SonicWall´¹Î£¸üн¨¸´GMSºÍAnalyticsÖеÄ15¸ö·ì϶
°ä²¼¹¦·ò 2023-07-141¡¢SonicWall´¹Î£¸üн¨¸´GMSºÍAnalyticsÖеÄ15¸ö·ì϶
7ÔÂ12ÈÕ£¬£¬£¬£¬£¬SonicWall°ä²¼´¹Î£¸üУ¬£¬£¬£¬£¬½¨¸´ÁËGMS·À»ðǽÖÎÀíϵͳºÍAnalyticsÍøÂç»ã±¨ÒýÇæÈí¼þÖеÄ15¸ö·ì϶¡£¡£¡£¡£¡£ÆäÖнÏΪÑϳÁµÄÊÇWeb·þÎñÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶£¨CVE-2023-34124£©¡¢¶à¸öδ¾Éí·ÝÑéÖ¤µÄSQLºÍ°²È«¹ýÂËÆ÷ÈÆ¹ý·ì϶£¨CVE-2023-34133£©¡¢Í¨¹ýWeb·þÎñ¶ÁÈ¡ÃÜÂëhash·ì϶£¨CVE-2023-34134£©ºÍCASÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶£¨CVE-2023-34137£©¡£¡£¡£¡£¡£ÕâЩ·ì϶ÉÐδ±»ÀûÓ㬣¬£¬£¬£¬¸Ã¹«Ë¾½¨ÒéʹÓÃÊÜÓ°Ïì²úÆ·µÄÓû§Á¢¼´ÀûÓò¹¶¡¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/sonicwall-warns-admins-to-patch-critical-auth-bypass-bugs-immediately/
2¡¢BlackLotus UEFI BootkitÔ´´úÂëÔÚGitHubÉϹ«¿ª
¾Ý7ÔÂ13ÈÕ±¨Â·£¬£¬£¬£¬£¬BlackLotus UEFI BootkitÔ´´úÂëÔÚGitHubÉϹ«¿ª¡£¡£¡£¡£¡£¸ÃbootkitרΪWindowsÉè¼Æ£¬£¬£¬£¬£¬È¥Äê10Ô³ʴ˿̺ڿÍÂÛ̳£¬£¬£¬£¬£¬Ðû³ÆÓµÓÐAPT¼¶´ËÍâÖ°ÄÜ£¬£¬£¬£¬£¬ÀýÈçÈÆ¹ýUACÒÔ¼°½ûÓð²È«ÀûÓúͷÀÓù»úÔì¡£¡£¡£¡£¡£BlackLotus×î³õÔÚºÚ¿ÍÂÛ̳ÉϵÄÊÛ¼ÛΪ5000ÃÀÔª£¬£¬£¬£¬£¬´Ë¿Ì£¬£¬£¬£¬£¬ÆäÔ´´úÂë±»Óû§YukariÔÚ°ä²¼ÔÚGitHubÉÏ£¬£¬£¬£¬£¬Ê¹Ëü¿É¹©ÈκÎÈËʹÓᣡ£¡£¡£¡£Ð¹Â¶µÄÔ´´úÂëɾ³ýÁËBaton Drop·ì϶£¨CVE-2022-21894 £©£¬£¬£¬£¬£¬ÖØÒªÔ̺¬rootkit²¿ÃźÍÈÆ¹ý°²È«Æô¶¯µÄbootkit´úÂë¡£¡£¡£¡£¡£
https://www.securityweek.com/blacklotus-uefi-bootkit-source-code-leaked-on-github/
