NCC³Æ½ü2000̨Citrix NetScaler·þÎñÆ÷Òѱ»Ö²ÈëºóÃÅ
Ðû²¼Ê±¼ä 2023-08-171¡¢NCC³Æ½ü2000̨Citrix NetScaler·þÎñÆ÷Òѱ»Ö²ÈëºóÃÅ
¾Ý8ÔÂ16ÈÕ±¨µÀ£¬NCC Group·¢Ã÷ÁËCitrix NetScalerÎó²îµÄ´ó¹æģʹÓÃÔ˶¯¡£¹¥»÷ÕßÒÔ×Ô¶¯»¯·½·¨Ê¹ÓÃÁËÎó²î£¨CVE-2023-3519£©£¬ÔÚNetscaler·þÎñÆ÷ÖÐÖ²ÈëÁËWebshell¡£×ÝÈ»NetScalerÒÑ´ò²¹¶¡»òÖØÆô£¬¹¥»÷ÕßÒ²¿ÉÒÔʹÓôËWebshellÖ´ÐÐí§ÒâÏÂÁî¡£Ñо¿Ö°Ô±×ܹ²ÔÚ1952¸ö²î±ðµÄNetScalerÖз¢Ã÷ÁË2491¸öWebshell£¬´ó´ó¶¼Î»Óڵ¹ú¡¢·¨¹ú¡¢ÈðÊ¿¡¢ÈÕ±¾ºÍÒâ´óÀûµÈ¹ú¡£×èÖ¹8ÔÂ14ÈÕ£¬ÈÔÓÐ1828¸öNetScaler±£´æºóÃÅ£¬ÆäÖÐÔ¼1248̨ÒѾÕë¶Ô¸ÃÎó²î¾ÙÐÐÁËÐÞ¸´¡£
https://thehackernews.com/2023/08/nearly-2000-citrix-netscaler-instances.html
2¡¢´ó×ÚLinkedInÓû§³ÆÆäÕË»§±»Ð®ÖÆ»òËø¶¨²¿·ÖÒª½»Êê½ð
¾ÝýÌå8ÔÂ15ÈÕ±¨µÀ£¬CyberintÔÚ×î½ü¼¸ÖÜ·¢Ã÷ÁËÒ»³¡Ò»Á¬µÄ¹¥»÷Ô˶¯Ö÷ÒªÕë¶ÔLinkedInÕÊ»§¡£¸ÃÔ˶¯µÄÓ°Ïì¹æÄ£ÁýÕÖÈ«Çò£¬µ¼Ö´ó×ÚÓû§ÎÞ·¨»á¼ûÆäÕÊ»§¡£Ðí¶àLinkedInÓû§Ëß¿àÆäÕË»§±»½ÓÊÜ»òËø¶¨£¬²¢ÇÒÎÞ·¨Í¨¹ýLinkedInµÄÖ§³Ö·þÎñ½â¾ö¡£ÓÐЩÈËÉõÖÁ±»ÆȽ»Êê½ð²Å»ªÖØлñµÃ¿ØÖÆȨ£¬»òÕßÃæÁÙÕË»§±»ÓÀÊÀɾ³ýµÄÇéÐΡ£ËäÈ»LinkedInÉÐδÐû²¼Õýʽͨ¸æ£¬µ«ËûÃǵÄÖ§³ÖÏìӦʱ¼äËƺõÒѾÑÓÉ죬Óб¨µÀ³ÆÖ§³ÖÇëÇóµÄÊýÄ¿ºÜ´ó¡£
https://www.bleepingcomputer.com/news/security/linkedin-accounts-hacked-in-widespread-hijacking-campaign/
3¡¢ÃÀ¹ú¸ßÀÖÊÏ(Clorox)Ôâµ½¹¥»÷µ¼ÖÂÔËÓªÔÝʱÖÐÖ¹
8ÔÂ16ÈÕ±¨µÀ³Æ£¬ÃÀ¹úÈÕÓÃÆ·Éú²úÉ̸ßÀÖÊÏ(Clorox)Ôâµ½¹¥»÷£¬µ¼ÖÂÔËÓªÔÝʱÖÐÖ¹¡£¸Ã¹«Ë¾ÔÚ2022ÄêµÄÊÕÈëÁè¼Ý70ÒÚÃÀÔª¡£´Ë´Î¹¥»÷ÓÚ8ÔÂ14ÈÕ±»¼ì²âµ½£¬CloroxÁ¬Ã¦½ÓÄÉÐж¯£¬¹Ø±ÕÁËÊÜÓ°ÏìµÄϵͳ¡£¸ÃÊÂÎñµÄÊÓ²ìÈÔÔÚÔçÆڽ׶Σ¬Éв»ÇåÎúÊÇÄÄÖÖÀàÐ͵Ĺ¥»÷¡£È»¶øÏÖÓÐÐÅÏ¢Åú×¢£¬Õâ¿ÉÄÜÊÇÀÕË÷¹¥»÷¡£´Ë´Î¹¥»÷Ó°ÏìÁËCloroxµÄÖÆÔìºÍÏúÊÛÁ÷³Ì£¬ÒÔ¼°ÆäÍÆÐж©µ¥ºÍά³ÖÕý³£ÔËÓªµÄÄÜÁ¦¡£
