RedTailÍÚ¿óÀûÓà Palo Alto Networks ·À»ðǽµÄ·ì϶

°ä²¼¹¦·ò 2024-06-03
1. RedTailÍÚ¿óÀûÓà Palo Alto Networks ·À»ðǽµÄ·ì϶


5ÔÂ31ÈÕ  £¬RedTail¼ÓÃÜÇ®±ÒÍÚ¾ò¶ñÒâÈí¼þ±³ºóµÄÍþвÐÐΪÕß½«×î½üÅû¶µÄÓ°Ïì Palo Alto Networks ·À»ðǽµÄ°²È«·ì϶Ôö³¤µ½Æä·ì϶ÀûÓÿâÖС£Æ¾¾ÝÍøÂç»ù´¡ÉèÊ©ºÍ°²È«¹«Ë¾ Akamai µÄ×êÑÐÁ˾Ö  £¬¸Ã¶ñÒâÈí¼þ²»½öÔÚÆä¹¤¾ß°üÖÐÔö³¤ÁË PAN-OS ·ì϶  £¬»¹¶ÔÆä½øÐÐÁ˸üР £¬Ä¿Ç°ÒÑѡȡÁËÐµķ´·ÖÎö¼¼Êõ¡£Akamai ·¢ÏÖµÄϰȾÐòÁÐÀûÓÃÁË PAN-OS ÖÐÏÖÒѽ¨²¹µÄ·ì϶CVE-2024-3400£¨CVSS ÆÀ·Ö£º10.0£©  £¬¸Ã·ì϶¿ÉÄÜÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÔÚ·À»ðǽÉÏÒÔ root ȨÏÞÖ´ÐÐËÁÒâ´úÂë¡£³É¹¦ÀûÓÃÖ®ºó  £¬½«Ö´ÐÐÖ¼ÔÚ´Ó±í²¿Óò¼ìË÷ºÍÔËÐÐ bash shell ¾ç±¾µÄºÅÁî  £¬¸Ã¾ç±¾·´¹ýÀ´ÕÆ¹ÜÆ¾¾Ý CPU ¼Ü¹¹ÏÂÔØ RedTail ÓÐЧ¸ºÔØ¡£RedTail µÄÆäËû´«²¼»úÔìÉæ¼°ÀûÓà TP-Link ·ÓÉÆ÷£¨CVE-2023-1389£©¡¢ThinkPHP£¨CVE-2018-20062£©¡¢Ivanti Connect Secure£¨CVE-2023-46805 ºÍ CVE-2024-21887£©ÒÔ¼° VMWare Workspace ONE Access ºÍ Identity Manager£¨CVE-2022-22954£©ÖÐÒÑÖªµÄ°²È«·ì϶¡£RedTailÓÚ 2024 Äê 1 Ô³õ´ÎÓɰ²È«×êÑÐÔ± Patryk Machowiak ¼Í¼  £¬Éæ¼°ÀûÓà Log4Shell ·ì϶ (CVE-2021-44228) ÔÚ»ùÓÚ Unix µÄϵͳÉϲ¿Êð¶ñÒâÈí¼þµÄ»î¶¯¡£


