LiteSpeed Cache²å¼þÎó²îµ¼ÖÂÊý°ÙÍòWordPressÍøÕ¾ÃæÁÙ±»¿ØΣº¦

Ðû²¼Ê±¼ä 2024-08-23
1. LiteSpeed Cache²å¼þÎó²îµ¼ÖÂÊý°ÙÍòWordPressÍøÕ¾ÃæÁÙ±»¿ØΣº¦


8ÔÂ21ÈÕ £¬LiteSpeed Cache×÷ΪWordPressƽ̨ÉÏÒ»¿î¹ãÊܽӴýµÄÍøÕ¾¼ÓËÙ²å¼þ £¬½üÆÚ±»·¢Ã÷±£´æÒ»¸öÑÏÖØÇå¾²Îó²î£¨CVE-2024-28000£© £¬¸ÃÎó²îÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õßͨ¹ý½¨Éè¶ñÒâÖÎÀíÔ±ÕË»§À´¿ØÖÆÊý°ÙÍò¸öÍøÕ¾¡£¸ÃÎó²îÔ´ÓÚLiteSpeed Cache 6.3.0.1¼°ÒÔÉÏ°æ±¾ÖÐÓû§Ä£Ä⹦ЧµÄÈõ¹þϣУÑéÎÊÌâ¡£Çå¾²Ñо¿Ô±John BlackbournÓÚ8Ô³õ±¨¸æÁË´ËÎó²î £¬LiteSpeedÍŶÓѸËÙÏìÓ¦ £¬²¢ÓÚ8ÔÂ13ÈÕÐû²¼ÁË°üÀ¨ÐÞ¸´²¹¶¡µÄ6.4°æ±¾¡£´ËÎó²îµÄÑÏÖØÐÔÔÚÓÚ £¬Ò»µ©ÀÖ³ÉʹÓà £¬¹¥»÷Õß¿ÉÒÔ»ñÈ¡ÖÎÀíԱȨÏÞ £¬½ø¶ø×°ÖöñÒâ²å¼þ¡¢¸Ä¶¯ÍøÕ¾ÉèÖá¢Öض¨ÏòÁ÷Á¿ÖÁ¶ñÒâÕ¾µã¡¢·Ö·¢¶ñÒâÈí¼þ»òÇÔÈ¡Óû§Êý¾Ý¡£Ñо¿Ö°Ô±Ö¸³ö £¬Í¨¹ý±©Á¦Æƽâ¹þÏ£ÖµµÄ·½·¨ £¬¹¥»÷ÕßÄܹ»ÔÚ¶Ìʱ¼äÄÚʵÏÖ¶ÔÌض¨Óû§IDµÄÖÎÀíÔ±¼¶»á¼û £¬ÓÈÆ䵱ʹÓó£¼ûµÄÓû§ID£¨Èç1£©Ê± £¬ÀÖ³ÉÂʸü¸ß¡£Ö»¹ÜLiteSpeedÒÑÐû²¼ÐÞ¸´°æ±¾ £¬µ«¼øÓÚWordPress¹Ù·½²å¼þ¿âÏÂÔØÊý¾ÝÏÔʾ½öÓаëÊýÍøÕ¾¸üР£¬Ê£ÓàÁè¼ÝÒ»°ëµÄÓû§ÈÔÃæÁÙΣº¦¡£½¨ÒéËùÓÐʹÓÃLiteSpeed CacheµÄWordPressÍøÕ¾ÖÎÀíÔ±Á¬Ã¦Éý¼¶ÖÁ×îа汾¡£


https://www.bleepingcomputer.com/news/security/litespeed-cache-bug-exposes-millions-of-wordpress-sites-to-takeover-attacks/


