Veeam°ä²¼¸üн¨¸´Veeam ONE¼à¿ØÆ½Ì¨Öжà¸ö·ì϶
°ä²¼¹¦·ò 2023-11-081¡¢Veeam°ä²¼¸üн¨¸´Veeam ONE¼à¿ØÆ½Ì¨Öжà¸ö·ì϶
11ÔÂ6ÈÕ£¬Veeam°ä²¼Á˰²È«¸üÐÂÒÔ½¨¸´Veeam ONE IT»ù´¡ÉèÊ©¼à¿ØºÍ·ÖÎöƽ̨ÖеÄ4¸ö·ì϶¡£ÆäÖнÏΪÑϳÁµÄÊÇCVE-2023-38547(CVSSÆÀ·Ö9.9)£¬¿ÉÓÃÀ´»ñÈ¡ÓйØVeeam ONEÓÃÓÚ½Ó¼ûÆäÅäÖÃÊý¾Ý¿âµÄSQL·þÎñÆ÷ÏνӵÄÐÅÏ¢£¬¿ÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐУ»ÒÔ¼°CVE-2023-38548£¨CVSSÆÀ·Ö9.8£©£¬¿É»ñÈ¡Veeam ONE Reporting ServiceËùʹÓÃÕÊ»§µÄNTLM¹þÏ£¡£Áí±íÁ½¸öÊÇ¿Éͨ¹ýXSS¹¥»÷ÇÔÈ¡ÖÎÀíÔ±ÁîÅÆµÄ·ì϶£¨CVE-2023-38549£©ºÍ¿É½Ó¼ûDashboard ScheduleµÄ·ì϶£¨CVE-2023-41723£©¡£
https://www.bleepingcomputer.com/news/security/veeam-warns-of-critical-bugs-in-veeam-one-monitoring-platform/
2¡¢ÈÕ±¾º½¿Õµç×Ó¹«Ë¾Ôâµ½AlphVµÄ¹¥»÷ÔËÓªÊܵ½Ó°Ïì
¾Ý11ÔÂ8ÈÕ±¨Â·£¬ÈÕ±¾º½¿Õµç×Ó¹«Ë¾Ð¹Â©£¬ÆäϵͳÔâµ½ÍøÂç¹¥»÷£¬ÍøÕ¾±»ÆÈ¹Ø¹Ø¡£ÖÜÒ»ÍíÉÏ£¬¸Ã¹«Ë¾µÄÍøÕ¾ÏÔʾÁËÒ»ÌõÐÂÎÅ£¬Åú×¢Æä²¿ÃÅ·þÎñÆ÷ÔÚÉÏÖÜËı»ºÚ¡£Õâ¼Ò¹«Ë¾°µÊ¾£¬ËûÃÇĿǰÔÚµ÷²éÈëÇÖÇé¿ö²¢¸´ÔÔËÓª£¬µ«Ò»Ð©ÏµÍ³ÒѾÖжϣ¬ÊÕ·¢µç×ÓÓʼþÒ²³öÏÖÁËһЩÑÓÎó£¬ÉÐδ·¢ÏÖÐÅϢй¶¡£AlphVÔÚ±¾ÖÜÒ»½«ÈÕ±¾º½¿Õµç×Ó¹«Ë¾²ÎÓëÆäÍøÕ¾£¬µ«¸Ã¹«Ë¾ÉÐδй©ÊÇ·ñÔÚÓ¦¶ÔÀÕË÷¹¥»÷¡£
https://therecord.media/japan-aviation-electronics-says-servers-accessed-during-cyberattack
3¡¢Unit 42·¢ÏÖAgriusÕë¶ÔÒÔÉ«ÁнÌÓýºÍ¿Æ¼¼ÐÐÒµµÄ¹¥»÷
Unit 42ÔÚ11ÔÂ6ÈÕ³ÆÆä·¢ÏÖÁËAgriusÕë¶ÔÒÔÉ«ÁнÌÓýºÍ¿Æ¼¼ÐÐÒµµÄ¹¥»÷¡£ÕâЩ¹¥»÷´Ó1ÔÂÒ»Ïò³ÖÐøµ½10Ô£¬Ö¼ÔÚÇÔÈ¡PIIºÍ֪ʶ²úȨµÈÃô¸ÐÐÅÏ¢¡£Ò»µ©ÇÔÈ¡ÁËÐÅÏ¢£¬¹¥»÷Õ߾ͻá×°Öø÷Àà²Á³ý·¨Ê½£¬À´¸²¸ÇÆä×ÙÓ°²¢Ê¹±»Ï°È¾µÄÖÕ¶ËÎÞ·¨Ê¹Óá£×î½üµÄ¹¥»÷»¹Ê¹ÓõÄ3ÖÖеIJÁ³ý·¨Ê½£¬MultiLayer Wiper¡¢PartialWasherºÍBFG Agonizer Wiper£¬ÒÔ¼°Ò»¸ö´ÓÊý¾Ý¿â·þÎñÆ÷ÌáÊØÐÅÏ¢µÄ×Ô½ç˵¹¤¾ßSqlextractor¡£
