Ð嵀 SSH-Snake ¶ñÒâÈí¼þÇÔÈ¡ SSH ÃÜÔ¿¿ÉÔÚÄÚÍøºáÏòÒÆ¶¯

°ä²¼¹¦·ò 2024-02-23

1. Ð嵀 SSH-Snake ¶ñÒâÈí¼þÇÔÈ¡ SSH ÃÜÔ¿¿ÉÔÚÄÚÍøºáÏòÒÆ¶¯


2ÔÂ21ÈÕ£¬ÍþвÐÐΪÕßÔÚʹÓÃÃûΪ SSH-Snake µÄ¿ªÔ´ÍøÂçÓ³É乤¾ßÀ´Ñ°ÕÒδ±»¼ì²âµ½µÄ˽Կ£¬²¢ÔÚÊܺ¦Õß»ù´¡ÉèÊ©ÉϺáÏòÒÆ¶¯¡£SSH-Snake ÊÇÓÉ Sysdig Íþв×êÑÐÍÅ¶Ó (TRT) ·¢Ïֵģ¬ËûÃǽ«ÆäÃèÊöΪһÖÖ¡°×ÔÎÒÅú¸ÄÈ䳿¡±£¬Ëüͨ¹ýÔ¤·Àͨ³£Óë¾ç±¾¹¥»÷ÓйصÄģʽ¶ø´Ó´«Í³ SSH È䳿ÖÐÍÑÓ±¶ø³ö¡£¸ÃÈ䳿ÔÚ¸÷¸öµØÎ»£¨Ô̺¬ shell º¹ÇàÎļþ£©ËÑË÷˽Կ£¬²¢ÔÚÓ³ÉäÍøÂçºóʹÓÃËüÃǰÂÃØ´«²¼µ½ÐÂϵͳ¡£SSH-Snake¿É×÷ΪһÖÖ¿ªÔ´×ʲú£¬ÓÃÓÚ»ùÓÚ SSH µÄ×Ô¶¯»¯ÍøÂç±éÀú£¬ËüÄܹ»´ÓÒ»¸öϵͳÆðÍ·£¬²¢ÏÔʾÓëͨ¹ý SSH ÏÎ½ÓµÄÆäËûÖ÷»úµÄ¹ØÏµ¡£SSH-Snake µÄÒ»¸öÌØÊâÐÔÊÇ¿ÉÄÜÔÚµÚÒ»´ÎÔËÐÐʱ½øÐÐ×ÔÎÒÅú¸Ä²¢Ê¹×ÔÉí±äÓס£Ëüͨ¹ý´Ó´úÂëÖÐɾ³ý×¢½â¡¢²»ÓÃÒªµÄº¯ÊýºÍ¿Õ¸ñÀ´ÊµÏÖÕâÒ»µã¡£SSH-Snake רΪ¶àÖ°ÄÜÐÔ¶øÉè¼Æ£¬¼´²å¼´Ó㬵«ÔÊÐíÆ¾¾ÝÌØ¶¨²Ù×÷ÐèÒª½øÐж¨Ô죬Ô̺¬µ÷ÕûÕ½ÊõÀ´·¢ÏÖ˽Կ²¢¼ø±ðÆäDZÔÚÓô¦¡£


https://www.bleepingcomputer.com/news/security/new-ssh-snake-malware-steals-ssh-keys-to-spread-across-the-network/


