NCC³Æ½ü2000̨Citrix NetScaler·þÎñÆ÷Òѱ»Ö²ÈëºóÃÅ
°ä²¼¹¦·ò 2023-08-171¡¢NCC³Æ½ü2000̨Citrix NetScaler·þÎñÆ÷Òѱ»Ö²ÈëºóÃÅ
¾Ý8ÔÂ16ÈÕ±¨Â·£¬NCC Group·¢ÏÖÁËCitrix NetScaler·ì϶µÄ´ó¹æÄ£ÀûÓû¡£¹¥»÷ÕßÒÔ×Ô¶¯»¯·½Ê½ÀûÓÃÁË·ì϶£¨CVE-2023-3519£©£¬ÔÚNetscaler·þÎñÆ÷ÖÐÖ²ÈëÁËWebshell¡£¼´±ãNetScalerÒÑ´ò²¹¶¡»ò³ÁÆô£¬¹¥»÷ÕßÒ²Äܹ»Ê¹ÓôËWebshellÖ´ÐÐËÁÒâºÅÁî¡£×êÑÐÈËÔ±×ܹ²ÔÚ1952¸ö·ÖÆçµÄNetScalerÖз¢ÏÖÁË2491¸öWebshell£¬´óÎÞÊýλÓڵ¹ú¡¢·¨¹ú¡¢ÈðÊ¿¡¢ÈÕ±¾ºÍÒâ´óÀûµÈ¹ú¡£½ØÖÁ8ÔÂ14ÈÕ£¬ÈÔÓÐ1828¸öNetScaler´æÔÚºóÃÅ£¬ÆäÖÐÔ¼1248̨ÒѾÕë¶Ô¸Ã·ì϶½øÐÐÁ˽¨¸´¡£
https://thehackernews.com/2023/08/nearly-2000-citrix-netscaler-instances.html
2¡¢´óÁ¿LinkedInÓû§³ÆÆäÕË»§±»½Ù³Ö»òËø¶¨²¿ÃÅÒª½»Êê½ð
¾ÝýÌå8ÔÂ15ÈÕ±¨Â·£¬CyberintÔÚ×î½ü¼¸ÖÜ·¢ÏÖÁËÒ»³¡³ÖÐøµÄ¹¥»÷»î¶¯ÖØÒªÕë¶ÔLinkedInÕÊ»§¡£¸Ã»î¶¯µÄÓ°ÏìÁìÓò¸²¸ÇÈ«Çò£¬µ¼Ö´óÁ¿Óû§ÎÞ·¨½Ó¼ûÆäÕÊ»§¡£ºÜ¶àLinkedInÓû§±§Ô¹ÆäÕË»§±»ÊÕÊÜ»òËø¶¨£¬²¢ÇÒÎÞ·¨Í¨¹ýLinkedInµÄÖ§³Ö·þÎñ½â¾ö¡£ÓÐЩÈËÉõÖÁ±»ÆÈ½»Êê½ðÄÜÁ¦³ÁлñµÃ½ÚÔìȨ£¬»òÕßÃæ¶ÔÕË»§±»ÓÀԶɾ³ýµÄÇé¿ö¡£¹ÌÈ»LinkedInÉÐδ°ä²¼Õýʽ²¼¸æ£¬µ«ËûÃǵÄÖ§³ÖÏìÓ¦¹¦·òËÆºõÒѾµ¢¸é£¬Óб¨Â·³ÆÖ§³ÖÒªÇóµÄÊýÁ¿ºÜ´ó¡£
https://www.bleepingcomputer.com/news/security/linkedin-accounts-hacked-in-widespread-hijacking-campaign/
3¡¢ÃÀ¹ú¸ßÀÖÊÏ(Clorox)Ôâµ½¹¥»÷µ¼ÖÂÔËÓªÁÙʱÖжÏ
8ÔÂ16ÈÕ±¨Â·³Æ£¬ÃÀ¹úÈÕÓÃÆ·³ö²úÉ̸ßÀÖÊÏ(Clorox)Ôâµ½¹¥»÷£¬µ¼ÖÂÔËÓªÁÙʱÖжϡ£¸Ã¹«Ë¾ÔÚ2022ÄêµÄÊÕÈ볬¹ý70ÒÚÃÀÔª¡£Õâ´Î¹¥»÷ÓÚ8ÔÂ14ÈÕ±»¼ì²âµ½£¬Cloroxµ±¼´²ÉÈ¡Ðж¯£¬¹Ø¹ØÁËÊÜÓ°ÏìµÄϵͳ¡£¸ÃÊÂÎñµÄµ÷²éÈÔÔÚÔçÆÚ½×¶Î£¬Éв»Ã÷ÏÔÊÇÄÄÖÖÀàÐ͵Ĺ¥»÷¡£È»¶øÏÖÓÐÐÅÏ¢Åú×¢£¬Õâ¿ÉÄÜÊÇÀÕË÷¹¥»÷¡£Õâ´Î¹¥»÷Ó°ÏìÁËCloroxµÄÔì×÷ºÍÏúÊÛÁ÷³Ì£¬ÒÔ¼°ÆäÍÆ¹ã¶©µ¥ºÍά³ÖÕý³£ÔËÓªµÄÄÜÁ¦¡£
