¶ñÒâÈí¼þBlank GrabberÕë¶ÔPython¿ª·¢ÈËÔ±ÇÔÊØÐÅÏ¢

°ä²¼¹¦·ò 2024-01-16
1. ¶ñÒâÈí¼þBlank GrabberÕë¶ÔPython¿ª·¢ÈËÔ±ÇÔÊØÐÅÏ¢


1ÔÂ14ÈÕ £¬Imperva Íþв×êÑÐÍŶÓ×î½üÔÚ PyPI Öз¢ÏÖÁËÒ»¸öÃûΪ¡°sellpass-sdk¡±µÄ¶ñÒâÈí¼þ°ü £¬¸ÃÈí¼þ°üÊÇ¡°Blank Grabber¡±ÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þµÄ´«²¼Õß¡£ÔÚ²úÉúһϵÁÐÀàËÆÊÂÎñÖ®ºó £¬ÕâÒ»·¢ÏÖ±ê־ȡ Python ¿ª·¢µÄÍøÂ簲ȫÁìÓò³öÏÖÁËÁîÈËÓÇÓôµÄÇ÷Ïò¡£¸Ã¶ñÒâÈí¼þ°ü·ÂÕպϷ¨Èí¼þ°ü¡°sellpass¡± £¬Ñ¡È¡¸÷ÀàÕ½ÊõÀ´³ÉÁ¢¿ÉÐŶÈ¡£ÆäÖÐÔ̺¬Ê¹ÓÃÀàËÆµÄ×÷ÕßÐÕÃûÒÔ¼°´´½¨¶à¸ö°æ±¾ÒÔʹÆä¿´ÆðÀ´µÃµ½»ý¼«ÊØ»¤¡£ÕâÖֽƼƵ¼Ö¸ÃÈí¼þ°ü±»ÂÅ´ÎÏÂÔØ £¬Í¹ÏÔ³ö´ËÀà¶ñÒâÈí¼þÄܹ»ÇáËÉÉøÈëϵͳ¡£Ò»µ©×°Öà £¬¡°Blank Grabber¡±¾Í»á²û·¢³öÓк¦ÐÐΪ¡£Ëü¿ÉÄÜ×èÖ¹ÊÜϰȾÉ豸ÉϵÄÀ´µçºÍÐÂÎÅ £¬Ô¤·ÀÊܺ¦ÕßÊÕµ½³ÁÒª¾¯±¨¡£¸Ã¶ñÒâÈí¼þÖ´ÐÐÁ˸´ÔÓµÄÊý¾Ýй¶ºÍϵͳÈëÇÖÕ½Êõ¡£ÕâÒ»ÊÂÎñÃ÷ÏÔµØÌáÐÑÈËÃÇά³ÖÍøÂ簲ȫ¾¯ÌèµÄ³ÁÒªÐÔ¡£¿ª·¢ÈËÔ±ºÍÓû§¶¼±ØÐëÉóÉ÷ÐÐÊ £¬ÓÈÆäÊÇ´Ó PyPI µÈ´æ´¢¿â»ñÈ¡Èí¼þ°üʱ¡£


