ShuckwormÍÅ»ïͨ¹ýUSB·Ö·¢Æä×Ô½ç˵ºóÃÅPterodo
°ä²¼¹¦·ò 2023-06-201¡¢ShuckwormÍÅ»ïͨ¹ýUSB·Ö·¢Æä×Ô½ç˵ºóÃÅPterodo
6ÔÂ15ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬SymantecÅû¶Á˶íÂÞ˹ÓйغڿÍÍÅ»ïShuckworm¸üÐµĹ¤¾ß¼¯ºÍϰȾսÊõ¡£¡£¡£¡£¡£Shuckworm³ÖÐø¶ÔÎÚ¿ËÀ¼ÌáÒéÁËÂŴι¥»÷£¬£¬£¬£¬£¬£¬£¬£¬×î½üµÄÖ¸±êÔ̺¬°²È«ÊýÃÅ¡¢¾ü¶ÓºÍµ±¾Ö×éÖ¯¡£¡£¡£¡£¡£ShuckwormʹÓõç×ÓÓʼþ×÷Ϊ³õÊ¼Ï°È¾ÔØÌåÀ´·Ö·¢¶ñÒâÈí¼þ£¬£¬£¬£¬£¬£¬£¬£¬¶øºóʹÓÃÁËÒ»¸öеÄPowerShell¾ç±¾£¬£¬£¬£¬£¬£¬£¬£¬Í¨¹ýUSB·Ö·¢Æä×Ô½ç˵ºóÃŶñÒâÈí¼þPterodo¡£¡£¡£¡£¡£ÔÚ×î½üµÄ»î¶¯ÖУ¬£¬£¬£¬£¬£¬£¬£¬¸ÃÍŻﻹÀûÓúϷ¨·þÎñ³äÈÎC&C·þÎñÆ÷£¬£¬£¬£¬£¬£¬£¬£¬Ô̺¬Telegram£¬£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°TelegramµÄ΢²©Æ½Ì¨£¬£¬£¬£¬£¬£¬£¬£¬¼´Telegraph£¬£¬£¬£¬£¬£¬£¬£¬À´´æ´¢C&CµØÖ·¡£¡£¡£¡£¡£
https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/shuckworm-russia-ukraine-military
2¡¢ÃÀ¹ú·Ò×˹°²ÄÇÖݺͶíÀÕ¸ÔÖÝÊý°ÙÍò¾ÓÃñµÄÐÅϢй¶
6ÔÂ16ÈÕ±¨Â·³Æ£¬£¬£¬£¬£¬£¬£¬£¬Â·Ò×˹°²ÄÇÖݺͶíÀÕ¸ÔÖݵÄMOVEit Transfer°²È«Îļþ´«ÊäϵͳÔâµ½¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬Êý°ÙÍò¾ÓÃñµÄÐÅϢй¶¡£¡£¡£¡£¡£Â·Ò×˹°²ÄÇÖÝ»ú¶¯³µÁ¾°ì¹«ÊÒ(OMV)й©£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÄÜËùÓÐÕ¼ÓиÃÖݵ±¾ÖÐû¸æµÄ¼ÝÊ»ÅÆÕÕ¡¢Éí·ÝÖ¤»òÆû³µµÇ¼ÇÖ¤µÄ¾ÓÃñ¶¼Êܵ½ÁËÓ°Ïì¡£¡£¡£¡£¡£¶íÀÕ¸ÔDMVÒ²°ä²¼ÁËÀàËÆµÄÉêÃ÷£¬£¬£¬£¬£¬£¬£¬£¬³ÆÕâ´ÎÊý¾Ýй¶ÊÂÎñÓ°ÏìÁËԼĪ3500000Ãû¶íÀÕ¸ÔÈË¡£¡£¡£¡£¡£¶íÀÕ¸ÔÖݵ±¾Ö°µÊ¾£¬£¬£¬£¬£¬£¬£¬£¬ËûÃÇÎÞ·¨È·¶¨¾ßÌåµÄÊÜÓ°ÏìÓ×ÎÒ£¬£¬£¬£¬£¬£¬£¬£¬Òò¶ø½¨ÒéËùÓй«Ãñ²ÉȡԤ·À´ëÊ©¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/millions-of-oregon-louisiana-state-ids-stolen-in-moveit-breach/
