AnimkerÊý¾Ý¿âÅäÖÃÃýÎ󳬹ý70ÍòÓû§µÄÐÅϢй¶
°ä²¼¹¦·ò 2023-03-021¡¢AnimkerÊý¾Ý¿âÅäÖÃÃýÎ󳬹ý70ÍòÓû§µÄÐÅϢй¶
¾Ý3ÔÂ1ÈÕ±¨Â·£¬×êÑÐÈËÔ±ÔÚShodanÉÏ·¢ÏÖÁËÒ»¸öÅäÖÃÃýÎóµÄÊý¾Ý¿â£¬Ð¹Â¶ÁËgetshow.ioºÍanimaker.comÍøÕ¾³¬¹ý700000Óû§µÄ²âÊÔºÍÓ×ÎÒÊý¾Ý¡£Getshow.ioÊôÓÚAnimker.com£¬ÓÐÎÊÌâµÄ·þÎñÆ÷×¢²áÔÚÓòÃûgetshow.ioÏ£¬ÓÉanimaker.comÖÎÀí¡£¸ÃÊý¾Ý¿âĿǰÔ̺¬5.3GBµÄÊý¾Ý£¬²¢ÇÒËæ×ÅÿÌìÐÂÔö³¤µÄÊý¾ÝÔÚ²»ÐÝÔö³¤£¬Éæ¼°Óû§ÐÕÃû¡¢É豸ÀàÐÍ¡¢IPµØÖ·ºÍÊÖ»úºÅÂëµÈ¡£Ä¿Ç°£¬AnimkerÒÑ»ñÖª´ËÊ£¬µ«ÈÔδ½øÐлØÓ¦¡£
https://www.hackread.com/video-marketing-software-animker-data-leak/
2¡¢Aruba Networks¸üн¨¸´ÆäArubaOSÖеÄ6¸ö·ì϶
ýÌå3ÔÂ1ÈÕ±¨Â·³Æ£¬Aruba Networks°ä²¼°²È«¸üУ¬½¨¸´ÁËÓ°ÏìÆäרÓÐÍøÂç²Ù×÷ϵͳArubaOS¶à¸ö°æ±¾µÄ6¸ö·ì϶¡£Õâ´Î½¨¸´µÄ·ì϶Äܹ»·ÖΪÁ½ÀࣺPAPIºÍ̸£¨Aruba Networks½ÓÈëµãÖÎÀíºÍ̸£©ÖеĺÅÁî×¢Èë·ì϶£¨CVE-2023-22747¡¢CVE-2023-22748¡¢CVE-2023-22749ºÍCVE-2023-22750£©ºÍ»ùÓÚ²Ö¿âµÄ»º³åÇøÒç¶Âí½Å£¨CVE-2023-22751ºÍCVE-2023-22752£©¡£ËüÃǵÄCVSSÆÀ·Ö¾ùΪ9.8£¬¿Éͨ¹ýUDP¶Ë¿Ú8211ÏòPAPI·¢ËÍÌØÔìÊý¾Ý°üÀ´ÀûÓ㬴ӶøÒÔÌØÈ¨Óû§Éí·ÝÖ´ÐÐËÁÒâ´úÂë¡£
https://www.bleepingcomputer.com/news/security/aruba-networks-fixes-six-critical-vulnerabilities-in-arubaos/
3¡¢Sysdig·¢ÏÖÖØÒªÕë¶ÔÔÆ»·¾³µÄSCARLETEEL¹¥»÷»î¶¯
SysdigÔÚ2ÔÂ28ÈÕ³ÆÆä·¢ÏÖÁËÒ»¸öÃûΪSCARLETEELµÄ¹¥»÷»î¶¯¡£¹¥»÷ʼÓÚ»ñµÃÍйÜÔÚAWSÉϵÄKubernetes¼¯ÈºµÄÃæÏò¹«¼ÒµÄ·þÎñµÄ³õʼ½Ó¼ûȨÏÞ£¬³É¹¦ºó¹¥»÷Õ߾ͻáÏÂÔØÒ»¸öXMRig coinminerºÍÒ»¸ö¾ç±¾£¬ÓÃÓÚ´ÓKubernetes podÖÐÇÔÈ¡ÕÊ»§Í´´¦¡£¹¥»÷Õß»áʹÓÃLambdaº¯Êýö¾ÙºÍ¼ìË÷ËùÓÐרÓдúÂëºÍÈí¼þ£¬ÒÔ¼°ÆäÖ´ÐÐÃÜÔ¿ºÍLambdaº¯Êý»·¾³±äÁ¿£¬ÒÔÕÒµ½IAMÓû§Æ¾Ö¤¡£SysdigÒÔΪ¼ÓÃܽٳֹ¥»÷±»ÓÃ×÷µö¶ü£¬Ö¼ÔÚ´ïµ½¹¥»÷ÕßµÄÕæÕýÖ÷ÕÅ£¬¼´µÁȡרÓÐÈí¼þ¡£
https://sysdig.com/blog/cloud-breach-terraform-data-theft/