2. ÎÚ¿ËÀ¼MonobankÔâ´ó¹æÄ£DDoS¹¥»÷ £¬¾èÇ®·þÎñ³ÉºÚ¿ÍÄ¿µÄ


8ÔÂ19ÈÕ £¬ÎÚ¿ËÀ¼×ÅÃûÍøÉÏÒøÐÐMonobank½üÆÚÔâÊÜÁËب¹ÅδÓеĴó¹æÄ£ÂþÑÜʽ¾Ü¾ø·þÎñ£¨DDoS£©¹¥»÷ £¬´Ë´Î¹¥»÷ÓÈÆäÕë¶ÔÆäÓÃÓÚΪÎÚ¿ËÀ¼¾ü¶Ó³ï¼¯¾èÇ®µÄÔÚÏß·þÎñ¡£´ÓÖÜÎåÍíÖÁÖÜÒ»Ôç £¬¹¥»÷·åÖµµÖ´ïÿÃë75ÒÚ´ÎÇëÇó £¬¹æÄ£Òì³£ÖØ´ó £¬Ö»¹Üδֱ½ÓÓ°ÏìÒøÐн¹µãÓªÒµÔËÐÐ £¬µ«Í¹ÏÔÁËÇå¾²ÌôÕ½µÄÑÏËàÐÔ¡£MonobankѸËÙÍŽáÎÚ¿ËÀ¼Çå¾²²¿·Ö¼°ÑÇÂíÑ·ÔÆ·þÎñר¼Ò¾ÙÐзÀÓù £¬ÓÐÓûº½âÁ˹¥»÷ѹÁ¦¡£ÖµµÃ×¢ÖصÄÊÇ £¬Monobank½öͨ¹ýÒƶ¯Ó¦ÓÃÌṩ·þÎñ £¬ÕâÒ»ÌØÕ÷ʹÆä³ÉΪºÚ¿ÍµÄÖص㹥»÷¹¤¾ß¡£´ËÇ° £¬¸ÃÒøÐÐÔÚ1ÔÂÒÑÔâÓö¹ýÒ»´ÎDDoS¹¥»÷ £¬ÈýÈÕÄÚÎüÊÕÁË5.8ÒÚÌõÀ¬»øÇëÇ󡣴˴ι¥»÷Ä¿µÄÃ÷È· £¬Ö¼ÔÚÆÆËðÎÚ¿ËÀ¼ÃñÖÚͨ¹ýMonobankƽ̨±ã½ÝµØΪ¾ü¶Ó¾èÇ®µÄÇþµÀ £¬¸Ã·þÎñÔÊÐíÓû§½¨ÉèÐéÄâÇ®°ü²¢Í¨¹ýÉ罻ýÌå·ÖÏí £¬¼ò»¯¾èÇ®Á÷³Ì¡£MonobankÊ×ϯִÐйÙOleh HorokhovskyiÖ¸³ö £¬ÒÑÍùÈýÄê¼ä £¬¸Ãƽ̨һÁ¬Ò»Ö±µÄ¾èÇ®Ô˶¯¿ÉÄÜÈÇÄÕÁ˳ðÊÓÊÆÁ¦ £¬´ÙʹËûÃǽÓÄɼ«¶ËÊÖ¶ÎÊÔͼ̱»¾·þÎñ¡£Ö»¹ÜÒøÐÐÌåÏÖ¶íÂÞ˹¿ÉÄÜΪ´Ë´Î¹¥»÷µÄÄ»ºó²ß»®Õß £¬µ«²¢Î´¹ûÕæÏêϸ֤¾Ý¡£HorokhovskyiÇ¿µ÷ £¬MonobankÒѳÉΪÎÚ¿ËÀ¼ITÁìÓòÔâÊÜ×îÑÏÖع¥»÷µÄÄ¿µÄÖ®Ò»¡£


