Nuclei·ì϶ɨÃè·¨Ê½ÆØ³ö¸ßΣ°²È«·ì϶£¬¿ÉÖ¶ñÒâ´úÂëÖ´ÐÐ
°ä²¼¹¦·ò 2025-01-071. Nuclei·ì϶ɨÃè·¨Ê½ÆØ³ö¸ßΣ°²È«·ì϶£¬¿ÉÖ¶ñÒâ´úÂëÖ´ÐÐ
1ÔÂ5ÈÕ£¬¿ªÔ´·ì϶ɨÃ蹤¾ß Nuclei£¨ÓÉ ProjectDiscovery ¿ª·¢£©´æÔÚÒ»¸ö±àºÅΪ CVE-2024-43405 µÄ¸ßÑϳÁÐÔ°²È«·ì϶£¬CVSS ÆÀ·ÖΪ 7.4¡£¸Ã·ì϶ÓÉ Wiz ¹¤³ÌÍŶӷ¢ÏÖ£¬Ô´ÓÚ»»Ðд¦Öòî¾àºÍ¶à³ÁÊðÃû´¦ÖûúÔ죬ÔÊÐí¹¥»÷ÕßÈÆ¹ýÊðÃû²é³²¢ÔÚÄ£°åÖÐ×¢Èë¶ñÒâÄÚÈÝ£¬½ø¶øÖ´ÐжñÒâ´úÂë¡£´Ë·ì϶ӰÏì Nuclei 3.0.0 ¼°ÒÔÉϰ汾£¬Ö±ÖÁ v3.3.2 °æ±¾²ÅµÃµ½½â¾ö¡£Nuclei ÔÚ GitHub ÉÏÕ¼ÓÐ 21,000+ ÐDZêºÍ³¬¹ý 210 Íò´ÎÏÂÔØ£¬¶Ô°²È«ÉçÇøÖÁ¹Ø³ÁÒª¡£Nuclei ÒÔÆä»ùÓÚ YAML µÄ½Ã½ÝÄ£°åÖø³Æ£¬Ö§³Ö¶àÖÖºÍ̸Ô̺¬ HTTP¡¢TCP¡¢DNS¡¢TLS ºÍ Code£¬ÆäÖÐ Code ºÍ̸ÔÊÐíÔÚÖ÷»úÉÏÖ´ÐÐ±í²¿´úÂ룬µ«Ò²¿ÉÄÜ´øÀ´ÑϳÁ·çÏÕ¡£·ì϶ԴÓÚʹÓÃÕýÔò±í°×ʽºÍ YAML ½âÎöÆ÷½øÐÐÊðÃûÑé֤ʱµÄ²»Ò»Ö£¬ÒÔ¼°¡°First-Signature Trust¡±ºÍÊðÃûÒÆ³ýµÄ²»Ò»Ö´¦Öã¬ÕâЩÈõµãÔÊÐí¹¥»÷Õß×¢Èëδ¾ÑéÖ¤µÄ¶ñÒâÄÚÈÝ¡£µ±×éÖ¯ÔËÐÐδ¾Êʵ±ÑéÖ¤»ò¸ôÀëµÄ²»ÊÜÐÅÀµ»òÉçÇø¹±Ï×µÄÄ£°åʱ£¬ÓÈÆäÈÝÒ×Êܵ½¹¥»÷£¬¿ÉÄܵ¼ÖÂËÁÒâºÅÁîÖ´ÐÓ×¢Êý¾Ýй¶»òϵͳÈëÇÖ¡£
https://securityaffairs.com/172692/security/nuclei-flaw-execute-malicious-code.html
2. жñÒâÈí¼þPLAYFULGHOST±»·¢ÏÖ£¬ÓµÓÐ¿í·ºÐÅÏ¢ÍøÂçÖ°ÄÜ
1ÔÂ4ÈÕ£¬ÍøÂ簲ȫ×êÑÐÈËÔ±·¢ÏÖÁËÒ»ÖÖÃûΪPLAYFULGHOSTµÄжñÒâÈí¼þ£¬Ëü¾ß±¸¶àÖÖÐÅÏ¢ÍøÂçÖ°ÄÜ£¬Èç¼üÅ̼ͼ¡¢ÆÁÄ»²¶»ñ¡¢ÒôƵ²¶»ñ¡¢Ô¶³ÌshellÒÔ¼°Îļþ´«Êä/Ö´ÐС£¸Ã¶ñÒâÈí¼þÓëÒÑÖªÔ¶³ÌÖÎÀí¹¤¾ßGh0st