RedTailÍÚ¿óÀûÓà Palo Alto Networks ·À»ðǽµÄ·ì϶
°ä²¼¹¦·ò 2024-06-035ÔÂ31ÈÕ£¬RedTail¼ÓÃÜÇ®±ÒÍÚ¾ò¶ñÒâÈí¼þ±³ºóµÄÍþвÐÐΪÕß½«×î½üÅû¶µÄÓ°Ïì Palo Alto Networks ·À»ðǽµÄ°²È«·ì϶Ôö³¤µ½Æä·ì϶ÀûÓÿâÖС£Æ¾¾ÝÍøÂç»ù´¡ÉèÊ©ºÍ°²È«¹«Ë¾ Akamai µÄ×êÑÐÁ˾֣¬¸Ã¶ñÒâÈí¼þ²»½öÔÚÆä¹¤¾ß°üÖÐÔö³¤ÁË PAN-OS ·ì϶£¬»¹¶ÔÆä½øÐÐÁ˸üУ¬Ä¿Ç°ÒÑѡȡÁËÐµķ´·ÖÎö¼¼Êõ¡£Akamai ·¢ÏÖµÄϰȾÐòÁÐÀûÓÃÁË PAN-OS ÖÐÏÖÒѽ¨²¹µÄ·ì϶CVE-2024-3400£¨CVSS ÆÀ·Ö£º10.0£©£¬¸Ã·ì϶¿ÉÄÜÔÊÐíδ¾Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÔÚ·À»ðǽÉÏÒÔ root ȨÏÞÖ´ÐÐËÁÒâ´úÂë¡£³É¹¦ÀûÓÃÖ®ºó£¬½«Ö´ÐÐÖ¼ÔÚ´Ó±í²¿Óò¼ìË÷ºÍÔËÐÐ bash shell ¾ç±¾µÄºÅÁ¸Ã¾ç±¾·´¹ýÀ´ÕÆ¹ÜÆ¾¾Ý CPU ¼Ü¹¹ÏÂÔØ RedTail ÓÐЧ¸ºÔØ¡£RedTail µÄÆäËû´«²¼»úÔìÉæ¼°ÀûÓà TP-Link ·ÓÉÆ÷£¨CVE-2023-1389£©¡¢ThinkPHP£¨CVE-2018-20062£©¡¢Ivanti Connect Secure£¨CVE-2023-46805 ºÍ CVE-2024-21887£©ÒÔ¼° VMWare Workspace ONE Access ºÍ Identity Manager£¨CVE-2022-22954£©ÖÐÒÑÖªµÄ°²È«·ì϶¡£RedTailÓÚ 2024 Äê 1 Ô³õ´ÎÓɰ²È«×êÑÐÔ± Patryk Machowiak ¼Í¼£¬Éæ¼°ÀûÓà Log4Shell ·ì϶ (CVE-2021-44228) ÔÚ»ùÓÚ Unix µÄϵͳÉϲ¿Êð¶ñÒâÈí¼þµÄ»î¶¯¡£
https://thehackernews.com/2024/05/redtail-crypto-mining-malware.html
2. Cooler Master È·ÈÏÊý¾Ýй¶ÊÂÎñÖпͻ§ÐÅÏ¢±»µÁ
