×êÑÐÈËÔ±³Æ¶ñÒâÈí¼þAVreconÒÑϰȾ7Íò¶àSOHO·ÓÉÆ÷

°ä²¼¹¦·ò 2023-07-17

1¡¢×êÑÐÈËÔ±³Æ¶ñÒâÈí¼þAVreconÒÑϰȾ7Íò¶àSOHO·ÓÉÆ÷


Black Lotus LabsÔÚ7ÔÂ12ÈÕ³Æ £¬£¬£¬£¬£¬£¬¶ñÒâÈí¼þAVreconÒÑϰȾ³¬¹ý70000¸ö»ùÓÚLinuxµÄSOHO·ÓÉÆ÷ £¬£¬£¬£¬£¬£¬²¢½«ËüÃÇÔö³¤µ½½©Ê¬ÍøÂçÖС£¡£¡£¡£¡£³ýÁË2021Äê5Ô³õ´Î±»·¢ÏÖÖ®±í £¬£¬£¬£¬£¬£¬AVreconÒѾ­ÔËÐÐÁËÁ½Äê¶à¶øÎ´±»¼ì²âµ½¡£¡£¡£¡£¡£×êÑÐÈËÔ±´§¶È £¬£¬£¬£¬£¬£¬¸Ã»î¶¯ËƺõÖ¼ÔÚ´´½¨Ò»¸ö°ÂÃØÍøÂç £¬£¬£¬£¬£¬£¬ÒÔ͵͵µØ·¢Õ¹ÃÜÂëÅçÈ÷ºÍÊý×Ö¸æ°×ڲƭµÈһϵÁй¥»÷»î¶¯¡£¡£¡£¡£¡£ÓÉÓÚ¶ñÒâÈí¼þµÄÒñ±ÎÐÔ £¬£¬£¬£¬£¬£¬±»Ï°È¾É豸µÄËùÓÐÕߺÜÉÙ°ÑÎȵ½¹¤×÷Öжϻò´ø¿íµÄËðʧ¡£¡£¡£¡£¡£°²È«ÍŶÓͨ¹ý½«½©Ê¬ÍøÂçµÄC2ÔÚÆäÖ÷¸ÉÍøÂçÉϽøÐÐÎÞЧ·ÓÉÀ´Ó¦¶Ô´ËÀàÍþв¡£¡£¡£¡£¡£


https://blog.lumen.com/routers-from-the-underground-exposing-avrecon/  


2¡¢ÎÚ¿ËÀ¼CERT-UAÅû¶UAC-0010ÍÅ»ï½üÆÚ¹¥»÷»î¶¯µÄϸ½Ú


7ÔÂ13ÈÕ £¬£¬£¬£¬£¬£¬ÎÚ¿ËÀ¼CERT-UAÅû¶ÁËUAC-0010£¨ÓÖ³ÆGamaredon£©ÍÅ»ï½üÆÚ¹¥»÷»î¶¯µÄϸ½Ú¡£¡£¡£¡£¡£Gamaredon»á½øÐм±¾ç¹¥»÷ £¬£¬£¬£¬£¬£¬ÔÚ³õ´ÎÈëÇÖºó30·ÖÖÓ¾ÍÆðÍ·ÇÔÈ¡Êý¾Ý¡£¡£¡£¡£¡£Ê×ÏÈÀûÓô¹µöÓʼþºÍÐÂÎÅ £¬£¬£¬£¬£¬£¬ÓÕʹָ±ê´ò¿ª¶øÒѸ½¼þ £¬£¬£¬£¬£¬£¬¶øºóÏÂÔØPowerShell¾ç±¾ºÍ¶ñÒâÈí¼þ£¨Í¨³£ÊÇGammaSteel£©¡£¡£¡£¡£¡£´Ë±í £¬£¬£¬£¬£¬£¬¹¥»÷ÕßÿÖÜÔÚ±»Ï°È¾µÄϵͳÉÏÖ²Èë¶à´ï120¸ö¶ñÒâÎļþ £¬£¬£¬£¬£¬£¬ÒÔÔö³¤ÔÙ´ÎϰȾµÄ¿ÉÄÜÐÔ¡£¡£¡£¡£¡£CERT-UA°µÊ¾ £¬£¬£¬£¬£¬£¬ÕмܴËÀ๥»÷µÄ×î¼Ñ²½ÖèÊÇ×èÖ¹»òÏÞ¶Èmshta.exe¡¢wscript.exe¡¢cscript.exeºÍpowershell.exeµÄδ¾­ÊÚȨִÐС£¡£¡£¡£¡£


