VulnCheckÅû¶ӰÏì90¶àÍǫ̀MikroTikÉ豸µÄÌáȨ·ì϶
°ä²¼¹¦·ò 2023-07-271¡¢VulnCheckÅû¶ӰÏì90¶àÍǫ̀MikroTikÉ豸µÄÌáȨ·ì϶
VulnCheckÔÚ7ÔÂ25ÈÕÅû¶ÁËMikroTik RouterOS·ÓÉÆ÷µÄÖеÄÌáȨ·ì϶£¨CVE-2023-30799£©¡£¡£¡£¡£¡£¡£¸Ã·ì϶¿É±»Õ¼ÓÐÖÎÀíÔ¹ØÊ»§µÄÔ¶³Ì¹¥»÷Õßͨ¹ýÉ豸µÄWinbox»òHTTP½Ó¿Ú£¬£¬£¬£¬£¬½«È¨ÏÞÌáÉýΪ³¬µÈÖÎÀíÔ±¡£¡£¡£¡£¡£¡£ÕâÊÇÓÉÓÚMikrotik RouterOS²Ù×÷ϵͳÎÞ·¨Ô¤·ÀÃÜÂëµÄ±©Á¦¹¥»÷£¬£¬£¬£¬£¬²¢ÇÒ»¹×Ô´øÄ¬ÈÏ"admin"Óû§¡£¡£¡£¡£¡£¡£Ô¤¼ÆÔ¼ÓÐ50ÍòºÍ90Íò¸öRouterOSÏµÍ³Ãæ¶Ôͨ¹ýWebºÍWinbox½Ó¿Ú±»ÀûÓõķçÏÕ¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±½¨ÒéÓû§¾¡¿ìÀûÓÃ×îиüÐÂÀ´½¨¸´¸Ã·ì϶¡£¡£¡£¡£¡£¡£
https://vulncheck.com/blog/mikrotik-foisted-revisited
2¡¢ºÚ¿ÍÔÚ°µÍøÏúÊÛÐû³Æ´Ó°£¼°ÎÀÉú²¿ÇÔÈ¡µÄ200Íò±Ê¼Í¼
ýÌå7ÔÂ25ÈÕ±¨Â·³Æ£¬£¬£¬£¬£¬Ä³ºÚ¿ÍÍÅ»ïÐû³Æ´Ó°£¼°ÎÀÉúºÍÈ˶¡²¿ÃÅÇÔÈ¡ÁËÁ½°ÙÍò±Ê¼Í¼¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±ÓÚ7ÔÂ25ÈÕÔÚºÚ¿ÍÂÛ̳Pop¨¹rlerÉÏ·¢ÏÖÁËÕâÒ»Ìû×Ó¡£¡£¡£¡£¡£¡£¾Ý³Æ£¬£¬£¬£¬£¬¸ÃÊý¾Ý¿âÔ̺¬»¼ÕßµÄÓ×ÎÒÐÅÏ¢£¬£¬£¬£¬£¬Éæ¼°ÐÕÃû¡¢ID¡¢µç»°¡¢µØÖ·¡¢ÊÖÊõ·ÖÀàÏêÇé¡¢Õï¶ÏºÍÒ½ÖξßÌåÐÅÏ¢µÈ¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬ºÚ¿Í»¹ÌṩÁË1000È˵ÄÊý¾Ý×÷ΪÑù±¾£¬£¬£¬£¬£¬À´Ö§³ÖÕâһ˵·¨¡£¡£¡£¡£¡£¡£ÕâÃûºÚ¿Í»¹ÔÚÉÏÖÜÏúÊÛÁËÊôÓÚÓ¡¶ÈÄáÎ÷ÑÇʵÌåµÄÊý¾Ý¿â¡£¡£¡£¡£¡£¡£
https://www.infosecurity-magazine.com/news/hacker-stolen-medical-records/
3¡¢SentinelOne·¢ÏÖMac¶ñÒâÈí¼þRealstµÄ´ó¹æÄ£¹¥»÷»î¶¯