4¡¢Blind Eagle¼ÙÒâµ±¾Ö˰Îñ»ú¹¹Õë¶Ô¸çÂ×±ÈÑǵĻú¹¹
2ÔÂ27ÈÕ£¬BlackberryÅû¶ÁËBlind EagleÕë¶Ô¸çÂ×±ÈÑǹؼüÐÐÒµµÄÐÂÒ»ÂÖ¹¥»÷»î¶¯¡£BlackberryÓÚ2ÔÂ20ÈÕ¼ì²âµ½Õâ´Î¹¥»÷»î¶¯£¬¹¥»÷Õß¼ÙÒâµ±¾Ö˰Îñ»ú¹¹¹ú¶È˰ÎñºÍº£¹Ø×ÜÊð(DIAN)£¬ÖØÒªÕë¶Ô¸çÂ×±ÈÑǵÄÎÀÉú¡¢½ðÈÚ¡¢·¨ÂÉ¡¢ÒÆÃñºÍÕÆ¹Ü½»ÉæµÄ»ú¹¹¡£´¹µöÓʼþ´øÓÐÒ»¸öÖ¸ÏòPDFÎļþµÄÁ´½Ó£¬¸ÃÎļþ¾Ý³ÆÍйÜÔÚDIANÍøÕ¾ÉÏ£¬ÏÖʵÉÏ»á×°ÖöñÒâÈí¼þ¡£PayloadÊÇÒ»¸ö»ìºÏµÄVBS£¬ËüÀûÓÃPowerShell¼ìË÷»ùÓÚ.NETµÄDLLÎļþ£¬×îÖÕ½«AsyncRAT¼ÓÔØµ½ÄÚ´æÖС£
https://blogs.blackberry.com/en/2023/02/blind-eagle-apt-c-36-targets-colombia
5¡¢FortiGuardÅû¶LockBitÐÂÒ»ÂÖ¹¥»÷µÄϰȾÁ´ºÍTTP
FortiGuardÓÚ2ÔÂ28ÈÕ°ä²¼»ã±¨ÏêÊöÁËLockBitÐÂÒ»ÂÖÀÕË÷¹¥»÷µÄϰȾÁ´ºÍTTP¡£×êÑÐÈËÔ±ÔÚ2022Äê12ÔºÍ2023Äê1Ô·¢ÏÖLockBitµÄ»î¶¯£¬ÖØÒªÕë¶ÔÄ«Î÷¸çºÍÎ÷°àÑÀµÄÕ÷ѯºÍ˾·¨ÐÐÒµµÄ¹«Ë¾¡£¸Ã»î¶¯Ê¹ÓÃÁË¿ÉÓÐЧƥµÐAVºÍEDR½â¾ö¹æ»®µÄ·½Ê½£¬Í¨¹ý.imgÈÝÆ÷·Ö·¢ÈƹýÁËWebÏóÕ÷(MOTW)±£»¤»úÔ죬¶à½×¶Î¾ç±¾ÌáÈ¡ÊÜÃÜÂë±£»¤µÄÀÕË÷Èí¼þ¿ÉÖ´ÐÐÎļþ£¨Ö»ÓÐÔÚʹÓùÖÒìÃÜÂëÔËÐÐʱ²Å»á±»½âѹ£©¿ÉÈÆ¹ý»ùÓÚÊðÃûµÄ¼ì²â¡£VirusTotalÖÐÑù±¾µÄ¼ì²âÂʺܵͣ¬Åú×¢¸Ã»î¶¯Ê¹ÓõIJ½ÖèÔÚ¼ì²âÈÆ¹ý·½ÃæÊÇÓÐЧµÄ¡£
https://www.fortinet.com/blog/threat-research/emerging-lockbit-campaign
6¡¢SonicWall°ä²¼2023ÄêÍøÂçÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨
ýÌå2ÔÂ28Èճƣ¬SonicWall°ä²¼ÁË2023ÄêÍøÂçÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨¡£»ã±¨Ö¸³ö£¬SonicWallÔÚ2022Äê×ܹ²¼Í¼ÁË55ÒڴζñÒâÈí¼þ¹¥»÷£¬Í¬±ÈÔö³¤2%¡£ÀÕË÷Èí¼þÔÚ2022Äê³ÖÐø½µÂ䣬ÊýÁ¿½µÂäÖÁ4.933ÒÚ£¬Í¬±È½µÂä21%¡£ÎïÁªÍø¶ñÒâÈí¼þÊýÁ¿ÔÚ´ó·ùÔ¾Éý£¬³õ´ÎÍ»ÆÆ1ÒÚ´ó¹Ø£¬¹²1.123Òڴι¥»÷£¬Í¬±ÈÔö³¤87%¡£¼ÓÃܽٳֹ¥»÷Ϊ1.393ÒڴΣ¬±È2021ÄêÔö³¤ÁË43%¡£È¥Äê·¢ÏÖÁË465501¸öеĶñÒâÈí¼þ±äÌ壬¾ùÔÈÿÌì1279¸ö¡£
https://www.sonicwall.com/2023-cyber-threat-report/


¾©¹«Íø°²±¸11010802024551ºÅ