https://therecord.media/ukraine-monobank-ddos-attack-donations


3. ÒÁÀÊAPT×éÖ¯GreenCharlie¶ÔÃÀ¹úÕþÖÎÔ˶¯ÌᳫÍøÂç¹¥»÷


8ÔÂ21ÈÕ £¬Insikt Group×îÐÂÐû²¼µÄ±¨¸æÕ¹ÏÖÁËÒÁÀÊÖ§³ÖµÄ¸ß¼¶Ò»Á¬ÐÔÍþв×éÖ¯GreenCharlieµÄÒþÃØÐж¯ £¬¸Ã×éÖ¯±»Ö¸ÓëÕë¶ÔÃÀ¹úÕþÖÎÔ˶¯µÄÍøÂç¹¥»÷Ïà¹ØÁª £¬ÇÒÊÜÒÁÀʸïÃüÎÀ¶ÓÇ鱨×éÖ¯(IRGC-IO)Ö¸»Ó¡£×Ô2024Äê5ÔÂÆ𠣬GreenCharlie¹¹½¨²¢À©´óÁËÆä¶ñÒâ»ù´¡ÉèÊ©ÍøÂç £¬Õë¶ÔÕþ¸®¹ÙÔ±¡¢Íâ½»¹ÙµÈ¸ß¼ÛֵĿµÄʵÑéÍøÂçÌع¤Ô˶¯¡£Æä»ù´¡ÉèʩʹÓö¯Ì¬DNS·þÎñºÍ¶àÖÖ¶¥¼¶ÓòÃû £¬Ôö½øÍøÂç´¹ÂںͶñÒâÈí¼þÈö²¥¡£±¨¸æÇ¿µ÷ £¬GreenCharlieÔËÓðüÀ¨GORBLE¡¢POWERSTARºÍNokNokÔÚÄÚµÄÖØ´ó¶ñÒâÈí¼þ¼Ò×å £¬Í¨¹ýÓã²æʽÍøÂç´¹ÂÚÊÖ¶ÎÇÔÈ¡Ãô¸ÐÐÅÏ¢ £¬ÕâЩ¶ñÒâÈí¼þ¼Ò×å¼ä±£´æÏÔÖø´úÂëÖصþ £¬ÏÔʾÆä±äÖÖ¼äµÄϸÃÜÁªÏµ¡£±ðµÄ £¬GreenCharlieƵÈÔʹÓÃÒÁÀÊIPµØµãÓë»ù´¡ÉèʩͨѶ £¬½øÒ»²½Ö¤ÊµÁËÆäÓëÒÁÀʵÄϸÃÜÁªÏµ¼°Ç鱨ÍøÂçÕ½ÂÔ¡£ÎªÑÚÊÎÔ˶¯ £¬GreenCharlie»¹½ÓÄÉÁË°üÀ¨ProtonVPNºÍProtonMailÔÚÄڵļÓÃÜ·þÎñ £¬ÕâÊÇÒÁÀÊAPTÕûÌåµÄÏ°ÓÃÊÖ·¨¡£ÆäÍøÂç´¹ÂÚ²Ù×÷¼«Æä½ÆÕ© £¬Í¨¹ýαÔìÕýµ±·þÎñÓòÃûÓÕÆ­Êܺ¦Õß¡£Ç¿ÁÒ½¨Òé¼ÓÈëÕþÖÎÔ˶¯µÄ×éÖ¯ £¬ÓÈÆäÊÇÃÀ¹úµÄÏà¹Ø×éÖ¯Ìá¸ßСÐÄ¡£


https://securityonline.info/iranian-apt-greencharlie-escalates-threats-against-us-political-targets-using-gorble-and-powerstar-malware/


4. ʯÓ;ÞÍ·HalliburtonÔâÊÜ»ùÓÚÔƵÄÍøÂç¹¥»÷


8ÔÂ21ÈÕ £¬È«ÇòµÚ¶þ´óÓÍÌï·þÎñ¹«Ë¾HalliburtonÈ·ÈÏÔâÊÜÁËÍøÂç¹¥»÷ £¬¸ÃÊÂÎñÒÑ´Ùʹ¹«Ë¾½ôÆÈָʾԱ¹¤ÖÜÈ«¶Ï¿ªÓëÄÚ²¿ÍøÂçµÄÅþÁ¬ £¬ÒÔ±ÜÃâDZÔÚµÄÊý¾Ý鶻òϵͳË𺦡£¹«Ë¾½²»°ÈËѸËÙ»ØÓ¦ £¬ÌåÏÖÒѲì¾õµ½ÏµÍ³ÊÜÓ°ÏìµÄ״̬ £¬²¢ÕýÈ«Á¦ÆÀ¹À¹¥»÷µÄÔµ¹ÊÔ­Óɼ°¿ÉÄÜ´øÀ´µÄЧ¹û¡£ÎªÓ¦¶Ô´Ë´ÎΣ»ú £¬Halliburton¼¤»îÁ˼ȶ¨µÄÓ¦¼±ÍýÏë £¬ÆäITÍŶÓÕýÆð¾¢Ð­Í¬Íⲿ¶¥¼âר¼ÒÅäºÏ´¦Öóͷ£ÕâÒ»ÎÊÌâ¡£×÷ΪӪҵ±é²¼70¸ö¹ú¼Ò¡¢ÓµÓг¬4ÍòÃû¹ú¼ÊÔ±¹¤µÄÐÐÒµ¾ÞÍ· £¬HalliburtonÔÚÄÜÔ´·þÎñÁìÓòÊÎÑÝמÙ×ãÇáÖصĽÇÉ« £¬Ìṩ´ÓÊÖÒÕ·þÎñ¡¢×°±¸¹©Ó¦µ½×ê¾®¡¢Á¶Óͼ°Ë®Á¦Ñ¹ÁÑ×÷ÒµµÄÈ«Á´Ìõ·þÎñ¡£´Ë´Î¹¥»÷²»µ«Ó°ÏìÁËÆäλÓÚÃÀ¹úÐÝ˹¶Ù¼°µÏ°ÝÁ½´ó×ܲ¿µÄÔËÓª £¬»¹²¨¼°ÁËÈ«Çò¹æÄ£ÄڵIJ¿·ÖÓªÒµÍøÂç¡£É罻ýÌåÉÏ £¬ÓйØHalliburtonÔâÊÜÔÆÇå¾²¹¥»÷µÄÐÂÎÅѸËÙÈö²¥ £¬Ò»Ð©Ì¸ÂÛÕßµ£ÐĵØÖ¸³ö £¬Ì«¹ýÒÀÀµÔÆÅÌËã¿ÉÄܼӾçÁË´Ë´ÎÊÂÎñµÄÑÏÖØÐÔ¡£ÏÖÔÚÉÐÎÞÈκÎÍøÂç·¸·¨×éÖ¯Õ¾³öÀ´Éù³Æ¶ÔHalliburtonÔâÊܵÄÏ®»÷ÈÏÕæ¡£


