SonicWall½ôÆÈ¸üÐÂÐÞ¸´GMSºÍAnalyticsÖеÄ15¸öÎó²î
Ðû²¼Ê±¼ä 2023-07-141¡¢SonicWall½ôÆÈ¸üÐÂÐÞ¸´GMSºÍAnalyticsÖеÄ15¸öÎó²î
7ÔÂ12ÈÕ£¬£¬£¬£¬SonicWallÐû²¼½ôÆÈ¸üУ¬£¬£¬£¬ÐÞ¸´ÁËGMS·À»ðǽÖÎÀíϵͳºÍAnalyticsÍøÂ籨¸æÒýÇæÈí¼þÖеÄ15¸öÎó²î¡£¡£¡£¡£¡£¡£ÆäÖнÏΪÑÏÖØµÄÊÇWebЧÀÍÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î£¨CVE-2023-34124£©¡¢¶à¸öδ¾Éí·ÝÑéÖ¤µÄSQLºÍÇå¾²¹ýÂËÆ÷ÈÆ¹ýÎó²î£¨CVE-2023-34133£©¡¢Í¨¹ýWebЧÀͶÁÈ¡ÃÜÂëhashÎó²î£¨CVE-2023-34134£©ºÍCASÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î£¨CVE-2023-34137£©¡£¡£¡£¡£¡£¡£ÕâЩÎó²îÉÐδ±»Ê¹Ó㬣¬£¬£¬¸Ã¹«Ë¾½¨ÒéʹÓÃÊÜÓ°Ïì²úÆ·µÄÓû§Á¬Ã¦Ó¦Óò¹¶¡¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/sonicwall-warns-admins-to-patch-critical-auth-bypass-bugs-immediately/
2¡¢BlackLotus UEFI BootkitÔ´´úÂëÔÚGitHubÉϹûÕæ
¾Ý7ÔÂ13ÈÕ±¨µÀ£¬£¬£¬£¬BlackLotus UEFI BootkitÔ´´úÂëÔÚGitHubÉϹûÕæ¡£¡£¡£¡£¡£¡£¸ÃbootkitרΪWindowsÉè¼Æ£¬£¬£¬£¬È¥Äê10Ô·ºÆðÔÚºÚ¿ÍÂÛ̳£¬£¬£¬£¬Éù³Æ¾ßÓÐAPT¼¶±ðµÄ¹¦Ð§£¬£¬£¬£¬ÀýÈçÈÆ¹ýUACÒÔ¼°½ûÓÃÇå¾²Ó¦ÓúͷÀÓù»úÖÆ¡£¡£¡£¡£¡£¡£BlackLotus×î³õÔÚºÚ¿ÍÂÛ̳ÉϵÄÊÛ¼ÛΪ5000ÃÀÔª£¬£¬£¬£¬ÏÖÔÚ£¬£¬£¬£¬ÆäÔ´´úÂë±»Óû§YukariÔÚÐû²¼ÔÚGitHubÉÏ£¬£¬£¬£¬Ê¹Ëü¿É¹©ÈκÎÈËʹÓᣡ£¡£¡£¡£¡£Ð¹Â¶µÄÔ´´úÂëɾ³ýÁËBaton DropÎó²î£¨CVE-2022-21894 £©£¬£¬£¬£¬Ö÷Òª°üÀ¨rootkit²¿·ÖºÍÈÆ¹ýÇå¾²Æô¶¯µÄbootkit´úÂë¡£¡£¡£¡£¡£¡£
https://www.securityweek.com/blacklotus-uefi-bootkit-source-code-leaked-on-github/
3¡¢Mandiant¹ûÕæÁ½Æðͨ¹ýUSB·Ö·¢µÄ¶ñÒâÈí¼þ»î¶¯µÄϸ½Ú
MandiantÔÚ7ÔÂ11ÈÕ͸¶Æä·¢Ã÷ÁËÁ½Æðͨ¹ýUSB·Ö·¢µÄ¶ñÒâÈí¼þ»î¶¯¡£¡£¡£¡£¡£¡£µÚÒ»¸ö»î¶¯±»¹éÒòÓÚTEMP.HEX£¬£¬£¬£¬Ê¹ÓöñÒâDLLÎļþ¼ÓÔØºóÃÅSogu¡£¡£¡£¡£¡£¡£¸Ã»î¶¯Õë¶ÔÈ«Çò¶à¸öÐÐÒµ£¬£¬£¬£¬²¢ÊÔͼ´ÓÄ¿µÄÅÌËã»úÖÐÇÔÈ¡Êý¾Ý£¬£¬£¬£¬ÆäÖдó´ó¶¼Ä¿µÄÊôÓÚÖÆÒ©¡¢IT¡¢ÄÜÔ´¡¢Í¨Ñ¶¡¢ÎÀÉúºÍÎïÊ¢ÐÐÒµ¡£¡£¡£¡£¡£¡£µÚ¶þ¸ö»î¶¯·Ö·¢»ùÓÚshellcodeµÄºóÃÅSnowydrive£¬£¬£¬£¬Ëü±»¼ÓÔØµ½Õýµ±Àú³ÌCUZ.exeÖУ¬£¬£¬£¬¾ßÓÐÊý¾Ýй¶¡¢·´Ïòshell¡¢ÏÂÁîÖ´ÐкÍÕì̽µÈ¹¦Ð§£¬£¬£¬£¬±»¹éÒòÓÚÕë¶ÔÑÇÖÞʯÓͺÍ×ÔÈ»Æø¹«Ë¾µÄUNC4698¡£¡£¡£¡£¡£¡£
https://www.mandiant.com/resources/blog/infected-usb-steal-secrets
4¡¢2023ÄêÉϰëÄêÈ«ÇòµÄ¼ÓÃÜÀÕË÷½ð¶î¸ß´ïÔ¼4.5ÒÚÃÀÔª