5ÔÂ31ÈÕ£¬ÍÆËã»úÓ²¼þÔì×÷ÉÌ Cooler Master È·ÈÏÆäÓÚ 5 Ô 19 ÈÕÔâ·êÊý¾Ýй¶£¬ÍþвÐÐΪÕßÇÔÈ¡Á˿ͻ§Êý¾Ý¡£Cooler Master ÊÇÒ»¼Ò³ÛÃûµÄÍÆËã»úÓ²¼þÔì×÷ÉÌ£¬ÒÔÆäÀäÈ´É豸¡¢ÍÆËã»ú»úÏä¡¢µçÔ´ºÍÆäËû±íΧÉ豸¶øÎÅÃû¡£BleepingComputer×òÌ챨·³Æ£¬Ò»¸öÃûΪ¡°Ghostr¡±µÄÍþвÐÐΪÕß֪ͨÎÒÃÇ£¬ËûÃÇÓÚ 5 Ô 18 ÈÕÈëÇÖÁ˸ù«Ë¾µÄ Fanzone ÍøÕ¾²¢ÏÂÔØÁËÆäÁ´½ÓµÄÊý¾Ý¿â¡£Cooler Master µÄ Fanzone ÍøÕ¾ÓÃÓÚ×¢²á²úÆ·±£½¨¡¢ÉêÇë RMA »ò¿ªÁ¢Ö§³Ôì±£¬ÒªÇó¿Í»§ÌîдÓ×ÎÒÊý¾Ý£¬ÀýÈçÐÕÃû¡¢µç×ÓÓʼþµØÖ·¡¢µØÖ·¡¢µç»°ºÅÂë¡¢µ®ÉúÈÕÆÚºÍÏÖʵµØÖ·¡£Ghostr °µÊ¾£¬ÔÚ Fanzone ·ì϶²úÉúÆÚ¼ä£¬ËûÃÇÏÂÔØÁË 103 GB µÄÊý¾Ý£¬ÆäÖÐÔ̺¬³¬¹ý 500,000 Ãû¿Í»§µÄ¿Í»§ÐÅÏ¢¡£ÍþвÐÐΪÕß»¹¹²ÏíÁËÊý¾ÝÑù±¾£¬Ê¹ BleepingComputer ¿ÉÄÜÓëÎ¥¹æÐÐΪÖÐÁгöµÄ¶à¶à¿Í»§È·ÈÏËûÃǵÄÊý¾ÝÊÇÕýÈ·µÄ£¬²¢ÇÒËûÃÇ×î½üÏò Cooler Master ÒªÇóÁËÖ§³Ö»ò RMA¡£Ñù±¾ÖÐµÄÆäËûÊý¾ÝÔ̺¬²úÆ·ÐÅÏ¢¡¢Ô±¹¤ÐÅÏ¢ÒÔ¼°Ó빩¸øÉ̵ĵç×ÓÓʼþÐÅÏ¢¡£ÍþвÕßÐû³ÆÕ¼Óв¿ÃÅÐÅÓþ¿¨ÐÅÏ¢£¬µ« BleepingComputer ÔÚÊý¾ÝÑù±¾ÖÐÕÒ²»µ½ÕâЩÊý¾Ý¡£
https://www.bleepingcomputer.com/news/security/cooler-master-confirms-customer-info-stolen-in-data-breach/
3. BBC Åû¶ÁËÓ°ÏìÆäÑøÀϽð´òËã³ÉÔ±µÄÊý¾Ýй¶ÊÂÎñ
