TruthFinderºÍInstant Checkmateй¶2000¶àÍòÕË»§ÐÅÏ¢

°ä²¼¹¦·ò 2023-02-06
1¡¢TruthFinderºÍInstant Checkmateй¶2000¶àÍòÕË»§ÐÅÏ¢

      

¾ÝýÌå2ÔÂ5ÈÕ±¨Â·£¬PeopleConnectµÄ²¼¾°µ÷²é·þÎñTruthFinderºÍInstant Checkmate²úÉúÊý¾Ýй¶¡£1ÔÂ21ÈÕ£¬ºÚ¿ÍÂÛ̳BreachedµÄÒ»Ãû³ÉԱй¶Á˽ØÖÁ2019Äê4ÔÂ16ÈÕʹÓ÷þÎñµÄ2022ÍòTruthFinderºÍInstant Checkmate¿Í»§µÄÊý¾Ý¡£±»µÁÊý¾Ý×÷ΪÁ½¸ö½öÔ̺¬¿Í»§ÐÅÏ¢µÄ2.9 GB CSVÎļþ¹²Ïí£¬ÌáÈ¡ºóÕû¸öÊý¾Ý¼¯¸ß´ï7 GB£¬Ô̺¬ÐÕÃû¡¢µç»°ºÅÂë¡¢ÓʼþµØÖ·¡¢ÃÜÂëhashºÍÃÜÂë³ÁÖÃÁîÅÆµÈ¡£PeopleConnectÒѶԴËÊ·¢Õ¹µ÷²é£¬²¢È·ÈϸÃÃûµ¥ÊǼ¸Äêǰ´´½¨µÄ£¬ËƺõÔ̺¬ÁË2011ÄêÖÁ2019ÄêÆÚ¼ä´´½¨µÄËùÓÐÕË»§¡£


https://www.hackread.com/instant-checkmate-truthfinder-data-breach/


2¡¢ÐµÄAndroidľÂíPixPirateÖØÒªÕë¶Ô°ÍÎ÷µÄ½ðÈÚ»ú¹¹

      

2ÔÂ3ÈÕ£¬Cleafy»ã±¨ÆäÔÚ2022Äêµ×ÖÁ2023ËêÊ×·¢ÏÖÁËÒ»ÖÖÕë¶Ô°ÍÎ÷½ðÈÚ»ú¹¹µÄ¶ñÒâÈí¼þPixPirate¡£PixPirateÊôÓÚ×îÐÂÒ»´úµÄAndroidÒøÐÐľÂí£¬ÓÉÓÚËüÄܹ»Ö´ÐÐATS£¨×Ô¶¯×ªÕËϵͳ£©£¬¹¥»÷Õß¿ÉÄÜͨ¹ý¶à¼Ò°ÍÎ÷ÒøÐÐѡȡµÄ¼´Ê±Ö§¸¶Æ½Ì¨Pix×Ô¶¯½øÐжñÒâ»ã¿î¡£³ýÁËÇÔÈ¡Óû§ÔÚÒøÐÐÀûÓÃÉÏÊäÈëµÄÃÜÂë±í£¬¹¥»÷Õß»¹ÀûÓÃAuto.js¿ò¼Ü½øÐдúÂë»ìºÏºÍ¼ÓÃÜÀ´ÈƹýÄæÏò¹¤³ÌµÄ·ÖÎö¡£


https://www.cleafy.com/cleafy-labs/pixpirate-a-new-brazilian-banking-trojan


3¡¢Ó¡¶È×î´ó»õÔ˹«Ë¾FR8·þÎñÆ÷ÅäÖÃÃýÎóй¶140GBÊý¾Ý

      

ýÌå2ÔÂ4ÈÕй©£¬Ó¡¶È×î´óµÄ¿¨³µÔËÊä·þÎñ¹«Ë¾FR8Òò·þÎñÆ÷ÅäÖÃÃýÎóй¶ÁË140 GBµÄÊý¾Ý¡£1ÔÂ30ÈÕ£¬×êÑÐÈËÔ±ÔÚShodanÉÏËÑË÷ÅäÖÃÃýÎóµÄÔÆÊý¾Ý¿âʱ·¢ÏÖÁ˸÷þÎñÆ÷¡£Ð¹Â¶ÐÅÏ¢Éæ¼°¿Í»§ºÍÔ±¹¤µÄÐÕÃû¡¢µç»°¡¢·¢Æ±ºÍ¸¶¿îÃ÷ϸµÈÃô¸ÐÐÅÏ¢¡£Ä¿Ç°£¬¸ÃÅäÖÃÃýÎóµÄ·þÎñÆ÷ÈÔ´¦ÓÚ¶³ö״̬£¬FR8Ò²²¢Î´»ØÓ¦¸ÃÊÂÎñ¡£ÓÉÓÚ·þÎñÆ÷ÊÇʵʱµÄÇҸù«Ë¾Ò»ÏòûÓлØÓ¦£¬ÈôÊÇÊý¾ÝÂäÈë¶ñÒâµÄµÚÈý·½ÊÖÖУ¬±»ÎóÓúÍÀÄÓõĿÉÄÜÐԺܴó¡£


https://www.hackread.com/india-truck-brokerage-company-data-leak/


4¡¢×êÑÐÍŶӷ¢ÏÖÕë¶ÔESXi·þÎñÆ÷µÄ´ó¹æÄ£ESXiArgsÀÕË÷¹¥»÷

      

