΢ÈíÐû²¼11ÔÂÄþ¾²¸üÐÂÐÞ¸´3¸öÒѱ»ÀûÓõÄ©¶´

Ðû²¼Ê±¼ä 2023-11-15
1¡¢Î¢ÈíÐû²¼11ÔÂÄþ¾²¸üÐÂÐÞ¸´3¸öÒѱ»ÀûÓõÄ©¶´


΢ÈíÔÚ11ÔÂ14ÈÕÐû²¼Á˱¾ÔµÄÖܶþ²¹¶¡£¬×ܼÆÐÞ¸´ÁË58¸ö©¶´£¬°üÂÞ5¸ö0day¡£´Ë´ÎÐÞ¸´µÄ0dayÖУ¬WindowsÔÆÎļþ΢ÐÍɸѡÆ÷Çý¶¯·¨Ê½ÌáȨ©¶´£¨CVE-2023-36036£©¡¢Windows DWMºËÐÄ¿âÌáȨ©¶´£¨CVE-2023-36033£©ºÍWindows SmartScreenÄþ¾²¹¦Ð§Èƹý©¶´£¨CVE-2023-36025£©Òѱ»ÀûÓã¬Microsoft OfficeÄþ¾²¹¦Ð§Èƹý©¶´£¨CVE-2023-36413£©ºÍASP.NET Core¾Ü¾ø·þÎñ©¶´£¨CVE-2023-36038£©Ò²Òѱ»¹ûÈ»Åû¶¡£


https://www.bleepingcomputer.com/news/microsoft/microsoft-november-2023-patch-tuesday-fixes-5-zero-days-58-flaws/


2¡¢SektorCERTÅû¶µ¤ÂóµÄ»ù´¡ÉèÊ©Ôâµ½´ó¹æÄ£¹¥»÷


¾Ý11ÔÂ14ÈÕ±¨µÀ£¬µ¤ÂóÒªº¦²¿ÃŵķÇÓªÀûÍøÂçÄþ¾²ÖÐÐÄSektorCERTÅû¶£¬ÆäÒªº¦»ù´¡ÉèÊ©Ôâµ½ÁËÓÐÊ·ÒÔÀ´×î´ó¹æÄ£µÄÍøÂç¹¥»÷¡£µÚÒ»²¨¹¥»÷ÓÚ5ÔÂ11ÈÕÌᳫ£¬¶ÌÔÝͣЪºó£¬µÚ¶þ²¨¹¥»÷ÓÚ5ÔÂ22ÈÕ¿ªÊ¼£¬SektorCERTÓÚ5ÔÂ22ÈÕÒâʶµ½ÕâЩ¹¥»÷¡£¹¥»÷ÕßÀûÓÃZyxel·À»ðǽÖеÄ©¶´£¨CVE-2023-28771£©£¬ÈëÇÖÁË22¼Ò´ÓÊÂÄÜÔ´»ù´¡ÉèÊ©ÔËÓªµÄ¹«Ë¾¡£SektorCERTÈÏΪ£¬¹¥»÷ÕßÕÆÎÕÁËÄ¿±êµÄÏêϸÐÅÏ¢£¬ºÜ¿ÉÄÜÊÇͨ¹ý֮ǰδ±»·¢ÏÖµÄÕì²ì»î¶¯ÊÕ¼¯µÄ¡£¶øÇÒÕâЩ¹¥»÷¿ÉÄÜÊǶà¸öÍÅ»ïÖ´ÐеÄ£¬ÆäÖÐÖÁÉÙÓÐÒ»¸ö¿É¹éÒòÓÚSandworm¡£


https://securityaffairs.com/154156/apt/denmark-critical-infrastructure-record-attacks.html


3¡¢RoyalÒÑÈëÇÖÖÁÉÙ350¸öÄ¿±ê²¢ÀÕË÷Áè¼Ý2.75ÒÚÃÀÔª


11ÔÂ13ÈÕ£¬FBIºÍCISAÐû²¼Á˹ØÓÚÀÕË÷Èí¼þRoyalµÄÁªºÏÍøÂçÄþ¾²×Éѯ(CSA)¡£¸Ã×Éѯָ³ö£¬×Ô2022Äê9ÔÂÒÔÀ´£¬RoyalÒѹ¥»÷È«Çò350¶à¸öÄ¿±ê£¬Ìá³öÁËÁè¼Ý2.75ÒÚÃÀÔªµÄÀÕË÷ÒªÇó¡£µöÓãÓʼþÊÇRoyal½øÐгõʼ·ÃÎʵÄ×îÀֳɵÄÔØÌåÖ®Ò»¡£Óм£Ïó±íÃ÷£¬Royal¿ÉÄÜÕýÔÚÎªÆ·ÅÆÖØËܺÍ/»òÑÜÉú±äÌå×ö×¼±¸£¬ÀÕË÷Èí¼þBlacksuit¾ßÓÐÐí¶àÓëRoyalÏàËÆµÄ±àÂëÌØÕ÷¡£


https://www.bleepingcomputer.com/news/security/fbi-royal-ransomware-asked-350-victims-to-pay-275-million/