2. Phemedrone StealerÀûÓÃCVE-2023-36025¶ã±Ü¼ì²â


1ÔÂ14ÈÕ £¬ÔÚ×î½üµÄÒ»Ïî·¢ÏÖÖÐ £¬Ç÷Ïò¿Æ¼¼µÄÍøÂ簲ȫ×êÑÐÈËÔ±·¢ÏÖ¶Ô CVE-2023-36025 µÄ»ý¼«ÀûÓà £¬µ¼ÖÂÏÈǰδ֪µÄ¶ñÒâÈí¼þ±äÌ壨³ÆÎª Phemedrone Stealer£©µÄ´«²¼¡£Phemedrone Stealer ÊÇÒ»ÖÖÒþÐζñÒâÈí¼þ £¬ÖØÒªÕë¶ÔÍøÂçä¯ÀÀÆ÷¡¢¼ÓÃÜÇ®±ÒÇ®°üºÍÐÂÎÅÀûÓ÷¨Ê½ £¬Ô̺¬Telegram¡¢Steam ºÍ Discord µÈÊ¢ÐÐÆ½Ì¨¡£ÕâÖÖ¶à·½ÃæµÄ¶ñÒâÈí¼þ²»½ö½öÊÇÇÔÈ¡Êý¾Ý£»Ëü»¹²¶»ñÆÁÄ»½ØÍ¼²¢ÍøÂç¹Ø¼üϵͳÐÅÏ¢ £¬ÀýÈçÓ²¼þ¾ßÌåÐÅÏ¢¡¢µØÎ»ºÍ²Ù×÷ϵͳϸ½Ú¡£±»µÁÊý¾Ýͨ¹ý Telegram »òÆäºÅÁîºÍ½ÚÔì·þÎñÆ÷ÉóÉ÷µØ´«Ê䏸¹¥»÷Õß¡£Phemedrone Stealer µÄÒìºõѰ³£Ö®´¦ÔÚÓÚÆä¿ªÔ´ÐÔÖÊ £¬Óà C# ±àд £¬²¢ÔÚ GitHub ºÍ Telegram ÉÏ»ý¼«ÊØ»¤¡£Phemedrone Stealer ³É¹¦µÄ±¾Ô­ÔÚÓÚËüÀûÓÃÁË CVE-2023-36025 £¬ÕâÊÇÒ»¸öÓ°ÏìMicrosoft Windows Defender SmartScreen µÄ·ì϶¡£´Ë·ì϶ÊÇÓÉÓÚ²»×ã¶Ô Internet ¿ì½Ý·½Ê½ (.url) ÎļþµÄ²é³­ºÍÓйØÌáÐѶøµ¼Ö嵀 £¬ÍþвÐÐΪÕßÀûÓÃÕâЩÎļþÀ´Ôì×÷¶ñÒâ .url Îļþ¡£ÕâЩÎļþÏÂÔØ²¢Ö´ÐжñÒâ¾ç±¾ £¬ÓÐÐ§ÈÆ¹ý Windows Defender SmartScreen ÖÒ¸æºÍ²é³­¡£Î¢ÈíÓÚ 2023 Äê 11 Ô 14 ÈÕ½¨²¹ÁË´Ë·ì϶ £¬µ«¹¥»÷ÀûÓõijöÏÖ´ÙÊ¹ÍøÂ簲ȫºÍ»ù´¡ÉèÊ©°²È«¾Ö (CISA) ½«ÆäÄÉÈëÒÑÖªÀûÓ÷ì϶ (KEV) ÁбíÖС£


3. ×êÑÐÍŶӳÆ2023ÄêÀÕË÷Èí¼þÍÅ»ïÒѹ¥»÷½ü5200¸öÆóÒµ


1ÔÂ12ÈÕ £¬Rapid7 µÄһƪ²©¿ÍÎÄÕÂÖаµÊ¾ £¬2023 Ä꽫Óнü 5,200 ¸ö×éÖ¯Ôâ·êÀÕË÷Èí¼þ¹¥»÷ £¬²¢´ÓÆäÖÎÀíµÄ¼ì²âºÍÏìÓ¦ÍŶӵĹ«¿ªÅû¶ºÍÊÂÎñÊý¾ÝÖнøÐÐÁË×êÑС£Rapid7 Íþв·ÖÎö¸ß¼¶×ܼà Christiaan Beek Ôڻ㱨ÖаµÊ¾£º¡°ÊÂʵÉÏ £¬ÎÒÃÇÒÔΪÕâ¸öÊý×ÖÏÖʵÉϸü¸ß £¬ÓÉÓÚËüûÓÐ˼¿¼µ½ºÜ¶à¿ÉÄÜδ±»»ã±¨µÄ¹¥»÷¡£¡±Rapid7 ûÓÐÌṩ 2022 ÄêµÄÊý¾Ý £¬µ«ÆäËû¹«Ë¾µÄ×êÑеóö½áÂÛ £¬ÀÕË÷Èí¼þ¹¥»÷µÄÊýÁ¿ÔÚÉÏÉý¡£BlackFog µÄÊý¾ÝÏÔʾ £¬2023 ÄêϰëÄêµÄÀÕË÷Èí¼þ¹¥»÷ÊýÁ¿ÊÇ2022 ÄêϰëÄêµÄÁ½±¶¡£¹ÌÈ»ÀÕË÷Èí¼þ»î¶¯ÒÀÈ»ºÜ¸ß £¬µ«ÓÃÓÚÕâЩ¹¥»÷µÄ¹ÖÒìÀÕË÷Èí¼þ¼Ò×åµÄÊýÁ¿Ï÷¼õÁËÒ»°ëÒÔÉÏ £¬´Ó2022ÄêµÄ95¸öмÒ×åÏ÷¼õµ½2023ÄêµÄ43¸ö¡£±È¿Ë°µÊ¾ £¬ÕâÅú×¢µ±Ç°µÄÀÕË÷Èí¼þϵÁкÍÄ£ÐÍÔÚÂú×ãÍþвÐÐΪÕßµÄÖ¸±ê¡£AlphV ÊÇÈ¥Äê×î»îÔ¾µÄÍþв×éÖ¯¡£2023 Äê½ÓÏÂÀ´µÄ4¸ö×î»îÔ¾µÄÀÕË÷Èí¼þ×éÖ¯Ô̺¬£ºBianLian£»Clop£»LockBit 3.0ºÍPlay¡£


