Kaspersky·¢ÏÖAPT41ÀûÓÃMoonBounceµÄ¹¥»÷»î¶¯
Ðû²¼Ê±¼ä 2022-01-24Kaspersky·¢ÏÖAPT41ÀûÓÃMoonBounceµÄ¹¥»÷»î¶¯
1ÔÂ20ÈÕ£¬KasperskyÐû²¼Á˹ØÓÚ¶ñÒâÈí¼þMoonBounceµÄ·ÖÎö³ÂËß¡£Ñо¿ÈËÔ±³Æ£¬MoonBounceÊÇÆù½ñΪֹÔÚÒ°Íâ·¢ÏÖµÄ×îÏȽøµÄUEFI¹Ì¼þ¶ñÒâÈí¼þ£¬ÓëºÚ¿Í×éÖ¯APT41£¨Ò²³ÆÎªWinnti£©Óйء£MoonBounceÖ²ÈëÔÚÖ÷°åµÄSPIÉÁ´æÉÏ£¬Òò´Ë¼´Ê¹¸ü»»Ó²ÅÌÒ²ÎÞ·¨½«Æä¸ù³ý¡£ÕâÊǽüÆÚ·¢ÏֵĵÚÈý¸öUEFI¶ñÒâÈí¼þ£¬Ö®Ç°Á½¸öΪFinFisherºÍESPecter¡£KasperskyÌåÏִ˴ι¥»÷¾ßÓи߶ÈÕë¶ÔÐÔ£¬Ä³¸ö¿ØÖÆ×ż¸¼ÒÔËÊä¼¼ÊõÏà¹ØÆóÒµµÄ×éÖ¯ÒѳÉΪ¹¥»÷Ä¿±ê¡£
https://securelist.com/moonbounce-the-dark-side-of-uefi-firmware/105468/
ContiÍÅ»ïÉù³Æ¶ÔÓ¡¶ÈÄáÎ÷ÑÇÑëÐеÄÀÕË÷¹¥»÷ÂôÁ¦
¾ÝýÌå1ÔÂ20ÈÕ±¨µÀ£¬Ó¡¶ÈÄáÎ÷ÑÇÒøÐУ¨BI£©ÈÏ¿ÉÆäÔâµ½ÀÕË÷¹¥»÷¡£¸ÃÐз¢ÑÔÈËÌåÏÖ£¬¹¥»÷·¢ÉúÔÚÉϸöÔ£¬¹¥»÷ÕßÇÔÈ¡Á˲¿ÃÅÔ±¹¤µÄÐÅÏ¢£¬²¢ÔÚÊ®¼¸¸öϵͳÉϰ²×°ÁËÀÕË÷Èí¼þ£¬µ«ÆäÔËÓª²¢Î´Êܵ½Ó°Ïì¡£ContiÍÅ»ïÉù³Æ¶Ô´ËÊÂÂôÁ¦£¬Èç¹ûÓ¡ÄáÒøÐв»Ö§¸¶Êê½ð£¬ËûÃǽ«¹ûÈ»¸ÃÒøÐÐ13.88 GBµÄÎļþ¡£Ç°²»¾Ã£¬Conti»¹¹¥»÷Á˰®¶ûÀ¼DoH¡¢HSE£¬ºÍÓªÏú¹«Ë¾RR Donnelly¡£
https://www.bleepingcomputer.com/news/security/indonesias-central-bank-confirms-ransomware-attack-conti-leaks-data/
Ñо¿ÈËÔ±³ÆÊýÊ®¸öWordPressÖ÷ÌâºÍ²å¼þÒѱ»Ö²ÈëºóÃÅ
JetPackÔÚ1ÔÂ18ÈÕÐû²¼³ÂËߣ¬³ÆÒÑÔÚÊýÊ®¸öWordPressÖ÷ÌâºÍ²å¼þÖз¢ÏÖºóÃÅ¡£Ñо¿ÈËÔ±³Æ£¬¹¥»÷ÕßÒÑÔÚAccessPress ThemesµÄ40¸öÖ÷ÌâºÍ53¸ö²å¼þÖÐÖ²ÈëºóÃÅ¡£¾¹ýÊÓ²ìµÃÖª£¬AccessPress ThemesÓÚ2021Äê9ÔÂÉϰëÔÂÔâµ½¹¥»÷£¬ÆäÊ±ÍøÕ¾ÉϵÄÀ©Õ¹·¨Ê½±»×¢ÈëÁ˺óÃÅ¡£ÊÜѬȾµÄÀ©Õ¹·¨Ê½°üÂÞÒ»¸öwebshell dropper£¬Ê¹¹¥»÷Õß¿ÉÒÔÍêÈ«·ÃÎÊÄ¿±êÍøÕ¾£¬¸Ã©¶´×·×ÙΪCVE-2021-24867¡£
https://thehackernews.com/2022/01/hackers-planted-secret-backdoor-in.html
ÀûÓÃCWPµÄÎļþ°üÂÞºÍÈÎÒâдÈë©¶´¿ÉʵÏÖÔ¶³Ì´úÂëÖ´ÐÐ
ýÌå1ÔÂ22ÈÕ±¨µÀ£¬Control Web PanelÖдæÔÚ2¸öÑÏÖØµÄ©¶´¡£Control Web Panel£¨ÒÔǰµÄCentOS Web Panel£©ÊÇÒ»¸ö¿ªÔ´µÄLinux¿ØÖÆÃæ°åÈí¼þ£¬ÓÃÓÚ²¿ÊðWebÍйܻ·¾³¡£µÚÒ»¸öÊÇÎļþ°üÂÞ©¶´£¨CVE-2021-45467£©£¬¹¥»÷ÕßÖ»ÐèÐÞ¸ÄincludeÓï¾ä¾Í¿ÉÒÔÔ¶³Ì×¢Èë¶ñÒâ´úÂë»òʵÏÖ´úÂëÖ´ÐС£µÚ¶þ¸öΪÈÎÒâÎļþдÈë©¶´£¨CVE-2021-45466£©£¬½áºÏÀûÓÃÕâÁ½¸ö©¶´¿ÉÒÔÔÚÒ×Êܹ¥»÷µÄLinux·þÎñÆ÷ÉÏʵÏÖÔ¶³Ì´úÂëÖ´ÐС£
