÉÏ£¬Ê¹Ëü¿É¹©ÈκÎÈËʹÓá£Ð¹Â¶µÄÔ´´úÂëɾ³ýÁËBaton Drop·ì϶£¨CVE-2022-21894 £©£¬ÖØÒªÔ̺¬rootkit²¿ÃźÍÈÆ¹ý°²È«Æô¶¯µÄbootkit´úÂë¡£


https://www.securityweek.com/blacklotus-uefi-bootkit-source-code-leaked-on-github/


3¡¢Mandiant¹«¿ªÁ½Æðͨ¹ýUSB·Ö·¢µÄ¶ñÒâÈí¼þ»î¶¯µÄϸ½Ú


MandiantÔÚ7ÔÂ11ÈÕй©Æä·¢ÏÖÁËÁ½Æðͨ¹ýUSB·Ö·¢µÄ¶ñÒâÈí¼þ»î¶¯¡£µÚÒ»¸ö»î¶¯±»¹éÒòÓÚTEMP.HEX£¬ÀûÓöñÒâDLLÎļþ¼ÓÔØºóÃÅSogu¡£¸Ã»î¶¯Õë¶ÔÈ«Çò¶à¸öÐÐÒµ£¬²¢ÊÔͼ´ÓÖ¸±êÍÆËã»úÖÐÇÔÈ¡Êý¾Ý£¬ÆäÖдóÎÞÊýÖ¸±êÊôÓÚÔìÒ©¡¢IT¡¢ÄÜÔ´¡¢Í¨Ñ¶¡¢ÎÀÉúºÍÎïÊ¢ÐÐÒµ¡£µÚ¶þ¸ö»î¶¯·Ö·¢»ùÓÚshellcodeµÄºóÃÅSnowydrive£¬Ëü±»¼ÓÔØµ½ºÏ·¨¹ý³ÌCUZ.exeÖУ¬¾ßº±¼û¾Ýй¶¡¢·´Ïòshell¡¢ºÅÁîÖ´ÐкͿúËŵÈÖ°ÄÜ£¬±»¹éÒòÓÚÕë¶ÔÑÇÖÞʯÓͺÍÌìÈ»Æø¹«Ë¾µÄUNC4698¡£


https://www.mandiant.com/resources/blog/infected-usb-steal-secrets


4¡¢2023ÄêÉϰëÄêÈ«ÇòµÄ¼ÓÃÜÀÕË÷½ð¶î¸ß´ïÔ¼4.5ÒÚÃÀÔª


ChainaanalysisÔÚ7ÔÂ12Èճƣ¬¾­ÀúÁË»ìÂÒµÄ2022ÄêÖ®ºó£¬2023ÄêÆù½ñΪֹÊǼÓÃÜÇ®±Ò¸´ËÕµÄÒ»Äê¡£½ØÖÁ6Ô·Ý£¬ÀÕË÷½ð¶îÒÑÖÁÉÙ4.491ÒÚÃÀÔª£¬´ïµ½ÁË2022ÄêÕûÄêÀÕË÷Èí¼þ×ÜÊÕÈëµÄ90%¡£ÈôÊÇά³ÖÕâһˮƽ£¬2023ÄêÕûÄêµÄÀÕË÷½ð¶î½«½ü9ÒÚÃÀÔª¡£×êÑÐÈËÔ±ÒÔΪ£¬¹¥»÷Õ߯ðÍ·Õë¶ÔÄܹ»ÀÕË÷µ½´ó±Ê½ðÇ®µÄ´óÐÍ×éÖ¯£¬µ¼ÖÂÁËÕâÖÖ´ó·ùÔö³¤¡£¸ß¶îÊê½ðÉæ¼°µÄÀÕË÷ÍÅ»ïÖØÒªÔ̺¬BlackBasta¡¢LockBit¡¢ALPHVºÍClop¡£ÆäÖÐClopµÄ¾ùÔÈÊê½ðΪ170ÍòÃÀÔª£¬Êê½ðµÄÖÐλÊýΪ190ÍòÃÀÔª¡£


https://blog.chainalysis.com/reports/crypto-crime-midyear-2023-update-ransomware-scams/   


5¡¢Check Point°ä²¼QuickBlox¿ò¼ÜÖзì϶µÄ·ÖÎö»ã±¨


7ÔÂ12ÈÕ£¬Check Point³ÆÆä¶ÔQuickBlox¿ò¼ÜµÄSDKºÍAPIµÄ°²È«ÐÔ½øÐÐ×êÑУ¬·¢ÏÖÁË¿ÉÄÜΣ¼°Êý°ÙÍòÓû§Ó×ÎÒÐÅÏ¢µÄ·ì϶¡£QuickBloxÊÇÒ»ÖÖÊ¢ÐеÄ̸ÌìºÍÊÓÆµ·þÎñ£¬ÖØÒªÓÃÓÚÔ¶³ÌÒ½ÁÆ¡¢½ðÈÚºÍÖÇÄÜÎïÁªÍøÉ豸¡£×êÑÐÈËÔ±»¹Ú¹ÊÏçËһЩ¹ÖÒìµÄ¹¥»÷·½Ê½£¬ÀýÈ磬Äܹ»Ê¹¹¥»÷Õß½Ó¼ûÖÇÄܶԽ²»ú²¢Ô¶³Ì¿ªÃÅ£¬»ò´ÓÔ¶³ÌÒ½ÁÆÀûÓÃÖÐй©»¼ÕßµÄÊý¾Ý¡£Ä¿Ç°£¬QuickBloxÒÑͨ¹ýÐµİ²È«¼Ü¹¹Éè¼ÆºÍAPI½¨¸´ÁËÕâЩ·ì϶¡£


https://research.checkpoint.com/2023/major-security-flaws-in-popular-quickblox-chat-and-video-framework-expose-sensitive-data-of-millions/


6¡¢FortiGuard°ä²¼½üÆÚ·Ö·¢LokiBotµÄ¹¥»÷»î¶¯µÄ»ã±¨


7ÔÂ12ÈÕ£¬FortiGuard°ä²¼»ã±¨£¬·ÖÎöÁËÀûÓ÷ì϶ºÍ¶ñÒâºê·Ö·¢¶ñÒâÈí¼þLokiBotµÄ»î¶¯¡£×êÑÐÈËÔ±»ñÈ¡²¢·ÖÎöÁËÁ½ÖÖWordÎĵµ£¬µÚÒ»ÖÖÔ̺¬Ç¶ÈëÔÚXMLÎļþword/_rels/document.xml.relsÖÐµÄ±í²¿Á´½Ó£¬µÚ¶þÖÖÔ̺¬ÔÚ´ò¿ªÎĵµºóµ±¼´Ö´ÐкêµÄVBA¾ç±¾¡£ÕâЩÎĵ·ûÓÃÁËÔ¶³Ì´úÂëÖ´Ðзì϶£¬¼´CVE-2021-40444ºÍCVE-2022-30190£¬×îÖÕ»áÔÚÖ¸±êµÄϵͳÖÐ×¢ÈëLokiBot¡£×êÑÐÈËÔ±½¨Ò飬ÔÚ´¦ÖÃOfficeÎĵµ»òδ֪ÎļþʱӦÉóÉ÷ÐÐÊ¡£


https://www.fortinet.com/blog/threat-research/lokibot-targets-microsoft-office-document-using-vulnerabilities-and-macros