4. ³¬¹ý100¸öÒÔÉ«ÁÐ×éÖ¯Ôâµ½ºÚ¿Í¹¥»÷ÇÒ´óÁ¿Êý¾Ýй¶


1ÔÂ15ÈÕ £¬Ò»¸öÃûΪ Cyber Toufan µÄºÚ¿Í×éÖ¯¾Ý³ÆÊܵ½Ä³¹úÖ§³Ö £¬Ðû³ÆÍ¨¹ýÊý¾Ýɾ³ýºÍ͵ÇÔÐж¯ÈëÇÖÁË 100 ¶à¸öÒÔÉ«ÁÐ×éÖ¯¡£ÕâÊÇÒò¸ÃµØÓòÈÕÒæÑÏÖØµÄÕþÖδóÊÆ¶øÌáÒéµÄÈ«ÃæÏ®»÷Ðж¯µÄÒ»²¿ÃÅ¡£°²È«×êÑÐÈËÔ±ÒÑ×·×Ùµ½³¬¹ý 100 ÆðÓë Cyber Toufan ÔËÓªÓйصĹ¥»÷ £¬ÆäÌØµãÊÇÇÔÈ¡´óÁ¿Êý¾Ý£¨Ô̺¬Ó×ÎÒÐÅÏ¢£©²¢ÔÚÍøÂçÉÏ´«²¼¡£¸ÃºÚ¿Í×éÖ¯ÔÚÆä Telegram Ƶ·ÉÏй¶ÁË 59 ¸ö×éÖ¯µÄÊý¾Ý¡£È»¶ø £¬¸Ã×éÖ¯ÔÚÕë¶ÔÍйܷþÎñÌṩÉÌ (MSP) µÄ¹¥»÷ÖпÉÄÜÒѾ­·çÏÕÁËÁí±í 40 ¶à¸ö×éÖ¯¡£¸Ã×é֯й¶µÄÊý¾ÝÔ̺¬·þÎñÆ÷µÄÆëÈ«´ÅÅÌÓ³Ïñ¡¢ÒÀÈ»ÓÐЧÇÒÔÚʹÓÃµÄ SSL Ö¤Êé¡¢SQL ת´¢¡¢CRM £¬ÉõÖÁ WordPress ±¸·Ý¡£Êܺ¦ÕßÔ̺¬ÒÔÉ«Áйú¶Èµµ°¸¹Ý£»ÒÔÉ«Áд´Ð¾Ö£»ÒÔÉ«ÁÐס·¿ÖÐÐÄ£»ÒÔÉ«ÁÐÌìÈ»ºÍ¹«Ô°ÖÎÀí¾Ö£»ÌØÀ­Î¬·òѧԺ£»ÒÔÉ«ÁÐÎÀÉú²¿£»¸£ÀûºÍÉç»áÊÂÎñ²¿¡¢ÒÔÉ«ÁÐ֤ȯÖÎÀí¾Ö£»Allot¡¢MAX Security & Intelligence¡¢Radware ºÍ·áÌïÒÔÉ«Áй«Ë¾µÈ¡£


5. ×êÑÐÍŶÓÅû¶SandwormÕë¶Ôµ¤ÂóºÍÎÚ¿ËÀ¼ÄÜÔ´µÄ¹¥»÷


1ÔÂ15ÈÕ £¬ÔÚÍøÂ簲ȫÁìÓò £¬ÄÜÔ´ÐÐÒµÒÀÈ»ÊÇÈÝÒ×Êܵ½¸´ÔÓÍøÂç¹¥»÷µÄ¹Ø¼üÁìÓò¡£Forescout Vedere Labs ×î½üµÄÍþв¼ò±¨½ÒʾÁËÕë¶Ôµ¤ÂóºÍÎÚ¿ËÀ¼ÕâÒ»ÁìÓòµÄÁ½´Î·ÖÆçÍøÂç¹¥»÷ £¬²¢½«Æä¹éÒòÓÚ Sandworm £¬ÕâÊÇÒ»¸öÒԸ߼¶³ÖÐøÍþв (APT) ÎÅÃûµÄ¶íÂÞ˹¾üÊÂÍþв×éÖ¯¡£Forescout Vedere LabsµÄ»ã±¨¶Ôµ¤ÂóÄÜÔ´»ù´¡ÉèÊ©µÄÁ½´Î¶ÀÁ¢¹¥»÷º£³±½øÐÐÁËÈ«Ãæ·ÖÎö¡£SektorCERTµÄ³õ´ëÊ©²éÁ˾ֵ¤Â󹨼ü»ù´¡ÉèÊ©ÍÆËã»ú´¹Î£ÏìÓ¦Ó××é (CERT) Ö¸³öÁËÁ½´Î·ÖÆçµÄ¹¥»÷¡£È»¶ø £¬Î¤´úÀ׳¢ÊÔÊҵķÖÎöÌá³öÁË·ÖÆçµÄ˵·¨¡£ÕâЩ¹¥»÷µÄÒ»¸öÖµÍ×ÌùÐĵķ½ÃæÊÇʹÓá°¿¿µØÉú¼Æ¡±(LotL) ¼¼Êõ¡£¹ÌÈ»²»Ô¸¶¨±È¶¨Ôì¶ñÒâÈí¼þ¸ü¿ì £¬µ« LotL ÌṩÁËÒþÃØÓÅÊÆ £¬Ê¹¹¥»÷Õß¿ÉÄÜÔ¤·À¼ì²â²¢ÀûÓÃÏÖÓÐϵͳ¡£ÕâÖÖ²½Öè͹ÏÔÁ˹¥»÷Õß²»Ðݱ䶯µÄÕ½ÊõÒÔ¼°¶Ô׳´ó·ÀÓù»úÔìµÄÐèÒª¡£


6. Balada InjectorÓÃPopup Builder¹¥»÷WordPressÍøÕ¾


1ÔÂ15ÈÕ £¬Sucuri ×êÑÐÈËÔ±»ã±¨³Æ £¬9Ô·ÝÓг¬¹ý 17,000 ¸ö WordPress ÍøÕ¾Ò×Êܵ½ Balada InjectorµÄ¹¥»÷¡£Balada InjectorÊÇÒ»¸ö×Ô 2017 ÄêÒÔÀ´Ò»Ïò»îÔ¾µÄ¶ñÒâÈí¼þ¼Ò×å¡£¸Ã¶ñÒâÈí¼þÖ§³Ö¶àÖÖ¹¥»÷ÏòÁ¿ºÍÓÆ¾ÃÐÔ»úÔì¡£¸Ã¶ñÒâ´úÂë×î³õÓÉ AV ¹«Ë¾ Doctor Web ÓÚ 2022 Äê 12 Ô·¢ÏÖ¡£Sucurity »ã±¨³Æ £¬12 Ô 13 ÈÕ £¬  Balada Injector »î¶¯ÆðͷʹÓþɰ汾µÄ Popup Builder£¨CVE-2023-6000 £¬CVSS ÆÀ·Ö 8.8£©Ï°È¾ÍøÕ¾¡£ÍþвÐÐΪÕßʹÓÃÁË×î½ü×¢²á£¨12 Ô 13 ÈÕ£©µÄÓòÃû specialcraftbox[.]com¡£½ØÖÁ׫д±¾ÎÄʱ £¬  PublicWWW ÔÚ 7100 ¶à¸öÍøÕ¾Éϼì²âµ½×¢Èë ¡£