Ñо¿Ö°Ô±Åû¶SolarWinds ARM²úÆ·Öжà¸öÎó²îµÄÏêÇé
Ðû²¼Ê±¼ä 2023-10-241¡¢Ñо¿Ö°Ô±Åû¶SolarWinds ARM²úÆ·Öжà¸öÎó²îµÄÏêÇé
¾ÝýÌå10ÔÂ20ÈÕ±¨µÀ£¬Ñо¿Ö°Ô±³ÆÆäÔÚSolarWinds Access Rights Manager(ARM)²úÆ·Öз¢Ã÷ÁË3¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£ÕâЩÎó²î»®·ÖÊÇcreateGlobalServerChannelInternalÖв»¿ÉÐÅÊý¾ÝµÄ·´ÐòÁл¯Îó²î£¨CVE-2023-35182£©¡¢ OpenFileÖжÔÓû§Ìṩ·¾¶Ñé֤ȱ·¦µÄÎó²î£¨CVE-2023-35185£©ÒÔ¼°OpenClientUpdateFileÖжÔÓû§Ìṩ·¾¶Ñé֤ȱ·¦µÄÎó²î£¨CVE-2023-35187£©¡£ËüÃǵÄCVSSÆÀ·Ö¾ùΪ9.8£¬ÒÑÓÚ10ÔÂ18ÈÕÐÞ¸´¡£
https://www.bleepingcomputer.com/news/security/critical-rce-flaws-found-in-solarwinds-access-audit-solution/
2¡¢ÃÀ¹úÃÜЪ¸ù´óѧÔâµ½¹¥»÷ѧÉúºÍÊÂÇéÖ°Ô±µÄÐÅϢй¶
¾Ý10ÔÂ23ÈÕ±¨µÀ£¬ÃÜЪ¸ù´óѧ͸¶£¬ºÚ¿ÍÔÚ8Ô·ÝÈëÇÖÆäϵͳ²¢»á¼ûÁË°üÀ¨Ñ§Éú¡¢ÉêÇëÈË¡¢Ð£ÓÑ¡¢¾èÇ®ÈË¡¢Ô±¹¤¡¢»¼ÕߺÍÑо¿¼ÓÈëÕßµÄÐÅÏ¢¡£Î´¾ÊÚȨµÄ»á¼û±¬·¢ÓÚ8ÔÂ23ÈÕÖÁ27ÈÕ£¬ÔÚ¼ì²âµ½¿ÉÒÉÔ˶¯ºó£¬¸ÃѧУÁ¬Ã¦ÇжÏÁËÕû¸öУ԰µÄÍøÂ磬ÒÔÖ»¹Ü¼õÇáÓ°Ïì¡£´Ë´ÎÊÂÎñ²»µ«Ð¹Â¶ÁËСÎÒ˽¼ÒÐÅÏ¢£¬»¹Ð¹Â¶Á˲ÆÎñºÍÒ½ÁÆÏêϸÐÅÏ¢¡£ÏÖÔÚ£¬ÃÜЪ¸ù´óѧÒÑ֪ͨËùÓÐÊÜÓ°ÏìµÄСÎÒ˽¼Ò£¬²¢½«ÎªËûÃÇÌṩÃâ·ÑÐÅÓüà¿Ø·þÎñ¡£
https://www.bleepingcomputer.com/news/security/university-of-michigan-employee-student-data-stolen-in-cyberattack/
3¡¢FacebookºÍInstagramÓëÖ´·¨²¿·ÖÁª¶¯µÄÕ˺ű»³öÊÛ
ýÌå10ÔÂ21Èճƣ¬ºÚ¿ÍÕýÔÚ°µÍø³öÊÛFacebookºÍInstagramµÄPolice PortalµÄ»á¼ûȨÏÞ¡£¸ÃÃÅ»§¿É±»Ö´·¨»ú¹¹ÓÃÓÚÇëÇóÓëÓû§Ïà¹ØµÄÊý¾Ý£¨IP¡¢µç»°¡¢Ë½ÐźÍ×°±¸ÐÅÏ¢£©»òÇëÇóɾ³ýÌû×ӺͽûÓÃÕÊ»§¡£¹¥»÷ÕßÒÔ700ÃÀÔªµÄ¼ÛÇ®Ìṩ»á¼ûȨÏÞ£¬²¢ÇÒËƺõÓµÓв»Ö¹Ò»¸öÃÅ»§µÄÕË»§¡£Ñо¿Ö°Ô±ÍƲ⣬ҪôÊÇMetaÔâµ½ÁËÉ繤¹¥»÷µ¼Ö»á¼ûȨÏÞй¶£¬ÒªÃ´¾ÍÊǹ¥»÷ÕßÓµÓÐÕýµ±µÄÖ´·¨ÕÊ»§µÄƾ֤¡£
https://securityaffairs.com/152811/cyber-crime/facebook-and-instagrams-police-portal-access.html