3¡¢Mandiant¹«¿ªÁ½Æðͨ¹ýUSB·Ö·¢µÄ¶ñÒâÈí¼þ»î¶¯µÄϸ½Ú
MandiantÔÚ7ÔÂ11ÈÕй©Æä·¢ÏÖÁËÁ½Æðͨ¹ýUSB·Ö·¢µÄ¶ñÒâÈí¼þ»î¶¯¡£¡£¡£¡£¡£µÚÒ»¸ö»î¶¯±»¹éÒòÓÚTEMP.HEX£¬£¬£¬£¬£¬ÀûÓöñÒâDLLÎļþ¼ÓÔØºóÃÅSogu¡£¡£¡£¡£¡£¸Ã»î¶¯Õë¶ÔÈ«Çò¶à¸öÐÐÒµ£¬£¬£¬£¬£¬²¢ÊÔͼ´ÓÖ¸±êÍÆËã»úÖÐÇÔÈ¡Êý¾Ý£¬£¬£¬£¬£¬ÆäÖдóÎÞÊýÖ¸±êÊôÓÚÔìÒ©¡¢IT¡¢ÄÜÔ´¡¢Í¨Ñ¶¡¢ÎÀÉúºÍÎïÊ¢ÐÐÒµ¡£¡£¡£¡£¡£µÚ¶þ¸ö»î¶¯·Ö·¢»ùÓÚshellcodeµÄºóÃÅSnowydrive£¬£¬£¬£¬£¬Ëü±»¼ÓÔØµ½ºÏ·¨¹ý³ÌCUZ.exeÖУ¬£¬£¬£¬£¬¾ßº±¼û¾Ýй¶¡¢·´Ïòshell¡¢ºÅÁîÖ´ÐкͿúËŵÈÖ°ÄÜ£¬£¬£¬£¬£¬±»¹éÒòÓÚÕë¶ÔÑÇÖÞʯÓͺÍÌìÈ»Æø¹«Ë¾µÄUNC4698¡£¡£¡£¡£¡£
https://www.mandiant.com/resources/blog/infected-usb-steal-secrets
4¡¢2023ÄêÉϰëÄêÈ«ÇòµÄ¼ÓÃÜÀÕË÷½ð¶î¸ß´ïÔ¼4.5ÒÚÃÀÔª
ChainaanalysisÔÚ7ÔÂ12Èճƣ¬£¬£¬£¬£¬¾ÀúÁË»ìÂÒµÄ2022ÄêÖ®ºó£¬£¬£¬£¬£¬2023ÄêÆù½ñΪֹÊǼÓÃÜÇ®±Ò¸´ËÕµÄÒ»Äê¡£¡£¡£¡£¡£½ØÖÁ6Ô·ݣ¬£¬£¬£¬£¬ÀÕË÷½ð¶îÒÑÖÁÉÙ4.491ÒÚÃÀÔª£¬£¬£¬£¬£¬´ïµ½ÁË2022ÄêÕûÄêÀÕË÷Èí¼þ×ÜÊÕÈëµÄ90%¡£¡£¡£¡£¡£ÈôÊÇά³ÖÕâһˮƽ£¬£¬£¬£¬£¬2023ÄêÕûÄêµÄÀÕË÷½ð¶î½«½ü9ÒÚÃÀÔª¡£¡£¡£¡£¡£×êÑÐÈËÔ±ÒÔΪ£¬£¬£¬£¬£¬¹¥»÷Õ߯ðÍ·Õë¶ÔÄܹ»ÀÕË÷µ½´ó±Ê½ðÇ®µÄ´óÐÍ×éÖ¯£¬£¬£¬£¬£¬µ¼ÖÂÁËÕâÖÖ´ó·ùÔö³¤¡£¡£¡£¡£¡£¸ß¶îÊê½ðÉæ¼°µÄÀÕË÷ÍÅ»ïÖØÒªÔ̺¬BlackBasta¡¢LockBit¡¢ALPHVºÍClop¡£¡£¡£¡£¡£ÆäÖÐClopµÄ¾ùÔÈÊê½ðΪ170ÍòÃÀÔª£¬£¬£¬£¬£¬Êê½ðµÄÖÐλÊýΪ190ÍòÃÀÔª¡£¡£¡£¡£¡£
https://blog.chainalysis.com/reports/crypto-crime-midyear-2023-update-ransomware-scams/
