Atlassian½¨¸´Confluence·ì϶CVE-2023-22518

°ä²¼¹¦·ò 2023-11-02

1¡¢Atlassian½¨¸´Confluence·ì϶CVE-2023-22518


¾ÝýÌå10ÔÂ31Èճƣ¬Atlassian½¨¸´ÁËÒ»¸öÑϳÁµÄ·ì϶£¨CVE-2023-22518£©£¬ËüÓ°ÏìÁËËùÓа汾µÄConfluence Data CenterºÍConfluence Server¡£ÕâÊÇÒ»¸öÊÚȨ²»µ±·ì϶£¬¹¥»÷Õß¿ÉÀûÓø÷ì϶·ÛËéÊÜÓ°Ïì·þÎñÆ÷ÉϵÄÊý¾Ý£¬µ¼ÖÂÊý¾ÝÃÔʧ£¬µ«ÎÞ·¨±»ÓÃÀ´ÇÔÈ¡Êý¾Ý¡£Í¨¹ýatlassian.netÓò½Ó¼ûµÄAtlassian CloudÍøÕ¾²»ÊÜ´Ë·ì϶µÄÓ°Ïì¡£´Ë·ì϶ÉÐδ±»×Ô¶¯ÀûÓ㬸ù«Ë¾½¨ÒéÓû§µ±¼´ÀûÓøüС£


https://www.bleepingcomputer.com/news/security/atlassian-warns-of-critical-confluence-flaw-leading-to-data-loss/


2¡¢Avastɱ¶¾Èí¼þ½«Android GoogleÏóÕ÷Ϊ¶ñÒâÈí¼þ


¾Ý10ÔÂ31ÈÕ±¨Â·£¬°²È«¹«Ë¾Avast³Æ×ÔÖÜÁùÒÔÀ´£¬Æäɱ¶¾Èí¼þ½«²¿ÃÅÐͺŵÄÖÇÄÜÊÖ»úÉϵÄGoogle AndroidÀûÓÃÏóÕ÷Ϊ¶ñÒâÈí¼þ¡£ÔÚÊÜÓ°ÏìÉ豸ÉÏ£¬Óû§±»ÌáÐѵ±¼´Ð¶ÔØGoogleÀûÓã¬ÓÉÓÚËü¿ÉÄÜ»á°ÂÃØ·¢ËͶÌÐÅ¡¢ÏÂÔØºÍ×°ÖÃÆäËüÀûÓûòÇÔÈ¡Óû§ÐÅÏ¢¡£»¹ÓÐÈË¿´µ½ÁË·ÖÆçµÄÌáÐÑ£¬³ÆGoogleÀûÓÃÊÇÒ»¸öľÂí£¬Äܹ»Ô¶³Ì½Ó¼ûËûÃǵÄÉ豸£¬±»¹¥»÷ÕßÓÃÀ´×°ÖöñÒâÈí¼þ²¢ÇÔÈ¡Êý¾Ý¡£Avastй©£¬Æäɱ¶¾SDKÎó½«Google¼±¾çËÑË÷¿òÀûÓ÷¨Ê½Æô¶¯Æ÷ÏóÕ÷Ϊ¶ñÒâÈí¼þ£¬¸ÃÎÊÌâÒÑÓÚ10ÔÂ30ÈÕ½â¾ö¡£


https://www.bleepingcomputer.com/news/security/avast-confirms-it-tagged-google-app-as-malware-on-android-phones/


3¡¢Scarred ManticoreÀûÓÃLIONTAIL¹¥»÷Öж«µÄ¹ú¶È


Check PointÓÚ10ÔÂ31ÈÕÅû¶ÁËScarred ManticoreÕë¶ÔÖж«¹ú¶È¾üÕþ»ú¹¹ºÍµçÐŹ«Ë¾µÄ¹¥»÷»î¶¯¡£¸ÃÍÅ»ï´Ó2019ÄêÆðÒ»Ïò»îÔ¾£¬Ä¿Ç°µÄ»î¶¯ÔÚ2023ÄêÖÐÆÚ´ïµ½¶¥·å¡£×îлÀûÓÃÁËLIONTAIL£¬ÕâÊÇÒ»ÖÖ×°ÖÃÔÚWindows·þÎñÆ÷Éϵı»¶¯¶ñÒâÈí¼þ¿ò¼Ü¡£³öÓÚÒñ±ÎÐÔ£¬LIONTIALÖ²È뷨ʽÀûÓöÔWindows HTTPÕ»Çý¶¯·¨Ê½HTTP.sysµÄÖ±½ÓŲÓÃÀ´¼ÓÔØ³£×¤ÄÚ´æµÄpayload¡£×êÑÐÈËÔ±»¹³Æ£¬Scarred ManticoreÓëOilRig£¨±ðÃûAPT34£©ÓйØÁª¡£


https://research.checkpoint.com/2023/from-albania-to-the-middle-east-the-scarred-manticore-is-listening/