https://unit42.paloaltonetworks.com/agonizing-serpens-targets-israeli-tech-higher-ed-sectors/
4¡¢Google³Æ¶à¸öÍÅ»ïÊÔͼ½«ÆäÈÕÀú·þÎñÓÃ×÷C2»ù´¡ÉèÊ©
¾ÝýÌå11ÔÂ6ÈÕ±¨Â·£¬GoogleÌáÐѶà¸ö¹¥»÷ÍÅ»ïÔÚ¹²ÏíÒ»¸öÃûΪGoogle Calendar RAT(GCR)µÄPoC£¬ËüÀûÓÃÈÕÀú·þÎñÀ´ÍйܺÅÁîºÍ½ÚÔ죨C2£©»ù´¡ÉèÊ©¡£Æä¿ª·¢Õß°µÊ¾£¬¸Ã¾ç±¾Í¨¹ýÀûÓÃGoogleÈÕÀúÖеÄÊÂÎñÃèÊö´´½¨ÁËÒ»¸ö¡°Òñ±Îͨ·¡±£¬Ö¸±ê½«Ö±½ÓÏνӵ½Google¡£Google³ÆÉÐδ·¢ÏÖGCRÔÚÒ°±íµÄʹÓÃÇé¿ö£¬µ«Mandiant°ÑÎȵ½¶à¸öÍÅ»ïÔÚºÚ¿ÍÂÛ̳ÉÏ·ÖÏíÁËPoC£¬Õâ˵ÁËÈ»ËûÃǶÔÀÄÓÃÔÆ·þÎñ¸ÐÐËÖ¡£
https://securityaffairs.com/153700/hacking/google-calendar-rat-attacks.html
5¡¢VMwareÅû¶JupyterбäÌåÔÚ½üÆÚ¼¤ÔöµÄ¹¥»÷»î¶¯
VMwareÔÚ11ÔÂ6ÈÕÅû¶ÁËJupyter Infostealer±äÌåÐÂÒ»ÂֵĹ¥»÷»î¶¯¡£¸Ã¶ñÒâÈí¼þÓÚ2020Äêµ×³õ´Î±»·¢ÏÖ£¬ÖØÒªÕë¶Ô½ÌÓýºÍÎÀÉú²¿ÃÅ¡£´ÓǰÁ½ÖÜ£¬×êÑÐÈËÔ±¹Û²ìµ½µÄJupyter InfostealerϰȾÊýÁ¿Öð²½ÉÏÉý£¬Ä¿Ç°Ï°È¾×ÜÊýΪ26Àý¡£ËüÕë¶ÔChrome¡¢EdgeºÍFirefoxä¯ÀÀÆ÷£¬ÀûÓÃSEOÖж¾ºÍËÑË÷ÒýÇæ³Á¶¨ÀúÀ´´«²¼¡£ÐÂÒ»ÂֵĹ¥»÷ÀûÓÃÁËPowerShellºÅÁîÀ´Åú¸ÄºÍÊðÃû˽Կ£¬ÊÔͼ½«¶ñÒâÈí¼þ¼ÙÒâΪºÏ·¨ÊðÃûµÄÎļþ¡£
https://blogs.vmware.com/security/2023/11/jupyter-rising-an-update-on-jupyter-infostealer.html
6¡¢Kaspersky°ä²¼2023ÄêÓëÓÎÏ·ÓйصÄÍøÂçÍþвµÄ»ã±¨
11ÔÂ6ÈÕ£¬Kaspersky°ä²¼ÁË2023ÄêÓëÓÎÏ·ÓйصÄÍøÂçÍþвµÄ·ÖÎö»ã±¨¡£¸Ã»ã±¨·ÖÎöÁË2022Äê7ÔÂ1ÈÕÖÁ2023Äê7ÔÂ1ÈÕÆÚ¼äÍøÂçµÄÊý¾Ý¡£»ã±¨Ö¸³ö£¬Kaspersky×ܹ²¼ì²âµ½4076530´ÎÓëÓÎÏ·ÓйصÄ×ÀÃæÏ°È¾³¢ÊÔ£¬Ó°ÏìÁËÈ«Çò192456ÃûÓÎÏ·Íæ¼Ò¡£×î³£¼ûµÄÍþвÊÇÏÂÔØ·¨Ê½£¨89.70%£©£¬Æä´ÎÊǸæ°×Èí¼þ£¨5.25%£©ºÍľÂí£¨2.39%£©¡£×î³£±»ÓÃ×÷µö¶üµÄÊÇÎÒµÄÊÀ½ç£¨70.29%£©£¬Æä´ÎÊÇRoblox£¨20.37%£©¡¢·´¿Ö¾«Ó¢£ºÈ«Çò¹¥ÊÆ£¨4.78%£©ºÍ¾øµØÇóÉú£¨2.85%£©¡£
https://securelist.com/game-related-threat-report-2023/110960/


¾©¹«Íø°²±¸11010802024551ºÅ