https://www.infosecurity-magazine.com/news/clorox-disrupted-cyber-attack/
4¡¢ÒÑÍù°ëÄêCloudflare R2ÍйܵĴ¹ÂÚÍøÒ³Á÷Á¿ÔöÌí61±¶
NetskopeÔÚ8ÔÂ14Èճƣ¬´Ó½ñÄê2Ôµ½7Ô£¬Cloudflare R2ÖÐÍйܵĴ¹ÂÚÒ³ÃæÁ÷Á¿ÔöÌíÁË61±¶¡£´ó´ó¶¼´¹ÂÚÔ˶¯¶¼Õë¶ÔMicrosoftµÇ¼ƾ֤£¬µ«Ò²ÓÐһЩÕë¶ÔAdobe¡¢DropboxºÍÆäËüÔÆÓ¦ÓóÌÐò¡£ÕâЩ¹¥»÷Ö÷ÒªÕë¶Ô±±ÃÀºÍÑÇÖÞ£¬Éæ¼°ÖÖÖÖÁìÓò£¬ÒÔÊÖÒÕ¡¢½ðÈÚ·þÎñºÍÒøÐÐҵΪÊס£ÕâЩ´¹ÂÚÔ˶¯²»µ«Ê¹ÓÃCloudflare R2·Ö·¢¾²Ì¬´¹ÂÚÒ³Ã棬»¹Ê¹Óøù«Ë¾µÄTurnstile²úÆ·À´Èƹý¼ì²â¡£
https://www.netskope.com/blog/evasive-phishing-campaign-steals-cloud-credentials-using-cloudflare-r2-and-turnstile
5¡¢AhnLab·¢Ã÷Hakuna MatataÕë¶Ôº«¹úÆóÒµµÄ¹¥»÷Ô˶¯
8ÔÂ16ÈÕ£¬AhnLab͸¶ÀÕË÷Èí¼þHakuna MatataÕý±»ÓÃÀ´¹¥»÷º«¹úµÄÆóÒµ¡£Hakuna MatataÊǽüÆÚ¿ª·¢µÄÀÕË÷Èí¼þ£¬ÓÚ7ÔÂ6ÈÕÊ״α»Åû¶¡£Hakuna MatataÓëÆäËü¹Å°åÀÕË÷Èí¼þµÄ²î±ðÖ®´¦ÔÚÓÚ£¬Ëü¾ßÓÐClipBanker¹¦Ð§¡£×ÝÈ»ÔÚ¼ÓÃÜÖ®ºó£¬ËüÈÔÈ»±£±£´æϵͳÖУ¬½«±ÈÌرÒÇ®°üµØµã¸ü¸ÄΪ¹¥»÷Õߵĵص㡣¼ÓÃÜϵͳºó£¬¹¥»÷Õß»áɾ³ý¹¥»÷ÖÐʹÓõÄÊÂÎñÈÕÖ¾ºÍ¶ñÒâÈí¼þ£¬Òò´ËºÜÄÑ»ñµÃÈ·ÇеÄÐÅÏ¢¡£¿ÉÊÇ£¬Æ¾Ö¤ÖÖÖÖÇéÐΣ¬ÍƲâÔ¶³Ì×ÀÃæÐÒ飨RDP£©±»×÷Ϊ³õʼ¹¥»÷ÔØÌå¡£
https://asec.ahnlab.com/en/56010/
6¡¢Group-IBÐû²¼¹ØÓÚ¶ñÒâÈí¼þGigabudµÄÆÊÎö±¨¸æ
8ÔÂ14ÈÕ£¬Group-IBÐû²¼Á˹ØÓÚ¶ñÒâÈí¼þGigabudµÄÆÊÎö±¨¸æ¡£ËüÖ÷ÒªÕë¶ÔÌ©¹ú¡¢Ó¡¶ÈÄáÎ÷ÑÇ¡¢Ô½ÄÏ¡¢·ÆÂɱöºÍÃسµÄ½ðÈÚ»ú¹¹¡£Gigabud RATÔÚÓû§±»ÊÚȨ½øÈë¶ñÒâÓ¦ÓÃ֮ǰ²»»áÖ´ÐÐÈκζñÒâÔ˶¯£¬Õâ¼Ó´óÁ˼ì²âµÄÄѶȡ£ËüÖ÷Ҫͨ¹ýÆÁĻ¼ÖÆÀ´ÍøÂçÃô¸ÐÐÅÏ¢£¬¶ø²»ÊÇHTMLÁýÕÖ¹¥»÷¡£¼ÌÐøÊӲ췢Ã÷ÁËÁíÒ»¸ö²»¾ß±¸RAT¹¦Ð§µÄÑù±¾£¬´úºÅΪGigabud.Loan£¬ÕâÊÇÒ»¸öαÔìµÄ´û¿îÓ¦Ó㬻áÇÔÈ¡Óû§ÊäÈëµÄÊý¾Ý¡£
https://www.group-ib.com/blog/gigabud-banking-malware/