Nuclei·ì϶ɨÃè·¨Ê½ÆØ³ö¸ßΣ°²È«·ì϶ £¬¿ÉÖ¶ñÒâ´úÂëÖ´ÐÐ

°ä²¼¹¦·ò 2025-01-07

1. Nuclei·ì϶ɨÃè·¨Ê½ÆØ³ö¸ßΣ°²È«·ì϶ £¬¿ÉÖ¶ñÒâ´úÂëÖ´ÐÐ


1ÔÂ5ÈÕ £¬¿ªÔ´·ì϶ɨÃ蹤¾ß Nuclei£¨ÓÉ ProjectDiscovery ¿ª·¢£©´æÔÚÒ»¸ö±àºÅΪ CVE-2024-43405 µÄ¸ßÑϳÁÐÔ°²È«·ì϶ £¬CVSS ÆÀ·ÖΪ 7.4 ¡£¸Ã·ì϶ÓÉ Wiz ¹¤³ÌÍŶӷ¢ÏÖ £¬Ô´ÓÚ»»Ðд¦Öòî¾àºÍ¶à³ÁÊðÃû´¦ÖûúÔì £¬ÔÊÐí¹¥»÷ÕßÈÆ¹ýÊðÃû²é³­²¢ÔÚÄ£°åÖÐ×¢Èë¶ñÒâÄÚÈÝ £¬½ø¶øÖ´ÐжñÒâ´úÂë ¡£´Ë·ì϶ӰÏì Nuclei 3.0.0 ¼°ÒÔÉϰ汾 £¬Ö±ÖÁ v3.3.2 °æ±¾²ÅµÃµ½½â¾ö ¡£Nuclei ÔÚ GitHub ÉÏÕ¼ÓÐ 21,000+ ÐDZêºÍ³¬¹ý 210 Íò´ÎÏÂÔØ £¬¶Ô°²È«ÉçÇøÖÁ¹Ø³ÁÒª ¡£Nuclei ÒÔÆä»ùÓÚ YAML µÄ½Ã½ÝÄ£°åÖø³Æ £¬Ö§³Ö¶àÖÖºÍ̸Ô̺¬ HTTP¡¢TCP¡¢DNS¡¢TLS ºÍ Code £¬ÆäÖÐ Code ºÍ̸ÔÊÐíÔÚÖ÷»úÉÏÖ´ÐÐ±í²¿´úÂë £¬µ«Ò²¿ÉÄÜ´øÀ´ÑϳÁ·çÏÕ ¡£·ì϶ԴÓÚʹÓÃÕýÔò±í°×ʽºÍ YAML ½âÎöÆ÷½øÐÐÊðÃûÑé֤ʱµÄ²»Ò»Ö £¬ÒÔ¼°¡°First-Signature Trust¡±ºÍÊðÃûÒÆ³ýµÄ²»Ò»Ö´¦Öà £¬ÕâЩÈõµãÔÊÐí¹¥»÷Õß×¢Èëδ¾­ÑéÖ¤µÄ¶ñÒâÄÚÈÝ ¡£µ±×éÖ¯ÔËÐÐδ¾­Êʵ±ÑéÖ¤»ò¸ôÀëµÄ²»ÊÜÐÅÀµ»òÉçÇø¹±Ï×µÄÄ£°åʱ £¬ÓÈÆäÈÝÒ×Êܵ½¹¥»÷ £¬¿ÉÄܵ¼ÖÂËÁÒâºÅÁîÖ´ÐÓ×¢Êý¾Ýй¶»òϵͳÈëÇÖ ¡£


https://securityaffairs.com/172692/security/nuclei-flaw-execute-malicious-code.html


