×êÑÐÈËÔ±³Æ¶ñÒâÈí¼þAVreconÒÑϰȾ7Íò¶àSOHO·ÓÉÆ÷
°ä²¼¹¦·ò 2023-07-171¡¢×êÑÐÈËÔ±³Æ¶ñÒâÈí¼þAVreconÒÑϰȾ7Íò¶àSOHO·ÓÉÆ÷
Black Lotus LabsÔÚ7ÔÂ12Èճƣ¬¶ñÒâÈí¼þAVreconÒÑϰȾ³¬¹ý70000¸ö»ùÓÚLinuxµÄSOHO·ÓÉÆ÷£¬²¢½«ËüÃÇÔö³¤µ½½©Ê¬ÍøÂçÖС£³ýÁË2021Äê5Ô³õ´Î±»·¢ÏÖÖ®±í£¬AVreconÒѾÔËÐÐÁËÁ½Äê¶à¶øÎ´±»¼ì²âµ½¡£×êÑÐÈËÔ±´§¶È£¬¸Ã»î¶¯ËƺõÖ¼ÔÚ´´½¨Ò»¸ö°ÂÃØÍøÂ磬ÒÔ͵͵µØ·¢Õ¹ÃÜÂëÅçÈ÷ºÍÊý×Ö¸æ°×ڲƵÈһϵÁй¥»÷»î¶¯¡£ÓÉÓÚ¶ñÒâÈí¼þµÄÒñ±ÎÐÔ£¬±»Ï°È¾É豸µÄËùÓÐÕߺÜÉÙ°ÑÎȵ½¹¤×÷Öжϻò´ø¿íµÄËðʧ¡£°²È«ÍŶÓͨ¹ý½«½©Ê¬ÍøÂçµÄC2ÔÚÆäÖ÷¸ÉÍøÂçÉϽøÐÐÎÞЧ·ÓÉÀ´Ó¦¶Ô´ËÀàÍþв¡£
https://blog.lumen.com/routers-from-the-underground-exposing-avrecon/
2¡¢ÎÚ¿ËÀ¼CERT-UAÅû¶UAC-0010ÍÅ»ï½üÆÚ¹¥»÷»î¶¯µÄϸ½Ú
7ÔÂ13ÈÕ£¬ÎÚ¿ËÀ¼CERT-UAÅû¶ÁËUAC-0010£¨ÓÖ³ÆGamaredon£©ÍÅ»ï½üÆÚ¹¥»÷»î¶¯µÄϸ½Ú¡£Gamaredon»á½øÐм±¾ç¹¥»÷£¬ÔÚ³õ´ÎÈëÇÖºó30·ÖÖÓ¾ÍÆðÍ·ÇÔÈ¡Êý¾Ý¡£Ê×ÏÈÀûÓô¹µöÓʼþºÍÐÂÎÅ£¬ÓÕʹָ±ê´ò¿ª¶øÒѸ½¼þ£¬¶øºóÏÂÔØPowerShell¾ç±¾ºÍ¶ñÒâÈí¼þ£¨Í¨³£ÊÇGammaSteel£©¡£´Ë±í£¬¹¥»÷ÕßÿÖÜÔÚ±»Ï°È¾µÄϵͳÉÏÖ²Èë¶à´ï120¸ö¶ñÒâÎļþ£¬ÒÔÔö³¤ÔÙ´ÎϰȾµÄ¿ÉÄÜÐÔ¡£CERT-UA°µÊ¾£¬ÕмܴËÀ๥»÷µÄ×î¼Ñ²½ÖèÊÇ×èÖ¹»òÏÞ¶Èmshta.exe¡¢wscript.exe¡¢cscript.exeºÍpowershell.exeµÄδ¾ÊÚȨִÐС£
https://cert.gov.ua/article/5160737
3¡¢WordPress²å¼þAIOS¼Í¼Ã÷ÎÄÃÜÂëÓ°Ïì100¶àÍò¸öÍøÕ¾
¾ÝýÌå7ÔÂ14ÈÕ±¨Â·£¬WordPress²å¼þAll-In-One Security(AIOS)±»·¢ÏÖ»áÒÔÃ÷ÎÄ´ó¾Ö´æ´¢Óû§ÃÜÂ룬´Ó¶øÊ¹ÕÊ»§°²È«Ãæ¶Ô·çÏÕ¡£¸Ã²å¼þ±»³¬¹ý100Íò¸öÍøÕ¾Ê¹Óã¬ÓÐЧ»§»ã±¨³Æ£¬Ëü²»½ö½«Óû§µÇ¼³¢ÊԼͼµ½aiowps_audit_logÊý¾Ý¿â±í£¨ÓÃÓÚ¸ú×ٵǼ¡¢×¢ÏúºÍµÇ¼ʧ°Ü¶Îñ£©£¬»¹¼Í¼ÁËÊäÈëµÄÃÜÂ롣Ŀǰ£¬AIOS¹©¸øÉÌÒÑÓÚ7ÔÂ11ÈÕ°ä²¼ÁË5.2.0°æ±¾£¬ÆäÖÐÔ̺¬Ô¤·À±£ÁôÃ÷ÎÄÃÜÂë²¢¶Ï¸ù¾ÉÌõ¿î±ê½¨¸´·¨Ê½¡£Í³¼ÆÊý¾ÝÏÔʾ£¬½ØÖÁĿǰ»¹Óг¬¹ý750000¸öÍøÕ¾Î´¸üУ¬ÈÝÒ×Ôâµ½¹¥»÷¡£