https://securityaffairs.co/wordpress/127058/hacking/control-web-panel-flaws.html
MoleratsÍÅ»ïÀûÓöà¸öÔÆ·þÎñ¶ÔÖж«µØÓò½øÐмäµý¹¥»÷
¾ÝýÌå1ÔÂ22ÈÕ±¨µÀ£¬Äþ¾²¹«Ë¾Zscaler·¢ÏÖMoleratsÍÅ»ïÕë¶ÔÖж«µØÓòµÄ¼äµý»î¶¯¡£¾ÝϤ£¬¹¥»÷´Ó2021Äê7Ô¾ÍÒÑ¿ªÊ¼£¬¹¥»÷ÕßÀûÓúϷ¨µÄÔÆ·þÎñ£¨ÈçGoogle DriveºÍDropbox£©ÍйܶñÒâÈí¼þpayload£¬´ÓÖж«µØÓòµÄÄ¿±êÖÐÇÔÈ¡Êý¾Ý¡£´Ë´Î»î¶¯ÀûÓÃÓëÒÔÉ«ÁкͰÍÀÕ˹̹³åÍ»Ïà¹ØµÄÓÕ¶ü£¬ÔÚÄ¿±êϵͳÉϰ²×°.NETºóÃÅ£¬Ö÷ҪĿ±ê°üÂÞ°ÍÀÕË¹Ì¹ÒøÐÐÒµÔ±¹¤¡¢°ÍÀÕ˹̹Õþµ³³ÉÔ±£¬ÒÔ¼°ÍÁ¶úÆä¼ÇÕߵȡ£
https://thehackernews.com/2022/01/molerats-hackers-hiding-new-espionage.html
×ÖÄ»ÍøÕ¾OpenSubtitles½ü700ÍòÓû§µÄÐÅϢй¶
¾Ý1ÔÂ23ÈÕ±¨µÀ£¬×ÖÄ»ÍøÕ¾OpenSubtitlesÔâµ½¹¥»÷£¬6783158¸öÓû§µÄÐÅÏ¢ÒѾй¶¡£2021Äê8Ô£¬ÍøÕ¾¹ÜÀíÔ±ÊÕµ½Êê½ð֪ͨºó²ÅÒâʶµ½ÆäÒÑÔâµ½¹¥»÷¡£¹¥»÷Õß»¹ÌåÏÖ»áÌṩ֧³ÖÒÔÐÞ¸´ÍøÕ¾ÖеÄ©¶´£¬µ«ÔÚÖ§¸¶Êê½ðºó¹¥»÷Õß´Óδ×ÊÖúËûÃǼӹÌÍøÕ¾£¬²¢ÔÚ1ÔÂ11ÈÕ¹ûÈ»Á˱»µÁÊý¾Ý¡£¾ÝϤ£¬ºÚ¿Íͨ¹ýSQL×¢Èë¹¥»÷·ÃÎÊÁËÍøÕ¾µÄÊý¾Ý¿â£¬ÇÔÈ¡ÁËÓû§Óʼþ¡¢IPµØÖ·¡¢Óû§Ãû¡¢ËùÔÚ¹ú¼ÒºÍÃÜÂëµÈÐÅÏ¢¡£
https://securityaffairs.co/wordpress/127092/data-breach/opensubtitles-data-breach.html
Äþ¾²¹¤¾ß
Narthex
ÊÇÒ»¸öÄ£¿é»¯ºÍ×îСµÄ×ÖµäÉú³ÉÆ÷£¬ÓÃÓÚÓà C ºÍ Shell ±àдµÄ Unix ºÍÀà Unix ²Ù×÷ϵͳ¡£
https://github.com/MichaelDim02/Narthex
Iptable_Evil
IptablesµÄºóÃÅ£¬Ê¹¶ñÒâÊý¾Ý°üͨ¹ýiptables£¬ÎÞÂÛ·À»ðǽ¹æÔòÈçºÎ¡£
https://github.com/FlamingSpork/iptable_evil
iMonitor
ÊÇÒ»¿î»ùÓÚiMonitorSDKµÄ¶ËµãÐÐΪ¼à¿Ø·ÖÎöÈí¼þ¡£
https://github.com/wecooperate/iMonitor/releases
Äþ¾²·ÖÎö
΢ÈíÐÞ¸´ÁË Windows 10 µÄ Outlook ËÑË÷ÎÊÌâ
΢ÈíÐÞ¸´Á˰²×°2021 Äê 11 ÔÂÐû²¼µÄ Windows 10 Äþ¾²¸üкóµ¼Ö Outlook Óû§·ºÆðËÑË÷ÎÊÌâµÄÎÊÌâ¡£
https://www.bleepingcomputer.com/news/microsoft/microsoft-fixes-outlook-search-issues-for-windows-10-users/
WordPress²å¼þ´æÔÚ©¶´
WP HTML MailÖдæÔÚÒ»¸öÑÏÖØµÄ¿çÕ¾µã½Å±¾(XSS)©¶´£¬Ó°ÏìÁè¼Ý20,000¸öWordPressÍøÕ¾¡£
https://threatpost.com/wordpress-insecure-plugin-rest-api/177866/