¼ÓÄôóʯÓ͹«Ë¾Ôâµ½¹¥»÷µ¼Ö¼ÓÓÍÕ¾ÎÞ·¨Ê¹ÓÃÐÅÓÿ¨¸¶¿î

Ðû²¼Ê±¼ä 2023-06-27

1¡¢¼ÓÄôóʯÓ͹«Ë¾Ôâµ½¹¥»÷µ¼Ö¼ÓÓÍÕ¾ÎÞ·¨Ê¹ÓÃÐÅÓÿ¨¸¶¿î


¾Ý6ÔÂ26ÈÕ±¨µÀ £¬¼ÓÄôóʯÓ͹«Ë¾(Petro-Canada)¼ÓÓÍÕ¾µÄ¿Í»§ÎÞ·¨Ê¹ÓÃÐÅÓÿ¨»ò½±Àø»ý·Ö¸¶¿î £¬Æäĸ¹«Ë¾Suncor Energy͸¶ËûÃÇÔâµ½Á˹¥»÷¡£Suncor EnergyÊÇÊǼÓÄôó×î´óµÄºÏ³ÉÔ­ÓÍÉú²úÉÌÖ®Ò» £¬ÄêÊÕÈë´ï310ÒÚÃÀÔª £¬Æä×Ó¹«Ë¾Petro-CanadaÔÚ¼ÓÄôó¸÷µØ¾­Óª1500¶à¸ö¼ÓÓÍÕ¾¡£Suncor͸¶ £¬¿Í»§ÎÞ·¨Í¨¹ýÓ¦ÓûòÍøÕ¾µÇ¼ÕÊ»§ £¬Ò²ÎÞ·¨ÔÚ¼ÓÓÍʱ»ñµÃ»ý·Ö¡£È»¶ø £¬ÕæÊµÇé¿öËÆºõ±È֪ͨµÄÒªÔã¸â £¬Ä¿Ç°¼ÓÓÍÕ¾ÎÞ·¨Ê¹ÓÃÒøÐп¨Ö§¸¶ £¬Ö»ÄÜʹÓÃÏֽ𠣬ӵÓÐÏ´³µ¼¾¿¨µÄ¿Í»§Ò²ÎÞ·¨ÏíÊÜÈ¨Òæ £¬ËûÃÇÏÖÔÚÒªÇóÍ˿


https://www.bleepingcomputer.com/news/security/suncor-energy-cyberattack-impacts-petro-canada-gas-stations/


2¡¢iOttieÍøÕ¾±»ÈëÇÖÏßÉϹºÎïÕßµÄÒøÐп¨ºÍ¸öÈËÐÅϢй¶


¾ÝýÌå6ÔÂ21ÈÕ±¨µÀ £¬Æû³µÖ§¼ÜºÍÒÆ¶¯Åä¼þÖÆÔìÉÌiOttie³Æ £¬ÆäÍøÕ¾ÔÚ½üÁ½¸öÔ±»ÈëÇÖ £¬ÍøÉϹºÎïÕßµÄÐÅÓÿ¨ºÍ¸öÈËÐÅϢй¶¡£iOttieÌåÏÖ £¬ËûÃÇÓÚ6ÔÂ13ÈÕ·¢ÏÖÆäÔÚÏßÉ̵êÔÚ4ÔÂ12ÈÕÖÁ6ÔÂ2ÈÕÔâµ½¶ñÒâ½Å±¾¹¥»÷¡£ÕâÖÖÀàÐ͵Ĺ¥»÷³ÆÎªMageCart £¬Ä¿Ç°¶ñÒâ´úÂëÒÑͨ¹ý²å¼þ¸üÐÂɾ³ý £¬µ«¹¥»÷Õß¿ÉÄÜÒѾ­»ñµÃÁËÓû§µÄÐÅÓÿ¨ÐÅÏ¢ £¬Éæ¼°Õʺš¢¿¨ºÅ¡¢Äþ¾²Âë¡¢·ÃÎÊÂë¡¢ÃÜÂëºÍPINµÈ¡£ËäÈ»iOttieûÓÐ͸¶ËûÃÇÊÇÈçºÎ±»¹¥»÷µÄ £¬µ«ËûÃǵÄÔÚÏßÉ̵êÊÇÒ»¸ö´øÓÐWooCommerce²å¼þµÄWordPressÍøÕ¾¡£


https://www.bleepingcomputer.com/news/security/iottie-discloses-data-breach-after-site-hacked-to-steal-credit-cards/


3¡¢Unit 42·¢ÏÖMuddled LibraÕë¶ÔBPOÐÐÒµµÄ¹¥»÷»î¶¯


Unit 42ÔÚ6ÔÂ21ÈÕÅû¶ÁËMuddled LibraÕýÔÚÕë¶ÔÒµÎñÁ÷³ÌÍâ°ü(BPO)ÐÐÒµµÄÁ¬Ðø¹¥»÷»î¶¯¡£2022Äêµ× £¬Ëæ×Å0ktapusµöÓ㹤¾ß°üµÄÐû²¼ £¬Muddled LibraµÄ¹¥»÷·ç¸ñ¸¡³öË®Ãæ¡£Ñо¿ÈËÔ±ÊÓ²ìÁË2022ÄêÖÐÖÁ2023Äê³õµÄ6ÆðÏà¹ØÊ¼þ £¬·¢ÏÖ¸Ã×éÖ¯µÄÌØµãÊÇʹÓÃ0ktapusÌ×¼þ¡¢ÍçÇ¿¡¢¹¥»÷¼ÆÄ±Áé»î¡¢Õë¶ÔBPOÐÐÒµ¡¢ÇÔÈ¡Êý¾ÝÒÔ¼°ÔÚÏÂÓι¥»÷ÖÐʹÓñ»ÈëÇֵĻù´¡ÉèÊ©µÈ¡£´ËÍâ £¬¸Ã×éÖ¯µÄÉ繤¹¥»÷·Ç³£ÀÖ³É £¬ÔÚ¶à¸ö°¸ÀýÖÐ˵·þÁËÄ¿±ê½øÐв»Äþ¾²µÄÐÐΪ¡£