2. Ð嵀 Wi-Fi ·ì϶ʹ Android ºÍ Linux Éè±¸Ãæ¶Ô¹¥»÷


2ÔÂ21ÈÕ£¬ÍøÂ簲ȫ×êÑÐÈËÔ±ÔÚ Android¡¢Linux ºÍ ChromeOS É豸Öз¢ÏֵĿªÔ´ Wi-Fi Èí¼þÖз¢ÏÖÁËÁ½¸öÉí·ÝÑéÖ¤ÈÆ¹ýȱµã£¬ÕâЩȱµã¿ÉÄÜ»áÓÕÆ­Óû§²ÎÓëËù·¨ÍøÂçµÄ¶ñÒâ¿Ë¡£¬»òÔÊÐí¹¥»÷ÕßÎÞÐèÃÜÂë¼´¿É²ÎÓëÊÜÐÅÀµµÄÍøÂç¡£ÕâЩ·ì϶±ðÀë±àºÅΪ CVE-2023-52160 ºÍ CVE-2023-52161£¬ÊÇÔÚ¶Ôwpa_supplicantºÍÓ¢ÌØ¶û iNet Wireless Daemon ( IWD ) ½øÐа²È«ÆÀ¹Àºó·¢Ïֵġ£³ö¸ñÊÇ£¬CVE-2023-52161 ÔÊÐí¹¥»÷Õßδ¾­ÊÚȨ½Ó¼ûÊܱ £»¤µÄ Wi-Fi ÍøÂ磬ʹÏÖÓÐЧ»§ºÍÉè±¸Ãæ¶Ô¶ñÒâÈí¼þϰȾ¡¢Êý¾Ý͵ÇÔºÍóÒ×µç×ÓÓʼþй¶ (BEC) µÈDZÔÚ¹¥»÷¡£ËüÓ°Ïì IWD 2.12 ¼°¸üµÍ°æ±¾¡£ÁíÒ»·½Ã棬CVE-2023-52160 Ó°Ïì wpa_supplicant °æ±¾ 2.10 ¼°¸üÔç°æ±¾¡£ÕâÒ²ÊÇÕâÁ½¸öȱµãÖиü½ôÆÈµÄÒ»¸ö£¬ÓÉÓÚËüÊÇ Android É豸ÖÐÓÃÓÚ´¦ÖÃÎÞÏßÍøÂçµÇ¼ҪÇóµÄĬÈÏÈí¼þ¡£


https://thehackernews.com/2024/02/new-wi-fi-vulnerabilities-expose.html


3. IBM X-Force °ä²¼ 2024 ÄêÍþвµý±¨Ö¸Êý»ã±¨


2ÔÂ21ÈÕ£¬IBM µÄ X-Force Íþвµý±¨ÍŶӰµÊ¾£¬ÍøÂç·¸×ï·Ö×ÓÔ½À´Ô½¶àµØÀûÓñ»µÁÉí·ÝÀ´·ÛËéÆóҵϵͳ£¬¶ø²»ÊÇÊÔͼÇÖÈëÆóҵϵͳ£¬ÕâÖÖÇ÷ÏòÓÐÍûÔÚ½«À´¼¸ÄêÄÚÔö³¤¡£Íþв×é֯Ϊ»ñÈ¡µÇ¼ϵͳËùÐèµÄÐÅÏ¢¶ø²ÉÈ¡µÄÐж¯Ìå´Ë¿ÌºÜ¶àÁìÓò£¬´Ó°µÍøÉÏÌṩµÄ´óÁ¿Æ¾Ö¤ºÍÆäËûÓ×ÎÒÐÅÏ¢µ½ 2023 Äêͬ±ÈÔö³¤ 266%¡£¾Ý IBM ³Æ£¬¸Ã¶ñÒâÈí¼þÖ¼ÔÚÇÔÈ¡µç×ÓÓʼþ¡¢É罻ýÌåºÍÐÂÎÅÀûÓ÷¨Ê½Í´´¦¡¢ÒøÐоßÌåÐÅÏ¢ºÍ¼ÓÃÜÇ®±ÒÇ®°üÊý¾ÝµÈÓ×ÎÒÉí·ÝÐÅÏ¢¡£·ÀÓùÕßÒ²¸üÄѼì²âµ½´ËÀ๥»÷£¬´Ó¶øÊ¹×éÖ¯Ó¦¶ÔÕâЩ¹¥»÷µÄ¹¦·ò¸ü³¤¡¢³É±¾¸ü¸ß¡£»ã±¨µÄ¼¸¸öÁÁµãÖ®Ò»ÊdzÖÐø×ªÏòÉí·Ý¼ø±ð¶ø²»ÊǺڿ͹¥»÷¡£ÆäËûÔ̺¬ÆóÒ·ÕË÷Èí¼þÊÂÎñÊýÁ¿Ï÷¼õÁË 11.5%£¬Ö»¹ÜÊý¾Ý͵ÇÔºÍй¶°¸¼þÕ¼ËùÓй¥»÷µÄ 32%£¬Ê¹Æä³ÉΪ¡°¶Ô×éÖ¯×î³£¼ûµÄÓ°Ï죬Åú×¢¸ü¶à¼¯Ì寫²îÓÚÕâÖÖ²½ÖèÀ´»ñÈ¡¾­¼ÃÊÕÒæ¡£


https://securityboulevard.com/2024/02/identity-based-attacks-grow-while-ransomware-declines-ibm-x-force/