3¡¢»ªË¶°ä²¼´¹Î£¹Ì¼þ¸üУ¬£¬£¬£¬£¬£¬£¬£¬½¨¸´Æä¶à¿î·ÓÉÆ÷Öеķì϶
ýÌå6ÔÂ19Èճƣ¬£¬£¬£¬£¬£¬£¬£¬»ªË¶°ä²¼ÁË´¹Î£¹Ì¼þ¸üУ¬£¬£¬£¬£¬£¬£¬£¬½¨¸´Æä¶à¸ö·ÓÉÆ÷ÐͺÅÖеÄ9¸ö·ì϶¡£¡£¡£¡£¡£ÆäÖÐÔ̺¬Á½¸öCVSSÆÀ·ÖΪ9.8µÄ·ì϶£¬£¬£¬£¬£¬£¬£¬£¬±ðÀëÊÇNetatalk 3.1.12֮ǰµÄÔ½½çдÈë·ì϶£¨CVE-2018-1160£©£¬£¬£¬£¬£¬£¬£¬£¬¿Éµ¼ÖÂËÁÒâ´úÂëÖ´ÐС£¡£¡£¡£¡£ÒÔ¼°Asuswrt¹Ì¼þÖеÄÄÚ´æ°Ü»µ·ì϶£¨CVE-2022-26376£©£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÄܵ¼Ö»ؾø·þÎñ״̬»òËÁÒâ´úÂëÖ´ÐС£¡£¡£¡£¡£¸Ã¹«Ë¾½¨ÒéÊÜÓ°Ïì·ÓÉÆ÷ÐͺŵÄÓû§¾¡¿ì½«É豸¸üе½×îй̼þ£¬£¬£¬£¬£¬£¬£¬£¬²¢ÎªÎÞÏßÍøÂçºÍ·ÓÉÆ÷ÖÎÀíÒ³ÃæÉèÖõ¥¶ÀµÄ¸´ÔÓµÄÃÜÂë¡£¡£¡£¡£¡£
https://www.securityweek.com/asus-patches-highly-critical-wifi-router-flaws/
4¡¢FTCÖ¸¿Ø»ùÒò¼ì²â¹«Ë¾1health.ioй¶Óû§µÄ½¡È«ÐÅÏ¢
ýÌå6ÔÂ16Èճƣ¬£¬£¬£¬£¬£¬£¬£¬ÃÀ¹úFTCÖ¸¿Ø»ùÒò½¡È«¼ì²â¹«Ë¾1health.ioδÄܱ£»£»£»£»£»¤Ãô¸ÐµÄ»ùÒòºÍ½¡È«ÐÅÏ¢¡£¡£¡£¡£¡£FTC³Æ£¬£¬£¬£¬£¬£¬£¬£¬1healthÒÔǰ³ÆÎªVitagene£¬£¬£¬£¬£¬£¬£¬£¬ÔÚÆäÒþÖÔÕþ²ß·½ÃæºýŪÁ˿ͻ§£¬£¬£¬£¬£¬£¬£¬£¬×·ÒäÐԵظü¸ÄÁ˸ÃÕþ²ß£¬£¬£¬£¬£¬£¬£¬£¬²¢ÔÚÆäɾ³ýÊý¾ÝµÄ¹ý³ÌÖÐÎóµ¼Á˿ͻ§¡£¡£¡£¡£¡£¸Ã¹«Ë¾±»ÒªÇóÏòFTCÖ§¸¶75000ÃÀÔªÓÃÓÚÏû·ÑÕßÍ˿£¬£¬£¬£¬£¬£¬£¬²¢±»²»ÈÝÔÚδ»ñµÃ¿Í»§Ã÷È·Ô޳ɵÄÇé¿öÏÂÓëµÚÈý·½¹²Ïí½¡È«Êý¾Ý£¬£¬£¬£¬£¬£¬£¬£¬»¹±ØÐëÖ´ÐÐÐµİ²È«´òËã¡£¡£¡£¡£¡£1healthµÄÊ×ϯִÐйٳÆFTCµÄµ÷²éÊÇ¡°µ±¾Ö¹ý¶È¹ýÎʵݸÀý¡±¡£¡£¡£¡£¡£
https://cyberscoop.com/ftc-1healthio-health-data-privacy/
5¡¢×êÑÐÈËÔ±ÑÝʾÐÂÐͲàÐÅ·¹¥»÷·½Ê½Freaky Leaky SMS
