Ñо¿ÈËÔ±³Æ¶ñÒâÈí¼þAVreconÒÑѬȾ7Íò¶àSOHO·ÓÉÆ÷
Ðû²¼Ê±¼ä 2023-07-171¡¢Ñо¿ÈËÔ±³Æ¶ñÒâÈí¼þAVreconÒÑѬȾ7Íò¶àSOHO·ÓÉÆ÷
Black Lotus LabsÔÚ7ÔÂ12Èճƣ¬¶ñÒâÈí¼þAVreconÒÑѬȾÁè¼Ý70000¸ö»ùÓÚLinuxµÄSOHO·ÓÉÆ÷£¬²¢½«ËüÃÇÌí¼Óµ½½©Ê¬ÍøÂçÖС£³ýÁË2021Äê5ÔÂÊ״α»·¢ÏÖÖ®Í⣬AVreconÒѾÔËÐÐÁËÁ½Äê¶à¶øÎ´±»¼ì²âµ½¡£Ñо¿ÈËÔ±ÍÆ¶Ï£¬¸Ã»î¶¯ËƺõÖ¼ÔÚ´´½¨Ò»¸öÃØÃÜÍøÂ磬ÒÔÇÄÇĵؿªÕ¹ÃÜÂëÅçÈ÷ºÍÊý×Ö¹ã¸æÆÛÕ©µÈһϵÁй¥»÷»î¶¯¡£ÓÉÓÚ¶ñÒâÈí¼þµÄÒþ±ÎÐÔ£¬±»Ñ¬È¾É豸µÄËùÓÐÕߺÜÉÙ×¢Òâµ½ÈÎÎñÖжϻò´ø¿íµÄËðʧ¡£Äþ¾²ÍŶÓͨ¹ý½«½©Ê¬ÍøÂçµÄC2ÔÚÆäÖ÷¸ÉÍøÂçÉϽøÐÐÎÞЧ·ÓÉÀ´Ó¦¶Ô´ËÀàÍþв¡£
https://blog.lumen.com/routers-from-the-underground-exposing-avrecon/
2¡¢ÎÚ¿ËÀ¼CERT-UAÅû¶UAC-0010ÍÅ»ï½üÆÚ¹¥»÷»î¶¯µÄϸ½Ú
7ÔÂ13ÈÕ£¬ÎÚ¿ËÀ¼CERT-UAÅû¶ÁËUAC-0010£¨ÓÖ³ÆGamaredon£©ÍÅ»ï½üÆÚ¹¥»÷»î¶¯µÄϸ½Ú¡£Gamaredon»á½øÐпìËÙ¹¥»÷£¬ÔÚÊ×´ÎÈëÇÖºó30·ÖÖӾͿªÊ¼ÇÔÈ¡Êý¾Ý¡£Ê×ÏÈÀûÓõöÓãÓʼþºÍÏûÏ¢£¬ÓÕʹĿ±ê´ò¿ª¶øÒѸ½¼þ£¬È»ºóÏÂÔØPowerShell½Å±¾ºÍ¶ñÒâÈí¼þ£¨Í¨³£ÊÇGammaSteel£©¡£´ËÍ⣬¹¥»÷ÕßÿÖÜÔÚ±»Ñ¬È¾µÄϵͳÉÏÖ²Èë¶à´ï120¸ö¶ñÒâÎļþ£¬ÒÔÔö¼ÓÔÙ´ÎѬȾµÄ¿ÉÄÜÐÔ¡£CERT-UAÌåÏÖ£¬µÖÓù´ËÀ๥»÷µÄ×î¼ÑÒªÁìÊÇ×èÖ¹»òÏÞÖÆmshta.exe¡¢wscript.exe¡¢cscript.exeºÍpowershell.exeµÄδ¾ÊÚȨִÐС£
https://cert.gov.ua/article/5160737
3¡¢WordPress²å¼þAIOS¼Ç¼Ã÷ÎÄÃÜÂëÓ°Ïì100¶àÍò¸öÍøÕ¾
¾ÝýÌå7ÔÂ14ÈÕ±¨µÀ£¬WordPress²å¼þAll-In-One Security(AIOS)±»·¢ÏÖ»áÒÔÃ÷ÎÄÐÎʽ´æ´¢Óû§ÃÜÂ룬´Ó¶øÊ¹ÕÊ»§Äþ¾²ÃæÁÙ·çÏÕ¡£¸Ã²å¼þ±»Áè¼Ý100Íò¸öÍøÕ¾Ê¹Óã¬ÓÐÓû§³ÂË߳ƣ¬Ëü²»½ö½«Óû§µÇ¼ʵÑé¼Ç¼µ½aiowps_audit_logÊý¾Ý¿â±í£¨ÓÃÓÚ¸ú×ٵǼ¡¢×¢ÏúºÍµÇ¼ʧ°Üʼþ£©£¬»¹¼Ç¼ÁËÊäÈëµÄÃÜÂ롣Ŀǰ£¬AIOS¹©Ó¦ÉÌÒÑÓÚ7ÔÂ11ÈÕÐû²¼ÁË5.2.0°æ±¾£¬ÆäÖаüÂÞ·ÀÖ¹Éú´æÃ÷ÎÄÃÜÂë²¢Çå³ý¾ÉÌõÄ¿µÄÐÞ¸´·¨Ê½¡£Í³¼ÆÊý¾ÝÏÔʾ£¬½ØÖÁĿǰ»¹ÓÐÁè¼Ý750000¸öÍøÕ¾Î´¸üУ¬ÈÝÒ×Ôâµ½¹¥»÷¡£
