MUT-1244ÍþвÐÐΪÕß´ó¹æÄ£ÇÔÈ¡WordPressƾ֤¼°Ãô¸ÐÐÅÏ¢

°ä²¼¹¦·ò 2024-12-17

1. MUT-1244ÍþвÐÐΪÕß´ó¹æÄ£ÇÔÈ¡WordPressƾ֤¼°Ãô¸ÐÐÅÏ¢


12ÔÂ14ÈÕ £¬ÃûΪMUT-1244µÄÍþвÐÐΪÕßÔÚÒ»³¡³¤´ïÒ»ÄêµÄ´ó¹æÄ£»î¶¯ÖÐ £¬Í¨¹ýľÂí²¡¶¾Ï°È¾µÄWordPressƾ֤²é³­Æ÷ÇÔÈ¡Á˳¬¹ý390,000¸öWordPressƾ֤¡£Í¬Ê± £¬¸ÃÐÐΪÕß»¹´ÓÊý°ÙÃûÊܺ¦Õߣ¨Ô̺¬ºì¶Ó³ÉÔ±¡¢ÉøÈë²âÊÔÈËÔ±¡¢°²È«×êÑÐÈËÔ±ÒÔ¼°¶ñÒâÐÐΪÕߣ©µÄÊÜϰȾϵͳÖеÁÈ¡ÁËSSH˽ԿºÍAWS½Ó¼ûÃÜÔ¿¡£¹¥»÷ÕßÀûÓñ»Ä¾Âí»¯µÄGitHub´æ´¢¿âÍÆËͶñÒâ¸ÅÏëÑéÖ¤·ì϶ºÍ½øÐÐÍøÂç´¹µö»î¶¯ £¬ºýŪָ±ê×°ÖüÙ×°³ÉCPU΢Âë¸üеļÙÄÚºËÉý¼¶¡£ÕâЩ´æ´¢¿âÔö³¤ÁËÆäºÏ·¨ÐÔ £¬Ê¹µÃ°²È«×¨ÒµÈËÔ±ºÍÍþвÐÐΪÕ߸üÈÝÒ×ÔËÐÐËüÃÇ¡£¹¥»÷Õßͨ¹ýGitHub reposÒÔ¶àÖÖ·½Ê½Í¶·ÅÓÐÐ§ÔØºÉ £¬Ô̺¬´øÓкóÃŵÄÅäÖñàÒëÎļþ¡¢¶ñÒâPDFÎļþ¡¢PythonͶ·ÅÆ÷ÒÔ¼°¶ñÒânpm°ü¡£Õâ´Î¹¥»÷»î¶¯ÓëÁíÒ»´Î³¤´ïÒ»ÄêµÄ¹©¸øÁ´¹¥»÷ÓгÁµþ £¬ÆäÖÐÉæ¼°ÇÔÈ¡Êý¾ÝºÍÍÚ¾òÃÅÂÞ±Ò¼ÓÃÜÇ®±Ò¡£MUT-1244¿ÉÄܽӼû²¢Ð¹Â¶¸öÈËSSHÃÜÔ¿¡¢AWSƾ֤µÈÃô¸ÐÐÅÏ¢ £¬²¢ÀûÓÃÍøÂ簲ȫÉçÇøÄÚµÄÐÅÀµ £¬ÔÚÖ¸±ê²»ÖªÇéµÄÇé¿öÏÂÖ´ÐжñÒâÈí¼þ £¬ÈëÇÖÁËÊýʮ̨»úе¡£


https://www.bleepingcomputer.com/news/security/390-000-wordpress-accounts-stolen-from-hackers-in-supply-chain-attack/


