IBMÔâµ½¹¥»÷µ¼Ö¿ÆÂÞÀ¶àÖÝHCPF³¬¹ý400ÍòÈ˵ÄÐÅϢй¶
°ä²¼¹¦·ò 2023-08-161¡¢IBMÔâµ½¹¥»÷µ¼Ö¿ÆÂÞÀ¶àÖÝHCPF³¬¹ý400ÍòÈ˵ÄÐÅϢй¶
¾ÝýÌå8ÔÂ14ÈÕ±¨Â·£¬ÃÀ¹ú¿ÆÂÞÀ¶àÖÝÒ½ÁƱ£½¡Õþ²ßÓëÈÚ×ʲ¿(HCPF)Ïò³¬¹ý400ÍòÈË·¢³ö֪ͨ£¬³ÆÊý¾Ýй¶ÊÂÎñÓ°ÏìÁËËûÃǵÄÓ×ÎҺͽ¡È«ÐÅÏ¢¡£HCPF³ÎÇå˵£¬ËûÃǵÄϵͳûÓÐÔâµ½¹¥»÷£¬µ«ÊÇËûÃǵijаüÉÌIBMÔâµ½ÁËÕë¶ÔMOVEitµÄ¹¥»÷¡£6ÔÂ13ÈÕµ÷²é·¢ÏÖ£¬IBMʹÓõÄMOVEitÀûÓÃÉϵIJ¿ÃÅHCPFÎļþÔÚ5ÔÂ28ÈÕ×óÓÒ±»½Ó¼û£¬¹¥»÷Õß¿ÉÄÜÇÔÈ¡ÁËÔ̺¬Ä³Ð©Health First ColoradoºÍCHP+»áÔ±ÐÅÏ¢µÄÎļþ¡£×ܹ²Ó°ÏìÁË4091794ÈË£¬HPCF½«Í¨¹ýExperianΪÊÜÓ°ÏìÓû§ÌṩÁ½ÄêµÄÐÅÓþ¼à¿Ø·þÎñ¡£
https://www.bleepingcomputer.com/news/security/colorado-warns-4-million-of-data-stolen-in-ibm-moveit-breach/
2¡¢Akamai·¢ÏÖÕë¶ÔÔËÐÐMagento 2µÄµçÉÌÆ½Ì¨µÄXurum»î¶¯
AkamaiÔÚ8ÔÂ9ÈÕ³ÆÆä·¢ÏÖÁËÕë¶ÔÔËÐÐMagento 2 CMSµÄµçÉÌÆ½Ì¨µÄ¹¥»÷»î¶¯£¬²¢½«¸Ã»î¶¯¶¨ÃûΪXurum¡£»î¶¯Ê¼ÓÚ1Ô·ݣ¬ÀûÓÃÁËAdobe CommerceºÍMagento Open SourceÖеķþÎñÆ÷¶ËÄ£°å×¢Èë·ì϶£¨CVE-2022-24086£©¡£¹¥»÷ÕßËÆºõ¶ÔÖ¸±êMagentoÉ̵ê´Óǰ10ÌìÄÚËù϶©µ¥µÄ¸¶¿îͳ¼ÆÊý¾Ý¸ÐÐËÖ¡£¹¥»÷»î¶¯Ê¹ÓÃÁËwso-ng£¬ÕâÊÇа汾µÄWSO webshell¡£»î¶¯»¹ÀûÓÃÁ˽ϾɵÄDirty COW·ì϶(CVE-2016-5195)£¬ÒÔ³¢ÊÔÔÚLinuxÖÐÌáȨ¡£ÓÐÖ¤¾ÝÅú×¢¹¥»÷Óë¶íÂÞ˹Óйء£
https://www.akamai.com/blog/security-research/new-sophisticated-magento-campaign-xurum-webshell
3¡¢ÀÕË÷Èí¼þMonti¾íÍÁ³ÁÀ´ÖØÒªÕë¶Ô˾·¨ºÍµ±¾ÖÁìÓò»ú¹¹
8ÔÂ14ÈÕ£¬Trend Micro·¢ÏÖʱ¸ô2¸öÔºóMonti¾íÍÁ³ÁÀ´£¬³Áµã¹Ø×¢Ë¾·¨ºÍµ±¾ÖÁìÓò»ú¹¹¡£Óë´Ëͬʱ£¬»ùÓÚLinuxƽ̨µÄMontiбäÌåÒ²ÒѸ¡³öË®Ãæ£¬Óë֮ǰµÄ°æ±¾ÓÐ×ÅÏÔÖø²î¾à¡£ÒÔǰ°æ±¾ºÜ´óˮƽÉÏ»ùÓÚContiй¶µÄ´úÂ루99%£©£¬µ«Ð¼ÓÃÜ·¨Ê½µÄÀàËÆ¶È½öΪ29%¡£×êÑÐÈËÔ±°µÊ¾£¬Í¨¹ý¶Ô´úÂ루ÓÈÆäÊǼÓÃÜËã·¨£©½øÐдóÁ¿Åú¸Ä£¬MontiÈÆ¹ý¼ì²âµÄÄÜÁ¦µÃµ½Ìá¸ß£¬ÕâÔö³¤Á˼ì²â»ººÍ½â´ËÀà¶ñÒâ»î¶¯µÄÄѶȡ£