https://thehackernews.com/2024/05/redtail-crypto-mining-malware.html


2. Cooler Master È·ÈÏÊý¾Ýй¶ÊÂÎñÖпͻ§ÐÅÏ¢±»µÁ


5ÔÂ31ÈÕ  £¬ÍÆËã»úÓ²¼þÔì×÷ÉÌ Cooler Master È·ÈÏÆäÓÚ 5 Ô 19 ÈÕÔâ·êÊý¾Ýй¶  £¬ÍþвÐÐΪÕßÇÔÈ¡Á˿ͻ§Êý¾Ý¡£Cooler Master ÊÇÒ»¼Ò³ÛÃûµÄÍÆËã»úÓ²¼þÔì×÷ÉÌ  £¬ÒÔÆäÀäÈ´É豸¡¢ÍÆËã»ú»úÏä¡¢µçÔ´ºÍÆäËû±íΧÉ豸¶øÎÅÃû¡£BleepingComputer×òÌ챨·³Æ  £¬Ò»¸öÃûΪ¡°Ghostr¡±µÄÍþвÐÐΪÕß֪ͨÎÒÃÇ  £¬ËûÃÇÓÚ 5 Ô 18 ÈÕÈëÇÖÁ˸ù«Ë¾µÄ Fanzone ÍøÕ¾²¢ÏÂÔØÁËÆäÁ´½ÓµÄÊý¾Ý¿â¡£Cooler Master µÄ Fanzone ÍøÕ¾ÓÃÓÚ×¢²á²úÆ·±£½¨¡¢ÉêÇë RMA »ò¿ªÁ¢Ö§³Ôì±  £¬ÒªÇó¿Í»§ÌîдÓ×ÎÒÊý¾Ý  £¬ÀýÈçÐÕÃû¡¢µç×ÓÓʼþµØÖ·¡¢µØÖ·¡¢µç»°ºÅÂë¡¢µ®ÉúÈÕÆÚºÍÏÖʵµØÖ·¡£Ghostr °µÊ¾  £¬ÔÚ Fanzone ·ì϶²úÉúÆÚ¼ä  £¬ËûÃÇÏÂÔØÁË 103 GB µÄÊý¾Ý  £¬ÆäÖÐÔ̺¬³¬¹ý 500,000 Ãû¿Í»§µÄ¿Í»§ÐÅÏ¢¡£ÍþвÐÐΪÕß»¹¹²ÏíÁËÊý¾ÝÑù±¾  £¬Ê¹ BleepingComputer ¿ÉÄÜÓëÎ¥¹æÐÐΪÖÐÁгöµÄ¶à¶à¿Í»§È·ÈÏËûÃǵÄÊý¾ÝÊÇÕýÈ·µÄ  £¬²¢ÇÒËûÃÇ×î½üÏò Cooler Master ÒªÇóÁËÖ§³Ö»ò RMA¡£Ñù±¾ÖÐµÄÆäËûÊý¾ÝÔ̺¬²úÆ·ÐÅÏ¢¡¢Ô±¹¤ÐÅÏ¢ÒÔ¼°Ó빩¸øÉ̵ĵç×ÓÓʼþÐÅÏ¢¡£ÍþвÕßÐû³ÆÕ¼Óв¿ÃÅÐÅÓþ¿¨ÐÅÏ¢  £¬µ« BleepingComputer ÔÚÊý¾ÝÑù±¾ÖÐÕÒ²»µ½ÕâЩÊý¾Ý¡£


https://www.bleepingcomputer.com/news/security/cooler-master-confirms-customer-info-stolen-in-data-breach/


