IBMÔâµ½¹¥»÷µ¼Ö¿ÆÂÞÀ¶àÖÝHCPFÁè¼Ý400ÍòÈ˵ÄÐÅϢй¶
Ðû²¼Ê±¼ä 2023-08-161¡¢IBMÔâµ½¹¥»÷µ¼Ö¿ÆÂÞÀ¶àÖÝHCPFÁè¼Ý400ÍòÈ˵ÄÐÅϢй¶
¾ÝýÌå8ÔÂ14ÈÕ±¨µÀ£¬ÃÀ¹ú¿ÆÂÞÀ¶àÖÝÒ½ÁƱ£½¡Õþ²ßÓëÈÚ×ʲ¿(HCPF)ÏòÁè¼Ý400ÍòÈË·¢³ö֪ͨ£¬³ÆÊý¾Ýй¶ÊÂÎñÓ°ÏìÁËËûÃǵÄСÎÒ˽¼ÒºÍ¿µ½¡ÐÅÏ¢¡£HCPF³ÎÇå˵£¬ËûÃǵÄϵͳûÓÐÔâµ½¹¥»÷£¬¿ÉÊÇËûÃǵijаüÉÌIBMÔâµ½ÁËÕë¶ÔMOVEitµÄ¹¥»÷¡£6ÔÂ13ÈÕÊӲ췢Ã÷£¬IBMʹÓõÄMOVEitÓ¦ÓÃÉϵIJ¿·ÖHCPFÎļþÔÚ5ÔÂ28ÈÕ×óÓÒ±»»á¼û£¬¹¥»÷Õß¿ÉÄÜÇÔÈ¡ÁË°üÀ¨Ä³Ð©Health First ColoradoºÍCHP+»áÔ±ÐÅÏ¢µÄÎļþ¡£×ܹ²Ó°ÏìÁË4091794ÈË£¬HPCF½«Í¨¹ýExperianΪÊÜÓ°ÏìÓû§ÌṩÁ½ÄêµÄÐÅÓüà¿Ø·þÎñ¡£
https://www.bleepingcomputer.com/news/security/colorado-warns-4-million-of-data-stolen-in-ibm-moveit-breach/
2¡¢Akamai·¢Ã÷Õë¶ÔÔËÐÐMagento 2µÄµçÉÌƽ̨µÄXurumÔ˶¯
AkamaiÔÚ8ÔÂ9ÈÕ³ÆÆä·¢Ã÷ÁËÕë¶ÔÔËÐÐMagento 2 CMSµÄµçÉÌƽ̨µÄ¹¥»÷Ô˶¯£¬²¢½«¸ÃÔ˶¯ÃüÃûΪXurum¡£Ô˶¯Ê¼ÓÚ1Ô·ݣ¬Ê¹ÓÃÁËAdobe CommerceºÍMagento Open SourceÖеķþÎñÆ÷¶ËÄ£°å×¢ÈëÎó²î£¨CVE-2022-24086£©¡£¹¥»÷ÕßËƺõ¶ÔÄ¿µÄMagentoÊÐËÁÒÑÍù10ÌìÄÚËù϶©µ¥µÄ¸¶¿îͳ¼ÆÊý¾Ý¸ÐÐËȤ¡£¹¥»÷Ô˶¯Ê¹ÓÃÁËwso-ng£¬ÕâÊÇа汾µÄWSO webshell¡£Ô˶¯»¹Ê¹ÓÃÁ˽ϾɵÄDirty COWÎó²î(CVE-2016-5195)£¬ÒÔʵÑéÔÚLinuxÖÐÌáȨ¡£ÓÐÖ¤¾ÝÅú×¢¹¥»÷Óë¶íÂÞ˹Óйء£
https://www.akamai.com/blog/security-research/new-sophisticated-magento-campaign-xurum-webshell
3¡¢ÀÕË÷Èí¼þMonti¾íÍÁÖØÀ´Ö÷ÒªÕë¶ÔÖ´·¨ºÍÕþ¸®ÁìÓò»ú¹¹
8ÔÂ14ÈÕ£¬Trend Micro·¢Ã÷ʱ¸ô2¸öÔºóMonti¾íÍÁÖØÀ´£¬Öصã¹Ø×¢Ö´·¨ºÍÕþ¸®ÁìÓò»ú¹¹¡£Óë´Ëͬʱ£¬»ùÓÚLinuxƽ̨µÄMontiбäÌåÒ²ÒѸ¡³öË®Ã棬Óë֮ǰµÄ°æ±¾ÓÐ×ÅÏÔ×Ųî±ð¡£ÒÔÇ°°æ±¾ºÜºéÁ÷ƽÉÏ»ùÓÚContiй¶µÄ´úÂ루99%£©£¬µ«ÐÈÎÃüܳÌÐòµÄÏàËƶȽöΪ29%¡£Ñо¿Ö°Ô±ÌåÏÖ£¬Í¨¹ý¶Ô´úÂ루ÓÈÆäÊǼÓÃÜËã·¨£©¾ÙÐдó×ÚÐ޸ģ¬MontiÈƹý¼ì²âµÄÄÜÁ¦»ñµÃÌá¸ß£¬ÕâÔöÌíÁ˼ì²â»ººÍ½â´ËÀà¶ñÒâÔ˶¯µÄÄѶȡ£