2. CISA½«Cleo·ì϶CVE-2024-50623Ôö³¤µ½ÆäÒÑÖª±»ÀûÓ÷ì϶Ŀ¼ÖÐ


12ÔÂ14ÈÕ £¬ÃÀ¹úÍøÂ簲ȫºÍ»ù´¡ÉèÊ©°²È«¾Ö£¨CISA£©Òѽ«Ó°ÏìCleo²úÆ·µÄ·ì϶CVE-2024-50623£¨CVSSÆÀ·Ö8.8£©ÁÐÈëÆäÒÑÖªÀûÓ÷ì϶£¨KEV£©Ä¿Â¼ÖС£Cleo¹«Ë¾·¢ÏÖÁËÒ»¸ö²»ÊÜÏ޶ȵÄÎļþÉÏ´«ºÍÏÂÔØ·ì϶ £¬¿ÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐÐ £¬²¢½¨Òé¿Í»§µ±¼´½«Harmony¡¢VLTraderºÍLexiComÊ·ýÉý¼¶µ½×îв¹¶¡°æ±¾5.8.0.21ÒÔ½â¾öDZÔÚ¹¥»÷ý½é¡£È»¶ø £¬°²È«¹«Ë¾Huntress»ã±¨³Æ £¬¼´±ã×°ÖÃÁ˸ò¹¶¡ £¬ÔËÐÐ5.8.0.21µÄϵͳÈÔ¿ÉÄܱ»ÀûÓá£Huntress·¢ÏÖÁËÕë¶ÔCleoÎļþ´«ÊäÈí¼þµÄ×Ô¶¯¹¥»÷ £¬²¢¹«¿ªÁËÉæ¼°ÈýÖÖCleo²úÆ·µÄ³ÖÐø¹¥»÷¡£Ê×ϯ°²È«×êÑÐÔ±Caleb Stewart¿ª·¢ÁËÀûÓÃËÁÒâÎļþдÈë·ì϶µÄPython¾ç±¾ £¬²¢Ö¤ÊµÁË·ì϶µÄÓÐЧÐÔ¡£CISAÒªÇóÁª¹ú»ú¹¹ÔÚ2025Äê1ÔÂ3ÈÕ֮ǰ½¨¸´´Ë·ì϶ £¬×¨¼ÒÒ²½¨Òé¸öÈË×éÖ¯Éó²é¸ÃĿ¼²¢½â¾öÆä»ù´¡ÉèÊ©Öеķì϶ £¬ÒÔ±£»¤ÍøÂçÃâÊܹ¥»÷¡£


https://securityaffairs.com/171973/security/u-s-cisa-adds-cleo-harmony-vltrader-and-lexicom-flaw-to-its-known-exploited-vulnerabilities-catalog.html