3. BBC Åû¶ÁËÓ°ÏìÆäÑøÀϽð´òËã³ÉÔ±µÄÊý¾Ýй¶ÊÂÎñ


6ÔÂ1ÈÕ  £¬BBC µÄÐÅÏ¢°²È«ÍŶÓÒÑÏòÎÒÃÇ´«µÝÁËһ·Êý¾Ý°²È«ÊÂÎñ  £¬ÆäÖв¿ÃÅÔ̺¬ BBC ÑøÀϽð´òËã³ÉÔ±Ó×ÎÒÐÅÏ¢µÄÎļþ±»´ÓÔÆ´æ´¢·þÎñÖи´Ôì¡£ÕâЩÎļþÔ̺¬Ò»Ð©ÑøÀϽð´òËã³ÉÔ±µÄÓ×ÎÒÐÅÏ¢  £¬Ô̺¬ÐÕÃû¡¢¹úÃñ±£Ïպ𢵮ÉúÈÕÆÚºÍ¼ÒͥסַµÈ¾ßÌåÐÅÏ¢¡£¡±²¼¸æÐ´Â·¡£¡°ËùÉæ¼°µÄÊý¾ÝÎļþÊǸ±±¾  £¬Òò¶ø¶Ô´òËãµÄÕý³£ÔË×÷ûÓÐÓ°Ïì¡£¸ÃÊÂÎñδӰÏìÑøÀϽð´òËãÃÅ»§ÍøÕ¾µÄÔËÐÐ  £¬Óû§Äܹ»³ÖÐøÊ¹Ó᣸ÃÊÂÎñй¶ÁËÔ¼ 25,000 Ãû BBC ÑøÀϽð´òËã³ÉÔ±µÄÓ×ÎÒÐÅÏ¢  £¬ÆäÖÐÔ̺¬ÏÖÈκÍǰÈÎÔ±¹¤¡£Ð¹Â¶µÄÊý¾ÝÔ̺¬È«Ãû¡¢¹úÃñ±£Ïպ𢵮ÉúÈÕÆÚ¡¢ÐÔ±ðºÍ¼Òͥסַ¡£Õâ¼ÒÓ¢¹ú¹«¹²·þÎñ¹ã²¥¹«Ë¾ÔÚ±í²¿×¨¼ÒµÄÔ®ÊÖϵ÷²éÁËÕâÒ»ÊÂÎñ  £¬²¢ÒѲÉÈ¡Á˶î±íµÄ°²È«´ëÊ©¡£×¨¼ÒÃÇÒѾ­È·¶¨Á˰²È«·ì϶µÄÔ­Òò²¢²ÉÈ¡Á˰²È«´ëÊ©¡£¸Ã¹«Ë¾ÔÚͨ¹ýµç×ÓÓʼþ»òÓʼķ½Ê½ÁªÏµËùÓÐÊÜÓ°ÏìµÄ»áÔ±¡£Ä¿Ç°  £¬¸Ã¹«Ë¾Ã»ÓÐÖ¤¾ÝÅú×¢ÊÜËðÎļþÒѱ»ÀÄÓá£


https://securityaffairs.com/163908/data-breach/bbc-disclosed-data-breach.html


4. FlyingYetiÀûÓÃWinRAR·ì϶½øÐÐÓÐÕë¶ÔÐԵĹ¥»÷»î¶¯


6ÔÂ2ÈÕ  £¬×Ô 2022 Äê 2 Ô 24 ÈÕ¶íÂÞ˹ÈëÇÖÎÚ¿ËÀ¼ÒÔÀ´  £¬ÁйúÖ®¼äÒÔ¼°È«ÊÀ½çÖ®¼äµÄÑÏÖØ´óÊÆÒ»ÏòºÜÑϳÁ¡£Õâ´ÎÊÂÎñºó  £¬ÎÚ¿ËÀ¼¶Ôδ³¥Õ®ÎñµÄס»§Ö´ÐÐÁ˱÷³ýºÍÖÕÖ¹¹«ÓÃÊÂÒµ·þÎñµÄ½ûÁî  £¬¸Ã½ûÁÓÚ2024Äê1ÔÂʵÏÖ¡£È»¶ø  £¬ÕâÒ»ÌØ°´Ê±ÆÚÈ´±»Ò»ÃûÃûΪFlyingYetiµÄÍþвÐÐΪÕßËùÀûÓ᣸ÃÍþвÐÐΪÕßÀûÓÃÎÚ¿ËÀ¼¹«Ãñ¶Ôδ³¥»¹Õ®ÎñºÍ¿ÉÄÜʧȥס·¿µÄ½¹ÂÇ  £¬·¢Õ¹ÁËÒÔÕ®ÎñΪÖ÷ÌâµÄÍøÂç´¹µö»î¶¯  £¬ÓÕÆ­Êܺ¦Õß½«¶ñÒâÈí¼þÎļþÏÂÔØµ½ËûÃǵÄϵͳÖС£¸Ã¶ñÒâÈí¼þÊÇÒ»ÖÖ³ÆÎª¡°COOKBOX¡±µÄ PowerShell ¶ñÒâÈí¼þ  £¬ËüʹÕâЩÍþвÐÐΪÕß¿ÉÄÜ×°Ööî±íµÄÓÐÐ§ÔØºÉ²¢½ÚÔìÊܺ¦ÕßµÄϵͳ¡£´Ë±í  £¬ÍøÂç´¹µö»î¶¯»¹ÀûÓÃÁË GitHub ·þÎñÆ÷ºÍ Cloudflare ¹¤×÷Æ÷ÒÔ¼° WinRAR ·ì϶£¨CVE-2023-38831£©¡£lyingYeti ÍþвÐÐΪÕߵĻÓë֮ǰȷ¶¨µÄÍþвÐÐΪÕß UAC-0149 ÓгÁµþ  £¬ºóÕßÔøÔÚ 2023 ÄêÇ^ʹÓÃÒ»ÑùµÄ¶ñÒâÈí¼þ¹¥»÷ÎÚ¿ËÀ¼¹ú·ÀʵÌå¡£2024 Äê 4 ÔÂÖÐÑ®ÖÁ 5 ÔÂÖÐÑ®ÆÚ¼ä  £¬¾Ý¹Û²ì  £¬FlyingYeti ÍþвÐÐΪÕßÔÚ¶ÔÊܺ¦Õß½øÐпúËŻ  £¬ÕâЩ»î¶¯ºÜ¿ÉÄÜÓÃÓÚÔ­¶¨ÓÚÐÂÉú½ÚÆÚ¼äÌáÒéµÄ»î¶¯¡£


