Symantec³ÆBillbug¹¥»÷ÑÇÖÞµØÇøµÄÊý×ÖÖ¤Êé½ÒÏþ»ú¹¹

Ðû²¼Ê±¼ä 2022-11-17
1¡¢Symantec³ÆBillbug¹¥»÷ÑÇÖÞµØÇøµÄÊý×ÖÖ¤Êé½ÒÏþ»ú¹¹

SymantecÔÚ11ÔÂ15ÈÕ³ÆÆä·¢Ã÷Billbug¹¥»÷ÁËÑÇÖ޵Ķà¸öÕþ¸®»ú¹¹£¬£¬£¬ £¬£¬£¬ÆäÖаüÀ¨Ò»¸öÊý×ÖÖ¤Êé½ÒÏþ»ú¹¹¡£¡£¡£¡£¡£¸ÃÍÅ»ï×Ô2009ÄêÒÔÀ´Ò»Ö±»îÔ¾£¬£¬£¬ £¬£¬£¬Symantec 2019ÄêË꼵ĻÖÐÏêϸÏÈÈÝÁ˸ÃÍÅ»ïÔõÑùʹÓúóÃÅHannotogºÍSagerunexµÄ£¬£¬£¬ £¬£¬£¬ÕâЩ¹¤¾ßÔÚ×î½üµÄ»î¶¯ÖÐÒ²ÓзºÆð¡£¡£¡£¡£¡£´Ë´Î»î¶¯ÖÁÉÙ´Ó3Ô¾ÍÒÑ×îÏÈ£¬£¬£¬ £¬£¬£¬Óм£ÏóÅú×¢¹¥»÷ÕßÕýÔÚʹÓÃÃæÏò¹«ÖÚµÄÓ¦ÓóÌÐòÀ´»ñµÃ¶ÔÄ¿µÄÍøÂçµÄ³õʼ»á¼ûȨÏÞ¡£¡£¡£¡£¡£Óë֮ǰµÄ»î¶¯Ò»Ñù£¬£¬£¬ £¬£¬£¬¹¥»÷ÕßҲʹÓÃÁ˶àÖÖÁ½Óù¤¾ß¼°×Ô½ç˵¶ñÒâÈí¼þ£¬£¬£¬ £¬£¬£¬ÈçAdFind¡¢Directory¡¢Winmail¡¢WinRAR¡¢PingºÍTracertµÈ¡£¡£¡£¡£¡£

https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/espionage-asia-governments-cert-authority

2¡¢VaronisÅû¶Zendesk ExploreÖÐSQL×¢ÈëµÈÎó²îµÄϸ½Ú

VaronisÔÚ11ÔÂ15ÈÕÅû¶ÁËZendesk ExploreÖÐÁ½¸öÎó²îµÄϸ½Ú¡£¡£¡£¡£¡£ÆäÖÐÒ»¸öÊÇSQL×¢ÈëÎó²î£¬£¬£¬ £¬£¬£¬¸ÃÎó²îÉæ¼°ÆäGraphQL APIÖеÄSQL×¢È룬£¬£¬ £¬£¬£¬¿É±»ÓÃÀ´Ð¹Â¶×÷ΪÖÎÀíÔ±´æ´¢ÔÚÊý¾Ý¿âÖеÄËùÓÐÐÅÏ¢£¬£¬£¬ £¬£¬£¬°üÀ¨ÓʼþµØµã¡¢¹¤µ¥ÒÔ¼°ÓëʵʱÊðÀíµÄ¶Ô»°µÈ¡£¡£¡£¡£¡£ÁíÒ»¸öÎó²îÊÇÉæ¼°ÓëÅÌÎÊÖ´ÐÐAPIÏà¹ØµÄÂß¼­»á¼ûÎÊÌ⣬£¬£¬ £¬£¬£¬¸ÃAPI±»ÉèÖÃΪÔËÐÐÅÌÎÊ£¬£¬£¬ £¬£¬£¬¶ø²»¼ì²é¾ÙÐÐŲÓõÄÓû§ÊÇ·ñÓÐ×ã¹»µÄȨÏÞÕâÑù×ö¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬ £¬£¬£¬ÕâЩÎó²îÒѱ»ÐÞ¸´¡£¡£¡£¡£¡£

https://securityaffairs.co/wordpress/138579/hacking/zendesk-explore-critical-flaws.html