6ÔÂ1ÈÕ£¬BBC µÄÐÅÏ¢°²È«ÍŶÓÒÑÏòÎÒÃÇ´«µÝÁËһ·Êý¾Ý°²È«ÊÂÎñ£¬ÆäÖв¿ÃÅÔ̺¬ BBC ÑøÀϽð´òËã³ÉÔ±Ó×ÎÒÐÅÏ¢µÄÎļþ±»´ÓÔÆ´æ´¢·þÎñÖи´Ôì¡£ÕâЩÎļþÔ̺¬Ò»Ð©ÑøÀϽð´òËã³ÉÔ±µÄÓ×ÎÒÐÅÏ¢£¬Ô̺¬ÐÕÃû¡¢¹úÃñ±£Ïպ𢵮ÉúÈÕÆÚºÍ¼ÒͥסַµÈ¾ßÌåÐÅÏ¢¡£¡±²¼¸æÐ´Â·¡£¡°ËùÉæ¼°µÄÊý¾ÝÎļþÊǸ±±¾£¬Òò¶ø¶Ô´òËãµÄÕý³£ÔË×÷ûÓÐÓ°Ïì¡£¸ÃÊÂÎñδӰÏìÑøÀϽð´òËãÃÅ»§ÍøÕ¾µÄÔËÐУ¬Óû§Äܹ»³ÖÐøÊ¹Ó᣸ÃÊÂÎñй¶ÁËÔ¼ 25,000 Ãû BBC ÑøÀϽð´òËã³ÉÔ±µÄÓ×ÎÒÐÅÏ¢£¬ÆäÖÐÔ̺¬ÏÖÈκÍǰÈÎÔ±¹¤¡£Ð¹Â¶µÄÊý¾ÝÔ̺¬È«Ãû¡¢¹úÃñ±£Ïպ𢵮ÉúÈÕÆÚ¡¢ÐÔ±ðºÍ¼Òͥסַ¡£Õâ¼ÒÓ¢¹ú¹«¹²·þÎñ¹ã²¥¹«Ë¾ÔÚ±í²¿×¨¼ÒµÄÔ®ÊÖϵ÷²éÁËÕâÒ»ÊÂÎñ£¬²¢ÒѲÉÈ¡Á˶î±íµÄ°²È«´ëÊ©¡£×¨¼ÒÃÇÒѾȷ¶¨Á˰²È«·ì϶µÄÔÒò²¢²ÉÈ¡Á˰²È«´ëÊ©¡£¸Ã¹«Ë¾ÔÚͨ¹ýµç×ÓÓʼþ»òÓʼķ½Ê½ÁªÏµËùÓÐÊÜÓ°ÏìµÄ»áÔ±¡£Ä¿Ç°£¬¸Ã¹«Ë¾Ã»ÓÐÖ¤¾ÝÅú×¢ÊÜËðÎļþÒѱ»ÀÄÓá£
https://securityaffairs.com/163908/data-breach/bbc-disclosed-data-breach.html
4. FlyingYetiÀûÓÃWinRAR·ì϶½øÐÐÓÐÕë¶ÔÐԵĹ¥»÷»î¶¯
6ÔÂ2ÈÕ£¬×Ô 2022 Äê 2 Ô 24 ÈÕ¶íÂÞ˹ÈëÇÖÎÚ¿ËÀ¼ÒÔÀ´£¬ÁйúÖ®¼äÒÔ¼°È«ÊÀ½çÖ®¼äµÄÑÏÖØ´óÊÆÒ»ÏòºÜÑϳÁ¡£Õâ´ÎÊÂÎñºó£¬ÎÚ¿ËÀ¼¶Ôδ³¥Õ®ÎñµÄס»§Ö´ÐÐÁ˱÷³ýºÍÖÕÖ¹¹«ÓÃÊÂÒµ·þÎñµÄ½ûÁ¸Ã½ûÁÓÚ2024Äê1ÔÂʵÏÖ¡£È»¶ø£¬ÕâÒ»ÌØ°´Ê±ÆÚÈ´±»Ò»ÃûÃûΪFlyingYetiµÄÍþвÐÐΪÕßËùÀûÓ᣸ÃÍþвÐÐΪÕßÀûÓÃÎÚ¿ËÀ¼¹«Ãñ¶Ôδ³¥»¹Õ®ÎñºÍ¿ÉÄÜʧȥס·¿µÄ½¹ÂÇ£¬·¢Õ¹ÁËÒÔÕ®ÎñΪÖ÷ÌâµÄÍøÂç´¹µö»î¶¯£¬ÓÕÆÊܺ¦Õß½«¶ñÒâÈí¼þÎļþÏÂÔØµ½ËûÃǵÄϵͳÖС£¸Ã¶ñÒâÈí¼þÊÇÒ»ÖÖ³ÆÎª¡°COOKBOX¡±µÄ PowerShell ¶ñÒâÈí¼þ£¬ËüʹÕâЩÍþвÐÐΪÕß¿ÉÄÜ×°Ööî±íµÄÓÐÐ§ÔØºÉ²¢½ÚÔìÊܺ¦ÕßµÄϵͳ¡£´Ë±í£¬ÍøÂç´¹µö»î¶¯»¹ÀûÓÃÁË