2. жñÒâÈí¼þPLAYFULGHOST±»·¢ÏÖ £¬ÓµÓÐ¿í·ºÐÅÏ¢ÍøÂçÖ°ÄÜ


1ÔÂ4ÈÕ £¬ÍøÂ簲ȫ×êÑÐÈËÔ±·¢ÏÖÁËÒ»ÖÖÃûΪPLAYFULGHOSTµÄжñÒâÈí¼þ £¬Ëü¾ß±¸¶àÖÖÐÅÏ¢ÍøÂçÖ°ÄÜ £¬Èç¼üÅ̼ͼ¡¢ÆÁÄ»²¶»ñ¡¢ÒôƵ²¶»ñ¡¢Ô¶³ÌshellÒÔ¼°Îļþ´«Êä/Ö´ÐÐ ¡£¸Ã¶ñÒâÈí¼þÓëÒÑÖªÔ¶³ÌÖÎÀí¹¤¾ßGh0st RATÔÚÖ°ÄÜÉÏ´æÔÚ³Áµþ ¡£PLAYFULGHOSTͨ¹ýÍøÂç´¹µöµç×ÓÓʼþ»òËÑË÷ÒýÇæÓÅ»¯Í¶¶¾¼¼Êõ·Ö·¢ £¬ÓÕÆ­Êܺ¦Õß´ò¿ª¼Ù×°³ÉͼÏñÎļþµÄ¶ñÒâRAR´æµµ»òÏÂÔØ´øÓжñÒâÈí¼þµÄLetsVPN×°Ö÷¨Ê½ ¡£¸Ã¶ñÒâÈí¼þÀûÓÃDLLËÑË÷°¤´Î½Ù³ÖºÍ²àÔØµÈ²½ÖèÆô¶¯¶ñÒâDLL £¬²¢ÔÚÖ÷»úÉÏÉèÖÃÓÆ¾ÃÐÔ £¬ÍøÂç´óÁ¿Êý¾Ý ¡£´Ë±í £¬PLAYFULGHOST»¹ÄÜͶ·Å¸ü¶àÓÐÐ§ÔØºÉ¡¢×èÖ¹Êó±êºÍ¼üÅÌÊäÈë¡¢¶Ï¸ùWindowsÊÂÎñÈÕÖ¾µÈ £¬²¢ÓëÆäËû¹¤¾ßÈçMimikatzºÍrootkitһ·ʹÓà ¡£Õë¶ÔËѹ·¡¢QQºÍ360°²È«µÅצÓ÷¨Ê½ÒÔ¼°Ê¹ÓÃLetsVPNµö¶ü £¬ÕâЩϰȾ¿ÉÄÜÕë¶ÔµÄÊǽ²ÖÐÎĵÄWindowsÓû§ ¡£ÀàËÆµÄ»î¶¯Ò²ÔøÔÚ2024Äê7ÔÂÓɼÓÄôóÍøÂ簲ȫ¹©¸øÉÌeSentireÅû¶ £¬ÀûÓÃGoogle ChromeµÄÐéαװÖ÷¨Ê½´«²¼Gh0st RAT ¡£


https://thehackernews.com/2025/01/playfulghost-delivered-via-phishing-and.html


3. PhishWP£º¶íÂÞË¹ÍøÂç·¸×ï·Ö×ÓµÄÐÂÐÍWordPress´¹µö²å¼þÍþв


1ÔÂ6ÈÕ £¬¶íÂÞË¹ÍøÂç·¸×ï·Ö×Ó¿ª·¢ÁËÒ»¿îÃûΪPhishWPµÄ¶ñÒâWordPress²å¼þ £¬¸Ã²å¼þͨ¹ý´´½¨¸ß·ÂÕæµÄÐéα֧¸¶Ò³ÃæÀ´ÇÔÈ¡Óû§µÄÐÅÓþ¿¨ÐÅÏ¢¡¢CVV°²È«ÂëºÍ3DSÒ»´ÎÐÔÃÜÂ루OTP£©µÈÃô¸ÐÊý¾Ý ¡£ÕâÐ©Ò³Ãæ·ÂÕպϷ¨Ö§¸¶·þÎñÈçStripe £¬ÓÕÆ­Óû§ÊäÈëÓ×ÎÒÐÅÏ¢ ¡£PhishWP²»½ö¾ß±¸¸ß¶È¿É¶¨ÔìµÄ½áÕËÒ³Ãæ £¬»¹¼¯³ÉÁËä¯ÀÀÆ÷·ÖÎöÖ°ÄܺÍ×Ô¶¯»Ø¸´µç×ÓÓʼþ £¬ÒÔ¼ÓÇ¿ÆäºýŪÐÔºÍÈÆ¹ý°²È«ÑéÖ¤µÄÄÜÁ¦ ¡£¸üΪÏȽøµÄÊÇ £¬¸Ã²å¼þ¿ÉÄÜʵʱͨ¹ýTelegram½«ÇÔÈ¡µÄÐÅÏ¢´«Ê䏸¹¥»÷Õß £¬±ãÓÚËûÃÇÔÚ°µÍøÊÜÆ­¼´½øÐÐδ¾­ÊÚȨµÄÂòÂô»òÏúÊÛ ¡£PhishWPµÄ¶à˵»°Ö§³ÖºÍ»ìºÏÖ°ÄÜʹµÃ¹¥»÷ÕßÄÜÔÚÈ«ÇòÁìÓòÄÚÌáÒéÕë¶ÔÐÔµÄÍøÂç´¹µö»î¶¯ £¬Ôì³É³Á´ó²ÆÕþËðʧºÍÓ×ÎÒÊý¾Ýй¶ ¡£ÎªÁËÓ¦¶ÔÕâÒ»Íþв £¬ÍøÂ簲ȫ¹«Ë¾SlashNext¶½´ÙÓû§²ÉÈ¡»ý¼«µÄÍøÂ簲ȫ´ëÊ© £¬ÈçʹÓÃÍøÂç´¹µö±£»¤¹¤¾ß £¬Î¬³Ö¸ß¶È¾¯Ìè £¬ÒÔÓÐЧÕмܴËÀิÔÓ¹¥»÷ ¡£


