×êÑÐÈËÔ±Åû¶SolarWinds ARM²úÆ·Öжà¸ö·ì϶µÄÏêÇé

°ä²¼¹¦·ò 2023-10-24

1¡¢×êÑÐÈËÔ±Åû¶SolarWinds ARM²úÆ·Öжà¸ö·ì϶µÄÏêÇé


¾ÝýÌå10ÔÂ20ÈÕ±¨Â· £¬×êÑÐÈËÔ±³ÆÆäÔÚSolarWinds Access Rights Manager(ARM)²úÆ·Öз¢ÏÖÁË3¸öÔ¶³Ì´úÂëÖ´Ðзì϶ ¡£ÕâЩ·ì϶±ðÀëÊÇcreateGlobalServerChannelInternalÖв»³ÉÐÅÊý¾ÝµÄ·´ÐòÁл¯·ì϶£¨CVE-2023-35182£©¡¢ OpenFileÖжÔÓû§Ìṩõè¾¶ÑéÖ¤²»×ãµÄ·ì϶£¨CVE-2023-35185£©ÒÔ¼°OpenClientUpdateFileÖжÔÓû§Ìṩõè¾¶ÑéÖ¤²»×ãµÄ·ì϶£¨CVE-2023-35187£© ¡£ËüÃǵÄCVSSÆÀ·Ö¾ùΪ9.8 £¬ÒÑÓÚ10ÔÂ18ÈÕ½¨¸´ ¡£


https://www.bleepingcomputer.com/news/security/critical-rce-flaws-found-in-solarwinds-access-audit-solution/


2¡¢ÃÀ¹úÃÜЪ¸ù´óѧÔâµ½¹¥»÷ѧÉúºÍ¹¤×÷ÈËÔ±µÄÐÅϢй¶


¾Ý10ÔÂ23ÈÕ±¨Â· £¬ÃÜЪ¸ù´óѧй© £¬ºÚ¿ÍÔÚ8Ô·ÝÈëÇÔìäϵͳ²¢½Ó¼ûÁËÔ̺¬Ñ§Éú¡¢ÉêÇëÈË¡¢Ð£ÓÑ¡¢¾è¿îÈË¡¢Ô±¹¤¡¢»¼ÕߺÍ×êÑвμÓÕßµÄÐÅÏ¢ ¡£Î´¾­ÊÚȨµÄ½Ó¼û²úÉúÓÚ8ÔÂ23ÈÕÖÁ27ÈÕ £¬ÔÚ¼ì²âµ½¿ÉÒɻºó £¬¸ÃѧÌõ±¼´¶Â½ØÁËÕû¸öУ԰µÄÍøÂç £¬ÒÔ¾¡Á¿¼õÇáÓ°Ïì ¡£Õâ´ÎÊÂÎñ²»½öй¶ÁËÓ×ÎÒÐÅÏ¢ £¬»¹Ð¹Â¶Á˲ÆÕþºÍÒ½ÁƾßÌåÐÅÏ¢ ¡£Ä¿Ç° £¬ÃÜЪ¸ù´óѧÒÑ֪ͨËùÓÐÊÜÓ°ÏìµÄÓ×ÎÒ £¬²¢½«ÎªËûÃÇÌṩÃâ·ÑÐÅÓþ¼à¿Ø·þÎñ ¡£


https://www.bleepingcomputer.com/news/security/university-of-michigan-employee-student-data-stolen-in-cyberattack/


3¡¢FacebookºÍInstagramÓë·¨Âɲ¿ÃÅÁª¶¯µÄÕ˺ű»ÏúÊÛ


ýÌå10ÔÂ21ÈÕ³Æ £¬ºÚ¿ÍÔÚ°µÍøÏúÊÛFacebookºÍInstagramµÄPolice PortalµÄ½Ó¼ûȨÏÞ ¡£¸ÃÃÅ»§¿É±»·¨ÂÉ»ú¹¹ÓÃÓÚÒªÇóÓëÓû§ÓйصÄÊý¾Ý£¨IP¡¢µç»°¡¢Ë½ÐźÍÉ豸ÐÅÏ¢£©»òÒªÇóɾ³ýÌû×ӺͽûÓÃÕÊ»§ ¡£¹¥»÷ÕßÒÔ700ÃÀÔªµÄ¼ÛÖµÌṩ½Ó¼ûȨÏÞ £¬²¢ÇÒËÆºõÕ¼Óв»Ö¹Ò»¸öÃÅ»§µÄÕË»§ ¡£×êÑÐÈËÔ±´§Ä¦ £¬ÒªÃ´ÊÇMetaÔâµ½ÁËÉ繤¹¥»÷µ¼Ö½ӼûȨÏÞй¶ £¬ÒªÃ´¾ÍÊǹ¥»÷ÕßÕ¼ÓкϷ¨µÄ·¨ÂÉÕÊ»§µÄÍ´´¦ ¡£


https://securityaffairs.com/152811/cyber-crime/facebook-and-instagrams-police-portal-access.html