https://cybernews.com/news/halliburton-oil-cyberattack-cloud-fuel-supply/


5. PG_MEM¶ñÒâÈí¼þʹÓÃPostgreSQLÈõÃÜÂ뱩Á¦ÆƽâÍÚ¾ò¼ÓÃÜÇ®±Ò


8ÔÂ22ÈÕ £¬ÍøÂçÇå¾²Ñо¿Ö°Ô±¿ËÈÕ·¢Ã÷ÁËÒ»ÖÖÐÂÐͶñÒâÈí¼þPG_MEM £¬ËüÕë¶ÔPostgreSQLÊý¾Ý¿âÌᳫ±©Á¦Æƽ⹥»÷ £¬Ö¼ÔÚÍÚ¾ò¼ÓÃÜÇ®±Ò¡£AquaÇå¾²¹«Ë¾µÄAssaf MoragÖ¸³ö £¬¹¥»÷Õßͨ¹ýһֱʵÑéÈõÃÜÂëÒÔ»ñÈ¡Êý¾Ý¿â»á¼ûȨÏÞ £¬²¢Ê¹ÓÃPostgreSQLµÄ¡°COPY ... FROM PROGRAM¡±¹¦Ð§Ö´ÐÐí§ÒâshellÏÂÁî £¬½ø¶øÖ´ÐÐÊý¾ÝÇÔÈ¡¡¢°²ÅŶñÒâÈí¼þµÈ¶ñÒâÔ˶¯¡£¹¥»÷Á´ÖÐ £¬¹¥»÷ÕßÊ×ÏÈÕë¶Ô¹ýʧÉèÖõÄPostgreSQLÊý¾Ý¿â½¨ÉèÖÎÀíÔ±½ÇÉ« £¬²¢Ê¹ÓÃPROGRAM¹¦Ð§ÔËÐÐshellÏÂÁî¡£µ½ÊÖºó £¬ËûÃDz»µ«°þ¶áÁË¡°postgres¡±Óû§µÄ³¬µÈÓû§È¨ÏÞ £¬»¹Í¨¹ýÔ¶³Ì·þÎñÆ÷Ͷ·ÅPG_MEMºÍPG_COREÁ½¸öÔغÉ £¬ÕâЩÔغÉÄÜÖÕÖ¹¾ºÕùÍÚ¿óÀú³Ì¡¢ÉèÖó¤ÆÚÐÔ £¬²¢×îÖÕ°²ÅÅMonero¼ÓÃÜÇ®±Ò¿ó¹¤¡£´Ë¹¥»÷µÄ½¹µãÔÚÓÚʹÓÃÁËPostgreSQLµÄCOPYÏÂÁî¼°ÆäPROGRAM²ÎÊý £¬ÔÊÐí·þÎñÆ÷Ö´ÐÐÍâÊÖÏÂÁî²¢½«Ð§¹ûµ¼ÈëÊý¾Ý¿â¡£Ö»¹Ü¼ÓÃÜÇ®±ÒÍÚ¾òÊÇÆäÖ÷ҪĿµÄ £¬µ«¹¥»÷ÕßͬÑùÄÜÖ´ÐÐÏÂÁî¡¢»á¼ûÊý¾Ý²¢¿ØÖÆÊÜѬȾ·þÎñÆ÷¡£´ËÇå¾²Íþв͹ÏÔÁË»¥ÁªÍøÅþÁ¬PostgreSQLÊý¾Ý¿âÒòÈõÃÜÂë¶øÃæÁÙµÄÖØ´óΣº¦ £¬ÕâÍùÍùÔ´ÓÚÉèÖò»µ±ºÍÉí·ÝÈÏÖ¤¿ØÖƵÄȱʧ¡£