https://cert.gov.ua/article/5160737


3¡¢WordPress²å¼þAIOS¼Í¼Ã÷ÎÄÃÜÂëÓ°Ïì100¶àÍò¸öÍøÕ¾


¾ÝýÌå7ÔÂ14ÈÕ±¨Â· £¬£¬£¬£¬£¬£¬WordPress²å¼þAll-In-One Security(AIOS)±»·¢ÏÖ»áÒÔÃ÷ÎÄ´ó¾Ö´æ´¢Óû§ÃÜÂë £¬£¬£¬£¬£¬£¬´Ó¶øÊ¹ÕÊ»§°²È«Ãæ¶Ô·çÏÕ¡£¡£¡£¡£¡£¸Ã²å¼þ±»³¬¹ý100Íò¸öÍøÕ¾Ê¹Óà £¬£¬£¬£¬£¬£¬ÓÐЧ»§»ã±¨³Æ £¬£¬£¬£¬£¬£¬Ëü²»½ö½«Óû§µÇ¼³¢ÊԼͼµ½aiowps_audit_logÊý¾Ý¿â±í£¨ÓÃÓÚ¸ú×ٵǼ¡¢×¢ÏúºÍµÇ¼ʧ°Ü¶Îñ£© £¬£¬£¬£¬£¬£¬»¹¼Í¼ÁËÊäÈëµÄÃÜÂë¡£¡£¡£¡£¡£Ä¿Ç° £¬£¬£¬£¬£¬£¬AIOS¹©¸øÉÌÒÑÓÚ7ÔÂ11ÈÕ°ä²¼ÁË5.2.0°æ±¾ £¬£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬Ô¤·À±£ÁôÃ÷ÎÄÃÜÂë²¢¶Ï¸ù¾ÉÌõ¿î±ê½¨¸´·¨Ê½¡£¡£¡£¡£¡£Í³¼ÆÊý¾ÝÏÔʾ £¬£¬£¬£¬£¬£¬½ØÖÁĿǰ»¹Óг¬¹ý750000¸öÍøÕ¾Î´¸üР£¬£¬£¬£¬£¬£¬ÈÝÒ×Ôâµ½¹¥»÷¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/wordpress-aios-plugin-used-by-1m-sites-logged-plaintext-passwords/


4¡¢Ð½×Ê·þÎñ¹«Ë¾UKGÔÞ³ÉÒÔ600ÍòÃÀÔªºÍ½âÊý¾Ýй¶µÄËßËÏ 


ýÌå7ÔÂ12ÈÕ³Æ £¬£¬£¬£¬£¬£¬Ð½×Ê·þÎñÌṩÉÌUKGÔÞ³ÉÒÔ600ÍòÃÀÔªºÍ½â2021ÄêÊý¾Ýй¶µÄËßËÏ¡£¡£¡£¡£¡£2021Äê12ÔµÄÀÕË÷¹¥»÷µ¼ÖÂUKGµÄKronos˽ÓÐÔÆ²¿ÃŲúÆ·ÀëÏß £¬£¬£¬£¬£¬£¬»¹µ¼Ö²¿ÃÅÔ±¹¤ºÍ³Ð°üÉ̵ÄÐÅϢй¶¡£¡£¡£¡£¡£Õâ´ÎÊÂÎñÓ°ÏìÁ˰Ùʹ«Ë¾¡¢Å¦Ô¼Êн»Í¨¾Ö¡¢Ó¢¹ú³¬ÊÐSainsburyºÍ¶à¸öÒ½ÁÆ»ú¹¹¡£¡£¡£¡£¡£UKGÓÚ2022Äê1Ô±»¸æ×´ £¬£¬£¬£¬£¬£¬ÆäʱÌá³öÁ˾ÅÏîËßËÏÀíÓÉ £¬£¬£¬£¬£¬£¬Ô̺¬ºöÂÔ¡¢²»µ±µÃÀû¡¢Î¥Ô¼ºÍÎ¥·´¼ÓÖÝÒþÖÔ·¨µÈ¡£¡£¡£¡£¡£UKGÔÞ³ÉÖ§¸¶550ÍòÃÀÔªÓÃÓÚË÷Åâ £¬£¬£¬£¬£¬£¬²¢³ÐŵÔÚ±ØÒªÊ±×·¼Ó50ÍòÃÀÔª¡£¡£¡£¡£¡£


https://www.wsj.com/articles/payroll-services-provider-ukg-agrees-to-6-million-settlement-in-data-breach-lawsuit-8ea87f01