4¡¢Cadre ServicesÔ¼100GBÊý¾Ýй¶²¢±»ÀÕË÷30ÍòÃÀÔª


10ÔÂ19ÈÕ±¨Â·³Æ £¬AlphVÐû³Æ¹¥»÷Á˾ÍÒµºÍÈËÊ·þÎñCadre Services²¢ÒÑÇÔÈ¡100 GBµÄÎļþ ¡£¹¥»÷ÍÅ»ïÔÚ9ÔÂ19ÈÕ³õ´ÎÁªÏµÁËCadre £¬²¢ÓÚ9ÔÂ22ÈÕÊÕµ½»Ø¸´ ¡£½»ÉæµÄ̸Ìì½ØÍ¼ÏÔʾ £¬AlphVÒªÇó30ÍòÃÀÔªÊê½ð £¬¸Ã¹«Ë¾×î³õ°µÊ¾Ô¸Òâ³ö¼Û25000ÃÀÔª £¬²¢³Æ×î¸ß±¨¼ÛΪ35000ÃÀÔª ¡£×î½ü¼¸ÈÕ £¬AlphVÔÙ´ÎÏò¸Ã¹«Ë¾ £¬ÒÔ¼°¿Í»§ºÍDataBreaches·¢ËÍÓʼþ £¬ÌṩÁ˽«ÒªÐ¹Â¶µÄÊý¾ÝµÄÑù±¾ £¬Ô̺¬Ô±¹¤Êý¾ÝºÍÉêÇëÈËÊý¾Ý ¡£


https://www.databreaches.net/another-small-firm-suffers-a-serious-ransomware-attack-cadre-services-gets-mauled-by-alphv/


5¡¢WithSecure·¢ÏÖÕë¶ÔÓ¢ÃÀµÈ¹úµÄDarkGate¹¥»÷»î¶¯


10ÔÂ20ÈÕ £¬WithSecureÅû¶ÁËÕë¶ÔÓ¢¹ú¡¢ÃÀ¹úºÍÓ¡¶ÈµÄDarkGate¹¥»÷»î¶¯ ¡£¸Ã»î¶¯ÓëÈ¥Äê³õ´Î·¢ÏÖµÄDucktail»î¶¯µÄÔ½ÄϹ¥»÷ÕßÓйØ £¬³õʼϰȾý½éÊÇLinkedInÐÂÎźÍÓ²¼þÔì×÷ÉÌCorsairµÄFacebook¸æ°×רԱְλ £¬»á½«Ö¸±ê³Á¶¨Ïòµ½Google DriveÉÏÍйܵÄÎļþ ¡£ÏÂÔØµÄÎĵµÔ̺¬Ò»¸öVBS¾ç±¾ £¬¿ÉÄÜǶÈëÔÚDOCXÎļþÖÐ £¬»áÏÂÔØautoit3.exeºÍÒ»¸ö±àÒëºóµÄAutoit3¾ç±¾ ¡£¿ÉÖ´ÐÐÎļþºó»áÀûÓþ籾ÖеÄ×Ö·û´®»ú¹ØDarkGate £¬×°ÖÃÈýÊ®Ãëºó £¬¶ñÒâÈí¼þ»á³¢ÊÔ´ÓÖ¸±êϵͳÖÐÐ¶ÔØ°²È«²úÆ· ¡£


https://labs.withsecure.com/publications/darkgate-malware-campaign


6¡¢Fortinet°ä²¼¶ñÒâÈí¼þExelaStealerµÄ·ÖÎö»ã±¨


10ÔÂ19ÈÕ £¬Fortinet°ä²¼Á˹ØÓÚ¶ñÒâÈí¼þExelaStealerµÄ·ÖÎö»ã±¨ ¡£ExelaStealerÊÇÒ»¸ö¸ù»ùÉÏ¿ªÔ´µÄÐÅÏ¢ÇÔÈ¡·¨Ê½ £¬Äܹ»Ìṩ¸¶·Ñ¶¨Ôì·þÎñ ¡£Æä¸¶·Ñ°æ±¾Ã¿ÔÂ20ÃÀÔª £¬Èý¸öÔÂ45ÃÀÔª £¬Æ½Éú°æ±¾120ÃÀÔª ¡£ËüÓÉPython¿ª·¢²¢Ö§³ÖJavaScript £¬ÓµÓÐÇÔÈ¡ÃÜÂë¡¢DiscordÁîÅÆ¡¢ÐÅÓþ¿¨¡¢cookieºÍ»á»°Êý¾Ý¡¢»÷¼ü¡¢ÆÁÄ»½ØÍ¼ºÍ¼ôÌù°åÄÚÈݵÄÖ°ÄÜ ¡£ExelaStealer¿ÉÄÜÊÇͨ¹ý¼Ù×°³ÉPDFÎĵµµÄ¿ÉÖ´ÐÐÎļþ½øÐзַ¢µÄ £¬Æô¶¯¶þ½øÔìÎļþºó £¬»áÏÔʾһ·ÝÒýÓÕÎļþ £¬Í¬Ê±ÔÚºó¶Ü͵͵Æô¶¯ÇÔÈ¡·¨Ê½ ¡£


https://www.fortinet.com/blog/threat-research/exelastealer-infostealer-enters-the-field