΢Èí°ä²¼11Ô°²È«¸üн¨¸´3¸öÒѱ»ÀûÓõķì϶
°ä²¼¹¦·ò 2023-11-15΢ÈíÔÚ11ÔÂ14ÈÕ°ä²¼Á˱¾ÔµÄÖܶþ²¹¶¡£¬×ܼƽ¨¸´ÁË58¸ö·ì϶£¬Ô̺¬5¸ö0day¡£Õâ´Î½¨¸´µÄ0dayÖУ¬WindowsÔÆÎļþ΢ÐÍɸѡÆ÷Çý¶¯·¨Ê½ÌáȨ·ì϶£¨CVE-2023-36036£©¡¢Windows DWMÖ÷Ìâ¿âÌáȨ·ì϶£¨CVE-2023-36033£©ºÍWindows SmartScreen°²È«Ö°ÄÜÈÆ¹ý·ì϶£¨CVE-2023-36025£©Òѱ»ÀûÓã¬Microsoft Office°²È«Ö°ÄÜÈÆ¹ý·ì϶£¨CVE-2023-36413£©ºÍASP.NET Core»Ø¾ø·þÎñ·ì϶£¨CVE-2023-36038£©Ò²Òѱ»¹«¿ªÅû¶¡£
https://www.bleepingcomputer.com/news/microsoft/microsoft-november-2023-patch-tuesday-fixes-5-zero-days-58-flaws/
2¡¢SektorCERTÅû¶µ¤ÂóµÄ»ù´¡ÉèÊ©Ôâµ½´ó¹æÄ£¹¥»÷
¾Ý11ÔÂ14ÈÕ±¨Â·£¬µ¤Â󹨼ü²¿ÃŵķÇͶ»úÍøÂ簲ȫÖÐÐÄSektorCERTÅû¶£¬Æä¹Ø¼ü»ù´¡ÉèÊ©Ôâµ½ÁËÓÐÊ·ÒÔÀ´×î´ó¹æÄ£µÄÍøÂç¹¥»÷¡£µÚÒ»²¨¹¥»÷ÓÚ5ÔÂ11ÈÕÌáÒ飬¶ÌÔÝͣϢºó£¬µÚ¶þ²¨¹¥»÷ÓÚ5ÔÂ22ÈÕÆðÍ·£¬SektorCERTÓÚ5ÔÂ22ÈÕÒâʶµ½ÕâЩ¹¥»÷¡£¹¥»÷ÕßÀûÓÃZyxel·À»ðǽÖеķì϶£¨CVE-2023-28771£©£¬ÈëÇÖÁË22¼Ò´ÓÊÂÄÜÔ´»ù´¡ÉèÊ©ÔËÓªµÄ¹«Ë¾¡£SektorCERTÒÔΪ£¬¹¥»÷Õß°ÑÎÕÁËÖ¸±êµÄ¾ßÌåÐÅÏ¢£¬ºÜ¿ÉÄÜÊÇͨ¹ý֮ǰδ±»·¢ÏֵĿúËÅ»î¶¯ÍøÂçµÄ¡£²¢ÇÒÕâЩ¹¥»÷¿ÉÄÜÊǶà¸öÍÅ»ïÖ´Ðе쬯äÖÐÖÁÉÙÓÐÒ»¸ö¿É¹éÒòÓÚSandworm¡£
https://securityaffairs.com/154156/apt/denmark-critical-infrastructure-record-attacks.html
3¡¢RoyalÒÑÈëÇÖÖÁÉÙ350¸öÖ¸±ê²¢ÀÕË÷³¬¹ý2.75ÒÚÃÀÔª
11ÔÂ13ÈÕ£¬FBIºÍCISA°ä²¼Á˹ØÓÚÀÕË÷Èí¼þRoyalµÄ½áºÏÍøÂ簲ȫÕ÷ѯ(CSA)¡£¸ÃÕ÷ѯָ³ö£¬×Ô2022Äê9ÔÂÒÔÀ´£¬RoyalÒѹ¥»÷È«Çò350¶à¸öÖ¸±ê£¬Ìá³öÁ˳¬¹ý2.75ÒÚÃÀÔªµÄÀÕË÷ÒªÇó¡£´¹µöÓʼþÊÇRoyal½øÐгõʼ½Ó¼ûµÄ×î³É¹¦µÄÔØÌåÖ®Ò»¡£Óм£ÏóÅú×¢£¬Royal¿ÉÄÜÔÚ뻮ၮ³ÁËܺÍ/»òÑÜÉú±äÌå×ö³ï±¸£¬ÀÕË÷Èí¼þBlacksuitÓµÓкܶàÓëRoyalÀàËÆµÄ±àÂëÌØµã¡£
https://www.bleepingcomputer.com/news/security/fbi-royal-ransomware-asked-350-victims-to-pay-275-million/