7ÔÂ25ÈÕ£¬£¬£¬£¬£¬SentinelOne³ÆÆä·¢ÏÖÁËMac¶ñÒâÈí¼þRealstµÄ´ó¹æÄ£¹¥»÷»î¶¯¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±·ÖÎöÁË59¸ö RealstÑù±¾£¬£¬£¬£¬£¬·¢ÏÖһЩÑù±¾ÒѾÕë¶ÔApple¼´½«°ä²¼µÄ²Ù×÷ϵͳ°æ±¾macOS 14 Sonoma¡£¡£¡£¡£¡£¡£¶ñÒâÈí¼þͨ¹ýαÔìµÄÓÎÏ·ÍøÕ¾·Ö·¢£¬£¬£¬£¬£¬ÒÔPKG×°Ö÷¨Ê½»òDMG´ÅÅÌÎļþµÄ´ó¾ÖÕë¶ÔMacÉ豸£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬¶ñÒâMach-OÎļþ£¬£¬£¬£¬£¬µ«Ã»ÓÐÕæÕýµÄÓÎÏ·»òÆäËüµö¶üÈí¼þ¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬ÓÉÓÚÕâЩÓÎÏ·Õë¶ÔµÄÊǼÓÃÜÇ®±ÒÓû§£¬£¬£¬£¬£¬Òò¶øÆäÖØÒªÖ÷ÕÅ¿ÉÄÜÊÇÇÔÈ¡¼ÓÃÜÇ®°ü¼°ÆäÄÚµÄ×ʽ𡣡£¡£¡£¡£¡£
https://www.sentinelone.com/blog/apple-crimeware-massive-rust-infostealer-campaign-aiming-for-macos-sonoma-ahead-of-public-release/
4¡¢FortinetÔÚMicrosoftÐÂÎŶÓÁзþÎñÖз¢ÏÖ¶à¸ö·ì϶
FortinetÓÚ7ÔÂ24ÈÕ³ÆÆäÔÚMicrosoftÐÂÎŶÓÁÐ(MSMQ)·þÎñÖз¢ÏÖÁ˶à¸ö·ì϶£¬£¬£¬£¬£¬¿ÉÄܻᵼÖÂÔ¶³Ì´úÂëÖ´ÐкÍDoS¹¥»÷¡£¡£¡£¡£¡£¡£ÆäÖÐÔ̺¬ÔÚÐÂÎÅÍ·½âÎö·¨Ê½ÖнӼûijЩ¹Ø¼üº¯Êý֮ǰδÑéÖ¤µ¼ÖµÄÔ½½ç¶ÁÈ¡·ì϶£¬£¬£¬£¬£¬Î´ÑéÖ¤ËÁÒâ´óÓ×µÄÐÂÎÅÍ·µ¼ÖµÄÔ½½çдÈë·ì϶£¬£¬£¬£¬£¬ÒÔ¼°CompoundMessageͷδÄÜ¶ÔÆäÊý¾Ý½á¹¹½øÐÐÕýÈ·ÐԲ鳵¼ÖµÄÔ½½çдÈë·ì϶¡£¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬Î¢ÈíÒÑÔÚ4ÔºÍ7Եݲȫ¸üн¨¸´ÁËÕâЩ·ì϶¡£¡£¡£¡£¡£¡£
https://www.fortinet.com/blog/threat-research/microsoft-message-queuing-service-vulnerabilities
5¡¢Èí¼þ¹«Ë¾OrtivusÔâµ½¹¥»÷Ó°ÏìÓ¢¹ú¾È»¤³µ·þÎñ»ú¹¹