3. ConnectOnCallÔ¶³ÌÒ½ÁÆÆ½Ì¨Ôâ³Á´óÊý¾Ýй¶


12ÔÂ16ÈÕ £¬ConnectOnCallÊÇÒ»¸öרһÓÚ¼ÓǿҽÁÆ·þÎñÌṩÕßÓ뻼Õß¹µÍ¨µÄÔ¶³ÌÒ½ÁÆÆ½Ì¨ £¬½üÈÕÅû¶ÁËһ·³Á´óÊý¾Ýй¶ÊÂÎñ £¬Ó°Ï쳬¹ý900,000È˵ÄÓ×ÎÒÐÅÏ¢¼°Ò½ÁÆÐÅÏ¢°²È«¡£¸Ãƽ̨Ìṩ×Ô¶¯»¼Õߺô½Ð¸ú×Ù¡¢HIPAAºÏ¹æÌ¸ÌìÖ°ÄÜ £¬²¢Óëµç×Ó½¡È«¼Í¼ϵͳ¼¯³É¡£5ÔÂ12ÈÕ £¬ConnectOnCall·¢ÏÖ°²È«·ì϶ £¬¾­µ÷²éÈ·ÈÏ £¬2024Äê2ÔÂ16ÈÕÖÁ5ÔÂ12ÈÕÆÚ¼ä £¬ÓÐδ֪µÚÈý·½½Ó¼ûÁËÆ½Ì¨¼°ÀûÓ÷¨Ê½ÄڵIJ¿ÃÅÊý¾Ý £¬Ô̺¬Ò½»¼Í¨Ñ¶ÐÅÏ¢¡£ÊÂÎñÆØ¹âºó £¬¹«Ë¾Ñ¸¿ìÀñÆ¸ÍøÂ簲ȫר¼Ò £¬ÏÂÏß²úÆ· £¬²¢ÔÚ°²È«»·¾³ÖнøÐÐÊý¾Ý¸´Ô­ £¬Í¬Ê±Í¨ÖªÁËÁª¹ú·¨Âɲ¿ÃÅ¡£Ð¹Â¶ÐÅÏ¢¿ÉÄÜÔ̺¬ÐÕÃû¡¢µç»°ºÅÂë¡¢µ®ÉúÈÕÆÚ¡¢Éç»á±£Ïպš¢Ò½ÁƼͼºÅ¼°½¡È«Çé¿öµÈ¡£Ö»¹ÜĿǰδ·¢ÏÖÐÅÏ¢ÀÄÓûò»¼ÕßÊܺ¦Çé¿ö £¬ConnectOnCallÈÔ½¨ÒéÊÜÓ°ÏìÓ×ÎÒά³Ö¾¯Ìè £¬²¢»ã±¨¿ÉÒÉÉí·Ý͵ÇÔ»òڲƭÐÐΪ¡£¹«Ë¾ÒÑÏò·¨Âɲ¿ÃŻ㱨²¢Í¨ÖªÊÜÓ°ÏìÓ×ÎÒ £¬ÎªÆäÖÐÓÐÏÞÊýÁ¿µÄÉç»á°²È«ºÅÂëÊÜÓ°ÏìÕßÌṩÉí·ÝºÍÐÅÓþ¼à¿Ø·þÎñ £¬Í¨¹ýÓʼÄ֪ͨÐŵķ½Ê½·î¸æÓйØÇé¿ö¡£


https://securityaffairs.com/172053/data-breach/connectoncall-data-breach-impacted-over-900000-individuals.html


4. µÂ¿ËÈøË¹Àí¹¤´óѧ½¡È«¿ÆÑ§ÖÐÐÄÔâÍøÂç¹¥»÷


12ÔÂ16ÈÕ £¬µÂ¿ËÈøË¹Àí¹¤´óѧ½¡È«¿ÆÑ§ÖÐÐļ°Æä°£¶ûÅÁË÷·ÖУ½üÆÚÔâ·êÁËÒ»´ÎÍøÂç¹¥»÷ £¬µ¼ÖÂÍÆËã»úϵͳºÍÀûÓ÷¨Ê½ÖжÏ £¬²¢¿ÉÄÜй¶ÁË140ÍòÃû»¼ÕßµÄÃô¸ÐÊý¾Ý¡£¸Ã»ú¹¹ÊÇÒ»¼Ò¹«¹²Ñ§ÊõÒ½ÁÆ»ú¹¹ £¬ÕƹܽÌÓý¡¢ÅàѵºÍ»¼Õß»¤Àí·þÎñ¡£¹¥»÷µ¼ÖÂ2024Äê9ÔÂ17ÈÕÖÁ9ÔÂ29ÈÕÆÚ¼ä´Ó¸Ã»ú¹¹ÍøÂçÖнӼû»òɾ³ýÁËijЩÎļþºÍÎļþ¼Ð¡£¿ÉÄÜй¶¸øºÚ¿ÍµÄÐÅÏ¢Ô̺¬ÐÕÃû¡¢µ®ÉúÈÕÆÚ¡¢µØÖ·¡¢Éç»á°²È«ºÅÂë¡¢¼ÝÊ»ÅÆÕÕºÅÂë¡¢µ±¾ÖÉí·ÝÖ¤ºÅÂë¡¢²ÆÕþÕË»§ÐÅÏ¢¡¢½¡È«±£ÏÕÐÅÏ¢¡¢Ò½ÁÆÐÅÏ¢¡¢Õ˵¥/Ë÷ÅâÊý¾Ý¡¢Õï¶ÏºÍÒ½ÖÎÐÅÏ¢µÈ¡£¸Ã»ú¹¹ÒÑ֪ͨÊÜÓ°ÏìµÄÈË £¬²¢ÎªËûÃÇÌṩÃâ·ÑµÄÐÅÓþ¼à¿Ø·þÎñ¡£½¨ÒéÊÜÓ°ÏìµÄÓ×ÎÒά³Ö¾¯Ìè £¬·À±¸Ç±ÔÚµÄÍøÂç´¹µöºÍÉç»á¹¤³Ì¹¥»÷ £¬²¢¼à¿ØËûÃǵÄÐÅÓþ»ã±¨ºÍ½¡È«±£ÏÕÕ˵¥¡£¾Ý³Æ £¬Õâ´Î¹¥»÷ÓÉÃûΪInterlockµÄÀÕË÷Èí¼þ×éÖ¯ÕÆ¹Ü £¬¸Ã×é֯й¶ÁË210Íò¸öÎļþ £¬×ܼÆ2.6TBµÄÊý¾Ý £¬¾Ý³ÆÊǴӸûú¹¹ÇÔÈ¡µÄ¡£InterlockË÷ÒªµÄÊê½ð½ð¶î´ÓÊýÊ®ÍòÃÀÔªµ½Êý°ÙÍòÃÀÔª²»µÈ¡£


