IBMÔâµ½¹¥»÷µ¼Ö¿ÆÂÞÀ­¶àÖÝHCPF³¬¹ý400ÍòÈ˵ÄÐÅϢй¶

°ä²¼¹¦·ò 2023-08-16

1¡¢IBMÔâµ½¹¥»÷µ¼Ö¿ÆÂÞÀ­¶àÖÝHCPF³¬¹ý400ÍòÈ˵ÄÐÅϢй¶


¾ÝýÌå8ÔÂ14ÈÕ±¨Â· £¬ÃÀ¹ú¿ÆÂÞÀ­¶àÖÝÒ½ÁƱ£½¡Õþ²ßÓëÈÚ×ʲ¿(HCPF)Ïò³¬¹ý400ÍòÈË·¢³ö֪ͨ £¬³ÆÊý¾Ýй¶ÊÂÎñÓ°ÏìÁËËûÃǵÄÓ×ÎҺͽ¡È«ÐÅÏ¢¡£HCPF³ÎÇå˵ £¬ËûÃǵÄϵͳûÓÐÔâµ½¹¥»÷ £¬µ«ÊÇËûÃǵijаüÉÌIBMÔâµ½ÁËÕë¶ÔMOVEitµÄ¹¥»÷¡£6ÔÂ13ÈÕµ÷²é·¢ÏÖ £¬IBMʹÓõÄMOVEitÀûÓÃÉϵIJ¿ÃÅHCPFÎļþÔÚ5ÔÂ28ÈÕ×óÓÒ±»½Ó¼û £¬¹¥»÷Õß¿ÉÄÜÇÔÈ¡ÁËÔ̺¬Ä³Ð©Health First ColoradoºÍCHP+»áÔ±ÐÅÏ¢µÄÎļþ¡£×ܹ²Ó°ÏìÁË4091794ÈË £¬HPCF½«Í¨¹ýExperianΪÊÜÓ°ÏìÓû§ÌṩÁ½ÄêµÄÐÅÓþ¼à¿Ø·þÎñ¡£


https://www.bleepingcomputer.com/news/security/colorado-warns-4-million-of-data-stolen-in-ibm-moveit-breach/


2¡¢Akamai·¢ÏÖÕë¶ÔÔËÐÐMagento 2µÄµçÉÌÆ½Ì¨µÄXurum»î¶¯


AkamaiÔÚ8ÔÂ9ÈÕ³ÆÆä·¢ÏÖÁËÕë¶ÔÔËÐÐMagento 2 CMSµÄµçÉÌÆ½Ì¨µÄ¹¥»÷»î¶¯ £¬²¢½«¸Ã»î¶¯¶¨ÃûΪXurum¡£»î¶¯Ê¼ÓÚ1Ô·Ý £¬ÀûÓÃÁËAdobe CommerceºÍMagento Open SourceÖеķþÎñÆ÷¶ËÄ£°å×¢Èë·ì϶£¨CVE-2022-24086£©¡£¹¥»÷ÕßËÆºõ¶ÔÖ¸±êMagentoÉ̵ê´Óǰ10ÌìÄÚËù϶©µ¥µÄ¸¶¿îͳ¼ÆÊý¾Ý¸ÐÐËÖ¡£¹¥»÷»î¶¯Ê¹ÓÃÁËwso-ng £¬ÕâÊÇа汾µÄWSO webshell¡£»î¶¯»¹ÀûÓÃÁ˽ϾɵÄDirty COW·ì϶(CVE-2016-5195) £¬ÒÔ³¢ÊÔÔÚLinuxÖÐÌáȨ¡£ÓÐÖ¤¾ÝÅú×¢¹¥»÷Óë¶íÂÞ˹ÓйØ¡£ 


https://www.akamai.com/blog/security-research/new-sophisticated-magento-campaign-xurum-webshell


3¡¢ÀÕË÷Èí¼þMonti¾íÍÁ³ÁÀ´ÖØÒªÕë¶Ô˾·¨ºÍµ±¾ÖÁìÓò»ú¹¹


8ÔÂ14ÈÕ £¬Trend Micro·¢ÏÖʱ¸ô2¸öÔºóMonti¾íÍÁ³ÁÀ´ £¬³Áµã¹Ø×¢Ë¾·¨ºÍµ±¾ÖÁìÓò»ú¹¹¡£Óë´Ëͬʱ £¬»ùÓÚLinuxƽ̨µÄMontiбäÌåÒ²ÒѸ¡³öË®Ãæ £¬Óë֮ǰµÄ°æ±¾ÓÐ×ÅÏÔÖø²î¾à¡£ÒÔǰ°æ±¾ºÜ´óˮƽÉÏ»ùÓÚContiй¶µÄ´úÂ루99%£© £¬µ«Ð¼ÓÃÜ·¨Ê½µÄÀàËÆ¶È½öΪ29%¡£×êÑÐÈËÔ±°µÊ¾ £¬Í¨¹ý¶Ô´úÂ루ÓÈÆäÊǼÓÃÜËã·¨£©½øÐдóÁ¿Åú¸Ä £¬MontiÈÆ¹ý¼ì²âµÄÄÜÁ¦µÃµ½Ìá¸ß £¬ÕâÔö³¤Á˼ì²â»ººÍ½â´ËÀà¶ñÒâ»î¶¯µÄÄѶÈ¡£


https://www.trendmicro.com/en_us/research/23/h/monti-ransomware-unleashes-a-new-encryptor-for-linux.html


