΢Èí°ä²¼11Ô°²È«¸üн¨¸´3¸öÒѱ»ÀûÓõķì϶

°ä²¼¹¦·ò 2023-11-15
1¡¢Î¢Èí°ä²¼11Ô°²È«¸üн¨¸´3¸öÒѱ»ÀûÓõķì϶


΢ÈíÔÚ11ÔÂ14ÈÕ°ä²¼Á˱¾ÔµÄÖܶþ²¹¶¡ £¬×ܼƽ¨¸´ÁË58¸ö·ì϶ £¬Ô̺¬5¸ö0day  ¡£Õâ´Î½¨¸´µÄ0dayÖÐ £¬WindowsÔÆÎļþ΢ÐÍɸѡÆ÷Çý¶¯·¨Ê½ÌáȨ·ì϶£¨CVE-2023-36036£©¡¢Windows DWMÖ÷Ìâ¿âÌáȨ·ì϶£¨CVE-2023-36033£©ºÍWindows SmartScreen°²È«Ö°ÄÜÈÆ¹ý·ì϶£¨CVE-2023-36025£©Òѱ»ÀûÓà £¬Microsoft Office°²È«Ö°ÄÜÈÆ¹ý·ì϶£¨CVE-2023-36413£©ºÍASP.NET Core»Ø¾ø·þÎñ·ì϶£¨CVE-2023-36038£©Ò²Òѱ»¹«¿ªÅû¶  ¡£


https://www.bleepingcomputer.com/news/microsoft/microsoft-november-2023-patch-tuesday-fixes-5-zero-days-58-flaws/


2¡¢SektorCERTÅû¶µ¤ÂóµÄ»ù´¡ÉèÊ©Ôâµ½´ó¹æÄ£¹¥»÷


¾Ý11ÔÂ14ÈÕ±¨Â· £¬µ¤Â󹨼ü²¿ÃŵķÇͶ»úÍøÂ簲ȫÖÐÐÄSektorCERTÅû¶ £¬Æä¹Ø¼ü»ù´¡ÉèÊ©Ôâµ½ÁËÓÐÊ·ÒÔÀ´×î´ó¹æÄ£µÄÍøÂç¹¥»÷  ¡£µÚÒ»²¨¹¥»÷ÓÚ5ÔÂ11ÈÕÌáÒé £¬¶ÌÔÝͣϢºó £¬µÚ¶þ²¨¹¥»÷ÓÚ5ÔÂ22ÈÕÆðÍ· £¬SektorCERTÓÚ5ÔÂ22ÈÕÒâʶµ½ÕâЩ¹¥»÷  ¡£¹¥»÷ÕßÀûÓÃZyxel·À»ðǽÖеķì϶£¨CVE-2023-28771£© £¬ÈëÇÖÁË22¼Ò´ÓÊÂÄÜÔ´»ù´¡ÉèÊ©ÔËÓªµÄ¹«Ë¾  ¡£SektorCERTÒÔΪ £¬¹¥»÷Õß°ÑÎÕÁËÖ¸±êµÄ¾ßÌåÐÅÏ¢ £¬ºÜ¿ÉÄÜÊÇͨ¹ý֮ǰδ±»·¢ÏֵĿúËÅ»î¶¯ÍøÂçµÄ  ¡£²¢ÇÒÕâЩ¹¥»÷¿ÉÄÜÊǶà¸öÍÅ»ïÖ´ÐеÄ £¬ÆäÖÐÖÁÉÙÓÐÒ»¸ö¿É¹éÒòÓÚSandworm  ¡£


https://securityaffairs.com/154156/apt/denmark-critical-infrastructure-record-attacks.html


3¡¢RoyalÒÑÈëÇÖÖÁÉÙ350¸öÖ¸±ê²¢ÀÕË÷³¬¹ý2.75ÒÚÃÀÔª


11ÔÂ13ÈÕ £¬FBIºÍCISA°ä²¼Á˹ØÓÚÀÕË÷Èí¼þRoyalµÄ½áºÏÍøÂ簲ȫÕ÷ѯ(CSA)  ¡£¸ÃÕ÷ѯָ³ö £¬×Ô2022Äê9ÔÂÒÔÀ´ £¬RoyalÒѹ¥»÷È«Çò350¶à¸öÖ¸±ê £¬Ìá³öÁ˳¬¹ý2.75ÒÚÃÀÔªµÄÀÕË÷ÒªÇó  ¡£´¹µöÓʼþÊÇRoyal½øÐгõʼ½Ó¼ûµÄ×î³É¹¦µÄÔØÌåÖ®Ò»  ¡£Óм£ÏóÅú×¢ £¬Royal¿ÉÄÜÔÚ뻮ၮ³ÁËܺÍ/»òÑÜÉú±äÌå×ö³ï±¸ £¬ÀÕË÷Èí¼þBlacksuitÓµÓкܶàÓëRoyalÀàËÆµÄ±àÂëÌØµã  ¡£


https://www.bleepingcomputer.com/news/security/fbi-royal-ransomware-asked-350-victims-to-pay-275-million/