https://www.bleepingcomputer.com/news/security/texas-tech-university-system-data-breach-impacts-14-million-patients/


5. ´ó¹æÄ£¶ñÒâ¸æ°×»î¶¯´«²¼Lumma StealerÐÅÏ¢ÇÔÈ¡Èí¼þ


12ÔÂ16ÈÕ £¬Ò»ÏîÃûΪ¡°DeceptionAds¡±µÄ´ó¹æÄ£¶ñÒâ¸æ°×»î¶¯ÔÚÀûÓÃMonetag¸æ°×ÍøÂç´«²¼Lumma StealerÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þ¡£¸Ã»î¶¯Í¨¹ýÐéαµÄCAPTCHAÑéÖ¤Ò³ÃæÓÕÆ­Óû§ÔËÐжñÒâPowerShellºÅÁî £¬´Ó¶øÏ°È¾¶ñÒâÈí¼þ¡£Guardio LabsºÍInfobloxµÄ×êÑÐÈËÔ±·¢ÏÖ £¬ÕâÒ»²Ù×÷ÓÉÃûΪ¡°Vane Viper¡±µÄÍþвÐÐΪÕßÖ´ÐÐ £¬ÀûÓúϷ¨¸æ°×ÍøÂçÉϵĴó¹æÄ£¸æ°×½«Óû§´øµ½ÐéαµÄCAPTCHAÒ³Ãæ¡£CAPTCHAÒ³ÃæÔ̺¬JavaScript´úÂë £¬½«¶ñÒâPowerShellºÅÁÔìµ½Óû§¼ôÌù°å £¬²¢ÓÕµ¼Óû§Ö´ÐС£Lumma Stealer¿É´Óä¯ÀÀÆ÷ÖÐÇÔÈ¡cookie¡¢Í´´¦¡¢ÃÜÂë¡¢ÐÅÓþ¿¨ºÍä¯ÀÀº¹Çà¼Í¼ £¬ÒÔ¼°¼ÓÃÜÇ®±ÒÇ®°ü¡¢Ë½Ô¿ºÍÃô¸ÐÎı¾Îļþ¡£GuardioLabsÒÑÏòMonetagºÍBeMob»ã±¨´ËÀÄÓÃÐÐΪ £¬²¢µÃµ½ÊµÊ±ÏìÓ¦¡£È»¶ø £¬¸Ã»î¶¯ÔÚ12Ô³öÏÖ¸´ËÕ £¬Åú×¢ÍþвÐÐΪÕßÊÔͼͨ¹ý·ÖÆç¸æ°×ÍøÂ縴ԭÔËÓª¡£Óû§Ó¦Ô¤·ÀÖ´ÐÐÍøÕ¾ÌáÐѵĺÅÁî £¬³ö¸ñÊÇÄÇЩ¼Ù×°½¨¸´»òÑéÖ¤ÂëµÄºÅÁî £¬²¢ÉóÉ÷ʹÓõÁ°æÈí¼þ»ò·¸·¨Á÷ýÌåÍøÕ¾¡£