3¡¢LazarusʹÓúóÃÅDTrack¹¥»÷Å·ÖÞºÍÀ­¶¡ÃÀÖÞµÄ×éÖ¯

¾Ý11ÔÂ15ÈÕ±¨µÀ£¬£¬£¬ £¬£¬£¬³¯ÏʺڿÍÍÅ»ïLazarusÕýÔÚʹÓÃа汾µÄDTrackºóÃÅÀ´¹¥»÷Å·ÖÞºÍÀ­¶¡ÃÀÖÞµÄ×éÖ¯¡£¡£¡£¡£¡£Ä¿µÄÐÐÒµ°üÀ¨Ñо¿ÖÐÐÄ¡¢Õþ²ß»ú¹¹¡¢»¯Ñ§Æ·ÖÆÔìÉÌ¡¢ITЧÀÍÌṩÉÌ¡¢µçÐÅÌṩÉÌ¡¢¹«ÓÃÊÂҵЧÀÍÌṩÉ̺ͽÌÓý¡£¡£¡£¡£¡£ÔÚеĻÖУ¬£¬£¬ £¬£¬£¬DTrackͨ³£Ê¹ÓÃÓëÕýµ±ÎļþÏà¹ØµÄÎļþÃû¾ÙÐзַ¢£¬£¬£¬ £¬£¬£¬ÈçÒ»¸öÑù±¾ÒÔ¡°NvContainer.exe¡±ÎªÃû·Ö·¢£¬£¬£¬ £¬£¬£¬ËüÓëÕýµ±µÄNVIDIAÎļþͬÃû¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬ £¬£¬£¬DTrackÈÔ¼ÌÐøÍ¨¹ýÇÔÈ¡µÄƾ֤ÈëÇÖÍøÂç»òʹÓÃÍøÉÏ̻¶µÄЧÀÍÆ÷À´¾ÙÐзַ¢¡£¡£¡£¡£¡£

https://securelist.com/dtrack-targeting-europe-latin-america/107798/

4¡¢Ñо¿ÍŶӷ¢Ã÷¿ÉÓ°Ï캽ÌìÆ÷ºÍ·É»úµÄ¹¥»÷·½·¨PCspooF

ýÌå11ÔÂ15ÈÕ±¨µÀ£¬£¬£¬ £¬£¬£¬Ñо¿ÍŶӷ¢Ã÷ÁËÒ»ÖÖÕë¶Ôʱ¼ä´¥·¢ÒÔÌ«Íø(TTE)µÄÐÂÐ͹¥»÷ÒªÁì¡£¡£¡£¡£¡£TTEÊôÓÚ»ìÏýÒªº¦ÐÔÍøÂçµÄÍøÂçÊÖÒÕÖ®Ò»£¬£¬£¬ £¬£¬£¬ÆäÖоßÓвî±ðʱÐòºÍÈÝ´íÒªÇóµÄÁ÷Á¿¹²´æÓÚͳһÎïÀíÍøÂçÖС£¡£¡£¡£¡£¸ÃÊÖÒÕÓÃÓÚÇå¾²»ù´¡ÉèÊ©£¬£¬£¬ £¬£¬£¬¿Éµ¼ÖÂΪº½ÌìÆ÷ºÍ·É»úÌṩ¶¯Á¦µÄϵͳ·ºÆð¹ÊÕÏ¡£¡£¡£¡£¡£ÕâÊÇʹÓöñÒâ×°±¸Í¨¹ýÒÔÌ«ÍøµçÀ½«µç´Å×ÌÈÅ(EMI)×¢ÈëTTE½»Á÷»úÀ´ÊµÏֵ쬣¬£¬ £¬£¬£¬¿ÉÓÐÓõØÓÕʹ½»Á÷»ú·¢ËÍ¿´ËÆÕæÊµµÄͬ²½ÐÂÎŲ¢ÈÃËüÃDZ»ÆäËûTTE×°±¸½ÓÊÜ¡£¡£¡£¡£¡£×÷Ϊ»º½â²½·¥£¬£¬£¬ £¬£¬£¬Ñо¿Ö°Ô±½¨ÒéʹÓùâñîºÏÆ÷»òÀËÓ¿±£»£»£»£»£»£»¤Æ÷À´×èÖ¹µç´Å×ÌÈÅ¡£¡£¡£¡£¡£