https://www.trendmicro.com/en_us/research/23/h/monti-ransomware-unleashes-a-new-encryptor-for-linux.html
4¡¢ZscaleÅû¶Õë¶ÔÀ¶¡ÃÀÖÞ½ðÈڿƼ¼ÐÐÒµµÄJanelaRAT
ZscaleÔÚ8ÔÂ10ÈÕÅû¶ÁËÕë¶ÔÀ¶¡ÃÀÖÞµØÓòµÄ½ðÈڿƼ¼ÐÐÒµµÄJanelaRAT¡£½ØÖÁ6Ô·ݣ¬JanelaRATÖØÒªÕë¶ÔÀ¶¡ÃÀÖÞµØÓòÒøÐкͽðÈÚ»ú¹¹£¬Ö¼ÔÚÇÔÈ¡½ðÈںͼÓÃÜÇ®±ÒÓйØÊý¾Ý£¬²¢ÀûÓÃÀ´×ԺϷ¨ÆðÔ´£¨ÈçVMWareºÍMicrosoft£©µÄDLL²à¼ÓÔØ¼¼ÊõÀ´Èƹý¼ì²â¡£´Ë±í£¬JanelaRATÓµÓд°¿Ú±êÌâ¸ÐÖª»úÔ죬²¢Ñ¡È¡¶¯Ì¬Ì×½Ó×ÖÅäÖÃϵͳ¡£JanelaRATµÄ¿ª·¢Õß¿ÉÄÜ´ÓBX RATµÄ´úÂëÖлñµÃÁËÁé¸Ð£¬µ«Ëü½ö¾ß±¸BX RATÌṩµÄ²¿ÃÅÖ°ÄÜ£¬Ã»Óе¼ÈëshellºÅÁîÖ´ÐеÈÖ°ÄÜ¡£
https://www.zscaler.com/blogs/security-research/janelarat-repurposed-bx-rat-variant-targeting-latam-fintech
5¡¢Kaspersky³Æ´óÁ¿±»ºÚµÄWPÍøÕ¾±»ÓÃÓÚÖ´Ðд¹µö¹¥»÷
¾Ý8ÔÂ14ÈÕ±¨Â·£¬Kaspersky·¢ÏÖ´óÁ¿±»ºÚµÄWordPressÍøÕ¾±»ÓÃÓÚÖ´Ðд¹µö¹¥»÷¡£5ÔÂ15ÈÕµ½7ÔÂ31ÈÕ£¬×êÑÐÈËÔ±·¢ÏÖÁË22400¸öWordPressÍøÕ¾±»ºÚ¿Í¹¥»÷ÒÔ´´½¨´¹µöÒ³Ãæ¡£Í³Ò»Ê±ÆÚÄÚ£¬Óû§×ܹ²³¢ÊÔ½Ó¼û±»Ï°È¾ÍøÕ¾ÉÏÍйܵÄÐéÎ±Ò³Ãæ200213´Î¡£×î³£±»´¹µö¹¥»÷µÄ·þÎñºÍÆóÒµÔ̺¬Netflix¡¢Å·ÖÞµÄÒøÐкͳ£¼ûµÄ¿ìµÝ·þÎñ¡£Kaspersky»¹ÏêÊöÁËÄÄÐ©ÍøÕ¾×îÈÝÒ×Ôâµ½ºÚ¿Í¹¥»÷¡¢ÈôºÎÈëÇÖWordPressÍøÕ¾ÒÔ¼°WordPressÍøÕ¾±»ºÚµÄ¼£ÏóµÈ¡£
https://securelist.com/phishing-with-hacked-sites/110334/
6¡¢Uptycs°ä²¼¹ØÓÚ¶ñÒâÈí¼þQwixxRATµÄ·ÖÎö»ã±¨
8ÔÂ14ÈÕ£¬Uptycs°ä²¼Á˹ØÓÚ¶ñÒâÈí¼þQwixxRATµÄ·ÖÎö»ã±¨¡£×êÑÐÈËÔ±ÓÚ8ÔÂÉÏÑ®·¢ÏÖÁ˸öñÒâÈí¼þ£¬Ëüͨ¹ýTelegramºÍDiscordƽ̨½øÐд«²¼¡£Ã¿Öܶ©ÔÄ·ÑΪ150¬²¼£¬µ«Ò²ÓÐÓÐÏÞµÄÃâ·Ñ°æ±¾¡£Ò»µ©×°Öã¬RAT¾Í»á°ÂÃØÍøÂçÊý¾Ý£¬¶øºó·¢Ë͵½¹¥»÷ÕßµÄTelegram bot¡£ÎªÁËÈÆ¹ýɱ¶¾Èí¼þµÄ¼ì²â£¬RATͨ¹ýTelegram bot½øÐÐC2¡£³ýÁËÇÔÈ¡Êý¾ÝÖ®±í£¬QwixxRAT»¹Õ¼ÓÐ׳´óµÄÔ¶³ÌÖÎÀí¹¤¾ß£¬¿É½ÚÔìÖ¸±êÉ豸ºÍÆô¶¯ºÅÁî¡£
https://www.uptycs.com/blog/remote-access-trojan-qwixx-telegram


¾©¹«Íø°²±¸11010802024551ºÅ