https://unit42.paloaltonetworks.com/muddled-libra/


4¡¢CERT-UA³Æ¶à¸öÎÚ¿ËÀ¼×éÖ¯µÄRoundcubeÓʼþ·þÎñÆ÷±»ºÚ


ýÌå6ÔÂ21ÈÕ±¨µÀ £¬ÎÚ¿ËÀ¼CERT-UAºÍRecorded FutureÁªºÏÊÓ²ìÏÔʾ £¬APT28ÈëÇÖÁ˶à¸öÎÚ¿ËÀ¼×éÖ¯µÄRoundcubeÓʼþ·þÎñÆ÷¡£´Ë´Î»î¶¯ÖÐ £¬¹¥»÷ÕßÒÔ¶íÎÚ³åÍ»µÄÐÂÎÅΪÓÕ¶ü·¢ËͶñÒâÓʼþ £¬ÕâЩÓʼþ½«ÀûÓÃRoundcube Webmail©¶´£¨CVE-2021-44026µÈ£©ÈëÇÖδ´ò²¹¶¡µÄ·þÎñÆ÷¡£È»ºó £¬¹¥»÷Õ߻ᰲװ¶ñÒâ½Å±¾ £¬½«Ä¿±êµÄ´«ÈëÓʼþÖØ¶¨Ïòµ½¹¥»÷ÕߵĵØÖ· £¬»¹ÇÔÈ¡µØÖ·²¾¡¢»á»°cookieÒÔ¼°´æ´¢ÔÚRoundcubeÊý¾Ý¿âÖÐµÄÆäËüÐÅÏ¢¡£¾ÝÔ¤¼Æ £¬APT28ÔÚÕâЩ¹¥»÷ÖÐʹÓõĻù´¡ÉèʩԼĪ×Ô2021Äê11ÔÂÆð¾Í¿ªÊ¼ÔËÐС£


https://securityaffairs.com/147681/apt/apt28-hacked-roundcube-ukraine.html


5¡¢Êý°ÙÍò¸öGitHub´æ´¢¿âÈÝÒ×Ôâµ½RepoJacking¹¥»÷


 AquaSecÔÚ6ÔÂ21ÈÕ³Æ £¬´óÁ¿GitHub´æ´¢¿âÈÝÒ×Ôâµ½ÒÀÀµÏî´æ´¢¿â½Ù³Ö£¨Ò²³ÆÎª¡°RepoJacking¡±£©¹¥»÷ £¬¿ÉÄܵ¼Ö¹©Ó¦Á´¹¥»÷¡£Ñо¿ÈËÔ±·ÖÎöÁË125Íò¸öGitHubÑù±¾ £¬·¢ÏÖÔ¼2.95%Ò×ÊÜRepoJacking¹¥»÷¡£½«´Ë°Ù·Ö±ÈÍÆ¹ãµ½GitHubÁè¼Ý3ÒڵĴ洢¿â £¬Ô¤¼Æ¸ÃÎÊÌâÓ°ÏìÁËԼĪ900Íò¸öÏîÄ¿¡£AquaSecɨÃèÁËÖªÃû×éÖ¯ÖеĴ洢¿â £¬²¢ÔÚGoogleºÍLyft¹ÜÀíµÄ´æ´¢¿âÖз¢ÏÖÁË¿ÉÀûÓõݸÀý¡£²»ÐÒµÄÊÇ £¬RepoJacking·Ç³£ÆÕ±éÇÒÄÑÒÔ»º½â £¬ÏîÄ¿ËùÓÐÕßÓ¦¾¡¿ÉÄܼõÉÙ´ÓÍⲿ´æ´¢¿â»ñÈ¡×ÊÔ´¡£


https://blog.aquasec.com/github-dataset-research-reveals-millions-potentially-vulnerable-to-repojacking


6¡¢½©Ê¬ÍøÂçCondiͨ¹ýTP-Link©¶´CVE-2023-1389Á÷´«


6ÔÂ20ÈÕ £¬Fortinet³ÆÆä·¢ÏÖÁËÒ»¸öеÄDDoS½©Ê¬ÍøÂçCondi £¬Ö÷ÒªÕë¶ÔTP-Link Archer AX21 (AX1800)·ÓÉÆ÷¡£¸Ã¶ñÒâÈí¼þÀûÓÃÁË·ÓÉÆ÷Web¹ÜÀí½çÃæAPIÖеÄÒ»¸öÃüÁî×¢Èë©¶´£¨CVE-2023-1389£© £¬¸Ã©¶´ÒÑÓÚ3Ô·ݱ»ÐÞ¸´¡£Condi»¹»áɱËÀ¾ºÕù¹ØÏµµÄÆäËü½©Ê¬ÍøÂçµÄÏà¹Ø½ø³Ì £¬Ò²»áÍ£Ö¹Æä×ÔÉíµÄ¾É°æ±¾¡£¹ØÓÚCondiµÄDDoS¹¥»÷ÄÜÁ¦ £¬ÆäÖ§³ÖÓëMiraiÀàËÆµÄÖÖÖÖTCPºÍUDP¹¥»÷ÒªÁì¡£


https://www.fortinet.com/blog/threat-research/condi-ddos-botnet-spreads-via-tp-links-cve-2023-1389