4¡¢ZscaleÅû¶Õë¶ÔÀ­¶¡ÃÀÖÞ½ðÈڿƼ¼ÐÐÒµµÄJanelaRAT


ZscaleÔÚ8ÔÂ10ÈÕÅû¶ÁËÕë¶ÔÀ­¶¡ÃÀÖÞµØÓòµÄ½ðÈڿƼ¼ÐÐÒµµÄJanelaRAT¡£½ØÖÁ6Ô·Ý £¬JanelaRATÖØÒªÕë¶ÔÀ­¶¡ÃÀÖÞµØÓòÒøÐкͽðÈÚ»ú¹¹ £¬Ö¼ÔÚÇÔÈ¡½ðÈںͼÓÃÜÇ®±ÒÓйØÊý¾Ý £¬²¢ÀûÓÃÀ´×ԺϷ¨ÆðÔ´£¨ÈçVMWareºÍMicrosoft£©µÄDLL²à¼ÓÔØ¼¼ÊõÀ´Èƹý¼ì²â¡£´Ë±í £¬JanelaRATÓµÓд°¿Ú±êÌâ¸ÐÖª»úÔì £¬²¢Ñ¡È¡¶¯Ì¬Ì×½Ó×ÖÅäÖÃϵͳ¡£JanelaRATµÄ¿ª·¢Õß¿ÉÄÜ´ÓBX RATµÄ´úÂëÖлñµÃÁËÁé¸Ð £¬µ«Ëü½ö¾ß±¸BX RATÌṩµÄ²¿ÃÅÖ°ÄÜ £¬Ã»Óе¼ÈëshellºÅÁîÖ´ÐеÈÖ°ÄÜ¡£


https://www.zscaler.com/blogs/security-research/janelarat-repurposed-bx-rat-variant-targeting-latam-fintech


5¡¢Kaspersky³Æ´óÁ¿±»ºÚµÄWPÍøÕ¾±»ÓÃÓÚÖ´Ðд¹µö¹¥»÷


¾Ý8ÔÂ14ÈÕ±¨Â· £¬Kaspersky·¢ÏÖ´óÁ¿±»ºÚµÄWordPressÍøÕ¾±»ÓÃÓÚÖ´Ðд¹µö¹¥»÷¡£5ÔÂ15ÈÕµ½7ÔÂ31ÈÕ £¬×êÑÐÈËÔ±·¢ÏÖÁË22400¸öWordPressÍøÕ¾±»ºÚ¿Í¹¥»÷ÒÔ´´½¨´¹µöÒ³Ãæ¡£Í³Ò»Ê±ÆÚÄÚ £¬Óû§×ܹ²³¢ÊÔ½Ó¼û±»Ï°È¾ÍøÕ¾ÉÏÍйܵÄÐéÎ±Ò³Ãæ200213´Î¡£×î³£±»´¹µö¹¥»÷µÄ·þÎñºÍÆóÒµÔ̺¬Netflix¡¢Å·ÖÞµÄÒøÐкͳ£¼ûµÄ¿ìµÝ·þÎñ¡£Kaspersky»¹ÏêÊöÁËÄÄÐ©ÍøÕ¾×îÈÝÒ×Ôâµ½ºÚ¿Í¹¥»÷¡¢ÈôºÎÈëÇÖWordPressÍøÕ¾ÒÔ¼°WordPressÍøÕ¾±»ºÚµÄ¼£ÏóµÈ¡£


https://securelist.com/phishing-with-hacked-sites/110334/


6¡¢Uptycs°ä²¼¹ØÓÚ¶ñÒâÈí¼þQwixxRATµÄ·ÖÎö»ã±¨


8ÔÂ14ÈÕ £¬Uptycs°ä²¼Á˹ØÓÚ¶ñÒâÈí¼þQwixxRATµÄ·ÖÎö»ã±¨¡£×êÑÐÈËÔ±ÓÚ8ÔÂÉÏÑ®·¢ÏÖÁ˸öñÒâÈí¼þ £¬Ëüͨ¹ýTelegramºÍDiscordƽ̨½øÐд«²¼¡£Ã¿Öܶ©ÔÄ·ÑΪ150¬²¼ £¬µ«Ò²ÓÐÓÐÏÞµÄÃâ·Ñ°æ±¾¡£Ò»µ©×°Öà £¬RAT¾Í»á°ÂÃØÍøÂçÊý¾Ý £¬¶øºó·¢Ë͵½¹¥»÷ÕßµÄTelegram bot¡£ÎªÁËÈÆ¹ýɱ¶¾Èí¼þµÄ¼ì²â £¬RATͨ¹ýTelegram bot½øÐÐC2¡£³ýÁËÇÔÈ¡Êý¾ÝÖ®±í £¬QwixxRAT»¹Õ¼ÓÐ׳´óµÄÔ¶³ÌÖÎÀí¹¤¾ß £¬¿É½ÚÔìÖ¸±êÉ豸ºÍÆô¶¯ºÅÁî¡£


https://www.uptycs.com/blog/remote-access-trojan-qwixx-telegram