4¡¢HuntersÉù³ÆÒÑÊÕ¼¯Homeland¹«Ë¾Áè¼Ý200GBµÄÊý¾Ý


¾ÝýÌå11ÔÂ13ÈÕ±¨µÀ£¬Hunters International½«ÃÀ¹úÎïÒµ¹ÜÀí¹«Ë¾HomelandÌí¼Óµ½ÁËÆäÍøÕ¾ÖС£¹¥»÷ÕßÉù³ÆÒÑÊÕ¼¯183793¸öÎļþ£¬¹²204.1GB£¬»¹ÔÚÍøÕ¾ÉÏÐû²¼ÁËÒ»·ÝÎļþÑù±¾×÷ΪÀÕË÷Ö¤¾Ý¡£Ñù±¾Îļþ°üÂÞ×â»§µÄ³öÉúÈÕÆÚ¡¢µØÖ·¡¢ÄêÊÕÈëºÍ×â½ðÏêϸÐÅÏ¢µÈ¸öÈËÐÅÏ¢¡£Hunters͸¶¹¥»÷·¢ÉúÓÚ10ÔÂ26ÈÕ£¬ËûÃÇÂú×ãHomelandµÄÒªÇóÌṩ½âÃܹ¤¾ßÑÝʾºÍй¶Êý¾ÝÑù±¾ºóûÓÐÊÕµ½Èκλظ´£¬»¹ÌåÏָù«Ë¾ÐèÒªÔÚ11ÔÂ18ÈÕ֮ǰ×ö³ö»ØÓ¦¡£


https://www.databreaches.net/property-management-firm-homeland-inc-allegedly-hacked-hackers-claim-to-have-hundreds-of-thousands-of-ssn-of-tenants/


5¡¢AhnLab¼ì²âµ½ÀûÓÃDdostf¹¥»÷MySQL·þÎñÆ÷µÄ»î¶¯


AhnLabÓÚ11ÔÂ14Èճƣ¬×î½ü·¢ÏÖÔÚMySQL·þÎñÆ÷Éϰ²×°DdostfµÄ»î¶¯¡£DDdostfÊÇÒ»ÖÖDDoS bot£¬¶ÔÌØ¶¨Ä¿±êÖ´ÐÐDDoS¹¥»÷£¬ÓÚ2016Äê×óÓÒÊ״α»·¢ÏÖ¡£ÔڿɹûÈ»·ÃÎʵÄϵͳÖУ¬É¨Ã跨ʽ»áËÑË÷ʹÓÃ3306/TCP¶Ë¿ÚµÄϵͳ£¬È»ºóÖ´Ðб©Á¦¹¥»÷»ò×ֵ乥»÷£¬»¹¿ÉÄÜ·ÃÎʹÜÀíÔ±ÕÊ»§Æ¾¾Ý¡£Èç¹ûϵͳÔËÐеÄÊÇ´æÔÚ©¶´µÄδÐÞ¸´°æ±¾£¬¹¥»÷Õß¿ÉÒÔÀûÓé¶´À´Ö´ÐÐÃüÁ¶øÎÞÐèÉÏÊö¹ý³Ì¡£Ä¿±êϵͳµÄѬȾÈÕÖ¾±íÃ÷£¬³ýÁËDdostfÖ®Í⣬Ŀ±êϵͳÉÏ»¹±»°²×°Á˶ñÒâUDF DLL¡£


https://asec.ahnlab.com/en/58878/


6¡¢Cado·¢ÏÖÕë¶ÔDocker Engine APIµÄ½©Ê¬ÍøÂçOracleIV 


11ÔÂ13ÈÕ£¬CadoÅû¶ÁË×î½ü·¢ÏÖµÄÒ»ÆðÕë¶Ô¹ûÈ»Docker Engine APIʵÀýµÄл¡£Ôڴ˻ÖУ¬¹¥»÷ÕßÀûÓÃDockerÈÝÆ÷ÖеĴíÎóÅäÖÃÀ´Á÷´«±àÒëΪELF¿ÉÖ´ÐÐÎļþµÄPython¶ñÒâÈí¼þ¡£¸Ã¶ñÒâÈí¼þ×Ô¼º³äµ±DDoS botÊðÀí£¬Äܹ»Í¨¹ý¶àÖÖÒªÁì½øÐÐDoS¹¥»÷¡£ÔÚеÄOracleIV DDoS½©Ê¬ÍøÂç¶ñÒâÈí¼þÖУ¬¹¥»÷Õßͨ¹ýHTTP POSTÇëÇóÆô¶¯¶ÔDocker APIµÄ·ÃÎÊ¡£Õâ»á´¥·¢docker pullÃüÁ´ÓDockerhub»ñȡָ¶¨¾µÏñ¡£


https://www.cadosecurity.com/oracleiv-a-dockerised-ddos-botnet/