https://thehackernews.com/2022/11/pcspoof-new-vulnerability-affects.html

5¡¢ÒÁÀÊÏà¹ØºÚ¿ÍʹÓÃLog4ShellÎó²îÈëÇÖÃÀ¹úÕþ¸®»ú¹¹

11ÔÂ16ÈÕ£¬£¬£¬ £¬£¬£¬FBIºÍCISAÁªºÏÐû²¼ÁËÒ»·Ýͨ¸æ£¬£¬£¬ £¬£¬£¬³ÆÓëÒÁÀÊÏà¹ØµÄºÚ¿ÍÈëÇÖÁËÒ»¸öÕþ¸®»ú¹¹²¢×°ÖÃÁËXMRig¿ó¹¤¶ñÒâÈí¼þ¡£¡£¡£¡£¡£Í¨¸æ³Æ£¬£¬£¬ £¬£¬£¬´Ó2022Äê6ÔÂÖÐÑ®µ½7Ô£¬£¬£¬ £¬£¬£¬CISAÔÚÁª°îÃñÓÃÐÐÕþ²¿·Ö(FCEB)×éÖ¯ÖÐÊӲ쵽ÁË¿ÉÒɵÄAPT»î¶¯¡£¡£¡£¡£¡£¹¥»÷ÕßʹÓÃδÐÞ¸´µÄVMware HorizonЧÀÍÆ÷ÖеÄLog4ShellÎó²î£¬£¬£¬ £¬£¬£¬×°ÖÃXMRig¿ó¹¤Èí¼þ£¬£¬£¬ £¬£¬£¬ºáÏòÒÆ¶¯µ½Óò¿ØÖÆÆ÷(DC)£¬£¬£¬ £¬£¬£¬ÇÔȡƾ֤£¬£¬£¬ £¬£¬£¬È»ºóÖ²ÈëNgrok·´ÏòÊðÀíÀ´ÔÚ¶à¸ö×°±¸Éϼá³Ö³¤ÆÚÐÔ¡£¡£¡£¡£¡£CISA ºÍ FBI Ðû²¼´ËCSAÌṩºÚ¿ÍµÄTTPºÍIOC£¬£¬£¬ £¬£¬£¬ÒÔ×ÊÖú×éÖ¯¼ì²âºÍ·ÀÓùÏà¹ØµÄ¹¥»÷¡£¡£¡£¡£¡£

https://www.cisa.gov/uscert/ncas/alerts/aa22-320a

6¡¢KasperskyÐû²¼¹ØÓÚ2023ÄêAPT¹¥»÷»î¶¯µÄÕ¹Íû±¨¸æ

KasperskyÔÚ11ÔÂ14ÈÕÐû²¼Á˹ØÓÚ2023ÄêAPT¹¥»÷»î¶¯µÄÕ¹Íû±¨¸æ¡£¡£¡£¡£¡£±¨¸æÕ¹ÍûÔÚ2023Ä꣬£¬£¬ £¬£¬£¬½«·ºÆð´ó×򵀮ÆËðÐÔÍøÂç¹¥»÷£¬£¬£¬ £¬£¬£¬Ó°ÏìÕþ¸®²¿·ÖºÍÒªº¦ÐÐÒµ£»£»£»£»£»£»ÓʼþЧÀÍÆ÷½«³ÉΪÖ÷ҪĿµÄ£¬£¬£¬ £¬£¬£¬ºÜ¿ÉÄÜËùÓÐÖ÷Òªµç×ÓÓʼþÈí¼þ¶¼·ºÆð0-day£»£»£»£»£»£»Ò»Ð©¾ßÓÐÓ°ÏìÁ¦µÄ²¡¶¾Ã¿6-7Ä걬·¢Ò»´Î£¬£¬£¬ £¬£¬£¬¿ÉÄÜ·ºÆðÏÂÒ»¸öWannaCry£»£»£»£»£»£»APT¹¥»÷ÍŻォĿµÄתÏòÎÀÐÇÊÖÒÕ¡¢Éú²úÉ̺ÍÔËÓªÉÌ£»£»£»£»£»£»¸ü¶àAPT×éÖ¯½«´ÓCobaltStrike×ªÒÆµ½ÆäËüÌæ»»¼Æ»®µÈ¡£¡£¡£¡£¡£

https://securelist.com/advanced-threat-predictions-for-2023/107939/