̨»ýµç͸¶Æ乩ӦÉÌÔâµ½¹¥»÷±»LockBitÀÕË÷7000ÍòÃÀÔª
Ðû²¼Ê±¼ä 2023-07-031¡¢Ì¨»ýµç͸¶Æ乩ӦÉÌÔâµ½¹¥»÷±»LockBitÀÕË÷7000ÍòÃÀÔª
¾ÝýÌå7ÔÂ1ÈÕ±¨µÀ£¬LockBitÉù³ÆÒÑÈëÇÖÖйų́ÍåоƬÖÆÔìÉĮ̀»ýµç(TSMC)£¬²¢ÀÕË÷7000ÍòÃÀÔªÊê½ð¡£Ì¨»ýµçÊÇÈ«Çò×î´óµÄоƬºÏÔ¼ÖÆÔìÉÌ£¬ÎªÆ»¹ûºÍ¸ßͨµÈ¿Æ¼¼¾ÞÍ·ÌṩоƬ¡£Ì¨»ýµç·ñ¶¨ÆäÔâµ½ºÚ¿Í¹¥»÷£¬²¢ÌåÏÖÊÇËûÃǵÄITÓ²¼þ¹©Ó¦ÉÌÖ®Ò»Kinmax TechnologyµÄϵͳÔâµ½¹¥»÷¡£Kinmax͸¶ËüÓÚ6ÔÂ29ÈÕÒâʶµ½¹¥»÷Ô˶¯£¬²¿·ÖÐÅϢй¶£¬Ö÷ÒªÉæ¼°¿Í»§µÄϵͳװÖúÍÉèÖÃÖ¸µ¼¡£ÓÉÓÚKinmax²¢²»ÊÇ̨»ýµçÄÇÑùµÄ¾ÞÍ·£¬Òò´ËLockBit 7000ÍòÃÀÔªÊê½ðµÄÒªÇó¿ÉÄܻᱻºöÂÔ¡£
https://www.bleepingcomputer.com/news/security/tsmc-denies-lockbit-hack-as-ransomware-gang-demands-70-million/
2¡¢AvastÐû²¼Windows°æ±¾µÄAkiraÀÕË÷Èí¼þÃ⺬»ìÃÜÆ÷
¾Ý7ÔÂ1ÈÕ±¨µÀ£¬Çå¾²¹«Ë¾AvastÐû²¼ÁËAkiraÀÕË÷Èí¼þµÄÃ⺬»ìÃÜÆ÷£¬ÎÞÐèÖ§¸¶Êê½ð¼´¿É»Ö¸´Êý¾Ý¡£AkiraÓÚ3ÔÂÊ״ηºÆ𠣬²¢ÒòÕë¶ÔÈ«Çò¸÷¸öÁìÓòµÄ×éÖ¯¶øÃûÉù´óÔë¡£6Ô£¬Akira×îÏÈ·Ö·¢ÆäÕë¶ÔVMware ESXiÐéÄâ»úµÄLinux±äÌå¡£AvastÐû²¼ÁËÁ½¸ö°æ±¾µÄAkira½âÃÜÆ÷£¬Ò»ÖÖÊÊÓÃÓÚ64λWindows¼Ü¹¹£¬ÁíÒ»¸öÊÊÓÃÓÚ32λ¡£Ëü½¨ÒéʹÓÃ64λ°æ±¾£¬ÓÉÓÚÆƽâÃÜÂëÐèÒª´ó×ÚµÄϵͳÄÚ´æ¡£¸ÃÇå¾²¹«Ë¾Ã»ÓÐÚ¹ÊÍËüÊÇÔõÑùÆƽâAkiraµÄ£¬µ«¿ÉÄÜʹÓÃÁËÀÕË÷Èí¼þµÄ²¿·ÖÎļþ¼ÓÃÜÒªÁì¡£
https://securityaffairs.com/148007/cyber-crime/akira-ransomware-decryptor.html
3¡¢Ñо¿Ö°Ô±·¢Ã÷ʹÓÃWP²å¼þUltimate MemberÎó²îµÄ¹¥»÷
ýÌå7ÔÂ2Èճƣ¬Ñо¿Ö°Ô±·¢Ã÷ʹÓÃWordPress²å¼þUltimate MemberÖеÄÎó²îµÄ¹¥»÷Ô˶¯£¬¸Ã²å¼þÒѱ»×°ÖÃÁè¼Ý200000´Î¡£Îó²î×·×ÙΪCVE-2023-3460£¬CVSSÆÀ·Ö9.8£¬Ó°ÏìÁË°üÀ¨×îа汾v2.6.6ÔÚÄÚµÄËùÓÐUltimate Member°æ±¾¡£¹¥»÷Õß¿ÉÒÔʹÓôËÎó²î½¨Éè¾ßÓÐÖÎÀíȨÏÞµÄÐÂÓû§ÕÊ»§£¬´Ó¶øÍêÈ«¿ØÖÆÍøÕ¾¡£ÓÉÓÚ¸ÃÎó²îÉÐδÐÞ¸´ÇÒºÜÈÝÒ×±»Ê¹Óã¬Ñо¿Ö°Ô±½¨ÒéÁ¬Ã¦Ð¶ÔØUltimate Member²å¼þ¡£
