ÃϼÓÀ¹úijµ±¾ÖÍøÕ¾ÅäÖÃÃýÎóй¶Êý°ÙÍò¹«ÃñµÄÐÅÏ¢
°ä²¼¹¦·ò 2023-07-101¡¢ÃϼÓÀ¹úijµ±¾ÖÍøÕ¾ÅäÖÃÃýÎóй¶Êý°ÙÍò¹«ÃñµÄÐÅÏ¢
¾ÝýÌå7ÔÂ7ÈÕ±¨Â·£¬ÃϼÓÀ¹úijµ±¾ÖÍøÕ¾Ð¹Â¶ÁËÊý°ÙÍò¹«ÃñµÄÓ×ÎÒÐÅÏ¢£¬Éæ¼°ÐÕÃû¡¢µç»°ºÅÂë¡¢µç×ÓÓʼþµØÖ·ºÍÉí·ÝÖ¤ºÅÂëµÈ¡£×êÑÐÈËÔ±ÓÚ6ÔÂ27ÈÕ³õ´Î·¢ÏÖÁ˸ÃÎÊÌ⣬²¢ÁªÏµÁËÃϼÓÀ¹úµç×ÓÕþÎñÍÆËã»úÊÂÎñÏìÓ¦Ó××é(CERT)¡£¾ÝϤ£¬Ð¹Â¶µÄÊý¾Ý³Ê´Ë¿ÌÓëSQLÃýÎóÓйصÄGoogle²éÎÊÁ˾ÖÖС£×êÑÐÈËÔ±²¢Î´Ð¹Â©Ó¦¸Ã¾ÖÍøÕ¾µÄ¾ßÌåÃû³Æ£¬ÓÉÓÚÕâЩÊý¾ÝÈÔ¿ÉÔÚÏß»ñÈ¡¡£Ä¿Ç°£¬Ã»ÓÐÈκÎÃϼÓÀ¹úµ±¾Ö×éÖ¯¶Ô´ËÊÂ×ö³ö»ØÓ¦¡£
https://techcrunch.com/2023/07/07/bangladesh-government-website-leaks-citizens-personal-data/
2¡¢TA453ͨ¹ýÐÂϰȾÁ´×°ÖÃPowerShellºóÃÅGorjolEcho
ProofpointÓÚ7ÔÂ6ÈÕÅû¶ÁËÒÁÀʺڿÍÍÅ»ïTA453Õë¶ÔWindowsºÍmacOSµÄ¶ñÒâÈí¼þ»î¶¯¡£TA453ÓÚ5ÔÂ·ÝÆðͷʹÓÃLNKϰȾÁ´£¬¶ø²»ÊÇ´øÓкêµÄMicrosoft WordÎĵµ¡£Õâ´Î»î¶¯ÖУ¬¹¥»÷Õß¼Ù×°³É»Ê¼Ò½áºÏ±øÖÖ×êÑÐËù(RUSI)µÄ¸ß¼¶×êÑÐÔ±£¬Õë¶ÔÒ»¼ÒרһÓÚ±í½»ÊÂÎñµÄÃÀ¹úÖÇ¿âµÄºË°²È«×¨¼Ò¡£¹¥»÷ÕßʹÓø÷ÀàÔÆÍйÜÌṩÉÌÀ´ÌṩеÄϰȾÁ´£¬Ö¼ÔÚ×°ÖÃÐÂÐÍPowerShellºóÃÅGorjolEcho¡£´Ë±í£¬TA453»¹ÒÆÖ²ÁËÆä¶ñÒâÈí¼þ£¬²¢ÊÔͼÆô¶¯Ò»¸öÃûΪNokNokµÄÕë¶ÔmacOSµÄϰȾÁ´¡£
https://www.proofpoint.com/us/blog/threat-insight/welcome-new-york-exploring-ta453s-foray-lnks-and-mac-malware
3¡¢Mastodon½¨¸´¿Éµ¼Ö·þÎñÆ÷½Ù³ÖµÄ·ì϶TootRoot
¾Ý7ÔÂ7ÈÕ±¨Â·£¬¿ªÔ´µÄÈ¥ÖÐÐÄ»¯Éç½»ÍøÂçÆ½Ì¨Mastodon½¨¸´ÁË4¸ö°²È«·ì϶¡£ÆäÖÐ×îÑϳÁµÄÊÇMastodonýÌå´¦ÖôúÂëÖеķì϶TootRoot£¨CVE-2023-36460£©£¬¿Éµ¼ÖÂDoSºÍËÁÒâÔ¶³Ì´úÂëÖ´ÐеÈÎÊÌ⣬¿ÉÓÃÓÚÔÚ·þÎñÆ÷ÖÐÖ²ÈëºóÃÅ¡£¹¥»÷ÕßÀûÓø÷ì϶£¬¿ÉÄÜÎÞÏ޶ȵؽÚÔì·þÎñÆ÷¼°ÆäÍйܺÍÖÎÀíµÄÊý¾Ý¡£µÚ¶þ¸öÊÇXSS·ì϶£¨CVE-2023-36459£©£¬¿ÉÈÆ¹ýÖ¸±êä¯ÀÀÆ÷ÉϵÄHTMLËãÕÊ¡£Áí±íÁ½¸ö·ì϶ÊÇCVE-2023-36461ºÍCVE-2023-36462¡£