ChainaanalysisÔÚ7ÔÂ12Èճƣ¬£¬£¬£¬ÂÄÀúÁËÔÓÂÒµÄ2022ÄêÖ®ºó£¬£¬£¬£¬2023ÄêÆù½ñΪֹÊǼÓÃÜÇ®±ÒËÕÐѵÄÒ»Äê¡£¡£¡£¡£¡£¡£×èÖ¹6Ô·ݣ¬£¬£¬£¬ÀÕË÷½ð¶îÒÑÖÁÉÙ4.491ÒÚÃÀÔª£¬£¬£¬£¬µÖ´ïÁË2022ÄêÕûÄêÀÕË÷Èí¼þ×ÜÊÕÈëµÄ90%¡£¡£¡£¡£¡£¡£ÈôÊǼá³ÖÕâһˮƽ£¬£¬£¬£¬2023ÄêÕûÄêµÄÀÕË÷½ð¶î¿ìÒª9ÒÚÃÀÔª¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÒÔΪ£¬£¬£¬£¬¹¥»÷Õß×îÏÈÕë¶Ô¿ÉÒÔÀÕË÷µ½´ó±Ê¿î×ӵĴóÐÍ×éÖ¯£¬£¬£¬£¬µ¼ÖÂÁËÕâÖÖ´ó·ùÔöÌí¡£¡£¡£¡£¡£¡£¸ß¶îÊê½ðÉæ¼°µÄÀÕË÷ÍÅ»ïÖ÷Òª°üÀ¨BlackBasta¡¢LockBit¡¢ALPHVºÍClop¡£¡£¡£¡£¡£¡£ÆäÖÐClopµÄƽ¾ùÊê½ðΪ170ÍòÃÀÔª£¬£¬£¬£¬Êê½ðµÄÖÐλÊýΪ190ÍòÃÀÔª¡£¡£¡£¡£¡£¡£
https://blog.chainalysis.com/reports/crypto-crime-midyear-2023-update-ransomware-scams/
5¡¢Check PointÐû²¼QuickBlox¿ò¼ÜÖÐÎó²îµÄÆÊÎö±¨¸æ
7ÔÂ12ÈÕ£¬£¬£¬£¬Check Point³ÆÆä¶ÔQuickBlox¿ò¼ÜµÄSDKºÍAPIµÄÇå¾²ÐÔ¾ÙÐÐÑо¿£¬£¬£¬£¬·¢Ã÷ÁË¿ÉÄÜΣ¼°Êý°ÙÍòÓû§Ð¡ÎÒ˽¼ÒÐÅÏ¢µÄÎó²î¡£¡£¡£¡£¡£¡£QuickBloxÊÇÒ»ÖÖÊ¢ÐеÄ̸ÌìºÍÊÓÆµÐ§ÀÍ£¬£¬£¬£¬Ö÷ÒªÓÃÓÚÔ¶³ÌÒ½ÁÆ¡¢½ðÈÚºÍÖÇÄÜÎïÁªÍø×°±¸¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±»¹Ú¹ÊÍÁËÒ»Ð©ÆæÒìµÄ¹¥»÷·½·¨£¬£¬£¬£¬ÀýÈ磬£¬£¬£¬¿ÉÒÔʹ¹¥»÷Õß»á¼ûÖÇÄܶԽ²»ú²¢Ô¶³Ì¿ªÃÅ£¬£¬£¬£¬»ò´ÓÔ¶³ÌÒ½ÁÆÓ¦ÓÃÖÐ×ß©»¼ÕßµÄÊý¾Ý¡£¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬QuickBloxÒÑͨ¹ýеÄÇå¾²¼Ü¹¹Éè¼ÆºÍAPIÐÞ¸´ÁËÕâЩÎó²î¡£¡£¡£¡£¡£¡£
https://research.checkpoint.com/2023/major-security-flaws-in-popular-quickblox-chat-and-video-framework-expose-sensitive-data-of-millions/
6¡¢FortiGuardÐû²¼½üÆÚ·Ö·¢LokiBotµÄ¹¥»÷»î¶¯µÄ±¨¸æ
7ÔÂ12ÈÕ£¬£¬£¬£¬FortiGuardÐû²¼±¨¸æ£¬£¬£¬£¬ÆÊÎöÁËʹÓÃÎó²îºÍ¶ñÒâºê·Ö·¢¶ñÒâÈí¼þLokiBotµÄ»î¶¯¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±»ñÈ¡²¢ÆÊÎöÁËÁ½ÖÖWordÎĵµ£¬£¬£¬£¬µÚÒ»ÖÖ°üÀ¨Ç¶ÈëÔÚXMLÎļþword/_rels/document.xml.relsÖеÄÍⲿÁ´½Ó£¬£¬£¬£¬µÚ¶þÖÖ°üÀ¨ÔÚ·¿ªÎĵµºóÁ¬Ã¦Ö´ÐкêµÄVBA¾ç±¾¡£¡£¡£¡£¡£¡£ÕâЩÎĵµÊ¹ÓÃÁËÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬£¬£¬£¬¼´CVE-2021-40444ºÍCVE-2022-30190£¬£¬£¬£¬×îÖÕ»áÔÚÄ¿µÄµÄϵͳÖÐ×¢ÈëLokiBot¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±½¨Ò飬£¬£¬£¬ÔÚ´¦Öóͷ£OfficeÎĵµ»òδ֪ÎļþʱӦÉóÉ÷ÐÐÊ¡£¡£¡£¡£¡£¡£
https://www.fortinet.com/blog/threat-research/lokibot-targets-microsoft-office-document-using-vulnerabilities-and-macros


¾©¹«Íø°²±¸11010802024551ºÅ