https://www.bleepingcomputer.com/news/security/malicious-ads-push-lumma-infostealer-via-fake-captcha-pages/


6. Â޵µºÖÝRIBridgesϵͳÔâBrain CipherÀÕË÷Èí¼þ¹¥»÷


12ÔÂ16ÈÕ £¬Â޵µºÖÝÖÒ¸æ³Æ £¬ÆäÓɵÂÇÚÖÎÀíµÄRIBridgesϵͳÔâ·êÁËBrain CipherÀÕË÷Èí¼þÍÅ»ïµÄÈëÇÖ £¬µ¼ÖÂÊý¾Ýй¶ £¬Â¶³öÁ˾ÓÃñµÄÓ×ÎÒÐÅÏ¢¡£RIBridgesÊǸÃÖÝÓÃÓÚÖÎÀíºÍÌṩ¹«¹²ÔöÔ®´òËãµÄÏÖ´ú×ۺϻï¸ñϵͳ¡£Õâ´ÎÊÂÎñÓÚ2024Äê12ÔÂ5ÈÕ±»·¢ÏÖ £¬µÂÇÚÆÀ¹ÀºóÒÔΪºÚ¿Í¿ÉÄÜÇÔÈ¡ÁËÔ̺¬Ó×ÎÒÉí·ÝÐÅÏ¢ºÍÆäËûÊý¾ÝµÄÎļþ¡£ÊÜÓ°ÏìµÄÏîÄ¿Ô̺¬Ò½ÁƲ¹Öú¡¢²¹³äÓªÑøÔöÔ®´òËã¡¢ÇîÀ§¼ÒͥһʱÔöÔ®µÈ¶à¸ö¹«¹²·þÎñÏîÄ¿¡£Ö»¹Üй¶µÄÊý¾ÝÈÔÔÚÆÀ¹ÀÖÐ £¬µ«¿ÉÄÜÔ̺¬ÐÕÃû¡¢µØÖ·¡¢µ®ÉúÈÕÆÚ¡¢Éç»á°²È«ºÅÂëºÍÄ³Ð©ÒøÐÐÐÅÏ¢¡£ÊÜÓ°ÏìµÄ¼ÒÍ¥½«Í¨¹ýÓʼþÊÕµ½Í¨Öª £¬²¢¿ÉÖµçרÓúô½ÐÖÐÐÄ×·ÇóÖ§³Ö¡£Â޵µºÖݵ±¾Ö½¨Òé¾ÓÃñ³ÁÖÃÃÜÂë¡¢ÉèÖÃڲƭ¾¯±¨ºÍÐÅÓþ¶³½á £¬²¢Æô¶¯ÒøÐÐÌṩµÄ°²È«´ëÊ©¡£µÂÇÚ½²»°ÈËÈ·ÈÏ £¬Â޵µºÖݵÄϵͳÊÇÊܵ½Brain CipherÊý¾Ýй¶ӰÏìµÄ¡°µ¥Ò»¿Í»§¶Ëϵͳ¡± £¬²¢°µÊ¾½«Óë¿Í»§ºÍ·¨ÂɹÙÔ±ºÏ×÷·¢Õ¹µ÷²é¡£


https://www.bleepingcomputer.com/news/security/rhode-island-confirms-data-breach-after-brain-cipher-ransomware-attack/