Veeam°ä²¼¸üн¨¸´Veeam ONE¼à¿ØÆ½Ì¨Öжà¸ö·ì϶

°ä²¼¹¦·ò 2023-11-08

1¡¢Veeam°ä²¼¸üн¨¸´Veeam ONE¼à¿ØÆ½Ì¨Öжà¸ö·ì϶


11ÔÂ6ÈÕ£¬Veeam°ä²¼Á˰²È«¸üÐÂÒÔ½¨¸´Veeam ONE IT»ù´¡ÉèÊ©¼à¿ØºÍ·ÖÎöƽ̨ÖеÄ4¸ö·ì϶ ¡£ÆäÖнÏΪÑϳÁµÄÊÇCVE-2023-38547(CVSSÆÀ·Ö9.9)£¬¿ÉÓÃÀ´»ñÈ¡ÓйØVeeam ONEÓÃÓÚ½Ó¼ûÆäÅäÖÃÊý¾Ý¿âµÄSQL·þÎñÆ÷ÏνӵÄÐÅÏ¢£¬¿ÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐУ»ÒÔ¼°CVE-2023-38548£¨CVSSÆÀ·Ö9.8£©£¬¿É»ñÈ¡Veeam ONE Reporting ServiceËùʹÓÃÕÊ»§µÄNTLM¹þÏ£ ¡£Áí±íÁ½¸öÊÇ¿Éͨ¹ýXSS¹¥»÷ÇÔÈ¡ÖÎÀíÔ±ÁîÅÆµÄ·ì϶£¨CVE-2023-38549£©ºÍ¿É½Ó¼ûDashboard ScheduleµÄ·ì϶£¨CVE-2023-41723£© ¡£


https://www.bleepingcomputer.com/news/security/veeam-warns-of-critical-bugs-in-veeam-one-monitoring-platform/


2¡¢ÈÕ±¾º½¿Õµç×Ó¹«Ë¾Ôâµ½AlphVµÄ¹¥»÷ÔËÓªÊܵ½Ó°Ïì


¾Ý11ÔÂ8ÈÕ±¨Â·£¬ÈÕ±¾º½¿Õµç×Ó¹«Ë¾Ð¹Â©£¬ÆäϵͳÔâµ½ÍøÂç¹¥»÷£¬ÍøÕ¾±»ÆÈ¹Ø¹Ø ¡£ÖÜÒ»ÍíÉÏ£¬¸Ã¹«Ë¾µÄÍøÕ¾ÏÔʾÁËÒ»ÌõÐÂÎÅ£¬Åú×¢Æä²¿ÃÅ·þÎñÆ÷ÔÚÉÏÖÜËı»ºÚ ¡£Õâ¼Ò¹«Ë¾°µÊ¾£¬ËûÃÇĿǰÔÚµ÷²éÈëÇÖÇé¿ö²¢¸´Ô­ÔËÓª£¬µ«Ò»Ð©ÏµÍ³ÒѾ­ÖжÏ£¬ÊÕ·¢µç×ÓÓʼþÒ²³öÏÖÁËһЩÑÓÎó£¬ÉÐδ·¢ÏÖÐÅϢй¶ ¡£AlphVÔÚ±¾ÖÜÒ»½«ÈÕ±¾º½¿Õµç×Ó¹«Ë¾²ÎÓëÆäÍøÕ¾£¬µ«¸Ã¹«Ë¾ÉÐδй©ÊÇ·ñÔÚÓ¦¶ÔÀÕË÷¹¥»÷ ¡£


https://therecord.media/japan-aviation-electronics-says-servers-accessed-during-cyberattack


3¡¢Unit 42·¢ÏÖAgriusÕë¶ÔÒÔÉ«ÁнÌÓýºÍ¿Æ¼¼ÐÐÒµµÄ¹¥»÷


Unit 42ÔÚ11ÔÂ6ÈÕ³ÆÆä·¢ÏÖÁËAgriusÕë¶ÔÒÔÉ«ÁнÌÓýºÍ¿Æ¼¼ÐÐÒµµÄ¹¥»÷ ¡£ÕâЩ¹¥»÷´Ó1ÔÂÒ»Ïò³ÖÐøµ½10Ô£¬Ö¼ÔÚÇÔÈ¡PIIºÍ֪ʶ²úȨµÈÃô¸ÐÐÅÏ¢ ¡£Ò»µ©ÇÔÈ¡ÁËÐÅÏ¢£¬¹¥»÷Õ߾ͻá×°Öø÷Àà²Á³ý·¨Ê½£¬À´¸²¸ÇÆä×ÙÓ°²¢Ê¹±»Ï°È¾µÄÖÕ¶ËÎÞ·¨Ê¹Óà ¡£×î½üµÄ¹¥»÷»¹Ê¹ÓõÄ3ÖÖеIJÁ³ý·¨Ê½£¬MultiLayer Wiper¡¢PartialWasherºÍBFG Agonizer Wiper£¬ÒÔ¼°Ò»¸ö´ÓÊý¾Ý¿â·þÎñÆ÷ÌáÊØÐÅÏ¢µÄ×Ô½ç˵¹¤¾ßSqlextractor ¡£


https://unit42.paloaltonetworks.com/agonizing-serpens-targets-israeli-tech-higher-ed-sectors/