https://www.bleepingcomputer.com/news/security/wordpress-aios-plugin-used-by-1m-sites-logged-plaintext-passwords/
4¡¢Ð½×Ê·þÎñ¹«Ë¾UKGÔÞ³ÉÒÔ600ÍòÃÀÔªºÍ½âÊý¾Ýй¶µÄËßËÏ
ýÌå7ÔÂ12Èճƣ¬Ð½×Ê·þÎñÌṩÉÌUKGÔÞ³ÉÒÔ600ÍòÃÀÔªºÍ½â2021ÄêÊý¾Ýй¶µÄËßËÏ¡£2021Äê12ÔµÄÀÕË÷¹¥»÷µ¼ÖÂUKGµÄKronos˽ÓÐÔÆ²¿ÃŲúÆ·ÀëÏߣ¬»¹µ¼Ö²¿ÃÅÔ±¹¤ºÍ³Ð°üÉ̵ÄÐÅϢй¶¡£Õâ´ÎÊÂÎñÓ°ÏìÁ˰Ùʹ«Ë¾¡¢Å¦Ô¼Êн»Í¨¾Ö¡¢Ó¢¹ú³¬ÊÐSainsburyºÍ¶à¸öÒ½ÁÆ»ú¹¹¡£UKGÓÚ2022Äê1Ô±»¸æ×´£¬ÆäʱÌá³öÁ˾ÅÏîËßËÏÀíÓÉ£¬Ô̺¬ºöÂÔ¡¢²»µ±µÃÀû¡¢Î¥Ô¼ºÍÎ¥·´¼ÓÖÝÒþÖÔ·¨µÈ¡£UKGÔÞ³ÉÖ§¸¶550ÍòÃÀÔªÓÃÓÚË÷Å⣬²¢³ÐŵÔÚ±ØÒªÊ±×·¼Ó50ÍòÃÀÔª¡£
https://www.wsj.com/articles/payroll-services-provider-ukg-agrees-to-6-million-settlement-in-data-breach-lawsuit-8ea87f01
5¡¢Uptycs·¢ÏÖ¼ÙµÄCVE-2023-35829µÄPoC·Ö·¢¶ñÒâÈí¼þ
UptycsÔÚ7ÔÂ12ÈÕ³ÆÆä·¢ÏÖÁËÒ»¸öαÔìµÄ·ì϶PoC£¬»á·Ö·¢LinuxÃÜÂëÇÔÈ¡¶ñÒâÈí¼þ¡£¸ÃPoCÐû³ÆÊÇÕë¶ÔCVE-2023-35829µÄ·ì϶ÀûÓã¬ÕâÊÇÒ»¸öÓ°Ïì6.3.2֮ǰµÄLinuxÄں˵ĿªÊͺóʹÓ÷ì϶¡£µ«ÏÖʵÉÏ£¬ËüÊÇÁíÒ»¸öLinuxÄں˷ì϶CVE-2022-34918µÄ¾É°æºÏ·¨·ì϶ÀûÓ᣸öñÒâÈí¼þ¿ÉÄÜÇÔÈ¡Ö÷»úÃû¡¢Óû§ÃûºÍÖ÷Ŀ¼ÄÚÈÝµÄÆëÈ«ÁбíµÈ¡£´Ë±í£¬¹¥»÷Õß»¹Í¨¹ý½«SSHÃÜÔ¿Ôö³¤µ½authorized_keysÎļþÖУ¬ÒÔʵÏÖ¶ÔÖ¸±êϵͳµÄÆëÈ«½ÚÔì¡£
https://www.uptycs.com/blog/new-poc-exploit-backdoor-malware
6¡¢SlashNext°ä²¼»ùÓÚAIµÄºÚ¿Í¹¤¾ßWormGPTµÄ·ÖÎö»ã±¨
7ÔÂ13ÈÕ£¬SlashNext°ä²¼ÁËÐÂÐÍÌìÉúʽÈËΪÖÇÄܺڿ͹¤¾ßWormGPTµÄ·ÖÎö»ã±¨¡£¸Ã¹¤¾ß½«×Ô¼ºÊÓΪGPTÄ£Ð͵ĺÚñ´úÌæÆ·£¬×¨Îª¶ñÒâ»î¶¯¶øÉè¼Æ¡£WormGPTÊÇÒ»¿î»ùÓÚGPTJ˵»°Ä£Ð͵ÄAIÄ£¿é£¬ÓÚ2021Ä꿪·¢£¬ÓµÓÐÎÞÏÞ×Ö·ûÖ§³Ö¡¢Ì¸ÌìÄÚ´æ±£ÁôºÍ´úÂëÌåʽ»¯µÈÖ°ÄÜ¡£¹¥»÷ÕßÄܹ»ÀûÓô˹¤¾ßÌìÉúÓÐ˵·þÁ¦µÄµç×ÓÓʼþ£¬½øÐи´ÔӵĴ¹µö¹¥»÷ºÍBEC¹¥»÷¡£
https://slashnext.com/blog/wormgpt-the-generative-ai-tool-cybercriminals-are-using-to-launch-business-email-compromise-attacks/


¾©¹«Íø°²±¸11010802024551ºÅ