4. WordPress ²å¼þȱµã£¨CVE-2024-1317£©¿Éµ¼ÖÂÊý¾Ýй¶


2ÔÂ21ÈÕ£¬Ò»¸öÑϳÁµÄ·ì϶»áΣ¼°Ê¹Óà Feedzy ²å¼þÌṩµÄÊ¢ÐÐ RSS ¾ÛºÏÆ÷µÄ WordPress ÍøÕ¾µÄ°²È«¡£WordPress µÄ»îÔ¾×°ÖÃÁ¿³¬¹ý 50,000 ¸ö£¬Òò¶øÓû§±ØÐëÏàʶ·çÏÕ²¢µ±¼´²ÉÈ¡Ðж¯¡£¸Ã²å¼þ 4.4.2 ֮ǰµÄ°æ±¾Ô̺¬Ò»¸öÑϳÁµÄ SQL ×¢Èëȱµã£¬Ê¹ÄúµÄÃô¸ÐÐÅÏ¢Êܵ½ÍøÂç·¸×ï·Ö×ӵĽÚÔì¡£¸Ãȱµã±»×·×ÙΪCVE-2024-1317 ( CVSS 8.8 )£¬ÔÚ Feedzy ²å¼þ 4.4.2 ¼°Ö®Ç°µÄËùÓа汾ÖоùÒÑ·¢ÏÖ¡£¡° search_key ¡±²ÎÊýÊÇÒ»¸öÍø¹Ø£¬SQL ²éÎÊͨ¹ý¸ÃÍø¹ØÏòÊý¾Ý¿âй©°ÂÃØ£¬µ«Ã»Óеõ½³ä·ÖµÄ± £»¤¡£¶ÔÓû§ÌṩµÄ²ÎÊýµÄתÒå²»³ä·ÖÒÔ¼° SQL ²éÎÊ×ÔÉí²»×ã³ï±¸£¬ÎªÓµÓй±Ï×Õß¼¶±ð»ò¸ü¸ßȨÏ޵ľ­¹ýÉí·ÝÑéÖ¤µÄ¹¥»÷Õß×¢Èë¶ñÒâ SQL ³¨¿ªÁË´óÃÅ£¬´Ó¶øÇÔÈ¡ÁËÔ̺¬ÃÜÂë¹þÏ£ÔÚÄÚµÄÊý¾Ý¡£2 Ô 9 ÈÕ°ä²¼Á˲¹¶¡¡£°æ±¾4.4.3½¨¸´Á˸÷ì϶¡£


https://securityonline.info/cve-2024-1317-critical-wordpress-plugin-flaw-leaves-your-data-exposed/


