ÓÎÏ·¿¯Ðй«Ë¾ActivisionµÄÊý¾Ý±»°ä²¼ÔÚijºÚ¿ÍÂÛ̳
°ä²¼¹¦·ò 2023-03-011¡¢ÓÎÏ·¿¯Ðй«Ë¾ActivisionµÄÊý¾Ý±»°ä²¼ÔÚijºÚ¿ÍÂÛ̳
¾ÝýÌå2ÔÂ27ÈÕ±¨Â·£¬¹¥»÷ÕßÔÚºÚ¿ÍÂÛ̳BreachedÉϰ䲼ÁË´ÓÃÀ¹úÓÎÏ·¿¯ÐÐÉÌActivisionµÄAzureÊý¾Ý¿âÖÐÇÔÈ¡µÄÊý¾Ý¡£¹¥»÷²úÉúÓÚ2022Äê12ÔÂ4ÈÕ£¬ºÚ¿Í´¹µö¹¥»÷ÁËActivisionµÄÒ»ÃûHRÔ±¹¤²¢ÇÔÈ¡ÆäÍ´´¦¡£Õâ´Îй¶µÄÊý¾ÝÔ̺¬19444±Ê¼Í¼£¬Éæ¼°Ô±¹¤µÄÐÕÃû¡¢µç»°¡¢Ö°Î»¡¢µØÎ»ºÍÓʼþµØÖ·µÈ¡£¸Ã¹«Ë¾°µÊ¾£¬¾¹ý³¹µ×µ÷²é£¬È·¶¨Ã»ÓÐÃô¸ÐµÄÔ±¹¤ÐÅÏ¢¡¢ÓÎÏ·´úÂë»òÍæ¼ÒÐÅϢй¶¡£
https://securityaffairs.com/142779/data-breach/activision-data-leak.html
2¡¢Bitdefender°ä²¼ÀÕË÷Èí¼þMortalKombatµÄ½âÃÜÆ÷
ýÌå2ÔÂ28Èճƣ¬°²È«¹«Ë¾Bitdefender°ä²¼ÁËÀÕË÷Èí¼þMortalKombatµÄ½âÃÜÆ÷¡£MortalKombat»ùÓÚXorist£¬ÓÚ2023Äê1Ô³õ´Î³öÏÖ£¬ÆäÖØÒªÕë¶ÔÃÀ¹ú£¬µ«Ò²ÓÐÓ¢¹ú¡¢ÍÁ¶úÆäºÍ·ÆÂɱöµÄϰȾ»î¶¯¡£¹¥»÷Õ߻ᷢËÍÔ̺¬¶ñÒâZIP¸½¼þµÄÓʼþ£¬ÆäÖÐÔ̺¬BAT¼ÓÔØ·¨Ê½¾ç±¾£¬Æô¶¯Ê±Ëü»áÏÂÔØ²¢Ö´ÐÐÀÕË÷Èí¼þ¶þ½øÔìÎļþºÍLaplas¡£´Ë½âÃÜÆ÷ÊÇÒ»¸ö¶ÀÁ¢µÄ¿ÉÖ´ÐÐÎļþ£¬ÎÞÐèÔÚ±»Ï°È¾µÄÉ豸ÉÏ×°Öá£Ëü¿ÉɨÃèÕû¸öÎļþϵͳÒÔ¶¨Î»Ï°È¾MortalKombatµÄÎļþ£¬µ«ÎÞ·¨¶¨Î»ºÍ¸ù³ýLaplasÎļþ¡£
https://www.bleepingcomputer.com/news/security/new-mortalkombat-ransomware-decryptor-recovers-your-files-for-free/
3¡¢ºÚ¿ÍÀûÓÃWordPress HouzezÖеķì϶À´½Ù³ÖÍøÕ¾
¾ÝPatchstackÔÚ2ÔÂ27ÈÕ±¨Â·£¬ºÚ¿ÍÔÚÀûÓÃWordPress²å¼þHouzezÖеÄÁ½¸ö·ì϶À´½Ù³ÖÍøÕ¾¡£HouzezÊÇThemeForestÉϵÄÒ»¿î¸ß¼¶²å¼þ£¬ÖØÒªÓÃÓÚ·¿µØ²úÍøÕ¾£¬ÌṩÇáËɵÄÁбíÖÎÀíºÍ˳³©µÄ¿Í»§ÂÄÀú¡£µÚÒ»¸öÊÇHouzezÖ÷Ìâ²å¼þÖеÄÌáȨ·ì϶£¨CVE-2023-26540£©£¬ÁíÒ»¸öÊÇÓ°ÏìHouzesµÇ¼ע²á²å¼þµÄÌáȨ·ì϶£¨CVE-2023-260090£©¡£PatchstackÔÚÒ°±í·¢ÏÖµÄÀûÓô˷ì϶µÄ¹¥»÷ÖУ¬¹¥»÷ÕßÉÏ´«ÁËÒ»¸ö¿ÉÄÜÖ´ÐкÅÁî¡¢ÔÚÍøÕ¾ÉÏ×¢Èë¸æ°×»ò½«Á÷Á¿³Á¶¨Ïòµ½ÆäËü¶ñÒâÍøÕ¾µÄºóÃÅ¡£
https://patchstack.com/articles/psa-houzez-theme-unauthenticated-privilege-escalation-vulnerability-exploited-in-the-wild/