https://thehackernews.com/2024/08/new-malware-pgmem-targets-postgresql.html


6. Tycoon 2FAÍøÂç´¹ÂÚÕë¶ÔÃÀ¹úÕþ¸®×éÖ¯


8ÔÂ22ÈÕ £¬ANY.RUNµÄÑо¿Ö°Ô±½ÒÆÆÁËÒ»ÏîеÄÍøÂç´¹ÂÚÔ˶¯ £¬¸ÃÔ˶¯Ê¹ÓÃTycoon 2FA¹¤¾ß°ü £¬Õë¶ÔÃÀ¹úÕþ¸®×éÖ¯Õö¿ª¹¥»÷¡£Tycoon 2FA×Ô2023ÄêÆð±ãƵÈÔ±»ÓÃÓÚ´¹ÂÚÔ˶¯ £¬ÒÔÆäÖØ´óÕ½ÂԺͶ๦ЧÐÔÖø³Æ¡£×î½ü £¬¹¥»÷Õßͨ¹ýÊÜѬȾµÄÑÇÂíÑ·SESÕË»§ £¬·¢ËÍαװ³ÉDocusignµÄÓʼþ £¬ÓÕµ¼ÊÕ¼þÈ˵ã»÷Á´½Ó £¬ÂÄÀúһϵÁÐÖض¨Ïòºó £¬×îÖÕµÖ´ïð³äµÄMicrosoft TeamsµÇ¼ҳÃæ¡£ÕâЩÓʼþÌØÊâÕë¶Ô.govÓòÄÚµÄ338¸öÕþ¸®×éÖ¯µÄÓÊÏä £¬ÏÔʾ³ö¸ß¶ÈµÄÄ¿µÄÑ¡ÔñÐÔ¡£ÔÚANY.RUNɳÏäÖÐÆÊÎöÏÔʾ £¬´¹ÂÚÁ´½Ó½«Êܺ¦ÕßÖ¸µ¼ÖÁMSOFT_DOCUSIGN_VERIFICATION_SECURED-DOC_OFFICE[.]zatrdg[.]comµÈÓòÃû £¬ÒªÇóÊäÈëµç×ÓÓʼþµØµã¡£ÈôµØµãÆ¥Åä¹¥»÷ÕßÁбí £¬Êܺ¦Õß½«±»½øÒ»²½Öض¨ÏòÖÁdonostain[.]com £¬¸ÃÓòͨ¹ýAES¼ÓÃܵĶಿ·ÖPOSTÇëÇóʵÑéÇÔÈ¡MicrosoftÕË»§ÃÜÂë¡£±ðµÄ £¬vereares[.]ruÓòÃû×÷Ϊ¹¥»÷ÕßµÄÖض¨Ïò¹¤¾ß £¬ÔöÇ¿ÁË´¹Âڼƻ®µÄÎÞаÐÔ¡£ÖµµÃ×¢ÖصÄÊÇ £¬¹¥»÷Õß»¹Ê¹ÓÃÁËÕýµ±·þÎñÈçmailmeteor[.]comÀ´ÔöÇ¿´¹ÂÚÒ³ÃæµÄ¿ÉÐŶÈ £¬²¢Í¨¹ýjsonip[.]com»ñÈ¡IPÐÅÏ¢¡£


https://securityonline.info/new-phishing-campaign-targets-us-government-organizations/