¾Ý6ÔÂ17ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬£¬£¬Ò»×é×êÑÐÈËÔ±Éè¼ÆÁËÃûΪFreaky Leaky SMSµÄÐÂÐͲàÐÅ·¹¥»÷·½Ê½£¬£¬£¬£¬£¬£¬£¬£¬ËüÒÀÀµÓÚSMS·¢Ëͻ㱨µÄ¹¦·òÀ´´§¶ÈÊÕ¼þÈ˵ĵØÎ»¡£¡£¡£¡£¡£¹¥»÷ÕßÊ×ÏȱØÒªÍøÂçһЩÕÉÁ¿Êý¾Ý£¬£¬£¬£¬£¬£¬£¬£¬ÒÔ±ãÔÚSMS·¢Ëͻ㱨ºÍÖ¸±êµÄµØÎ»Ö®¼ä³ÉÁ¢¾ßÌåµÄ¹ØÁª¡£¡£¡£¡£¡£¹¥»÷Õß°ÑÎÕµÄÖ¸±êÐÐ×ÙÊý¾ÝÔ½¾«È·£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷½×¶ÎMLÄ£ÐÍÔ¤²âÖеĵØÎ»·ÖÀàÁ˾־ÍÔ½ÕýÈ·¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬£¬Í³Ò»×é×êÑÐÈËÔ±ÔÚÈ¥Ä꿪·¢ÁËÀàËÆµÄ°´Ê±¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬¿ÉʹÓÃÐÂÎŽӹܻ㱨´óÌ嶨λSignal¡¢ThreemaºÍWhatsAppµÈ¼´Ê±Í¨Ñ¶¹¤¾ßµÄÓû§¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/sms-delivery-reports-can-be-used-to-infer-recipients-location/
6¡¢MandiantÅû¶UNC4841ÀûÓÃBarracuda ESG·ì϶µÄ¹¥»÷ÏêÇé
MandiantÔÚ6ÔÂ15ÈÕÅû¶ÁËUNC4841ÀûÓÃBarracuda ESG·ì϶µÄ¹¥»÷ÏêÇé¡£¡£¡£¡£¡£Ô¼Äª´Ó2022Äê10ÔÂ10ÈÕÆðÍ·£¬£¬£¬£¬£¬£¬£¬£¬UNC4841ÆðÍ·ÀûÓÃÔ¶³ÌºÅÁî×¢Èë·ì϶£¨CVE-2023-2868£©¡£¡£¡£¡£¡£¹¥»÷ʼÓÚÔ̺¬¶ñÒ⸽¼þµÄµç×ÓÓʼþ£¬£¬£¬£¬£¬£¬£¬£¬µ±Barracuda ESG³¢ÊÔɨÃèÎļþʱ£¬£¬£¬£¬£¬£¬£¬£¬¸½¼þ»áÀûÓø÷ì϶ÔÚÉ豸ÉÏÔ¶³ÌÖ´ÐдúÂë¡£¡£¡£¡£¡£Ò»µ©»ñÈ¡½Ó¼ûȨÏÞ£¬£¬£¬£¬£¬£¬£¬£¬¾Í»áʹÓöñÒâÈí¼þϵÁÐSaltwater¡¢SeaspyºÍSeasideϰȾËü£¬£¬£¬£¬£¬£¬£¬£¬À´´ÓÉ豸ÖÐÇÔÈ¡µç×ÓÓʼþÊý¾Ý¡£¡£¡£¡£¡£Mandiant»¹³ÆBarracudaÉÏÖÜÒªÇóÓû§¸ü»»É豸ÊdzöÓÚÉóÉ÷µÄÖ÷ÕÅ£¬£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚËüÎÞ·¨È·±£ÒÑÆëȫɾ³ý¶ñÒâÈí¼þ¡£¡£¡£¡£¡£
https://www.mandiant.com/resources/blog/barracuda-esg-exploited-globally


¾©¹«Íø°²±¸11010802024551ºÅ