4¡¢×êÑÐÈËÔ±·¢ÏÖ¼Ù×°³ÉºÏ·¨Windowsµ÷ÊÔ¹¤¾ßµÄPlugX
2ÔÂ24ÈÕ£¬Trend MicroÅû¶ÁËPlugX¼Ù×°³É¿ªÔ´Windowsµ÷ÊÔ¹¤¾ßx32dbgµÄ¹¥»÷»î¶¯¡£¸Ãx32dbg.exeÓµÓÐÓÐЧµÄÊý×ÖÊðÃû£¬Ê¹¹¥»÷Õß¿ÉÄܰµ²Ø¡¢Î¬³ÖÓÆ¾ÃÐÔ¡¢ÌáÉýȨÏÞ²¢ÈƹýÎļþÖ´ÐÐÏÞ¶È¡£Õâ´Î»î¶¯ÒÀȻʹÓÃÁËDLL²à¼ÓÔØµÄ¼¼Êõ£¬ÀûÓþ¹ýÊý×ÖÊðÃûµÄÈí¼þÀûÓ÷¨Ê½¼ÓÔØ¶ñÒâDLL¡£×êÑÐÈËÔ±¶Ô¸Ã¹¥»÷Á´µÄ·ÖÎö»¹ÏÔʾ£¬Ê¹ÓÃx32dbg.exe×°ÖÃÁËÒ»¸öºóÃÅ¡£ÕâÊÇÒ»¸öUDP shell¿Í»§¶Ë£¬ÍøÂçϵͳÐÅÏ¢²¢ÆÚ´ýÔ¶³Ì·þÎñÆ÷µÄ¶î±íÖ¸Áî¡£
https://www.trendmicro.com/en_us/research/23/b/investigating-the-plugx-trojan-disguised-as-a-legitimate-windows.html
5¡¢Proofpoint°ä²¼¹ØÓÚTA569¹¥»÷»î¶¯µÄ·ÖÎö»ã±¨
ProofpointÔÚ2ÔÂ26ÈÕ°ä²¼Á˹ØÓÚTA569¹¥»÷»î¶¯µÄ·ÖÎö»ã±¨¡£TA569ÊÇÒ»¸ö¶à²úµÄ¹¥»÷ÍŻÀûÓÃÁ˶àÖÖÀàÐ͵Ä×¢È뷽ʽ¡¢Á÷Á¿·ÖÅäϵͳ(TDS)ºÍpayload£¬Ô̺¬µ«²»ÏÞÓÚSocGholish¡£TA569±»ÒÔΪÊÇÒ»¸ö³õʼ½Ó¼û´úÀí(IAB)»ò¶ÀÁ¢µÄÍøÂç·¸×ïÍŻÆäTTPÔÚ´Óǰ¼¸¸öÔÂÖвúÉúÁ˱䶯¡£Ö¸±ê½Ó¼ûÔâµ½TA569×¢Èë¹¥»÷µÄÍøÕ¾Ê±£¬Æää¯ÀÀÆ÷»áÚ¹ÊÍ×¢ÈëµÄJavaScript£¬Âú×ãÌØ¶¨Ç°Ìáºó»áÅ׳öÒ»¸öµö¶ü£¬ÈçÐéαµÄä¯ÀÀÆ÷¸üС£ÕâЩµö¶üÓÃÓÚ·Ö·¢¸÷Àà¶ñÒâÈí¼þpayload£¬Ô̺¬ÐÅÏ¢ÇÔÈ¡·¨Ê½»òRAT¡£
https://www.proofpoint.com/us/blog/threat-insight/ta569-socgholish-and-beyond
6¡¢Kaspersky°ä²¼2022ÄêÒÆ¶¯¶ñÒâÈí¼þÌ¬ÊÆµÄ·ÖÎö»ã±¨
2ÔÂ27ÈÕ£¬Kaspersky°ä²¼ÁË2022ÄêÒÆ¶¯¶ñÒâÈí¼þÌ¬ÊÆµÄ·ÖÎö»ã±¨¡£ÔÚ2022Ä꣬Kaspersky¼ì²âµ½1661743¸ö¶ñÒâ×°Ö÷¨Ê½¡¢196476¸öеÄÊÖ»úÒøÐÐľÂíºÍ10543¸öеÄÒÆ¶¯ÀÕË÷Èí¼þ¡£Òƶ¯¹¥»÷ÔÚ2021ϰëÄê½µÂäºóÇ÷ÓÚ°²ÎÈ£¬²¢ÔÚÕû¸ö2022Äêά³ÖÔÚͳһˮƽ¡£°´Òƶ¯¶ñÒâÈí¼þÀàÐÍ·ÖÀ࣬RiskToolÀàÀ¬»øÈí¼þ£¨27.39%£©Î»¾Ó°ñÊ×£¬È¡´úÁË֮ǰ×î¶àµÄ¸æ°×Èí¼þ£¨24.05%£©¡£Òƶ¯¸æ°×Èí¼þÖÐAdloϵÁÐÕ¼±È×î´ó (22.07%)£¬Æä´ÎÊÇEwind£¨16.46%£©ºÍHiddenAd£¨15.02%£©¡£
https://securelist.com/mobile-threat-report-2022/108844/


¾©¹«Íø°²±¸11010802024551ºÅ