https://www.bleepingcomputer.com/news/security/wordpress-aios-plugin-used-by-1m-sites-logged-plaintext-passwords/
4¡¢Ð½×Ê·þÎñ¹«Ë¾UKGͬÒâÒÔ600ÍòÃÀÔªºÍ½âÊý¾Ýй¶µÄËßËÏ
ýÌå7ÔÂ12Èճƣ¬Ð½×Ê·þÎñÌṩÉÌUKGͬÒâÒÔ600ÍòÃÀÔªºÍ½â2021ÄêÊý¾Ýй¶µÄËßËÏ¡£2021Äê12ÔµÄÀÕË÷¹¥»÷µ¼ÖÂUKGµÄKronos˽ÓÐÔÆ²¿ÃŲúÎïÀëÏߣ¬»¹µ¼Ö²¿ÃÅÔ±¹¤ºÍ³Ð°üÉ̵ÄÐÅϢй¶¡£´Ë´ÎʼþÓ°ÏìÁ˰Ùʹ«Ë¾¡¢Å¦Ô¼Êн»Í¨¾Ö¡¢Ó¢¹ú³¬ÊÐSainsburyºÍ¶à¸öÒ½ÁÆ»ú¹¹¡£UKGÓÚ2022Äê1Ô±»ÆðËߣ¬ÆäʱÌá³öÁ˾ÅÏîËßËÏÀíÓÉ£¬°üÂÞÊèºö¡¢²»Í×µÃÀû¡¢Î¥Ô¼ºÍÎ¥·´¼ÓÖÝÒþ˽·¨µÈ¡£UKGͬÒâÖ§¸¶550ÍòÃÀÔªÓÃÓÚË÷Å⣬²¢ÔÊÐíÔÚÐëҪʱ׷¼Ó50ÍòÃÀÔª¡£
https://www.wsj.com/articles/payroll-services-provider-ukg-agrees-to-6-million-settlement-in-data-breach-lawsuit-8ea87f01
5¡¢Uptycs·¢ÏÖ¼ÙµÄCVE-2023-35829µÄPoC·Ö·¢¶ñÒâÈí¼þ
UptycsÔÚ7ÔÂ12ÈÕ³ÆÆä·¢ÏÖÁËÒ»¸öαÔìµÄ©¶´PoC£¬»á·Ö·¢LinuxÃÜÂëÇÔÈ¡¶ñÒâÈí¼þ¡£¸ÃPoCÉù³ÆÊÇÕë¶ÔCVE-2023-35829µÄ©¶´ÀûÓã¬ÕâÊÇÒ»¸öÓ°Ïì6.3.2֮ǰµÄLinuxÄں˵ÄÊͷźóʹÓé¶´¡£µ«Êµ¼ÊÉÏ£¬ËüÊÇÁíÒ»¸öLinuxÄں˩¶´CVE-2022-34918µÄ¾É°æºÏ·¨Â©¶´ÀûÓ᣸öñÒâÈí¼þÄܹ»ÇÔÈ¡Ö÷»úÃû¡¢Óû§ÃûºÍÖ÷Ŀ¼ÄÚÈݵÄÍêÕûÁбíµÈ¡£´ËÍ⣬¹¥»÷Õß»¹Í¨¹ý½«SSHÃÜÔ¿Ìí¼Óµ½authorized_keysÎļþÖУ¬ÒÔʵÏÖ¶ÔÄ¿±êϵͳµÄÍêÈ«¿ØÖÆ¡£
https://www.uptycs.com/blog/new-poc-exploit-backdoor-malware
6¡¢SlashNextÐû²¼»ùÓÚAIµÄºÚ¿Í¹¤¾ßWormGPTµÄ·ÖÎö³ÂËß
7ÔÂ13ÈÕ£¬SlashNextÐû²¼ÁËÐÂÐÍÉú³ÉʽÈ˹¤ÖÇÄܺڿ͹¤¾ßWormGPTµÄ·ÖÎö³ÂËß¡£¸Ã¹¤¾ß½«×Ô¼ºÊÓΪGPTÄ£Ð͵ĺÚÃ±Ìæ´úÆ·£¬×¨Îª¶ñÒâ»î¶¯¶øÉè¼Æ¡£WormGPTÊÇÒ»¿î»ùÓÚGPTJÓïÑÔÄ£Ð͵ÄAIÄ£¿é£¬ÓÚ2021Ä꿪·¢£¬¾ßÓÐÎÞÏÞ×Ö·ûÖ§³Ö¡¢ÁÄÌìÄÚ´æ±£ÁôºÍ´úÂë¸ñʽ»¯µÈ¹¦Ð§¡£¹¥»÷Õß¿ÉÒÔÀûÓô˹¤¾ßÉú³ÉÓÐ˵·þÁ¦µÄµç×ÓÓʼþ£¬½øÐÐÅÓ´óµÄµöÓã¹¥»÷ºÍBEC¹¥»÷¡£
https://slashnext.com/blog/wormgpt-the-generative-ai-tool-cybercriminals-are-using-to-launch-business-email-compromise-attacks/