Symantec³ÆBillbug¹¥»÷ÑÇÖÞµØÓòµÄÊý×ÖÖ¤ÊéÐû¸æ»ú¹¹

°ä²¼¹¦·ò 2022-11-17
1¡¢Symantec³ÆBillbug¹¥»÷ÑÇÖÞµØÓòµÄÊý×ÖÖ¤ÊéÐû¸æ»ú¹¹

SymantecÔÚ11ÔÂ15ÈÕ³ÆÆä·¢ÏÖBillbug¹¥»÷ÁËÑÇÖ޵Ķà¸öµ±¾Ö»ú¹¹£¬£¬£¬£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬Ò»¸öÊý×ÖÖ¤ÊéÐû¸æ»ú¹¹ ¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÍÅ»ï×Ô2009ÄêÒÔÀ´Ò»Ïò»îÔ¾£¬£¬£¬£¬£¬£¬£¬£¬Symantec 2019Äê¼Í¼µÄ»î¶¯ÖоßÌå½éÉÜÁ˸ÃÍÅ»ïÈôºÎʹÓúóÃÅHannotogºÍSagerunexµÄ£¬£¬£¬£¬£¬£¬£¬£¬ÕâЩ¹¤¾ßÔÚ×î½üµÄ»î¶¯ÖÐÒ²ÓгöÏÖ ¡£¡£¡£¡£¡£¡£¡£¡£Õâ´Î»î¶¯ÖÁÉÙ´Ó3Ô¾ÍÒÑÆðÍ·£¬£¬£¬£¬£¬£¬£¬£¬Óм£ÏóÅú×¢¹¥»÷ÕßÔÚÀûÓÃÃæÏò¹«¼ÒµÄÀûÓ÷¨Ê½À´»ñµÃ¶ÔÖ¸±êÍøÂçµÄ³õʼ½Ó¼ûȨÏÞ ¡£¡£¡£¡£¡£¡£¡£¡£Óë֮ǰµÄ»î¶¯Ò»Ñù£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßҲʹÓÃÁ˶àÖÖÁ½Óù¤¾ß¼°×Ô½ç˵¶ñÒâÈí¼þ£¬£¬£¬£¬£¬£¬£¬£¬ÈçAdFind¡¢Directory¡¢Winmail¡¢WinRAR¡¢PingºÍTracertµÈ ¡£¡£¡£¡£¡£¡£¡£¡£

https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/espionage-asia-governments-cert-authority

2¡¢VaronisÅû¶Zendesk ExploreÖÐSQL×¢ÈëµÈ·ì϶µÄϸ½Ú

VaronisÔÚ11ÔÂ15ÈÕÅû¶ÁËZendesk ExploreÖÐÁ½¸ö·ì϶µÄϸ½Ú ¡£¡£¡£¡£¡£¡£¡£¡£ÆäÖÐÒ»¸öÊÇSQL×¢Èë·ì϶£¬£¬£¬£¬£¬£¬£¬£¬¸Ã·ìÏ¶Éæ¼°ÆäGraphQL APIÖеÄSQL×¢È룬£¬£¬£¬£¬£¬£¬£¬¿É±»ÓÃÀ´Ð¹Â¶×÷ΪÖÎÀíÔ±´æ´¢ÔÚÊý¾Ý¿âÖеÄËùÓÐÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬£¬Ô̺¬ÓʼþµØÖ·¡¢¹¤µ¥ÒÔ¼°ÓëʵʱÆÚÀíµÄ¶Ô»°µÈ ¡£¡£¡£¡£¡£¡£¡£¡£ÁíÒ»¸ö·ì϶ÊÇÉæ¼°Óë²éÎÊÖ´ÐÐAPIÓйصÄÂß¼­½Ó¼ûÎÊÌ⣬£¬£¬£¬£¬£¬£¬£¬¸ÃAPI±»ÅäÖÃΪÔËÐвéÎÊ£¬£¬£¬£¬£¬£¬£¬£¬¶ø²»²é³­½øÐÐŲÓõÄÓû§ÊÇ·ñÓÐ×ã¹»µÄȨÏÞÕâÑù×ö ¡£¡£¡£¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬£¬£¬£¬ÕâЩ·ì϶Òѱ»½¨¸´ ¡£¡£¡£¡£¡£¡£¡£¡£

https://securityaffairs.co/wordpress/138579/hacking/zendesk-explore-critical-flaws.html