5¡¢Check Point°ä²¼QuickBlox¿ò¼ÜÖзì϶µÄ·ÖÎö»ã±¨
7ÔÂ12ÈÕ£¬£¬£¬£¬£¬Check Point³ÆÆä¶ÔQuickBlox¿ò¼ÜµÄSDKºÍAPIµÄ°²È«ÐÔ½øÐÐ×êÑУ¬£¬£¬£¬£¬·¢ÏÖÁË¿ÉÄÜΣ¼°Êý°ÙÍòÓû§Ó×ÎÒÐÅÏ¢µÄ·ì϶¡£¡£¡£¡£¡£QuickBloxÊÇÒ»ÖÖÊ¢ÐеÄ̸ÌìºÍÊÓÆµ·þÎñ£¬£¬£¬£¬£¬ÖØÒªÓÃÓÚÔ¶³ÌÒ½ÁÆ¡¢½ðÈÚºÍÖÇÄÜÎïÁªÍøÉ豸¡£¡£¡£¡£¡£×êÑÐÈËÔ±»¹Ú¹ÊÏçËһЩ¹ÖÒìµÄ¹¥»÷·½Ê½£¬£¬£¬£¬£¬ÀýÈ磬£¬£¬£¬£¬Äܹ»Ê¹¹¥»÷Õß½Ó¼ûÖÇÄܶԽ²»ú²¢Ô¶³Ì¿ªÃÅ£¬£¬£¬£¬£¬»ò´ÓÔ¶³ÌÒ½ÁÆÀûÓÃÖÐй©»¼ÕßµÄÊý¾Ý¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬QuickBloxÒÑͨ¹ýÐµİ²È«¼Ü¹¹Éè¼ÆºÍAPI½¨¸´ÁËÕâЩ·ì϶¡£¡£¡£¡£¡£
https://research.checkpoint.com/2023/major-security-flaws-in-popular-quickblox-chat-and-video-framework-expose-sensitive-data-of-millions/
6¡¢FortiGuard°ä²¼½üÆÚ·Ö·¢LokiBotµÄ¹¥»÷»î¶¯µÄ»ã±¨
7ÔÂ12ÈÕ£¬£¬£¬£¬£¬FortiGuard°ä²¼»ã±¨£¬£¬£¬£¬£¬·ÖÎöÁËÀûÓ÷ì϶ºÍ¶ñÒâºê·Ö·¢¶ñÒâÈí¼þLokiBotµÄ»î¶¯¡£¡£¡£¡£¡£×êÑÐÈËÔ±»ñÈ¡²¢·ÖÎöÁËÁ½ÖÖWordÎĵµ£¬£¬£¬£¬£¬µÚÒ»ÖÖÔ̺¬Ç¶ÈëÔÚXMLÎļþword/_rels/document.xml.relsÖÐµÄ±í²¿Á´½Ó£¬£¬£¬£¬£¬µÚ¶þÖÖÔ̺¬ÔÚ´ò¿ªÎĵµºóÁ¢¼´Ö´ÐкêµÄVBA¾ç±¾¡£¡£¡£¡£¡£ÕâЩÎĵ·ûÓÃÁËÔ¶³Ì´úÂëÖ´Ðзì϶£¬£¬£¬£¬£¬¼´CVE-2021-40444ºÍCVE-2022-30190£¬£¬£¬£¬£¬×îÖÕ»áÔÚÖ¸±êµÄϵͳÖÐ×¢ÈëLokiBot¡£¡£¡£¡£¡£×êÑÐÈËÔ±½¨Ò飬£¬£¬£¬£¬ÔÚ´¦ÖÃOfficeÎĵµ»òδ֪ÎļþʱӦÉóÉ÷ÐÐÊ¡£¡£¡£¡£¡£
https://www.fortinet.com/blog/threat-research/lokibot-targets-microsoft-office-document-using-vulnerabilities-and-macros


¾©¹«Íø°²±¸11010802024551ºÅ