ÍøÐŰì°ä²¼¡¶¹ØÓÚÅú¸Ä¡´ÖлªÈËÃñ¹²ºÍ¹úÍøÂ簲ȫ·¨¡µµÄ¾ö¶¨£¨Õ÷Ç󶨼û¸å£©¡·
°ä²¼¹¦·ò 2022-09-15
9ÔÂ14ÈÕ£¬¹ú¶È»¥ÁªÍøÐÅÏ¢°ì¹«ÊÒ°ä²¼¹ØÓÚ¹«¿ªÕ÷Çó¡¶¹ØÓÚÅú¸Ä¡´ÖлªÈËÃñ¹²ºÍ¹úÍøÂ簲ȫ·¨¡µµÄ¾ö¶¨£¨Õ÷Ç󶨼û¸å£©¡·¶¨¼ûµÄ֪ͨ¡£ÎªÁË×öºÃ¡¶ÖлªÈËÃñ¹²ºÍ¹úÍøÂ簲ȫ·¨¡·ÓëÓйØË¾·¨µÄÏνÓе÷£¬ÃÀÂú˾·¨ÔðÈÎÔì¶È£¬±£»¤Ó×ÎÒ¡¢×éÖ¯ÔÚÍøÂç¿Õ¼äµÄºÏ·¨È¨Àû£¬ÊØ»¤¹ú¶È°²È«ºÍ¹«¹²ÀûÒæ£¬ÍøÐŰì»áͬÓйز¿ÃŲÝÄâÁ˸þö¶¨£¬ÏÖÏòÉç»á¹«¿ªÕ÷Ç󶨼û¡£¹«¼Ò¿Éͨ¹ý·¢Ë͵ç×ÓÓʼþºÍ¼ÄËÍÐź¯µÄõè¾¶ºÍ·½Ê½·´À¡¶¨¼û£¬¶¨¼û·´À¡½ØÖ¹¹¦·òΪ2022Äê9ÔÂ29ÈÕ¡£
http://www.cac.gov.cn/2022-09/14/c_1664781649609823.htm
2¡¢Trend Micro½¨¸´Apex OneÖÐÒѱ»ÀûÓõÄRCE·ì϶
°²È«Èí¼þ¹«Ë¾Trend MicroÔÚ9ÔÂ13ÈÕ½¨¸´ÁËApex Oneƽ̨Öеķì϶(CVE-2022-40139)¡£¸Ã·ì϶ÊÇÓë»Ø¹öÖ°ÄÜÓйصIJ»ÕýÈ·ÑéÖ¤ÎÊÌâµ¼Öµģ¬´úÀíÄܹ»ÀûÓø÷ì϶ÏÂÔØÎ´¾ÑéÖ¤µÄ»Ø¹ö×é¼þ²¢Ö´ÐÐËÁÒâ´úÂë¡£µ«Êǹ¥»÷Õß±ØÐëÏÈ»ñµÃ¶ÔApex One·þÎñÆ÷ÖÎÀí½ÚÔį̀µÄ½Ó¼ûȨÏÞÄÜÁ¦³É¹¦ÀûÓô˷ì϶¡£¸Ã¹«Ë¾³ÆÒѾ·¢ÏÖÖÁÉÙÒ»´ÎÀûÓô˷ì϶µÄ³¢ÊÔ£¬µ«Ã»Óй«¿ª¹¥»÷µÄ¾ßÌåÐÅÏ¢¡£´Ë±í£¬Õâ´Î¸üл¹½¨¸´Á˵ǼÑéÖ¤ÈÆ¹ý·ì϶(CVE-2022-40144)ºÍ±¾µØÌáȨ·ì϶£¨CVE-2022-40143£©µÈ¶à¸ö·ì϶¡£
https://www.bleepingcomputer.com/news/security/trend-micro-warns-of-actively-exploited-apex-one-rce-vulnerability/
3¡¢ºÚ¿ÍÀûÓÃWP²å¼þWPGatewayÖеķì϶¹¥»÷28Íò¸öÍøÕ¾
¾ÝýÌå9ÔÂ14Èճƣ¬WordPress¸ß¼¶²å¼þWPGatewayÖеÄÒ»¸öÁãÈÕ·ì϶Õý±»¿í·ºÀûÓá£WordfenceÖ¸³ö£¬Õâ¸öÌáȨ·ì϶׷×ÙΪCVE-2022-3180£¨CVSSÆÀ·Ö9.8£©£¬±»¹¥»÷Õß±øÆ÷»¯À´½«¶ñÒâÖÎÀíÔ±Óû§Ôö³¤µ½ÔËÐÐWPGateway²å¼þµÄÍøÕ¾£¬Ö¼ÔÚÆëÈ«ÊÕÊÜÖ¸±êÍøÕ¾¡£Wordfence°µÊ¾£¬ËüÔÚ´Óǰ30ÌìÄÚ¼ì²âµ½Á˳¬¹ý460Íò´ÎÊÔIJÀûÓø÷ì϶µÄ¹¥»÷£¬Õë¶Ô³¬¹ý280000¸öÍøÕ¾¡£ÎªÁË·ÀÓù´ËÀ๥»÷£¬×êÑÐÈËÔ±½¨ÒéÓû§ÏÈ´ÓWordPress×°ÖÃÖÐɾ³ý¸Ã²å¼þ¡£
https://thehackernews.com/2022/09/over-280000-wordpress-sites-attacked.html