RATÔÚÖ°ÄÜÉÏ´æÔÚ³Áµþ¡£PLAYFULGHOSTͨ¹ýÍøÂç´¹µöµç×ÓÓʼþ»òËÑË÷ÒýÇæÓÅ»¯Í¶¶¾¼¼Êõ·Ö·¢£¬ÓÕÆÊܺ¦Õß´ò¿ª¼Ù×°³ÉͼÏñÎļþµÄ¶ñÒâRAR´æµµ»òÏÂÔØ´øÓжñÒâÈí¼þµÄLetsVPN×°Ö÷¨Ê½¡£¸Ã¶ñÒâÈí¼þÀûÓÃDLLËÑË÷°¤´Î½Ù³ÖºÍ²àÔØµÈ²½ÖèÆô¶¯¶ñÒâDLL£¬²¢ÔÚÖ÷»úÉÏÉèÖÃÓÆ¾ÃÐÔ£¬ÍøÂç´óÁ¿Êý¾Ý¡£´Ë±í£¬PLAYFULGHOST»¹ÄÜͶ·Å¸ü¶àÓÐÐ§ÔØºÉ¡¢×èÖ¹Êó±êºÍ¼üÅÌÊäÈë¡¢¶Ï¸ùWindowsÊÂÎñÈÕÖ¾µÈ£¬²¢ÓëÆäËû¹¤¾ßÈçMimikatzºÍrootkitһ·ʹÓá£Õë¶ÔËѹ·¡¢QQºÍ360°²È«µÅצÓ÷¨Ê½ÒÔ¼°Ê¹ÓÃLetsVPNµö¶ü£¬ÕâЩϰȾ¿ÉÄÜÕë¶ÔµÄÊǽ²ÖÐÎĵÄWindowsÓû§¡£ÀàËÆµÄ»î¶¯Ò²ÔøÔÚ2024Äê7ÔÂÓɼÓÄôóÍøÂ簲ȫ¹©¸øÉÌeSentireÅû¶£¬ÀûÓÃGoogle ChromeµÄÐéαװÖ÷¨Ê½´«²¼Gh0st RAT¡£
https://thehackernews.com/2025/01/playfulghost-delivered-via-phishing-and.html
3. PhishWP£º¶íÂÞË¹ÍøÂç·¸×ï·Ö×ÓµÄÐÂÐÍWordPress´¹µö²å¼þÍþв
1ÔÂ6ÈÕ£¬¶íÂÞË¹ÍøÂç·¸×ï·Ö×Ó¿ª·¢ÁËÒ»¿îÃûΪPhishWPµÄ¶ñÒâWordPress²å¼þ£¬¸Ã²å¼þͨ¹ý´´½¨¸ß·ÂÕæµÄÐéα֧¸¶Ò³ÃæÀ´ÇÔÈ¡Óû§µÄÐÅÓþ¿¨ÐÅÏ¢¡¢CVV°²È«ÂëºÍ3DSÒ»´ÎÐÔÃÜÂ루OTP£©µÈÃô¸ÐÊý¾Ý¡£ÕâÐ©Ò³Ãæ·ÂÕպϷ¨Ö§¸¶·þÎñÈçStripe£¬ÓÕÆÓû§ÊäÈëÓ×ÎÒÐÅÏ¢¡£PhishWP²»½ö¾ß±¸¸ß¶È¿É¶¨ÔìµÄ½áÕËÒ³Ãæ£¬»¹¼¯³ÉÁËä¯ÀÀÆ÷·ÖÎöÖ°ÄܺÍ×Ô¶¯»Ø¸´µç×ÓÓʼþ£¬ÒÔ¼ÓÇ¿ÆäºýŪÐÔºÍÈÆ¹ý°²È«ÑéÖ¤µÄÄÜÁ¦¡£¸üΪÏȽøµÄÊÇ£¬¸Ã²å¼þ¿ÉÄÜʵʱͨ¹ýTelegram½«ÇÔÈ¡µÄÐÅÏ¢´«Ê䏸¹¥»÷Õߣ¬±ãÓÚËûÃÇÔÚ°µÍøÊÜÆ¼´½øÐÐδ¾ÊÚȨµÄÂòÂô»òÏúÊÛ¡£PhishWPµÄ¶à˵»°Ö§³ÖºÍ»ìºÏÖ°ÄÜʹµÃ¹¥»÷ÕßÄÜÔÚÈ«ÇòÁìÓòÄÚÌáÒéÕë¶ÔÐÔµÄÍøÂç´¹µö»î¶¯£¬Ôì³É³Á´ó²ÆÕþËðʧºÍÓ×ÎÒÊý¾Ýй¶¡£ÎªÁËÓ¦¶ÔÕâÒ»Íþв£¬ÍøÂ簲ȫ¹«Ë¾SlashNext¶½´ÙÓû§²ÉÈ¡»ý¼«µÄÍøÂ簲ȫ´ëÊ©£¬ÈçʹÓÃÍøÂç´¹µö±£»¤¹¤¾ß£¬Î¬³Ö¸ß¶È¾¯Ì裬ÒÔÓÐЧÕмܴËÀิÔÓ¹¥»÷¡£