https://hackread.com/phishwp-plugin-russian-hacker-forum-phishing-sites/


4. Moxa·¢³ö¸ßΣ·ì϶ÖÒ¸æ £¬Ó°Ïì¶à¿î·ÓÉÆ÷ºÍÍøÂ簲ȫÉ豸


1ÔÂ6ÈÕ £¬¹¤ÒµÍøÂçºÍͨѶ¹©¸øÉÌMoxa·¢³ö´¹Î£ÖÒ¸æ £¬Ö¸³öÆä·äÎÑ·ÓÉÆ÷¡¢°²È«Â·ÓÉÆ÷ºÍÍøÂ簲ȫÉ豸µÄ¶à¸öÐͺŴæÔÚ¸ßΣ·ì϶ ¡£ÕâЩ·ì϶Ô̺¬CVE-2024-9138ºÍCVE-2024-9140 £¬ÔÊÐíÔ¶³Ì¹¥»÷Õß»ñÈ¡rootȨÏÞ²¢Ö´ÐÐËÁÒâºÅÁî £¬µ¼ÖÂËÁÒâ´úÂëÖ´ÐÐ ¡£MoxaÉ豸¿í·ºÀûÓÃÓÚ½»Í¨ÔËÊä¡¢¹«ÓÃÊÂÒµ¡¢ÄÜÔ´ºÍµçÐÅÁìÓòµÄ¹¤Òµ×Ô¶¯»¯ºÍ½ÚÔìϵͳ»·¾³ ¡£ÊÜÓ°ÏìµÄÉ豸Ô̺¬EDR-8010ϵÁÓ×¢EDR-G9004ϵÁÓ×¢EDR-G9010ϵÁÓ×¢EDF-G1002-BPϵÁÓ×¢NAT-102ϵÁÓ×¢OnCell G4302-LTE4ϵÁкÍTN-4900ϵÁеÈ £¬¾ßÌåÊÜÓ°ÏìµÄÊÇÕâЩϵÁеÄijЩ¹Ì¼þ°æ±¾ ¡£MoxaÒѰ䲼¹Ì¼þ¸üÐÂÒÔ½¨¸´ÕâЩ·ì϶ £¬²¢Ç¿ÁÒ½¨ÒéÓû§µ±¼´Éý¼¶ÒÔÔ¤·ÀDZÔÚ·çÏÕ ¡£¶ÔÓÚNAT-102ϵÁÐ £¬Ä¿Ç°Ã»ÓпÉÓò¹¶¡ £¬½¨Òé²ÉÈ¡»º½â´ëÊ© ¡£Moxa»¹½¨ÒéÏÞ¶ÈÉè±¸ÍøÂç¶³öºÍSSH½Ó¼û £¬²¢Ê¹Ó÷À»ðǽ¡¢IDS»òIPSÀ´¼à¿ØºÍ×èÖ¹¹¥»÷³¢ÊÔ ¡£Í¬Ê± £¬²¼¸æÖ¸³öMRC-1002ϵÁÓ×¢TN-5900ϵÁкÍOnCell 3120-LTE-1ϵÁÐÉ豸²»ÊÜÕâÁ½¸ö·ì϶ӰÏì ¡£


https://www.bleepingcomputer.com/news/security/vulnerable-moxa-devices-expose-industrial-networks-to-attacks/