4¡¢Mandiant¼ì²âµ½¶àÆðÀûÓÃCitrix Bleed·ì϶µÄ»î¶¯


10ÔÂ31ÈÕ£¬Mandiant³ÆÆä¼ì²âµ½¶àÆðÀûÓÃCitrix Bleed·ì϶£¬À´¹¥»÷ÃÀÖÞ¡¢Å·ÖÞ¡¢·ÇÖÞºÍÑÇÌ«µØÓòµÄ»î¶¯¡£ÕâÊÇNetScaler ADCºÍNetScaler GatewayÉ豸ÖеÄÐÅϢй¶·ì϶£¨CVE-2023-4966£©£¬×Ô8ÔÂÏÂÑ®ÒÔÀ´Ò»ÏòÔÚ±»ÀûÓá£ÀûÓ÷ì϶ºó£¬¹¥»÷Õß»á½øÐÐÍøÂç¿úËÅ¡¢ÇÔÈ¡ÕÊ»§Í´´¦²¢Í¨¹ýRDP½øÐкáÏòÒÆ¶¯¡£Mandiant°µÊ¾£¬ÔÚ¸÷Àà»î¶¯ÖÐÀûÓÃCVE-2023-4966µÄ4¸ö¹¥»÷ÍŻÔÚPost-Exploitation½×¶Î´æÔÚһЩ³Áµþ¡£


https://www.mandiant.com/resources/blog/session-hijacking-citrix-cve-2023-4966


5¡¢¶ñÒâNuGet°üÀûÓÃMSBuild¼¯³ÉÀ´·Ö·¢¶ñÒâÈí¼þ


 ReversingLabsÔÚ10ÔÂ31ÈÕÅû¶ÁËͨ¹ý¶ñÒâNuGet°üÀ´·Ö·¢¶ñÒâÈí¼þµÄ»î¶¯¡£×êÑÐÈËÔ±ÓÚ10ÔÂ15ÈÕ·¢ÏÖÁË×îÐÂNuGet»î¶¯£¬ÀûÓÃ·ÖÆçµÄƴдÃýÎóµÄÈí¼þ°üÀ´×°ÖöñÒâÈí¼þ¡£´Ë»î¶¯µÄÐÂÏÊÖ®´¦ÔÚÓÚ£¬ÕâЩÈí¼þ°üûÓÐʹÓÃÔÚ×°Öþ籾ÖÐÖ²ÈëÏÂÔØ·¨Ê½µÄ³£Óò½Ö裬¶øÊÇÀûÓÃNuGetµÄMSBuild¼¯³ÉÀ´Ö´ÐдúÂë¡£ÕâÊÇ8Ô³õÒÔÀ´µÄ³ÖÐø»î¶¯µÄÒ»²¿ÃÅ£¬Ö±µ½10ÔÂÖÐÑ®£¬¹¥»÷Õ߲ůðÍ·ÀûÓÃMSBuild¼¯³É¡£ÔçÆÚ°æ±¾ÀûÓÃPowerShell¾ç±¾£¨init.ps1£©´ÓGitHub´æ´¢¿â»ñÈ¡¶ñÒâÈí¼þpayload¡£


https://www.reversinglabs.com/blog/iamreboot-malicious-nuget-packages-exploit-msbuild-loophole


6¡¢Cisco°ä²¼¹ØÓÚArid Viper¹¥»÷»î¶¯µÄ·ÖÎö»ã±¨


10ÔÂ31ÈÕ£¬Cisco Talos°ä²¼Á˹ØÓÚArid Viper¹¥»÷»î¶¯µÄ·ÖÎö»ã±¨¡£¸Ã»î¶¯×Ô2022Äê4ÔÂÆðÍ·»îÔ¾£¬Ò»Ö¹Øë¶Ô°¢À­²®ÓïµØÓò¡£¹¥»÷ÕßÀûÓÃαÔìµÄ¶ñÒâAndroidÀûÓã¬Ö¼ÔÚ´ÓÖ¸±êÊÖ»úÖÐÍøÂçÊý¾Ý¡£ÓÐȤµÄÊÇ£¬¸Ã¶ñÒâÈí¼þÓëÔ¼»áÈí¼þSkippedµÄÔ´´úÂëÀàËÆ£¬ÕâÅú×¢ÔËÓªÍÅ»ïҪôÓëSkippedµÄ¿ª·¢ÈËÔ±ÓÐÁªÏµ£¬ÒªÃ´·¸·¨»ñµÃÁËÏîÖ÷ÕŽӼûȨÏÞ¡£¹¥»÷Õß»á·Ö·¢¼Ù×°³ÉÔ¼»áÀûÓøüеĶñÒâÁ´½Ó£¬´Ó¶ø½«¶ñÒâÈí¼þ×°Öõ½Óû§µÄÉ豸¡£


https://blog.talosintelligence.com/arid-viper-mobile-spyware/