¾Ý7ÔÂ26ÈÕ±¨Â·£¬£¬£¬£¬£¬ÈðµäÈí¼þ¹«Ë¾OrtivusÔâµ½ÍøÂç¹¥»÷£¬£¬£¬£¬£¬µ¼ÖÂÖÁÉÙÁ½¼ÒÓ¢¹ú¾È»¤³µ·þÎñ»ú¹¹ÎÞ·¨½Ó¼ûµç×Ó²¡Àú¡£¡£¡£¡£¡£¡£¹¥»÷²úÉúÓÚ7ÔÂ18ÈÕÍíÉÏ£¬£¬£¬£¬£¬Ó°ÏìÁËÆäÍйÜÊý¾ÝÖÐÐÄ»·¾³ÖеÄÓ¢¹ú¿Í»§ÏµÍ³£¬£¬£¬£¬£¬µ¼Öµç×Ó²¡ÀúÎÞ·¨Ê¹Ó㬣¬£¬£¬£¬Ä¿Ç°±»ÆÈʹÓÃÊÖ¶¯ÏµÍ³½øÐд¦Öᣡ£¡£¡£¡£¡£Ortivus³Æ£¬£¬£¬£¬£¬´úÌæÏµÍ³ÔÚ¹¥»÷²úÉúºó24Ó×ʱÄھͳﱸºÃÁË£¬£¬£¬£¬£¬Ã»Óпͻ§ÐÅϢй¶¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾Ã»ÓÐй©ÊÜÓ°Ïì¾È»¤³µ·þÎñµÄÃû³Æ£¬£¬£¬£¬£¬µ«¾Ýй©£¬£¬£¬£¬£¬±ðÀëÊÇSouth Western Ambulance Service TrustºÍSouth Central Ambulance Service Trust£¬£¬£¬£¬£¬ËüÃÇΪԼ1200Íò³£×¡È˶¡Ìṩ·þÎñ¡£¡£¡£¡£¡£¡£
https://securityaffairs.com/148847/cyber-crime/ambulance-services-cyberattack.html
6¡¢SygniaÏêÊöCasbaneiroÖØÒªÕë¶ÔÄÏÃÀºÍ±±ÃÀµÄ¹¥»÷»î¶¯
7ÔÂ25ÈÕ£¬£¬£¬£¬£¬Sygnia¹«¿ªÁËÒøÐÐľÂíCasbaneiro¹¥»÷»î¶¯µÄÏêÇé¡£¡£¡£¡£¡£¡£CasbaneiroÓÚ2018³õ´Î±»·¢ÏÖ£¬£¬£¬£¬£¬ÖØÒªÓÃÓÚ¹¥»÷À¶¡ÃÀÖÞ½ðÈÚÐÐÒµµÄ×éÖ¯¡£¡£¡£¡£¡£¡£ÔÚ×î½ü¹Û²ìµ½µÄ¹¥»÷ÖУ¬£¬£¬£¬£¬¹¥»÷ÊÇÓÉǶÈëHTMLÎļþÁ´½ÓµÄÓã²æÊ½´¹µöÓʼþÆô¶¯µÄ£¬£¬£¬£¬£¬»á³Á¶¨ÏòÖ¸±ê²¢ÏÂÔØRARÎļþ¡£¡£¡£¡£¡£¡£ÁíÒ»¸ö±ä¶¯É漰ʹÓÃfodhelper.exeÀ´ÊµÏÖUACÈÆ¹ý£¬£¬£¬£¬£¬²¢»ñµÃÆëÈ«µÄÍÆËã»úÖÎÀíȨÏÞ¡£¡£¡£¡£¡£¡£¶ÔÉÏ´«µ½VirusTotalµÄÑù±¾½øÐзÖÎö£¬£¬£¬£¬£¬·¢ÏÖËüÃÇÔÚÏòÄÏÃÀºÍ±±ÃÀ¼¯ÖС£¡£¡£¡£¡£¡£
https://blog.sygnia.co/breaking-down-casbaneiro-infection-chain-part2


¾©¹«Íø°²±¸11010802024551ºÅ