GitHub ·þÎñÆ÷ºÍ Cloudflare ¹¤×÷Æ÷ÒÔ¼° WinRAR ·ì϶£¨CVE-2023-38831£©¡£lyingYeti ÍþвÐÐΪÕߵĻÓë֮ǰȷ¶¨µÄÍþвÐÐΪÕß UAC-0149 ÓгÁµþ£¬ºóÕßÔøÔÚ 2023 ÄêÇ^ʹÓÃÒ»ÑùµÄ¶ñÒâÈí¼þ¹¥»÷ÎÚ¿ËÀ¼¹ú·ÀʵÌå¡£2024 Äê 4 ÔÂÖÐÑ®ÖÁ 5 ÔÂÖÐÑ®ÆÚ¼ä£¬¾Ý¹Û²ì£¬FlyingYeti ÍþвÐÐΪÕßÔÚ¶ÔÊܺ¦Õß½øÐпúËŻ£¬ÕâЩ»î¶¯ºÜ¿ÉÄÜÓÃÓÚÔ¶¨ÓÚÐÂÉú½ÚÆÚ¼äÌáÒéµÄ»î¶¯¡£
https://gbhackers.com/flyingyeti-winrar-vulnerability-malware-attacks/
5. LilacSquid ºÚ¿Í¹¥»÷ IT ÐÐÒµÒÔ»ñÈ¡»úÃÜÊý¾Ý
6ÔÂ1ÈÕ£¬ºÚ¿Í¶Ô×¼ IT ÐÐÒµ£¬ÓÉÓÚÕâЩÐÐÒµ°ÑÎÕ׏óÖØµÄÊý¾Ý¡¢¹Ø¼üµÄ»ù´¡ÉèÊ©£¬²¢ÇÒͨ³£Äܹ»½Ó¼û¸÷¸öÁìÓòµÄÃô¸ÐÐÅÏ¢¡£ÈëÇÖ IT ¹«Ë¾¿ÉÒÔΪºÚ¿ÍÌṩ½øÐмäµý»î¶¯¡¢»ñÈ¡¾¼ÃÀûÒæÒÔ¼°·ÛËé¸ù»ù·þÎñµÄ¾Þ´ó»úÓö¡£½üÈÕ£¬Ë¼¿ÆTalosÍøÂ簲ȫ×êÑÐÈËÔ±·¢ÏÖ£¬LilacSquidºÚ¿ÍÒ»ÏòÔÚ»ý¼«¹¥»÷ITÐÐÒµ£¬ÒÔ»ñÈ¡»úÃÜÊý¾Ý¡£Talos È·ÐÅ¡°LilacSquid¡± APT ×éÖ¯ÖÁÉÙ´Ó 2021 ÄêÆðÍ·¾ÍÒ»ÏòÔÚ½øÐÐÊý¾ÝÇÔÈ¡»î¶¯£¬³É¹¦ÈëÇÖÁËÑÇÖÞ¡¢Å·ÖÞºÍÃÀ¹úµÄÔìÒ©¡¢Ê¯ÓÍ¡¢ÌìÈ»ÆøºÍ¼¼ÊõÐÐÒµµÄÖ¸±ê ³õʼ½Ó¼ûÀûÓÃÁË·ì϶ºÍ±»µÁµÄ RDP Í´´¦¡£ÈëÇÖºó£¬LilacSquid ²¿ÊðÁË MeshAgent Ô¶³Ì½Ó¼û¹¤¾ß¡¢QuasarRAT µÄ¶¨Ôì¡°PurpleInk¡±±äÌåÒÔ¼° SSF µÈ¿ªÔ´´úÀí¹¤¾ß£¬Óë Lazarus ºÍ Andariel µÈ³¯ÏÊ×éÖ¯µÄ TTP ³Áµþ¡£¸Ã»î¶¯³ÉÁ¢ÁËÊý¾Ýй¶µÄ³Ö¾Ã½Ó¼ûȨÏÞ£¬ÏÈǰµÄ¹©¸øÁ´·ì϶͹ÏÔÁËÕâÖÖ³ÖÐø¡¢¸ß¼¶ÍþвµÄ·çÏÕ¡£ÈëÇÖºó£¬ËûÃÇʹÓà MeshAgent µÈ·¨Ê½½øÐÐÔ¶³Ì½Ó¼û¡¢Ê¹Óà SSF ½øÐа²È«Ëí·ÒÔ¼°Ê¹Óö¨Ôì¶ñÒâÈí¼þ InkLoader¡¢PurpleInk RAT µÈ¡£