https://www.infosecurity-magazine.com/news/clorox-disrupted-cyber-attack/
4¡¢´Óǰ°ëÄêCloudflare R2ÍйܵĴ¹µöÍøÒ³Á÷Á¿Ôö³¤61±¶
NetskopeÔÚ8ÔÂ14Èճƣ¬´Ó½ñÄê2Ôµ½7Ô£¬Cloudflare R2ÖÐÍйܵĴ¹µöÒ³ÃæÁ÷Á¿Ôö³¤ÁË61±¶¡£´óÎÞÊý´¹µö»î¶¯¶¼Õë¶ÔMicrosoftµÇ¼ʹ´¦£¬µ«Ò²ÓÐһЩÕë¶ÔAdobe¡¢DropboxºÍÆäËüÔÆÀûÓ÷¨Ê½¡£ÕâЩ¹¥»÷ÖØÒªÕë¶Ô±±ÃÀºÍÑÇÖÞ£¬Éæ¼°¸÷ÀàÁìÓò£¬ÒÔ¼¼Êõ¡¢½ðÈÚ·þÎñºÍÒøÐÐҵΪÊס£ÕâЩ´¹µö»î¶¯²»½öÀûÓÃCloudflare R2·Ö·¢¾²Ì¬´¹µöÒ³Ãæ£¬»¹ÀûÓøù«Ë¾µÄTurnstile²úÆ·À´Èƹý¼ì²â¡£
https://www.netskope.com/blog/evasive-phishing-campaign-steals-cloud-credentials-using-cloudflare-r2-and-turnstile
5¡¢AhnLab·¢ÏÖHakuna MatataÕë¶Ôº«¹úÆóÒµµÄ¹¥»÷»î¶¯
8ÔÂ16ÈÕ£¬AhnLabй©ÀÕË÷Èí¼þHakuna MatataÕý±»ÓÃÀ´¹¥»÷º«¹úµÄÆóÒµ¡£Hakuna MatataÊǽüÆÚ¿ª·¢µÄÀÕË÷Èí¼þ£¬ÓÚ7ÔÂ6ÈÕ³õ´Î±»Åû¶¡£Hakuna MatataÓëÆäËü´«Í³ÀÕË÷Èí¼þµÄ·ÖÆçÖ®´¦ÔÚÓÚ£¬ËüÓµÓÐClipBankerÖ°ÄÜ¡£¼´±ãÔÚ¼ÓÃÜÖ®ºó£¬ËüÒÀÈ»±£ÁôÔÚϵͳÖУ¬½«±ÈÌØ±ÒÇ®°üµØÖ·¸ü¸ÄΪ¹¥»÷ÕߵĵØÖ·¡£¼ÓÃÜϵͳºó£¬¹¥»÷Õß»áɾ³ý¹¥»÷ÖÐʹÓõÄÊÂÎñÈÕÖ¾ºÍ¶ñÒâÈí¼þ£¬Òò¶øºÜÄÑ»ñµÃÈ·ÇеÄÐÅÏ¢¡£µ«ÊÇ£¬Æ¾¾Ý¸÷ÀàÇé¿ö£¬´§Ä¦Ô¶³Ì×ÀÃæºÍ̸£¨RDP£©±»×÷Ϊ³õʼ¹¥»÷ÔØÌå¡£
https://asec.ahnlab.com/en/56010/
6¡¢Group-IB°ä²¼¹ØÓÚ¶ñÒâÈí¼þGigabudµÄ·ÖÎö»ã±¨
8ÔÂ14ÈÕ£¬Group-IB°ä²¼Á˹ØÓÚ¶ñÒâÈí¼þGigabudµÄ·ÖÎö»ã±¨¡£ËüÖØÒªÕë¶ÔÌ©¹ú¡¢Ó¡¶ÈÄáÎ÷ÑÇ¡¢Ô½ÄÏ¡¢·ÆÂɱöºÍÃØÂ³µÄ½ðÈÚ»ú¹¹¡£Gigabud RATÔÚÓû§±»ÊÚȨ½øÈë¶ñÒâÀûÓÃ֮ǰ²»»áÖ´ÐÐÈκζñÒâ»î¶¯£¬Õâ¼Ó´óÁ˼ì²âµÄÄѶȡ£ËüÖØÒªÍ¨¹ýÆÁϼÔìÀ´ÍøÂçÃô¸ÐÐÅÏ¢£¬¶ø²»ÊÇHTML¸²¸Ç¹¥»÷¡£³ÖÐøµ÷²é·¢ÏÖÁËÁíÒ»¸ö²»¾ß±¸RATÖ°ÄܵÄÑù±¾£¬´úºÅΪGigabud.Loan£¬ÕâÊÇÒ»¸öαÔìµÄ´û¿îÀûÓ㬻áÇÔÈ¡Óû§ÊäÈëµÄÊý¾Ý¡£
https://www.group-ib.com/blog/gigabud-banking-malware/


¾©¹«Íø°²±¸11010802024551ºÅ