https://gbhackers.com/flyingyeti-winrar-vulnerability-malware-attacks/


5. LilacSquid ºÚ¿Í¹¥»÷ IT ÐÐÒµÒÔ»ñÈ¡»úÃÜÊý¾Ý


6ÔÂ1ÈÕ  £¬ºÚ¿Í¶Ô×¼ IT ÐÐÒµ  £¬ÓÉÓÚÕâЩÐÐÒµ°ÑÎÕ׏óÖØµÄÊý¾Ý¡¢¹Ø¼üµÄ»ù´¡ÉèÊ©  £¬²¢ÇÒͨ³£Äܹ»½Ó¼û¸÷¸öÁìÓòµÄÃô¸ÐÐÅÏ¢¡£ÈëÇÖ IT ¹«Ë¾¿ÉÒÔΪºÚ¿ÍÌṩ½øÐмäµý»î¶¯¡¢»ñÈ¡¾­¼ÃÀûÒæÒÔ¼°·ÛËé¸ù»ù·þÎñµÄ¾Þ´ó»úÓö¡£½üÈÕ  £¬Ë¼¿ÆTalosÍøÂ簲ȫ×êÑÐÈËÔ±·¢ÏÖ  £¬LilacSquidºÚ¿ÍÒ»ÏòÔÚ»ý¼«¹¥»÷ITÐÐÒµ  £¬ÒÔ»ñÈ¡»úÃÜÊý¾Ý¡£Talos È·ÐÅ¡°LilacSquid¡± APT ×éÖ¯ÖÁÉÙ´Ó 2021 ÄêÆðÍ·¾ÍÒ»ÏòÔÚ½øÐÐÊý¾ÝÇÔÈ¡»î¶¯  £¬³É¹¦ÈëÇÖÁËÑÇÖÞ¡¢Å·ÖÞºÍÃÀ¹úµÄÔìÒ©¡¢Ê¯ÓÍ¡¢ÌìÈ»ÆøºÍ¼¼ÊõÐÐÒµµÄÖ¸±ê ³õʼ½Ó¼ûÀûÓÃÁË·ì϶ºÍ±»µÁµÄ RDP Í´´¦¡£ÈëÇÖºó  £¬LilacSquid ²¿ÊðÁË MeshAgent Ô¶³Ì½Ó¼û¹¤¾ß¡¢QuasarRAT µÄ¶¨Ôì¡°PurpleInk¡±±äÌåÒÔ¼° SSF µÈ¿ªÔ´´úÀí¹¤¾ß  £¬Óë Lazarus ºÍ Andariel µÈ³¯ÏÊ×éÖ¯µÄ TTP ³Áµþ¡£¸Ã»î¶¯³ÉÁ¢ÁËÊý¾Ýй¶µÄ³Ö¾Ã½Ó¼ûȨÏÞ  £¬ÏÈǰµÄ¹©¸øÁ´·ì϶͹ÏÔÁËÕâÖÖ³ÖÐø¡¢¸ß¼¶ÍþвµÄ·çÏÕ¡£ÈëÇÖºó  £¬ËûÃÇʹÓà MeshAgent µÈ·¨Ê½½øÐÐÔ¶³Ì½Ó¼û¡¢Ê¹Óà SSF ½øÐа²È«Ëí·ÒÔ¼°Ê¹Óö¨Ôì¶ñÒâÈí¼þ InkLoader¡¢PurpleInk RAT µÈ¡£