https://www.bleepingcomputer.com/news/security/critical-tootroot-bug-lets-attackers-hijack-mastodon-servers/
4¡¢¼ÓÃÜÇ®±Òƽ̨MultichainÔâµ½¹¥»÷Ëðʧ³¬¹ý1.25ÒÚÃÀÔª
ýÌå7ÔÂ8ÈÕ±¨Â·³Æ£¬¼ÓÃÜÇ®±Òƽ̨MultichainÒÑÔÝÍ£Æä·þÎñ£¬ÓÉÓÚËüÔÚµ÷²éÉæ¼°³¬¹ý1.25ÒÚÃÀÔªµÄ¼ÓÃÜÇ®±Ò±»µÁÊÂÎñ¡£ÉÏÖÜËÄÍí¼ä£¬¸Ã¹«Ë¾°µÊ¾£¬Æ½Ì¨²¿ÃÅ×ʲú¡°ÒÑÒì³£×ªÒÆÖÁδ֪µØÖ·¡±£¬²¢ÔÚ¼¸Ó×ʱºóÔÝÍ£ÁËËùÓзþÎñÒÔ½øÐе÷²é¡£ÖÜÎåÔçÉÏ£¬¸Ã¹«Ë¾°ä²¼ÉêÃ÷È·ÈÏËûÃÇÔâµ½Á˺ڿ͹¥»÷£¬²¢°µÊ¾½«»áÍË¿î¸ø¸÷ÈË¡£Óд«ÑÔ³ÆÕâ´Î¹¥»÷Êǰ×ñºÚ¿ÍËùΪ£¬µ«Éв»Ã÷ÏÔÕâЩ˵·¨ÊÇ·ñÕýÈ·¡£
https://therecord.media/millions-stolen-from-multichain-crypto
5¡¢Google PlayÖеÄÁ½¿î¼äµýÈí¼þÇÔÈ¡150ÍòÓû§µÄÐÅÏ¢
7ÔÂ8ÈÕ±¨Â·³Æ£¬PradeoÔÚGoogle PlayÉ̵êÖз¢ÏÖÁËÁ½¿î¶ñÒâÀûÓ㬰µ²Ø×żäµýÈí¼þ²¢¼à¶½¶à´ï150ÍòÓû§¡£ÕâÁ½¸öÀûÓ÷¨Ê½¶¼ÊÇÀ´×Ôͳһ¿ª·¢É̵ÄÎļþÖÎÀíµ±Ó㬱ðÀëÊÇ×°ÖÃÁ¿³¬¹ý100ÍòµÄÎļþ¸´ÔºÍÊý¾Ý¸´ÔÀûÓúÍ×°ÖÃÁ¿³¬¹ý50ÍòµÄÎļþÖÎÀíÆ÷¡£Á½¿îÀûÓûáÇÔÈ¡ÁªÏµÈËÁÐ±í¡¢Ã½ÌåÎļþ¡¢ÊµÊ±µØÎ»ºÍÒÆ¶¯¹ú¶È´úÂëµÈÐÅÏ¢¡£×êÑÐÈËÔ±°ÑÎȵ½£¬ÕâЩÀûÓöÔÍøÂçµ½µÄÊý¾ÝÖ´ÐÐÁËÒ»°ÙÂŴδ«Ê䣬Õâ¶ÔÓÚ¼äµýÈí¼þÀ´ËµÊDz»Ñ°³£µÄ¡£
https://thehackernews.com/2023/07/two-spyware-apps-on-google-play-with-15.html
6¡¢Î¢Èí°ä²¼¹ØÓÚÀÕË÷Èí¼þBlackByteµÄ¹¥»÷Á´µÄµ÷²é»ã±¨
7ÔÂ6ÈÕ£¬Î¢Èí°ä²¼¹ØÓÚÀÕË÷Èí¼þBlackByteµÄ·ÖÎö»ã±¨¡£×êÑÐÈËÔ±×î½ü¶ÔÒ»´ÎÈëÇֵĵ÷²éÖУ¬·¢ÏÖ¹¥»÷ÕßÔÚ²»µ½ÎåÌìµÄ¹¦·òÀïʵÏÖÁË´Ó³õʼ½Ó¼ûµ½Ö´ÐÐÕû¸ö¹¥»÷Á´¡£ÔÚÕâÎåÌìÄÚ£¬¹¥»÷ÕßʹÓÃÁËһϵÁй¤¾ßºÍ¼¼Êõ£¬×îÖÕ×°ÖÃÁËBlackByte 2.0À´ÊµÏÔìäÖ¸±ê¡£ÕâЩ¼¼ÊõÔ̺¬£ºÀûÓÃδ´ò²¹¶¡µÄExchange·þÎñÆ÷¡¢Ê¹ÓÃliving-off-the-land¹¤¾ß½øÐÐÓÆ¾ÃÐԺͿúËÅ¡¢²¿ÊðÓÃÓÚC2µÄCobalt StrikeÐűêÒÔ¼°²¿Êð¶¨ÔìµÄÊý¾ÝÍøÂçºÍÉøÈ빤¾ßµÈ¡£
https://www.microsoft.com/en-us/security/blog/2023/07/06/the-five-day-job-a-blackbyte-ransomware-intrusion-case-study/


¾©¹«Íø°²±¸11010802024551ºÅ