4¡¢Google³Æ¶à¸öÍÅ»ïÊÔͼ½«ÆäÈÕÀú·þÎñÓÃ×÷C2»ù´¡ÉèÊ©


¾ÝýÌå11ÔÂ6ÈÕ±¨Â·£¬GoogleÌáÐѶà¸ö¹¥»÷ÍÅ»ïÔÚ¹²ÏíÒ»¸öÃûΪGoogle Calendar RAT(GCR)µÄPoC£¬ËüÀûÓÃÈÕÀú·þÎñÀ´ÍйܺÅÁîºÍ½ÚÔ죨C2£©»ù´¡ÉèÊ© ¡£Æä¿ª·¢Õß°µÊ¾£¬¸Ã¾ç±¾Í¨¹ýÀûÓÃGoogleÈÕÀúÖеÄÊÂÎñÃèÊö´´½¨ÁËÒ»¸ö¡°Òñ±Îͨ·¡±£¬Ö¸±ê½«Ö±½ÓÏνӵ½Google ¡£Google³ÆÉÐδ·¢ÏÖGCRÔÚÒ°±íµÄʹÓÃÇé¿ö£¬µ«Mandiant°ÑÎȵ½¶à¸öÍÅ»ïÔÚºÚ¿ÍÂÛ̳ÉÏ·ÖÏíÁËPoC£¬Õâ˵ÁËÈ»ËûÃǶÔÀÄÓÃÔÆ·þÎñ¸ÐÐËÖ ¡£


https://securityaffairs.com/153700/hacking/google-calendar-rat-attacks.html


5¡¢VMwareÅû¶JupyterбäÌåÔÚ½üÆÚ¼¤ÔöµÄ¹¥»÷»î¶¯


VMwareÔÚ11ÔÂ6ÈÕÅû¶ÁËJupyter Infostealer±äÌåÐÂÒ»ÂֵĹ¥»÷»î¶¯ ¡£¸Ã¶ñÒâÈí¼þÓÚ2020Äêµ×³õ´Î±»·¢ÏÖ£¬ÖØÒªÕë¶Ô½ÌÓýºÍÎÀÉú²¿ÃÅ ¡£´ÓǰÁ½ÖÜ£¬×êÑÐÈËÔ±¹Û²ìµ½µÄJupyter InfostealerϰȾÊýÁ¿Öð²½ÉÏÉý£¬Ä¿Ç°Ï°È¾×ÜÊýΪ26Àý ¡£ËüÕë¶ÔChrome¡¢EdgeºÍFirefoxä¯ÀÀÆ÷£¬ÀûÓÃSEOÖж¾ºÍËÑË÷ÒýÇæ³Á¶¨ÀúÀ´´«²¼ ¡£ÐÂÒ»ÂֵĹ¥»÷ÀûÓÃÁËPowerShellºÅÁîÀ´Åú¸ÄºÍÊðÃû˽Կ£¬ÊÔͼ½«¶ñÒâÈí¼þ¼ÙÒâΪºÏ·¨ÊðÃûµÄÎļþ ¡£


https://blogs.vmware.com/security/2023/11/jupyter-rising-an-update-on-jupyter-infostealer.html


6¡¢Kaspersky°ä²¼2023ÄêÓëÓÎÏ·ÓйصÄÍøÂçÍþвµÄ»ã±¨


11ÔÂ6ÈÕ£¬Kaspersky°ä²¼ÁË2023ÄêÓëÓÎÏ·ÓйصÄÍøÂçÍþвµÄ·ÖÎö»ã±¨ ¡£¸Ã»ã±¨·ÖÎöÁË2022Äê7ÔÂ1ÈÕÖÁ2023Äê7ÔÂ1ÈÕÆÚ¼äÍøÂçµÄÊý¾Ý ¡£»ã±¨Ö¸³ö£¬Kaspersky×ܹ²¼ì²âµ½4076530´ÎÓëÓÎÏ·ÓйصÄ×ÀÃæÏ°È¾³¢ÊÔ£¬Ó°ÏìÁËÈ«Çò192456ÃûÓÎÏ·Íæ¼Ò ¡£×î³£¼ûµÄÍþвÊÇÏÂÔØ·¨Ê½£¨89.70%£©£¬Æä´ÎÊǸæ°×Èí¼þ£¨5.25%£©ºÍľÂí£¨2.39%£© ¡£×î³£±»ÓÃ×÷µö¶üµÄÊÇÎÒµÄÊÀ½ç£¨70.29%£©£¬Æä´ÎÊÇRoblox£¨20.37%£©¡¢·´¿Ö¾«Ó¢£ºÈ«Çò¹¥ÊÆ£¨4.78%£©ºÍ¾øµØÇóÉú£¨2.85%£© ¡£


https://securelist.com/game-related-threat-report-2023/110960/