3¡¢LazarusÀûÓúóÃÅDTrack¹¥»÷Å·ÖÞºÍÀ­¶¡ÃÀÖÞµÄ×éÖ¯

¾Ý11ÔÂ15ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬£¬£¬³¯ÏʺڿÍÍÅ»ïLazarusÔÚʹÓÃа汾µÄDTrackºóÃÅÀ´¹¥»÷Å·ÖÞºÍÀ­¶¡ÃÀÖÞµÄ×éÖ¯ ¡£¡£¡£¡£¡£¡£¡£¡£Ö¸±êÐÐÒµÔ̺¬×êÑÐÖÐÐÄ¡¢Õþ²ß»ú¹¹¡¢»¯Ñ§Æ·Ôì×÷ÉÌ¡¢IT·þÎñÌṩÉÌ¡¢µçÐÅÌṩÉÌ¡¢¹«ÓÃÊÂÒµ·þÎñÌṩÉ̺ͽÌÓý ¡£¡£¡£¡£¡£¡£¡£¡£ÔÚеĻÖУ¬£¬£¬£¬£¬£¬£¬£¬DTrackͨ³£Ê¹ÓÃÓëºÏ·¨ÎļþÓйصÄÎļþÃû½øÐзַ¢£¬£¬£¬£¬£¬£¬£¬£¬ÈçÒ»¸öÑù±¾ÒÔ¡°NvContainer.exe¡±ÎªÃû·Ö·¢£¬£¬£¬£¬£¬£¬£¬£¬ËüÓëºÏ·¨µÄNVIDIAÎļþͬÃû ¡£¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬£¬DTrackÈÔ³ÖÐøÍ¨¹ýÇÔÈ¡µÄƾ֤ÈëÇÖÍøÂç»òÀûÓÃÍøÉ϶³öµÄ·þÎñÆ÷À´½øÐзַ¢ ¡£¡£¡£¡£¡£¡£¡£¡£

https://securelist.com/dtrack-targeting-europe-latin-america/107798/

4¡¢×êÑÐÍŶӷ¢ÏÖ¿ÉÓ°Ï캽ÌìÆ÷ºÍ·É»úµÄ¹¥»÷·½Ê½PCspooF

ýÌå11ÔÂ15ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬£¬£¬×êÑÐÍŶӷ¢ÏÖÁËÒ»ÖÖÕë¶Ô¹¦·ò´¥·¢ÒÔÌ«Íø(TTE)µÄÐÂÐ͹¥»÷²½Öè ¡£¡£¡£¡£¡£¡£¡£¡£TTEÊôÓÚ»ìºÏ¹Ø¼üÐÔÍøÂçµÄÍøÂç¼¼ÊõÖ®Ò»£¬£¬£¬£¬£¬£¬£¬£¬ÆäÖÐÓµÓÐ·ÖÆçʱÐòºÍÈÝ´íÒªÇóµÄÁ÷Á¿¹²´æÓÚͳһÎïÀíÍøÂçÖÐ ¡£¡£¡£¡£¡£¡£¡£¡£¸Ã¼¼ÊõÓÃÓÚ°²È«»ù´¡ÉèÊ©£¬£¬£¬£¬£¬£¬£¬£¬¿Éµ¼ÖÂΪº½ÌìÆ÷ºÍ·É»úÌṩ¶¯Á¦µÄϵͳ³öÏÖ¹ÊÕÏ ¡£¡£¡£¡£¡£¡£¡£¡£ÕâÊÇʹÓöñÒâÉ豸ͨ¹ýÒÔÌ«ÍøµçÀ½«µç´Å×ÌÈÅ(EMI)×¢ÈëTTE»¥»»»úÀ´ÊµÏֵ쬣¬£¬£¬£¬£¬£¬£¬¿ÉÓÐЧµØÓÕʹ»¥»»»ú·¢ËÍ¿´ËÆÕæÊµµÄͬ²½ÐÂÎŲ¢ÈÃËüÃDZ»ÆäËûTTEÉ豸½ÓÊÜ ¡£¡£¡£¡£¡£¡£¡£¡£×÷Ϊ»º½â´ëÊ©£¬£¬£¬£¬£¬£¬£¬£¬×êÑÐÈËÔ±½¨ÒéʹÓùâñîºÏÆ÷»òÀËÓ¿±£»£»£»£»£»¤Æ÷À´×èÖ¹µç´Å×ÌÈÅ ¡£¡£¡£¡£¡£¡£¡£¡£