https://hackread.com/phishwp-plugin-russian-hacker-forum-phishing-sites/
4. Moxa·¢³ö¸ßΣ·ì϶ÖҸ棬ӰÏì¶à¿î·ÓÉÆ÷ºÍÍøÂ簲ȫÉ豸
1ÔÂ6ÈÕ£¬¹¤ÒµÍøÂçºÍͨѶ¹©¸øÉÌMoxa·¢³ö´¹Î£ÖҸ棬ָ³öÆä·äÎÑ·ÓÉÆ÷¡¢°²È«Â·ÓÉÆ÷ºÍÍøÂ簲ȫÉ豸µÄ¶à¸öÐͺŴæÔÚ¸ßΣ·ì϶¡£ÕâЩ·ì϶Ô̺¬CVE-2024-9138ºÍCVE-2024-9140£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß»ñÈ¡rootȨÏÞ²¢Ö´ÐÐËÁÒâºÅÁµ¼ÖÂËÁÒâ´úÂëÖ´ÐС£MoxaÉ豸¿í·ºÀûÓÃÓÚ½»Í¨ÔËÊä¡¢¹«ÓÃÊÂÒµ¡¢ÄÜÔ´ºÍµçÐÅÁìÓòµÄ¹¤Òµ×Ô¶¯»¯ºÍ½ÚÔìϵͳ»·¾³¡£ÊÜÓ°ÏìµÄÉ豸Ô̺¬EDR-8010ϵÁÓ×¢EDR-G9004ϵÁÓ×¢EDR-G9010ϵÁÓ×¢EDF-G1002-BPϵÁÓ×¢NAT-102ϵÁÓ×¢OnCell G4302-LTE4ϵÁкÍTN-4900ϵÁеȣ¬¾ßÌåÊÜÓ°ÏìµÄÊÇÕâЩϵÁеÄijЩ¹Ì¼þ°æ±¾¡£MoxaÒѰ䲼¹Ì¼þ¸üÐÂÒÔ½¨¸´ÕâЩ·ì϶£¬²¢Ç¿ÁÒ½¨ÒéÓû§µ±¼´Éý¼¶ÒÔÔ¤·ÀDZÔÚ·çÏÕ¡£¶ÔÓÚNAT-102ϵÁУ¬Ä¿Ç°Ã»ÓпÉÓò¹¶¡£¬½¨Òé²ÉÈ¡»º½â´ëÊ©¡£Moxa»¹½¨ÒéÏÞ¶ÈÉè±¸ÍøÂç¶³öºÍSSH½Ó¼û£¬²¢Ê¹Ó÷À»ðǽ¡¢IDS»òIPSÀ´¼à¿ØºÍ×èÖ¹¹¥»÷³¢ÊÔ¡£Í¬Ê±£¬²¼¸æÖ¸³öMRC-1002ϵÁÓ×¢TN-5900ϵÁкÍOnCell 3120-LTE-1ϵÁÐÉ豸²»ÊÜÕâÁ½¸ö·ì϶ӰÏì¡£
https://www.bleepingcomputer.com/news/security/vulnerable-moxa-devices-expose-industrial-networks-to-attacks/
5. ¶íÂÞ˹½«´ó¹æÄ£»¥ÁªÍøÖжϹé×ïÓÚµçÐÅÍøÂç±äÂÒ
1ÔÂ6ÈÕ£¬¶íÂÞ˹»¥ÁªÍø¼à¹Ü»ú¹¹»ã±¨³Æ£¬ÓÉÓÚµçÐÅÔËÓªÉÌÖ÷ÍøÂç¹ÊÕÏ£¬µ¼Ö¸ùú¶àÏîÔÚÏß·þÎñÔâ·ê´ó¹æÄ£Öжϣ¬Ô̺¬ÈȵãÔÚÏ߯½Ì¨¹È¸è¡¢Yandex¡¢Rutube¡¢VKontakteºÍDiscord£¬ÒÔ¼°±¾µØÒøÐкÍÒÆ¶¯ÔËÓªÉÌMTSµÈ·þÎñ¡£¾Ý»¥ÁªÍø¼à¿Ø·þÎñDowndetectorµÄÊý¾ÝÏÔʾ£¬´óÎÞÊýͶËßÀ´×ÔĪ˹¿Æ£¬Éæ¼°MTSÌṩµÄ·þÎñ£¬µ«MTSδ¾ÍÖжÏÔÒò°ä·¢ÆÀÂÛ¡£Ö»¹Ü¸ÃÊÂÎñÒѵõ½½â¾öÇÒ·þÎñÔÚ¸´Ô£¬µ«½ØÖÁ׫дʱÈÔÓв¿ÃÅÓû§ÎÞ·¨½Ó¼û·þÎñ¡£¶íÂÞ˹ʱʱ²úÉú»¥ÁªÍøÖжϣ¬ÓÐʱÊDZ¾µØµ±¾ÖÓÐÒâΪ֮£¬ÈçÈ¥Äê12Ô²âÊÔ¡°Ö÷Ȩ»¥ÁªÍø¡±»ù´¡Éèʩʱµ¼Ö¶à¸öµØÓò¾ÓÃñÎÞ·¨½Ó¼ûһЩ±í¹úºÍ±¾µØÀûÓ÷¨Ê½ºÍÍøÕ¾¡£´Ë±í£¬¶íÂÞ˹»¹Òò¹È¸è»Ø¾ø×ñÊØ¼¼ÊõÂÉÀý¶øÓÐÒâ½µµÍYouTube¼ÓÔØ¿ìÂÊ£¬²¢¹Ø±ÕÁËViber¡¢SignalºÍDiscordµÈͨѶÀûÓ÷¨Ê½µÄ½Ó¼û¡£
https://therecord.media/russia-widespread-accident-outage-wifi
6. Eagerbee¶ñÒâÈí¼þбäÖÖÕë¶ÔÖж«µ±¾Ö×éÖ¯¼°ISP½øÐÐÈ«ÇòÐÔ¹¥»÷
1ÔÂ6ÈÕ£¬Eagerbee¶ñÒâÈí¼þ¿ò¼ÜµÄбäÖÖÔÚÕë¶ÔÖж«È·µ±¾Ö×éÖ¯ºÍ»¥ÁªÍø·þÎñÌṩÉ̽øÐв¿Ê𣬴Ëǰ¸Ã¶ñÒâÈí¼þÒѱ»·¢ÏÖÓëÖйúµ±¾ÖÖ§³ÖµÄÍþвÐÐΪÕßÓйء£¿¨°Í˹»ù×êÑÐÈËÔ±·¢ÏÖ£¬¸Ã¶ñÒâÈí¼þÓëÃûΪ¡°CoughingDown¡±µÄÍþв×éÖ¯´æÔÚDZÔÚÁªÏµ¡£¹¥»÷Õßͨ¹ýÔÚsystem32Ŀ¼Öв¿Êð×¢ÈëÆ÷À´¼ÓÔØÓÐÐ§ÔØºÉÎļþ£¬ÀÄÓÃWindows·þÎñ²¢ÔÚÄÚ´æÖÐдÈëºóßºÔØ¡£¸ÃºóÃÅÄܹ»È«ÌìºòÔËÐУ¬ÍøÂçϵͳÐÅÏ¢²¢ÓëºÅÁîºÍ½ÚÔì·þÎñÆ÷³ÉÁ¢TCP/SSLͨ·£¬½Ó¹Ü¸½¼Ó²å¼þÒÔÀ©´óÆäÖ°ÄÜ¡£ÕâЩ²å¼þÔ̺¬ÎļþÖÎÀíÆ÷¡¢¹ý³ÌÖÎÀíÆ÷¡¢Ô¶³Ì½Ó¼ûÖÎÀíÆ÷¡¢·þÎñÖÎÀíÆ÷ºÍÍøÂçÖÎÀíÆ÷£¬Ê¹¹¥»÷ÕßÔÚÊÜϰȾµÄϵͳÉÏÓµÓÐ¿í·ºµÄÄÜÁ¦¡£Í¬ÑùµÄºóÃżÓÔØÁ´Ò²ÔÚÈÕ±¾±»·¢ÏÖ£¬Åú×¢Õâ´Î¹¥»÷ÊÇÈ«ÇòÐԵġ£×éÖ¯Ó¦½¨²¹Exchange·þÎñÆ÷ÉϵÄProxyLogon·ì϶£¬²¢Ê¹Óÿ¨°Í˹»ù»ã±¨ÖÐÁгöµÄ·çÏÕÖ¸±ê¾¡Ôç·¢ÏÖÍþв¡£
https://www.bleepingcomputer.com/news/security/eagerbee-backdoor-deployed-against-middle-eastern-govt-orgs-isps/


¾©¹«Íø°²±¸11010802024551ºÅ