https://gbhackers.com/lilacsquid-hackers-attacking-it-industries/


6. Êý°ÙÃûÓ¢¹ú¡¢·¨¹úºÍÅ·ÃËÕþ¿ÍµÄÐÅÏ¢ÔÚÍøÉϰ䲼


5ÔÂ31ÈÕ  £¬¾ÝרһÓÚÒþÖԵĽâ¾ö¹æ»®ÌṩÉÌ Proton ³Æ  £¬Êý°ÙÃûÓ¢¹ú¡¢·¨¹úºÍÅ·ÖÞÒé»áÕþ¿ÍµÄµç×ÓÓʼþµØÖ·ºÍÆäËûÐÅÏ¢Äܹ»ÔÚ°µÍøÊг¡ÉÏÕÒµ½¡£×÷Ϊ Proton Óë Constella Intelligence ºÏ×÷·¢Õ¹µÄÒ»Ïî×êÑеÄÒ»²¿ÃÅ  £¬×êÑÐÈËÔ±ÔÚ°µÍøÉÏËÑË÷Á˽ü 2,300 ¸öÊôÓÚÓ¢¹ú¡¢·¨¹úºÍÅ·ÖÞÒé»áÒéÔ±µÄ¹Ù·½µ±¾Öµç×ÓÓʼþµØÖ·¡£×ܹ²ÓÐ 918 ¸öµç×ÓÓʼþµØÖ·±»Ð¹Â¶µ½ÍøÂç·¸×ïÊг¡  £¬µ«Ã¿¸ö×éÖ¯ÊÜÓ°ÏìµÄÕþ¿Í±ÈÀýÓÐËù·ÖÆç¡£ÀýÈç  £¬Ó¢¹úÒéÔ±Êܵ½µÄÓ°Ïì×î´ó  £¬68% µÄÖ¸±êµç×ÓÓʼþµØÖ·³Ê´Ë¿Ì°µÍøÉÏ¡£¾ÍÅ·ÃËÒé»áÒéÔ±¶øÑÔ  £¬44% µÄµç×ÓÓʼþµØÖ·±»°ä²¼ÔÚºÚ¿ÍÂÛ̳ÉÏ¡£Ö»ÓÐ 18% µÄ·¨¹úÒéÔ±ºÍ²ÎÒéÔ±µÄÊý¾Ý±»Ð¹Â¶¡£¾ÍÓ¢¹úÕþ¿ÍµÄ°¸Àý¶øÑÔ  £¬ÆäÖÐÔ̺¬µ±¾Ö¸ß²ãºÍ·ñ¾öÅÉÈËÎï  £¬ËûÃǵĵç×ÓÓʼþµØÖ·ÔÚ°µÍøÉϱ»·¢ÏÖ³¬¹ý 2,100 ´Î¡£ÔںܶàÇé¿öÏ  £¬µç×ÓÓʼþµØÖ·ÔÚµ±¾ÖÍøÕ¾ÉÏÊǹ«¿ªµÄ¡£ÎÊÌâÔÚÓÚ  £¬µç×ÓÓʼþµØÖ·³Ê´Ë¿Ì°µÍøÊг¡ÉÏÅú×¢ÕâЩµØÖ·Ôø±»ÓÃÀ´ÔÚ¸÷ÀàµÚÈý·½ÔÚÏß·þÎñÉϳÉÁ¢ÕË»§  £¬¶øÕâЩ·þÎñÔÚij¸öʱ³½Ôâµ½Á˺ڿ͹¥»÷¡£ 


https://www.securityweek.com/information-of-hundreds-of-european-politicians-found-on-dark-web/