https://thehackernews.com/2022/11/pcspoof-new-vulnerability-affects.html

5¡¢ÒÁÀÊÓйغڿÍÀûÓÃLog4Shell·ì϶ÈëÇÖÃÀ¹úµ±¾Ö»ú¹¹

11ÔÂ16ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬FBIºÍCISA½áºÏ°ä²¼ÁËÒ»·Ý¹«¸æ£¬£¬£¬£¬£¬£¬£¬£¬³ÆÓëÒÁÀÊÓйصĺڿÍÈëÇÖÁËÒ»¸öµ±¾Ö»ú¹¹²¢×°ÖÃÁËXMRig¿ó¹¤¶ñÒâÈí¼þ ¡£¡£¡£¡£¡£¡£¡£¡£¹«¸æ³Æ£¬£¬£¬£¬£¬£¬£¬£¬´Ó2022Äê6ÔÂÖÐÑ®µ½7Ô£¬£¬£¬£¬£¬£¬£¬£¬CISAÔÚÁª¹úÃñÓÃÐÐÕþ²¿ÃÅ(FCEB)×éÖ¯Öй۲쵽ÁË¿ÉÒɵÄAPT»î¶¯ ¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÀûÓÃ佨¸´µÄVMware Horizon·þÎñÆ÷ÖеÄLog4Shell·ì϶£¬£¬£¬£¬£¬£¬£¬£¬×°ÖÃXMRig¿ó¹¤Èí¼þ£¬£¬£¬£¬£¬£¬£¬£¬ºáÏòÒÆ¶¯µ½Óò½ÚÔìÆ÷(DC)£¬£¬£¬£¬£¬£¬£¬£¬ÇÔȡʹ´¦£¬£¬£¬£¬£¬£¬£¬£¬¶øºóÖ²ÈëNgrok·´Ïò´úÀíÀ´ÔÚ¶à¸öÉ豸ÉÏά³ÖÓÆ¾ÃÐÔ ¡£¡£¡£¡£¡£¡£¡£¡£CISA ºÍ FBI °ä²¼´ËCSAÌṩºÚ¿ÍµÄTTPºÍIOC£¬£¬£¬£¬£¬£¬£¬£¬ÒÔÔ®ÊÖ×éÖ¯¼ì²âºÍ·ÀÓùÓйصĹ¥»÷ ¡£¡£¡£¡£¡£¡£¡£¡£

https://www.cisa.gov/uscert/ncas/alerts/aa22-320a

6¡¢Kaspersky°ä²¼¹ØÓÚ2023ÄêAPT¹¥»÷»î¶¯µÄÔ¤²â»ã±¨

KasperskyÔÚ11ÔÂ14ÈÕ°ä²¼Á˹ØÓÚ2023ÄêAPT¹¥»÷»î¶¯µÄÔ¤²â»ã±¨ ¡£¡£¡£¡£¡£¡£¡£¡£»ã±¨Ô¤²âÔÚ2023Ä꣬£¬£¬£¬£¬£¬£¬£¬½«³öÏÖ´óÁ¿µÄ·ÛËéÐÔÍøÂç¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬Ó°Ïìµ±²¿ÃÅÃź͹ؼüÐÐÒµ£»£»£»£»£»Óʼþ·þÎñÆ÷½«³ÉΪ³ÁÒªÖ¸±ê£¬£¬£¬£¬£¬£¬£¬£¬ºÜ¿ÉÄÜËùÓÐÖØÒªµç×ÓÓʼþÈí¼þ¶¼³öÏÖ0-day£»£»£»£»£»Ò»Ð©ÓµÓÐÓ°ÏìÁ¦µÄ²¡¶¾Ã¿6-7Äê²úÉúÒ»´Î£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÄܳöÏÖÏÂÒ»¸öWannaCry£»£»£»£»£»APT¹¥»÷ÍŻォָ±êתÏòÎÀÐǼ¼Êõ¡¢³ö²úÉ̺ÍÔËÓªÉÌ£»£»£»£»£»¸ü¶àAPT×éÖ¯½«´ÓCobaltStrike×ªÒÆµ½ÆäËü´úÌæ¹æ»®µÈ ¡£¡£¡£¡£¡£¡£¡£¡£

https://securelist.com/advanced-threat-predictions-for-2023/107939/