https://gbhackers.com/lilacsquid-hackers-attacking-it-industries/
6. Êý°ÙÃûÓ¢¹ú¡¢·¨¹úºÍÅ·ÃËÕþ¿ÍµÄÐÅÏ¢ÔÚÍøÉϰ䲼
5ÔÂ31ÈÕ£¬¾ÝרһÓÚÒþÖԵĽâ¾ö¹æ»®ÌṩÉÌ Proton ³Æ£¬Êý°ÙÃûÓ¢¹ú¡¢·¨¹úºÍÅ·ÖÞÒé»áÕþ¿ÍµÄµç×ÓÓʼþµØÖ·ºÍÆäËûÐÅÏ¢Äܹ»ÔÚ°µÍøÊг¡ÉÏÕÒµ½¡£×÷Ϊ Proton Óë Constella Intelligence ºÏ×÷·¢Õ¹µÄÒ»Ïî×êÑеÄÒ»²¿ÃÅ£¬×êÑÐÈËÔ±ÔÚ°µÍøÉÏËÑË÷Á˽ü 2,300 ¸öÊôÓÚÓ¢¹ú¡¢·¨¹úºÍÅ·ÖÞÒé»áÒéÔ±µÄ¹Ù·½µ±¾Öµç×ÓÓʼþµØÖ·¡£×ܹ²ÓÐ 918 ¸öµç×ÓÓʼþµØÖ·±»Ð¹Â¶µ½ÍøÂç·¸×ïÊг¡£¬µ«Ã¿¸ö×éÖ¯ÊÜÓ°ÏìµÄÕþ¿Í±ÈÀýÓÐËù·ÖÆç¡£ÀýÈ磬Ӣ¹úÒéÔ±Êܵ½µÄÓ°Ïì×î´ó£¬68% µÄÖ¸±êµç×ÓÓʼþµØÖ·³Ê´Ë¿Ì°µÍøÉÏ¡£¾ÍÅ·ÃËÒé»áÒéÔ±¶øÑÔ£¬44% µÄµç×ÓÓʼþµØÖ·±»°ä²¼ÔÚºÚ¿ÍÂÛ̳ÉÏ¡£Ö»ÓÐ 18% µÄ·¨¹úÒéÔ±ºÍ²ÎÒéÔ±µÄÊý¾Ý±»Ð¹Â¶¡£¾ÍÓ¢¹úÕþ¿ÍµÄ°¸Àý¶øÑÔ£¬ÆäÖÐÔ̺¬µ±¾Ö¸ß²ãºÍ·ñ¾öÅÉÈËÎËûÃǵĵç×ÓÓʼþµØÖ·ÔÚ°µÍøÉϱ»·¢ÏÖ³¬¹ý 2,100 ´Î¡£ÔںܶàÇé¿öÏ£¬µç×ÓÓʼþµØÖ·ÔÚµ±¾ÖÍøÕ¾ÉÏÊǹ«¿ªµÄ¡£ÎÊÌâÔÚÓÚ£¬µç×ÓÓʼþµØÖ·³Ê´Ë¿Ì°µÍøÊг¡ÉÏÅú×¢ÕâЩµØÖ·Ôø±»ÓÃÀ´ÔÚ¸÷ÀàµÚÈý·½ÔÚÏß·þÎñÉϳÉÁ¢ÕË»§£¬¶øÕâЩ·þÎñÔÚij¸öʱ³½Ôâµ½Á˺ڿ͹¥»÷¡£
https://www.securityweek.com/information-of-hundreds-of-european-politicians-found-on-dark-web/


¾©¹«Íø°²±¸11010802024551ºÅ