5. µÂ¹ú PSI Software SE È·ÈÏÆäÔâµ½ÀÕË÷Èí¼þµÄ¹¥»÷


2ÔÂ22ÈÕ£¬µÂ¹ú¸´ÔÓÔì×÷ºÍÎïÁ÷Á÷³ÌÈí¼þ¿ª·¢ÉÌ PSI Software SE ֤ʵ£¬¸Ã¹«Ë¾³ÉÎªÉæ¼°ÀÕË÷Èí¼þµÄÍøÂç¹¥»÷µÄÊܺ¦Õߣ¬¸Ã¹¥»÷ÇÖº¦ÁËÆäÄÚ²¿»ù´¡ÉèÊ©¡£¸Ã¹«Ë¾ÔÚÈ«ÇòÔËÓª£¬Õ¼Óг¬¹ý 2,000 ÃûÔ±¹¤£¬ÒÔÎªÖØÒªÄÜÔ´¹©¸øÉÌ´òÔìÈí¼þ½â¾ö¹æ»®¶øÎÅÃû¡£Ëü»¹ÌṩһÕûÌ×·þÎñ£¬ÓÃÓÚÖÎÀíºÍÊØ»¤ÏÖÓÐÄÜÔ´»ù´¡ÉèÊ©¡¢Í¶×Ê×éºÏÖÎÀíÒÔ¼°ÄÜÔ´×ÊÔ´µÄÓªÏúºÍ·ÖÅä¡£2ÔÂ15ÈÕ£¬PSI Software°ä·¢Õâ´ÎÍøÂç¹¥»÷ÔÚÆäÍøÕ¾Ö÷Ò³µÄÏÔ×ŵØÎ»ÏÔʾ£¬ÁÙʱ°µ²ØÁËÆäÓàÄÚÈÝ¡£Õâ´Î¹¥»÷µ¼Ö¶à¸ö IT ϵͳ£¨Ô̺¬µç×ÓÓʼþ£©¹Ø¹Ø£¬ÒÔ½µµÍÊý¾ÝÃÔʧµÄ·çÏÕ¡£ÔÚËæºóµÄ¸üÐÂÖУ¬PSI Software È·ÈÏÕâ´ÎÖжÏÊÇÓÉÍøÂç·¸×ï·Ö×ÓʹÓÃÀÕË÷Èí¼þÔì³ÉµÄ¡£¸Ã¹«Ë¾ÉÐδȷ¶¨ÕØÊÂÕß½øÈë¼òÖ±Çз½Ê½¡£¸Ã¹«Ë¾ÉÐδÌṩÓйؿͻ§¶Ëϵͳµ±Ç°ÔËÐÐ״̬µÄÐÅÏ¢¡£


https://meterpreter.org/psi-software-se-confirms-ransomware-disruption/


6. ΢ÈíÆðÍ·Ç¿Ôì¸üÐÂWindows 11 23H2


2ÔÂ22ÈÕ£¬Î¢ÈíÔÚÈ¥Äê°ä²¼ÁËWindows 11µÄ³Á´ó¸üУ¬°æ±¾23H2£¬ÒýÈëÁËÈËΪÖÇÄܸ±ÊÖCopilot£¬Ê¹Windows 11³ÉΪµÚÒ»¸öÏòÓû§Ìṩ¼¯ÖÐʽÈËΪÖÇÄÜÔ®ÊÖµÄPCƽ̨¡£È»¶ø£¬ÓÉÓÚ·½±ãµÄ¡°¿ÉÑ¡¡±¿ª¹Ø£¬ºÜ¶àÓû§Ñ¡Ôñ²»Éý¼¶µ½Windows 11 23H2¡£¶ÔÓÚ΢ÈíÀ´Ëµ£¬ÕâÖÖÇ÷Ïò²¢²»ÃÎÏ룬΢Èí×î½ü°µÊ¾ÔÚÆäÖ§³ÖÎĵµÖаµÊ¾£¬Ëü½«×Ô¶¯½«¡°ÇкÏǰÌáµÄ¡±É豸¸üе½ Windows 11 23H2¡£´ËÕ½ÊõÖØÒªÕë¶ÔÒÑ´ïµ½»ò¿¿½üʹÓÃÊÙÃüµÄ Windows 11 É豸£¬³ö¸ñÊÇ Windows 11 21H2 / 22H1 °æ±¾¡£Windows 11 21H2 ÓÚ 2023 Äê 10 Ô 10 ÈÕ´ïµ½ÐÔÃüÖÜÆÚÖÕÖ¹ (EOL)£¬¶ø Windows 11 22H2 Ò²½«ÓÚ 2024 Äê 10 Ô 8 ÈÕÖÕÖ¹¡£ÔÚÕâЩÈÕÆÚÖ®ºó£¬Microsoft ½«ÖÕ³¡ÎªÕâЩ°æ±¾Ìṩ°²È«¸üÐÂºÍÆäËû¸Ä½ø¡£


https://meterpreter.org/microsoft-begins-mandatory-update-to-windows-11-23h2/