×êÑÐÈËÔ±Åû¶SolarWinds ARM²úÆ·Öжà¸ö·ì϶µÄÏêÇé
°ä²¼¹¦·ò 2023-10-241¡¢×êÑÐÈËÔ±Åû¶SolarWinds ARM²úÆ·Öжà¸ö·ì϶µÄÏêÇé
¾ÝýÌå10ÔÂ20ÈÕ±¨Â·£¬×êÑÐÈËÔ±³ÆÆäÔÚSolarWinds Access Rights Manager(ARM)²úÆ·Öз¢ÏÖÁË3¸öÔ¶³Ì´úÂëÖ´Ðзì϶¡£ÕâЩ·ì϶±ðÀëÊÇcreateGlobalServerChannelInternalÖв»³ÉÐÅÊý¾ÝµÄ·´ÐòÁл¯·ì϶£¨CVE-2023-35182£©¡¢ OpenFileÖжÔÓû§Ìṩõè¾¶ÑéÖ¤²»×ãµÄ·ì϶£¨CVE-2023-35185£©ÒÔ¼°OpenClientUpdateFileÖжÔÓû§Ìṩõè¾¶ÑéÖ¤²»×ãµÄ·ì϶£¨CVE-2023-35187£©¡£ËüÃǵÄCVSSÆÀ·Ö¾ùΪ9.8£¬ÒÑÓÚ10ÔÂ18ÈÕ½¨¸´¡£
https://www.bleepingcomputer.com/news/security/critical-rce-flaws-found-in-solarwinds-access-audit-solution/
2¡¢ÃÀ¹úÃÜЪ¸ù´óѧÔâµ½¹¥»÷ѧÉúºÍ¹¤×÷ÈËÔ±µÄÐÅϢй¶
¾Ý10ÔÂ23ÈÕ±¨Â·£¬ÃÜЪ¸ù´óѧй©£¬ºÚ¿ÍÔÚ8Ô·ÝÈëÇÔìäϵͳ²¢½Ó¼ûÁËÔ̺¬Ñ§Éú¡¢ÉêÇëÈË¡¢Ð£ÓÑ¡¢¾è¿îÈË¡¢Ô±¹¤¡¢»¼ÕߺÍ×êÑвμÓÕßµÄÐÅÏ¢¡£Î´¾ÊÚȨµÄ½Ó¼û²úÉúÓÚ8ÔÂ23ÈÕÖÁ27ÈÕ£¬ÔÚ¼ì²âµ½¿ÉÒɻºó£¬¸ÃѧÌõ±¼´¶Â½ØÁËÕû¸öУ԰µÄÍøÂ磬ÒÔ¾¡Á¿¼õÇáÓ°Ïì¡£Õâ´ÎÊÂÎñ²»½öй¶ÁËÓ×ÎÒÐÅÏ¢£¬»¹Ð¹Â¶Á˲ÆÕþºÍÒ½ÁƾßÌåÐÅÏ¢¡£Ä¿Ç°£¬ÃÜЪ¸ù´óѧÒÑ֪ͨËùÓÐÊÜÓ°ÏìµÄÓ×ÎÒ£¬²¢½«ÎªËûÃÇÌṩÃâ·ÑÐÅÓþ¼à¿Ø·þÎñ¡£
https://www.bleepingcomputer.com/news/security/university-of-michigan-employee-student-data-stolen-in-cyberattack/
3¡¢FacebookºÍInstagramÓë·¨Âɲ¿ÃÅÁª¶¯µÄÕ˺ű»ÏúÊÛ
ýÌå10ÔÂ21Èճƣ¬ºÚ¿ÍÔÚ°µÍøÏúÊÛFacebookºÍInstagramµÄPolice PortalµÄ½Ó¼ûȨÏÞ¡£¸ÃÃÅ»§¿É±»·¨ÂÉ»ú¹¹ÓÃÓÚÒªÇóÓëÓû§ÓйصÄÊý¾Ý£¨IP¡¢µç»°¡¢Ë½ÐźÍÉ豸ÐÅÏ¢£©»òÒªÇóɾ³ýÌû×ӺͽûÓÃÕÊ»§¡£¹¥»÷ÕßÒÔ700ÃÀÔªµÄ¼ÛÖµÌṩ½Ó¼ûȨÏÞ£¬²¢ÇÒËÆºõÕ¼Óв»Ö¹Ò»¸öÃÅ»§µÄÕË»§¡£×êÑÐÈËÔ±´§Ä¦£¬ÒªÃ´ÊÇMetaÔâµ½ÁËÉ繤¹¥»÷µ¼Ö½ӼûȨÏÞй¶£¬ÒªÃ´¾ÍÊǹ¥»÷ÕßÕ¼ÓкϷ¨µÄ·¨ÂÉÕÊ»§µÄÍ´´¦¡£
https://securityaffairs.com/152811/cyber-crime/facebook-and-instagrams-police-portal-access.html
4¡¢Cadre ServicesÔ¼100GBÊý¾Ýй¶²¢±»ÀÕË÷30ÍòÃÀÔª