https://www.trendmicro.com/en_us/research/23/h/monti-ransomware-unleashes-a-new-encryptor-for-linux.html
4¡¢ZscaleÅû¶Õë¶ÔÀ¶¡ÃÀÖÞ½ðÈڿƼ¼ÐÐÒµµÄJanelaRAT
ZscaleÔÚ8ÔÂ10ÈÕÅû¶ÁËÕë¶ÔÀ¶¡ÃÀÖÞµØÇøµÄ½ðÈڿƼ¼ÐÐÒµµÄJanelaRAT¡£×èÖ¹6Ô·ݣ¬JanelaRATÖ÷ÒªÕë¶ÔÀ¶¡ÃÀÖÞµØÇøÒøÐкͽðÈÚ»ú¹¹£¬Ö¼ÔÚÇÔÈ¡½ðÈںͼÓÃÜÇ®±ÒÏà¹ØÊý¾Ý£¬²¢Ê¹ÓÃÀ´×ÔÕýµ±ÈªÔ´£¨ÈçVMWareºÍMicrosoft£©µÄDLL²à¼ÓÔØÊÖÒÕÀ´Èƹý¼ì²â¡£±ðµÄ£¬JanelaRAT¾ßÓд°¿ÚÎÊÌâ¸ÐÖª»úÖÆ£¬²¢½ÓÄɶ¯Ì¬Ì×½ÖÉ×ÓèÖÃϵͳ¡£JanelaRATµÄ¿ª·¢Õß¿ÉÄÜ´ÓBX RATµÄ´úÂëÖлñµÃÁËÁé¸Ð£¬µ«Ëü½ö¾ß±¸BX RATÌṩµÄ²¿·Ö¹¦Ð§£¬Ã»Óе¼ÈëshellÏÂÁîÖ´Ðеȹ¦Ð§¡£
https://www.zscaler.com/blogs/security-research/janelarat-repurposed-bx-rat-variant-targeting-latam-fintech
5¡¢Kaspersky³Æ´ó×Ú±»ºÚµÄWPÍøÕ¾±»ÓÃÓÚÖ´Ðд¹ÂÚ¹¥»÷
¾Ý8ÔÂ14ÈÕ±¨µÀ£¬Kaspersky·¢Ã÷´ó×Ú±»ºÚµÄWordPressÍøÕ¾±»ÓÃÓÚÖ´Ðд¹ÂÚ¹¥»÷¡£5ÔÂ15ÈÕµ½7ÔÂ31ÈÕ£¬Ñо¿Ö°Ô±·¢Ã÷ÁË22400¸öWordPressÍøÕ¾±»ºÚ¿Í¹¥»÷ÒÔ½¨Éè´¹ÂÚÒ³Ã档ͳһʱÆÚÄÚ£¬Óû§×ܹ²ÊµÑé»á¼û±»Ñ¬È¾ÍøÕ¾ÉÏÍйܵÄÐéαҳÃæ200213´Î¡£×î³£±»´¹ÂÚ¹¥»÷µÄ·þÎñºÍÆóÒµ°üÀ¨Netflix¡¢Å·ÖÞµÄÒøÐкͳ£¼ûµÄ¿ìµÝ·þÎñ¡£Kaspersky»¹ÏêÊöÁËÄÄЩÍøÕ¾×îÈÝÒ×Ôâµ½ºÚ¿Í¹¥»÷¡¢ÔõÑùÈëÇÖWordPressÍøÕ¾ÒÔ¼°WordPressÍøÕ¾±»ºÚµÄ¼£ÏóµÈ¡£
https://securelist.com/phishing-with-hacked-sites/110334/
6¡¢UptycsÐû²¼¹ØÓÚ¶ñÒâÈí¼þQwixxRATµÄÆÊÎö±¨¸æ
8ÔÂ14ÈÕ£¬UptycsÐû²¼Á˹ØÓÚ¶ñÒâÈí¼þQwixxRATµÄÆÊÎö±¨¸æ¡£Ñо¿Ö°Ô±ÓÚ8ÔÂÉÏÑ®·¢Ã÷Á˸öñÒâÈí¼þ£¬Ëüͨ¹ýTelegramºÍDiscordƽ̨¾ÙÐÐÈö²¥¡£Ã¿Öܶ©ÔÄ·ÑΪ150¬²¼£¬µ«Ò²ÓÐÓÐÏÞµÄÃâ·Ñ°æ±¾¡£Ò»µ©×°Öã¬RAT¾Í»áÉñÃØÍøÂçÊý¾Ý£¬È»ºó·¢Ë͵½¹¥»÷ÕßµÄTelegram bot¡£ÎªÁËÈƹýɱ¶¾Èí¼þµÄ¼ì²â£¬RATͨ¹ýTelegram bot¾ÙÐÐC2¡£³ýÁËÇÔÈ¡Êý¾ÝÖ®Í⣬QwixxRAT»¹ÓµÓÐÇ¿Ê¢µÄÔ¶³ÌÖÎÀí¹¤¾ß£¬¿É¿ØÖÆÄ¿µÄ×°±¸ºÍÆô¶¯ÏÂÁî¡£
https://www.uptycs.com/blog/remote-access-trojan-qwixx-telegram