4¡¢HuntersÐû³ÆÒÑÍøÂçHomeland¹«Ë¾³¬¹ý200GBµÄÊý¾Ý
¾ÝýÌå11ÔÂ13ÈÕ±¨Â·£¬Hunters International½«ÃÀ¹úÎïÒµÖÎÀí¹«Ë¾HomelandÔö³¤µ½ÁËÆäÍøÕ¾ÖС£¹¥»÷ÕßÐû³ÆÒÑÍøÂç183793¸öÎļþ£¬¹²204.1GB£¬»¹ÔÚÍøÕ¾Éϰ䲼ÁËÒ»·ÝÎļþÑù±¾×÷ΪÀÕË÷Ö¤¾Ý¡£Ñù±¾ÎļþÔ̺¬×â»§µÄµ®ÉúÈÕÆÚ¡¢µØÖ·¡¢ÄêÊÕÈëºÍ×â½ð¾ßÌåÐÅÏ¢µÈÓ×ÎÒÐÅÏ¢¡£Huntersй©¹¥»÷²úÉúÓÚ10ÔÂ26ÈÕ£¬ËûÃÇÂú×ãHomelandµÄÒªÇóÌṩ½âÃܹ¤¾ßÑÝʾºÍй¶Êý¾ÝÑù±¾ºóûÓÐÊÕµ½Èκλظ´£¬»¹°µÊ¾¸Ã¹«Ë¾±ØÒªÔÚ11ÔÂ18ÈÕ֮ǰ×ö³ö»ØÓ¦¡£
https://www.databreaches.net/property-management-firm-homeland-inc-allegedly-hacked-hackers-claim-to-have-hundreds-of-thousands-of-ssn-of-tenants/
5¡¢AhnLab¼ì²âµ½ÀûÓÃDdostf¹¥»÷MySQL·þÎñÆ÷µÄ»î¶¯
AhnLabÓÚ11ÔÂ14Èճƣ¬×î½ü·¢´Ë¿ÌMySQL·þÎñÆ÷ÉÏ×°ÖÃDdostfµÄ»î¶¯¡£DDdostfÊÇÒ»ÖÖDDoS bot£¬¶ÔÌØ¶¨Ö¸±êÖ´ÐÐDDoS¹¥»÷£¬ÓÚ2016Äê×óÓÒ³õ´Î±»·¢ÏÖ¡£Ôڿɹ«¿ª½Ó¼ûµÄϵͳÖУ¬É¨Ã跨ʽ»áËÑË÷ʹÓÃ3306/TCP¶Ë¿ÚµÄϵͳ£¬¶øºóÖ´Ðб©Á¦¹¥»÷»ò×ֵ乥»÷£¬»¹¿ÉÄܽӼûÖÎÀíÔ¹ØÊ»§Í´´¦¡£ÈôÊÇϵͳÔËÐеÄÊÇ´æÔÚ·ì϶µÄ佨¸´°æ±¾£¬¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶À´Ö´ÐкÅÁ¶øÎÞÐèÉÏÊö¹ý³Ì¡£Ö¸±êϵͳµÄϰȾÈÕÖ¾Åú×¢£¬³ýÁËDdostfÖ®±í£¬Ö¸±êϵͳÉÏ»¹±»×°ÖÃÁ˶ñÒâUDF DLL¡£
https://asec.ahnlab.com/en/58878/
6¡¢Cado·¢ÏÖÕë¶ÔDocker Engine APIµÄ½©Ê¬ÍøÂçOracleIV
11ÔÂ13ÈÕ£¬CadoÅû¶ÁË×î½ü·¢ÏÖµÄһ·Õë¶Ô¹«¿ªDocker Engine APIÊ·ýµÄл¡£Ôڴ˻ÖУ¬¹¥»÷ÕßÀûÓÃDockerÈÝÆ÷ÖеÄÃýÎóÅäÖÃÀ´´«²¼±àÒëΪELF¿ÉÖ´ÐÐÎļþµÄPython¶ñÒâÈí¼þ¡£¸Ã¶ñÒâÈí¼þ×ÔÉí³äÈÎDDoS bot´úÀí£¬¿ÉÄÜͨ¹ý¶àÖÖ²½Öè½øÐÐDoS¹¥»÷¡£ÔÚеÄOracleIV DDoS½©Ê¬ÍøÂç¶ñÒâÈí¼þÖУ¬¹¥»÷Õßͨ¹ýHTTP POSTÒªÇóÆô¶¯¶ÔDocker APIµÄ½Ó¼û¡£Õâ»á´¥·¢docker pullºÅÁ´ÓDockerhub»ñȡָ¶¨¾µÏñ¡£
https://www.cadosecurity.com/oracleiv-a-dockerised-ddos-botnet/


¾©¹«Íø°²±¸11010802024551ºÅ