10ÔÂ19ÈÕ±¨Â·³Æ£¬AlphVÐû³Æ¹¥»÷Á˾ÍÒµºÍÈËÊ·þÎñCadre Services²¢ÒÑÇÔÈ¡100 GBµÄÎļþ¡£¹¥»÷ÍÅ»ïÔÚ9ÔÂ19ÈÕ³õ´ÎÁªÏµÁËCadre£¬²¢ÓÚ9ÔÂ22ÈÕÊÕµ½»Ø¸´¡£½»ÉæµÄ̸Ìì½ØÍ¼ÏÔʾ£¬AlphVÒªÇó30ÍòÃÀÔªÊê½ð£¬¸Ã¹«Ë¾×î³õ°µÊ¾Ô¸Òâ³ö¼Û25000ÃÀÔª£¬²¢³Æ×î¸ß±¨¼ÛΪ35000ÃÀÔª¡£×î½ü¼¸ÈÕ£¬AlphVÔÙ´ÎÏò¸Ã¹«Ë¾£¬ÒÔ¼°¿Í»§ºÍDataBreaches·¢ËÍÓʼþ£¬ÌṩÁ˽«ÒªÐ¹Â¶µÄÊý¾ÝµÄÑù±¾£¬Ô̺¬Ô±¹¤Êý¾ÝºÍÉêÇëÈËÊý¾Ý¡£
https://www.databreaches.net/another-small-firm-suffers-a-serious-ransomware-attack-cadre-services-gets-mauled-by-alphv/
5¡¢WithSecure·¢ÏÖÕë¶ÔÓ¢ÃÀµÈ¹úµÄDarkGate¹¥»÷»î¶¯
10ÔÂ20ÈÕ£¬WithSecureÅû¶ÁËÕë¶ÔÓ¢¹ú¡¢ÃÀ¹úºÍÓ¡¶ÈµÄDarkGate¹¥»÷»î¶¯¡£¸Ã»î¶¯ÓëÈ¥Äê³õ´Î·¢ÏÖµÄDucktail»î¶¯µÄÔ½ÄϹ¥»÷ÕßÓйأ¬³õʼϰȾý½éÊÇLinkedInÐÂÎźÍÓ²¼þÔì×÷ÉÌCorsairµÄFacebook¸æ°×רԱְ룬»á½«Ö¸±ê³Á¶¨Ïòµ½Google DriveÉÏÍйܵÄÎļþ¡£ÏÂÔØµÄÎĵµÔ̺¬Ò»¸öVBS¾ç±¾£¬¿ÉÄÜǶÈëÔÚDOCXÎļþÖУ¬»áÏÂÔØautoit3.exeºÍÒ»¸ö±àÒëºóµÄAutoit3¾ç±¾¡£¿ÉÖ´ÐÐÎļþºó»áÀûÓþ籾ÖеÄ×Ö·û´®»ú¹ØDarkGate£¬×°ÖÃÈýÊ®Ãëºó£¬¶ñÒâÈí¼þ»á³¢ÊÔ´ÓÖ¸±êϵͳÖÐÐ¶ÔØ°²È«²úÆ·¡£
https://labs.withsecure.com/publications/darkgate-malware-campaign
6¡¢Fortinet°ä²¼¶ñÒâÈí¼þExelaStealerµÄ·ÖÎö»ã±¨
10ÔÂ19ÈÕ£¬Fortinet°ä²¼Á˹ØÓÚ¶ñÒâÈí¼þExelaStealerµÄ·ÖÎö»ã±¨¡£ExelaStealerÊÇÒ»¸ö¸ù»ùÉÏ¿ªÔ´µÄÐÅÏ¢ÇÔÈ¡·¨Ê½£¬Äܹ»Ìṩ¸¶·Ñ¶¨Ôì·þÎñ¡£Æä¸¶·Ñ°æ±¾Ã¿ÔÂ20ÃÀÔª£¬Èý¸öÔÂ45ÃÀÔª£¬Æ½Éú°æ±¾120ÃÀÔª¡£ËüÓÉPython¿ª·¢²¢Ö§³ÖJavaScript£¬ÓµÓÐÇÔÈ¡ÃÜÂë¡¢DiscordÁîÅÆ¡¢ÐÅÓþ¿¨¡¢cookieºÍ»á»°Êý¾Ý¡¢»÷¼ü¡¢ÆÁÄ»½ØÍ¼ºÍ¼ôÌù°åÄÚÈݵÄÖ°ÄÜ¡£ExelaStealer¿ÉÄÜÊÇͨ¹ý¼Ù×°³ÉPDFÎĵµµÄ¿ÉÖ´ÐÐÎļþ½øÐзַ¢µÄ£¬Æô¶¯¶þ½øÔìÎļþºó£¬»áÏÔʾһ·ÝÒýÓÕÎļþ£¬Í¬Ê±ÔÚºó¶Ü͵͵Æô¶¯ÇÔÈ¡·¨Ê½¡£
https://www.fortinet.com/blog/threat-research/exelastealer-infostealer-enters-the-field


¾©¹«Íø°²±¸11010802024551ºÅ