4¡¢Cadre ServicesÔ¼100GBÊý¾Ýй¶²¢±»ÀÕË÷30ÍòÃÀÔª
10ÔÂ19ÈÕ±¨µÀ³Æ£¬AlphVÉù³Æ¹¥»÷Á˾ÍÒµºÍÈËÊ·þÎñCadre Services²¢ÒÑÇÔÈ¡100 GBµÄÎļþ¡£¹¥»÷ÍÅ»ïÔÚ9ÔÂ19ÈÕÊ×´ÎÁªÏµÁËCadre£¬²¢ÓÚ9ÔÂ22ÈÕÊÕµ½»Ø¸´¡£Ì¸ÅеÄ̸Ìì½ØͼÏÔʾ£¬AlphVÒªÇó30ÍòÃÀÔªÊê½ð£¬¸Ã¹«Ë¾×î³õÌåÏÖÔ¸Òâ³ö¼Û25000ÃÀÔª£¬²¢³Æ×î¸ß±¨¼ÛΪ35000ÃÀÔª¡£×î½ü¼¸ÈÕ£¬AlphVÔÙ´ÎÏò¸Ã¹«Ë¾£¬ÒÔ¼°¿Í»§ºÍDataBreaches·¢ËÍÓʼþ£¬ÌṩÁ˽«ÒªÐ¹Â¶µÄÊý¾ÝµÄÑù±¾£¬°üÀ¨Ô±¹¤Êý¾ÝºÍÉêÇëÈËÊý¾Ý¡£
https://www.databreaches.net/another-small-firm-suffers-a-serious-ransomware-attack-cadre-services-gets-mauled-by-alphv/
5¡¢WithSecure·¢Ã÷Õë¶ÔÓ¢ÃÀµÈ¹úµÄDarkGate¹¥»÷Ô˶¯
10ÔÂ20ÈÕ£¬WithSecureÅû¶ÁËÕë¶ÔÓ¢¹ú¡¢ÃÀ¹úºÍÓ¡¶ÈµÄDarkGate¹¥»÷Ô˶¯¡£¸ÃÔ˶¯ÓëÈ¥ÄêÊ״η¢Ã÷µÄDucktailÔ˶¯µÄÔ½ÄϹ¥»÷ÕßÓйأ¬³õʼѬȾǰÑÔÊÇLinkedInÐÂÎźÍÓ²¼þÖÆÔìÉÌCorsairµÄFacebook¹ã¸æרԱְ룬»á½«Ä¿µÄÖض¨Ïòµ½Google DriveÉÏÍйܵÄÎļþ¡£ÏÂÔصÄÎĵµ°üÀ¨Ò»¸öVBS¾ç±¾£¬¿ÉÄÜǶÈëÔÚDOCXÎļþÖУ¬»áÏÂÔØautoit3.exeºÍÒ»¸ö±àÒëºóµÄAutoit3¾ç±¾¡£¿ÉÖ´ÐÐÎļþºó»áʹÓþ籾ÖеÄ×Ö·û´®½á¹¹DarkGate£¬×°ÖÃÈýÊ®Ãëºó£¬¶ñÒâÈí¼þ»áʵÑé´ÓÄ¿µÄϵͳÖÐжÔØÇå¾²²úÆ·¡£
https://labs.withsecure.com/publications/darkgate-malware-campaign
6¡¢FortinetÐû²¼¶ñÒâÈí¼þExelaStealerµÄÆÊÎö±¨¸æ
10ÔÂ19ÈÕ£¬FortinetÐû²¼Á˹ØÓÚ¶ñÒâÈí¼þExelaStealerµÄÆÊÎö±¨¸æ¡£ExelaStealerÊÇÒ»¸ö»ù±¾ÉÏ¿ªÔ´µÄÐÅÏ¢ÇÔÈ¡³ÌÐò£¬¿ÉÒÔÌṩ¸¶·Ñ¶¨ÖÆ·þÎñ¡£Æ丶·Ñ°æ±¾Ã¿ÔÂ20ÃÀÔª£¬Èý¸öÔÂ45ÃÀÔª£¬ÖÕÉí°æ±¾120ÃÀÔª¡£ËüÓÉPython¿ª·¢²¢Ö§³ÖJavaScript£¬¾ßÓÐÇÔÈ¡ÃÜÂë¡¢DiscordÁîÅÆ¡¢ÐÅÓÿ¨¡¢cookieºÍ»á»°Êý¾Ý¡¢»÷¼ü¡¢ÆÁÄ»½ØͼºÍ¼ôÌù°åÄÚÈݵĹ¦Ð§¡£ExelaStealer¿ÉÄÜÊÇͨ¹ýαװ³ÉPDFÎĵµµÄ¿ÉÖ´ÐÐÎļþ¾ÙÐзַ¢µÄ£¬Æô¶¯¶þ½øÖÆÎļþºó£¬»áÏÔʾһ·ÝÒýÓÕÎļþ£¬Í¬Ê±ÔÚºǫ́ÇÄÇÄÆô¶¯ÇÔÈ¡³ÌÐò¡£
https://www.fortinet.com/blog/threat-research/exelastealer-infostealer-enters-the-field