5. ¶íÂÞ˹½«´ó¹æÄ£»¥ÁªÍøÖжϹé×ïÓÚµçÐÅÍøÂç±äÂÒ


1ÔÂ6ÈÕ £¬¶íÂÞ˹»¥ÁªÍø¼à¹Ü»ú¹¹»ã±¨³Æ £¬ÓÉÓÚµçÐÅÔËÓªÉÌÖ÷ÍøÂç¹ÊÕÏ £¬µ¼Ö¸ùú¶àÏîÔÚÏß·þÎñÔâ·ê´ó¹æÄ£ÖжÏ £¬Ô̺¬ÈȵãÔÚÏ߯½Ì¨¹È¸è¡¢Yandex¡¢Rutube¡¢VKontakteºÍDiscord £¬ÒÔ¼°±¾µØÒøÐкÍÒÆ¶¯ÔËÓªÉÌMTSµÈ·þÎñ ¡£¾Ý»¥ÁªÍø¼à¿Ø·þÎñDowndetectorµÄÊý¾ÝÏÔʾ £¬´óÎÞÊýͶËßÀ´×ÔĪ˹¿Æ £¬Éæ¼°MTSÌṩµÄ·þÎñ £¬µ«MTSδ¾ÍÖжÏÔ­Òò°ä·¢ÆÀÂÛ ¡£Ö»¹Ü¸ÃÊÂÎñÒѵõ½½â¾öÇÒ·þÎñÔÚ¸´Ô­ £¬µ«½ØÖÁ׫дʱÈÔÓв¿ÃÅÓû§ÎÞ·¨½Ó¼û·þÎñ ¡£¶íÂÞ˹ʱʱ²úÉú»¥ÁªÍøÖжÏ £¬ÓÐʱÊDZ¾µØµ±¾ÖÓÐÒâΪ֮ £¬ÈçÈ¥Äê12Ô²âÊÔ¡°Ö÷Ȩ»¥ÁªÍø¡±»ù´¡Éèʩʱµ¼Ö¶à¸öµØÓò¾ÓÃñÎÞ·¨½Ó¼ûһЩ±í¹úºÍ±¾µØÀûÓ÷¨Ê½ºÍÍøÕ¾ ¡£´Ë±í £¬¶íÂÞ˹»¹Òò¹È¸è»Ø¾ø×ñÊØ¼¼ÊõÂÉÀý¶øÓÐÒâ½µµÍYouTube¼ÓÔØ¿ìÂÊ £¬²¢¹Ø±ÕÁËViber¡¢SignalºÍDiscordµÈͨѶÀûÓ÷¨Ê½µÄ½Ó¼û ¡£


https://therecord.media/russia-widespread-accident-outage-wifi


6. Eagerbee¶ñÒâÈí¼þбäÖÖÕë¶ÔÖж«µ±¾Ö×éÖ¯¼°ISP½øÐÐÈ«ÇòÐÔ¹¥»÷


1ÔÂ6ÈÕ £¬Eagerbee¶ñÒâÈí¼þ¿ò¼ÜµÄбäÖÖÔÚÕë¶ÔÖж«È·µ±¾Ö×éÖ¯ºÍ»¥ÁªÍø·þÎñÌṩÉ̽øÐв¿Ê𠣬´Ëǰ¸Ã¶ñÒâÈí¼þÒѱ»·¢ÏÖÓëÖйúµ±¾ÖÖ§³ÖµÄÍþвÐÐΪÕßÓйØ ¡£¿¨°Í˹»ù×êÑÐÈËÔ±·¢ÏÖ £¬¸Ã¶ñÒâÈí¼þÓëÃûΪ¡°CoughingDown¡±µÄÍþв×éÖ¯´æÔÚDZÔÚÁªÏµ ¡£¹¥»÷Õßͨ¹ýÔÚsystem32Ŀ¼Öв¿Êð×¢ÈëÆ÷À´¼ÓÔØÓÐÐ§ÔØºÉÎļþ £¬ÀÄÓÃWindows·þÎñ²¢ÔÚÄÚ´æÖÐдÈëºóßºÔØ ¡£¸ÃºóÃÅÄܹ»È«ÌìºòÔËÐÐ £¬ÍøÂçϵͳÐÅÏ¢²¢ÓëºÅÁîºÍ½ÚÔì·þÎñÆ÷³ÉÁ¢TCP/SSLͨ· £¬½Ó¹Ü¸½¼Ó²å¼þÒÔÀ©´óÆäÖ°ÄÜ ¡£ÕâЩ²å¼þÔ̺¬ÎļþÖÎÀíÆ÷¡¢¹ý³ÌÖÎÀíÆ÷¡¢Ô¶³Ì½Ó¼ûÖÎÀíÆ÷¡¢·þÎñÖÎÀíÆ÷ºÍÍøÂçÖÎÀíÆ÷ £¬Ê¹¹¥»÷ÕßÔÚÊÜϰȾµÄϵͳÉÏÓµÓÐ¿í·ºµÄÄÜÁ¦ ¡£Í¬ÑùµÄºóÃżÓÔØÁ´Ò²ÔÚÈÕ±¾±»·¢ÏÖ £¬Åú×¢Õâ´Î¹¥»÷ÊÇÈ«ÇòÐ﵀ ¡£×éÖ¯Ó¦½¨²¹Exchange·þÎñÆ÷ÉϵÄProxyLogon·ì϶ £¬²¢Ê¹Óÿ¨°Í˹»ù»ã±¨ÖÐÁгöµÄ·çÏÕÖ¸±ê¾¡Ôç·¢ÏÖÍþв ¡£


https://www.bleepingcomputer.com/news/security/eagerbee-backdoor-deployed-against-middle-eastern-govt-orgs-isps/