4¡¢HuntersÐû³ÆÒÑÍøÂçHomeland¹«Ë¾³¬¹ý200GBµÄÊý¾Ý


¾ÝýÌå11ÔÂ13ÈÕ±¨Â· £¬Hunters International½«ÃÀ¹úÎïÒµÖÎÀí¹«Ë¾HomelandÔö³¤µ½ÁËÆäÍøÕ¾ÖÐ  ¡£¹¥»÷ÕßÐû³ÆÒÑÍøÂç183793¸öÎļþ £¬¹²204.1GB £¬»¹ÔÚÍøÕ¾Éϰ䲼ÁËÒ»·ÝÎļþÑù±¾×÷ΪÀÕË÷Ö¤¾Ý  ¡£Ñù±¾ÎļþÔ̺¬×â»§µÄµ®ÉúÈÕÆÚ¡¢µØÖ·¡¢ÄêÊÕÈëºÍ×â½ð¾ßÌåÐÅÏ¢µÈÓ×ÎÒÐÅÏ¢  ¡£Huntersй©¹¥»÷²úÉúÓÚ10ÔÂ26ÈÕ £¬ËûÃÇÂú×ãHomelandµÄÒªÇóÌṩ½âÃܹ¤¾ßÑÝʾºÍй¶Êý¾ÝÑù±¾ºóûÓÐÊÕµ½Èκλظ´ £¬»¹°µÊ¾¸Ã¹«Ë¾±ØÒªÔÚ11ÔÂ18ÈÕ֮ǰ×ö³ö»ØÓ¦  ¡£


https://www.databreaches.net/property-management-firm-homeland-inc-allegedly-hacked-hackers-claim-to-have-hundreds-of-thousands-of-ssn-of-tenants/


5¡¢AhnLab¼ì²âµ½ÀûÓÃDdostf¹¥»÷MySQL·þÎñÆ÷µÄ»î¶¯


AhnLabÓÚ11ÔÂ14ÈÕ³Æ £¬×î½ü·¢´Ë¿ÌMySQL·þÎñÆ÷ÉÏ×°ÖÃDdostfµÄ»î¶¯  ¡£DDdostfÊÇÒ»ÖÖDDoS bot £¬¶ÔÌØ¶¨Ö¸±êÖ´ÐÐDDoS¹¥»÷ £¬ÓÚ2016Äê×óÓÒ³õ´Î±»·¢ÏÖ  ¡£Ôڿɹ«¿ª½Ó¼ûµÄϵͳÖÐ £¬É¨Ã跨ʽ»áËÑË÷ʹÓÃ3306/TCP¶Ë¿ÚµÄϵͳ £¬¶øºóÖ´Ðб©Á¦¹¥»÷»ò×ֵ乥»÷ £¬»¹¿ÉÄܽӼûÖÎÀíÔ¹ØÊ»§Í´´¦  ¡£ÈôÊÇϵͳÔËÐеÄÊÇ´æÔÚ·ì϶µÄ佨¸´°æ±¾ £¬¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶À´Ö´ÐкÅÁî £¬¶øÎÞÐèÉÏÊö¹ý³Ì  ¡£Ö¸±êϵͳµÄϰȾÈÕÖ¾Åú×¢ £¬³ýÁËDdostfÖ®±í £¬Ö¸±êϵͳÉÏ»¹±»×°ÖÃÁ˶ñÒâUDF DLL  ¡£


https://asec.ahnlab.com/en/58878/


6¡¢Cado·¢ÏÖÕë¶ÔDocker Engine APIµÄ½©Ê¬ÍøÂçOracleIV 


11ÔÂ13ÈÕ £¬CadoÅû¶ÁË×î½ü·¢ÏÖµÄһ·Õë¶Ô¹«¿ªDocker Engine APIÊ·ýµÄл  ¡£Ôڴ˻ÖÐ £¬¹¥»÷ÕßÀûÓÃDockerÈÝÆ÷ÖеÄÃýÎóÅäÖÃÀ´´«²¼±àÒëΪELF¿ÉÖ´ÐÐÎļþµÄPython¶ñÒâÈí¼þ  ¡£¸Ã¶ñÒâÈí¼þ×ÔÉí³äÈÎDDoS bot´úÀí £¬¿ÉÄÜͨ¹ý¶àÖÖ²½Öè½øÐÐDoS¹¥»÷  ¡£ÔÚеÄOracleIV DDoS½©Ê¬ÍøÂç¶ñÒâÈí¼þÖÐ £¬¹¥»÷Õßͨ¹ýHTTP POSTÒªÇóÆô¶¯¶ÔDocker APIµÄ½Ó¼û  ¡£Õâ»á´¥·¢docker pullºÅÁî £¬´ÓDockerhub»ñȡָ¶¨¾µÏñ  ¡£


https://www.cadosecurity.com/oracleiv-a-dockerised-ddos-botnet/