5¡¢Uptycs·¢ÏÖ¼ÙµÄCVE-2023-35829µÄPoC·Ö·¢¶ñÒâÈí¼þ


UptycsÔÚ7ÔÂ12ÈÕ³ÆÆä·¢ÏÖÁËÒ»¸öαÔìµÄ·ì϶PoC £¬£¬£¬£¬£¬£¬»á·Ö·¢LinuxÃÜÂëÇÔÈ¡¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¸ÃPoCÐû³ÆÊÇÕë¶ÔCVE-2023-35829µÄ·ì϶ÀûÓà £¬£¬£¬£¬£¬£¬ÕâÊÇÒ»¸öÓ°Ïì6.3.2֮ǰµÄLinuxÄں˵ĿªÊͺóʹÓ÷ì϶¡£¡£¡£¡£¡£µ«ÏÖʵÉÏ £¬£¬£¬£¬£¬£¬ËüÊÇÁíÒ»¸öLinuxÄں˷ì϶CVE-2022-34918µÄ¾É°æºÏ·¨·ì϶ÀûÓᣡ£¡£¡£¡£¸Ã¶ñÒâÈí¼þ¿ÉÄÜÇÔÈ¡Ö÷»úÃû¡¢Óû§ÃûºÍÖ÷Ŀ¼ÄÚÈÝµÄÆëÈ«ÁбíµÈ¡£¡£¡£¡£¡£´Ë±í £¬£¬£¬£¬£¬£¬¹¥»÷Õß»¹Í¨¹ý½«SSHÃÜÔ¿Ôö³¤µ½authorized_keysÎļþÖÐ £¬£¬£¬£¬£¬£¬ÒÔʵÏÖ¶ÔÖ¸±êϵͳµÄÆëÈ«½ÚÔì¡£¡£¡£¡£¡£


https://www.uptycs.com/blog/new-poc-exploit-backdoor-malware


6¡¢SlashNext°ä²¼»ùÓÚAIµÄºÚ¿Í¹¤¾ßWormGPTµÄ·ÖÎö»ã±¨


7ÔÂ13ÈÕ £¬£¬£¬£¬£¬£¬SlashNext°ä²¼ÁËÐÂÐÍÌìÉúʽÈËΪÖÇÄܺڿ͹¤¾ßWormGPTµÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¸Ã¹¤¾ß½«×Ô¼ºÊÓΪGPTÄ£Ð͵ĺÚñ´úÌæÆ· £¬£¬£¬£¬£¬£¬×¨Îª¶ñÒâ»î¶¯¶øÉè¼Æ¡£¡£¡£¡£¡£WormGPTÊÇÒ»¿î»ùÓÚGPTJ˵»°Ä£Ð͵ÄAIÄ£¿£¿£¿£¿£¿£¿£¿é £¬£¬£¬£¬£¬£¬ÓÚ2021Ä꿪·¢ £¬£¬£¬£¬£¬£¬ÓµÓÐÎÞÏÞ×Ö·ûÖ§³Ö¡¢Ì¸ÌìÄÚ´æ±£ÁôºÍ´úÂëÌåʽ»¯µÈÖ°ÄÜ¡£¡£¡£¡£¡£¹¥»÷ÕßÄܹ»ÀûÓô˹¤¾ßÌìÉúÓÐ˵·þÁ¦µÄµç×ÓÓʼþ £¬£¬£¬£¬£¬£¬½øÐи´ÔӵĴ¹µö¹¥»÷ºÍBEC¹¥»÷¡£¡£¡£¡£¡£


https://slashnext.com/blog/wormgpt-the-generative-ai-tool-cybercriminals-are-using-to-launch-business-email-compromise-attacks/