¾Ý2ÔÂ3ÈÕ±¨Â·£¬×êÑÐÍŶӷ¢ÏÖÁËÀûÓÃVMware ESXi·þÎñÆ÷ÖÐ佨¸´µÄÔ¶³Ì´úÂëÖ´Ðзì϶װÖÃÐÂÀÕË÷Èí¼þESXiArgsµÄ»î¶¯¡£·ì϶׷×ÙΪCVE-2021-21974£¬ÓÉOpenSLP·þÎñÖеĶÑÒç³öÒýÆð£¬¿É±»ÓÃÀ´Ö´Ðе͸´ÔӶȹ¥»÷¡£OVHcloudй©£¬¸Ã»î¶¯Í¨¹ýOpenSLP¶Ë¿Ú(427)Õë¶Ô7.0 U3i֮ǰ°æ±¾µÄESXi·þÎñÆ÷¡£Æ¾¾ÝShodanËÑË÷µÄÊý¾Ý£¬È«ÇòÖÁÉÙÓÐ120̨VMware ESXi·þÎñÆ÷ÒÑÔâµ½¹¥»÷¡£Õë¶Ô¸Ã»î¶¯µÄµ÷²éÈÔÔÚ½øÐÐÖС£


https://www.bleepingcomputer.com/news/security/massive-esxiargs-ransomware-attack-targets-vmware-esxi-servers-worldwide/


5¡¢ÒÁÀʺڿÍÍÅ»ïOilRigÀûÓÃкóÃŹ¥»÷Öж«È·µ±¾Ö»ú¹¹

      

Trend MicroÔÚ2ÔÂ2ÈÕÅû¶ÁËÒÁÀÊOilRigÕë¶ÔÖж«µ±¾Ö»ú¹¹µÄ¹¥»÷»î¶¯¡£2022Äê12Ô£¬×êÑÐÈËÔ±·¢ÏÖÁËÒ»¸ö¿ÉÖ´ÐÐÎļþ£¨¼ì²âΪTrojan.MSIL.REDCAP.AD£©ÒÑÔÚ¶àÌ¨ÍÆËã»úÉÏ·Ö·¢²¢Ö´ÐС£·ÖÎö·¢ÏָûÓëAPT×éÖ¯OilRig£¨APT34£©ÓйØ£¬ÖØÒªÖ÷ÕÅÊÇÇÔÈ¡Óû§µÄÍ´´¦¡£¸Ã»î¶¯Ê¼ÓÚÒ»¸ö»ùÓÚ.NETµÄÖ²È뷨ʽ£¬Æä¹¤×÷ÊÇ·Ö·¢Ëĸö·ÖÆçµÄÎļþ¡£µÚ¶þ½×¶Î»¹Ê¹ÓÃÁËÒ»¸öDLLÎļþ£¬ÄÜ´ÓÓòÓû§ºÍ±¾µØÕÊ»§Öлñȡʹ´¦¡£´Ë±í£¬Õâ´Î»î¶¯ÖеĺóÃÅ¿ÉÀûÓñ»Ï°È¾µÄÓÊÏäÕÊ»§½«ÇÔÈ¡µÄÊý¾Ý´ÓÄÚ²¿ÓÊÏä·¢Ë͵½¹¥»÷ÕßµÄÓʼþÕÊ»§¡£


https://www.trendmicro.com/en_us/research/23/b/new-apt34-malware-targets-the-middle-east.html


6¡¢Cisco½¨¸´IOxÀûÓÃÖеĺÅÁî×¢Èë·ì϶CVE-2023-20076

      

2ÔÂ3ÈÕ£¬Cisco°ä²¼°²È«¸üУ¬½¨¸´ÁËIOxÀûÓ÷¨Ê½Íйܻ·¾³ÖеĺÅÁî×¢Èë·ì϶£¨CVE-2023-20076£©¡£¸Ã·ì϶ÊÇÓÉÓÚ¼¤»îÀûÓ÷¨Ê½Ê±´«ÈëµÄ²ÎÊýδµÃµ½ÆëÈ«µÄ¾»»¯µ¼ÖµÄ£¬¹¥»÷ÕßÄܹ»Ê¹ÓÃÌØÔìµÄ¼¤»îpayloadÎļþÔÚCisco IOxÀûÓ÷¨Ê½Íйܻ·¾³ÖÐ×°Öúͼ¤»îÀûÓ÷¨Ê½À´ÀûÓô˷ì϶¡£³É¹¦ÀûÓø÷ì϶ºó£¬Äܹ»ÔڵײãÖ÷»ú²Ù×÷ϵͳÉÏÒÔrootÉí·ÝÖ´ÐÐËÁÒâºÅÁî¡£¸Ã·ì϶ӰÏìÁËÆôÓÃCisco IOxÖ°Äܲ¢ÇÒ²»Ö§³Ö±¾»ú dockerµÄÉ豸¡£


https://securityaffairs.com/141743/security/cisco-bug-iox-application-hosting-environment.html