https://securityaffairs.com/148030/hacking/wordpress-ultimate-member-plugin-attacks.html
4¡¢VolexityÅû¶APT35ºóÃÅPOWERSTARµÄ¸üа汾µÄϸ½Ú
VolexityÔÚ6ÔÂ28ÈÕÅû¶ÁËAPT35£¨ÓÖÃûCharming Kitten£©ºóÃÅPOWERSTARµÄ¸üа汾¡£¹¥»÷ÕßÔöÇ¿ÁËPOWERSTARµÄ·´ÆÊÎö²½·¥¡£2021Äê¼ì²âµ½µÄ³õ¼¶°æ±¾Ê¹ÓÃDOCMÎļþÖÐǶÈëµÄ¶ñÒâºê·Ö·¢£¬¶øÔÚ½ñÄê5ÔµĹ¥»÷Ô˶¯ÖÐʹÓÃÁËÊÜÃÜÂë±£»¤µÄRARÎļþÄÚµÄLNKÎļþ£¬´ÓBackblazeÏÂÔغóÃÅ¡£±ðµÄ£¬½ü¼¸¸öÔÂÀ´£¬¸ÃÍŻﻹÓÃ˽ÓÐÍйܻù´¡ÉèÊ©BackblazeºÍIPFSÈ¡´úÁËËûÃÇ֮ǰµÄÔÆÍйÜÌṩÉÌ£¨OneDrive¡¢AWS S3ºÍDropbox£©¡£
https://www.volexity.com/blog/2023/06/28/charming-kitten-updates-powerstar-with-an-interplanetary-twist/
5¡¢MITRE¹ûÕæ2023ÄêCWE 25¸ö×îΣÏÕµÄÈí¼þÎó²îµÄÇåµ¥
6ÔÂ29ÈÕ£¬MITRE¹ûÕæÁË2023ÄêCWE 25¸ö×îΣÏÕµÄÈí¼þÎó²îµÄÇåµ¥¡£MITREÆÊÎöÁËNIST¹ú¼ÒÎó²îÊý¾Ý¿â£¨NVD£©ÖеÄ43996¸öCVE£¬¼´2021ÄêºÍ2022Äêʱ´ú·¢Ã÷ºÍ±¨¸æµÄÎó²î£¬Æ¾Ö¤ÆäÑÏÖØÐÔºÍÆÕ±éÐÔ¶Ôÿ¸öÎó²î¾ÙÐÐÁËÆÀ·Ö£¬´Ó¶ø½¨ÉèÁ˸ÃÁÐ±í¡£ÆäÖÐ×îΪÑÏÖصÄÊÇÔ½½çдÈë¡¢ÍøÒ³ÌìÉúʱ´úÊäÈëµÄ²»×¼È·Öкͣ¨¿çÕ¾¾ç±¾£©¡¢SQLÏÂÁîÖÐʹÓõÄÌØÊâÔªËصIJ»×¼È·Öкͣ¨SQL×¢È룩ºÍÊͷźóʹÓÃÎó²îµÈ¡£
https://cwe.mitre.org/top25/
6¡¢ElasticÐû²¼Õë¶ÔmacOSµÄRustBucketбäÌåµÄÆÊÎö±¨¸æ
6ÔÂ29ÈÕ£¬ElasticÐû²¼±¨¸æ£¬Åû¶ÁËÕë¶ÔmacOSµÄRustBucketбäÌå¡£Ñо¿Ö°Ô±·¢Ã÷ÁËRustBucketϵÁÐÖÐÒÔǰûÓеij¤ÆÚÐÔ¹¦Ð§£¬²¢ÒÔΪ¸ÃϵÁÐÕýÔÚÆ𾢿ª·¢ÖС£±ðµÄ£¬×èÖ¹ÏÖÔÚ£¬¸ÃбäÖÖÔÚVirusTotalÉϵļì²âÂÊΪÁ㣬²¢Ê¹Óö¯Ì¬ÍøÂç»ù´¡ÉèÊ©µÄÒªÁì¾ÙÐÐC2¡£¹¥»÷µÄµÚÒ»½×¶Î£¬»áÖ´ÐÐÒ»¸öAppleScript£¬Æô¶¯Ê¹ÓÃcURL´ÓC2ÏÂÔصڶþ½×¶ÎpayloadµÄ¶þ½øÖÆÎļþ¡£µÚ¶þ½×¶Î¶þ½øÖÆÎļþ(.pd)ÓÃSwift±àÒ룬´ÓC2ÏÂÔØÖ÷Òª¶ñÒâÈí¼þ¡£µÚÈý½×¶ÎµÄ¶ñÒâÈí¼þÊÇÒ»¸öFAT macOS¶þ½øÖÆÎļþ¡£
https://www.elastic.co/cn/security-labs/DPRK-strikes-using-a-new-variant-of-rustbucket