4¡¢DaixinÐû³ÆÒÑÇÔȡҽÁÆÖÐÐÄOakBendµÄ100Íò±Ê¼Í¼
¾Ý9ÔÂ14ÈÕ±¨Â·£¬ºÚ¿ÍÍÅ»ïDaixin¹¥»÷Á˵¿ËÈøË¹ÖݵÄÒ½ÁÆÖÐÐÄOakBend£¬µ¼Ö¸Ã×éÖ¯µÄͨѶºÍITϵͳÖжϡ£¸ÃÍÅ»ïÐû³ÆÒѾÇÔÈ¡Á˳¬¹ý100Íò±Ê¼Í¼£¬Ô̺¬ÐÕÃû¡¢µ®ÉúÈÕÆÚ¡¢Éç»á°²È«ºÅÂëºÍ²¡ÈËÒ½ÖÎÐÅÏ¢¡£OakBend°µÊ¾ÒѸôÀ뱻ϰȾÉ豸£¬Ä¿Ç°µç»°ÏµÍ³²¿ÃŸ´Ô£¬Ö»¹ÜûÓÐÓïÒôÐÅÏ䣬µ«µç×ÓÓʼþ·þÎñÄܹ»ÔËÐС£´Ë±í£¬±öϦ·¨ÄáÑÇÖÝ×î´óµÄÒ½ÁÆ×éÖ¯MATLVÔÚÉÏÖÜÎ峯Ôâµ½Á˸´ÔÓµÄÀÕË÷¹¥»÷£¬75628Ó×ÎÒµÄÐÅϢй¶¡£
https://www.theregister.com/2022/09/14/ransomware_medical_groups/
5¡¢°¢¸ùÍ¢µÄ²¼ÒËŵ˹°¬Àû˹ÊÐÒé»á³ÆÆäÔâµ½ÀÕË÷¹¥»÷
¾ÝýÌå9ÔÂ13ÈÕ±¨Â·£¬°¢¸ùÍ¢Ê×¶¼µÄ²¼ÒËŵ˹°¬Àû˹ÊÐÒé»á³ÆÆäÔâµ½ÀÕË÷¹¥»÷¡£¸Ã»ú¹¹ÔÚ¼¸ÌõÍÆÎÄÖаµÊ¾£¬¹¥»÷ÆðÍ·ÓÚÉÏÖÜÈÕ£¬ÆäÄÚ²¿²Ù×÷ϵͳ±»¹¥»÷£¬WiFiÏνÓÖжϡ£»ú¹¹³ÆËûÃÇѸ¿ì²ÉÈ¡Á˱ØÒª´ëÊ©ÒÔÈ·±£¹¤×÷µÄÂ½ÐøÐÔ£¬´òËãÔÚÖܶþ¸´ÔWiFiÍøÂ磬²¢Öð²½ÆôÓÃÆäËüµÄϵͳ¡£½ØÖÁÃÀ¹ú¶«²¿¹¦·òÖܶþÏÂÎ磬¸Ã»ú¹¹µÄÍøÕ¾ÈÔ´¦ÓڹعØ×´Ì¬£¬Ä¿Ç°Ã»ÓÐÀÕË÷ÍÅ»ï¶Ô´ËÊÂÕÆ¹Ü¡£´Ë±í£¬°¢¸ùÍ¢¿Æ¶û¶àÍß˾·¨»ú¹¹ÔÚÉϸöÔÂÒ²ÔøÔâµ½ÀÕË÷¹¥»÷¡£
https://therecord.media/buenos-aires-legislature-announces-ransomware-attack/
6¡¢Symantec·¢ÏÖÕë¶ÔÑÇÖÞÈ·µ±¾Ö»ú¹¹µÄÐÂÒ»ÂÖ¹¥»÷»î¶¯
9ÔÂ13ÈÕ£¬Symantecй©Æä·¢ÏÖÁËÐÂÒ»ÂÖ¼äµý»î¶¯£¬ÖØÒªÕë¶ÔÑÇÖÞÈ·µ±¾Ö»ú¹¹£¬ÒÔ¼°¹úÓк½¿Õº½ÌìºÍ¹ú·À¹«Ë¾¡¢µçÐŹ«Ë¾ºÍIT×éÖ¯¡£¹¥»÷Õß֮ǰÓëShadowPad RATÓйأ¬ÔÚÕâ´Î»î¶¯ÖÐÀûÓÃÁËÔ½·¢¶àÑù»¯µÄ¹¤¾ß¼¯¡£´ËÂÖ¹¥»÷»î¶¯ÖÁÉÙ´Ó2021ËêÊ×¾ÍÆðÍ·ÁË£¬ÒÔÍøÂçµý±¨ÎªÖØÒªÖ¸±ê¡£ÕâЩ¹¥»÷µÄÒ»¸öÏÔ×ÅÌØµãÊÇ£¬¹¥»÷ÕßÀûÓø÷ÀàºÏ·¨Èí¼þ°üÀ´Í¨¹ýDLL²à¼ÓÔØ¼¼Êõ¼ÓÔØ¶ñÒâÈí¼þpayload¡£´Ë±í£¬×êÑÐÈËÔ±ÒÔ2022Äê4ÔÂÌáÒéµÄ¹¥»÷ΪÀý£¬½ÒʾÁ˹¥»÷ÕßÈôºÎÈëÇÖµ±¾Ö»ú¹¹¡£
https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/espionage-asia-governments


¾©¹«Íø°²±¸11010802024551ºÅ