ºÚ¿ÍÀûÓþɰæMS Excel©¶´Á÷´«¶ñÒâÈí¼þAgent Tesla
Ðû²¼Ê±¼ä 2023-12-221. ºÚ¿ÍÀûÓþɰæMS Excel©¶´Á÷´«¶ñÒâÈí¼þAgent Tesla
21ÈÕýÌ屨µÀ£¬¹¥»÷ÕßÕýÔÚÀûÓÃ¾ÉµÄ Microsoft Office ©¶´À´Á÷´«ÃûΪAgent TeslaµÄ¶ñÒâÈí¼þ¡£ÒÔ·¢Æ±ÎªÖ÷ÌâµÄÏûÏ¢Öи½¼ÓµÄÓÕ¶ü Excel ÎĵµÀ´ÓÕÆÇ±ÔÚÄ¿±ê´ò¿ªËüÃDz¢ÀûÓÃCVE-2017-11882£¨CVSS ÆÀ·Ö£º7.8£©£¬ÕâÊÇ Office ¹«Ê½±à¼Æ÷ÖеÄÄÚ´æËð»µÂ©¶´£¬¿ÉÄܻᵼÖ´úÂëÒÔÓû§È¨ÏÞÖ´ÐС£Agent TeslaÊÇÒ»ÖÖ»ùÓÚ .NET µÄ¸ß¼¶¼üÅ̼ǼÆ÷ºÍÔ¶³Ì·ÃÎÊľÂí (RAT)£¬Äܹ»´ÓÊÜѬȾµÄÖ÷»ú»ñÈ¡Ãô¸ÐÐÅÏ¢¡£È»ºóÌáÈ¡ÊÕ¼¯µÄÊý¾Ý¡£
https://thehackernews.com/2023/12/hackers-exploiting-old-ms-excel.html
2. FBI³ÆÀÕË÷ÍÅ»ïPlayÔÚ17¸öÔÂÄÚ·¢¶¯Á˽ü300´Î¹¥»÷»î¶¯
¾ÝýÌå19ÈÕ±¨µÀ£¬½ñÄêÕë¶ÔÃÀ¹úÊÐÕþ·þÎñµÄ¼¸ÆðÆÆ»µÐÔ¹¥»÷Ö»ÊÇÀÕË÷ÍÅ»ï Play µÄ±ùɽһ½Ç£¬¾Ý FBI ³Æ£¬¸ÃÍÅ»ïÔÚ 17 ¸öÔÂÄÚÏ®»÷Á˽ü 300 ¸ö×éÖ¯¡£¸Ã×éÖ¯£¨Ò²³ÆÎª Playcrypt£©Ó°ÏìÁ˱±ÃÀ¡¢ÄÏÃÀºÍÅ·Ö޵Ĺ㷺ÆóÒµºÍÒªº¦»ù´¡ÉèÊ©¡£Play ÀÕË÷Èí¼þ¹¥»÷Õß½ÓÄÉË«ÖØÀÕË÷Ä£ÐÍ£¬ÔÚÇÔÈ¡Êý¾Ýºó¶Ôϵͳ½øÐмÓÃÜ¡£Êê½ðƱ¾Ý²»°üÂÞ×î³õµÄÊê½ðÒªÇó»ò¸¶¿î˵Ã÷£¬¶øÊÇָʾÊܺ¦Õßͨ¹ýµç×ÓÓʼþÁªÏµÍþвÐÐΪÕß¡£
https://www.scmagazine.com/news/play-ransomware-gang-tied-to-300-attacks-in-17-months
3. Äþ¾²Ñо¿ÈËÔ±·¢ÏÖ25%µÄ¸ßΣ©¶´ÔÚÐû²¼µÄµ±Ìì¾Í±»ÀûÓÃ
19ÈÕýÌ屨µÀÖУ¬ÔÚQualysÐû²¼µÄÑо¿²©¿ÍÖУ¬Ñо¿ÈËÔ±·¢ÏÖÁËһЩÓë¹ýÈ¥Ò»Äê³ÂËߵij£¼û©¶´ºÍCVEÐû²¼Ïà¹ØµÄÇ÷ÊÆ¡£³ýÁ˺ڿÍÀûÓÃÒÑ֪©¶´µÄËÙ¶ÈÖ®Í⣬³ÂËß»¹Ö¸³ö£¬2023 Ä꣨Æù½ñΪֹ£©³ÂËߵĸ߷çÏÕ©¶´ÖÐÓÐ 97 ¸ö¿ÉÄÜÒѱ»ÀûÓ㬵«´Óδ·ºÆðÔÚ CISA µÄÒÑÖª¿ÉÀûÓé¶´ (KEV) Ŀ¼ÖС£³ÂËßÖл¹Ìá¼°²»µ½ 1% µÄ©¶´Ôì³É×î¸ß·çÏÕ£¬¶øÇÒ¾³£±»¹ã·ºÀûÓá£
https://www.scmagazine.com/news/1-in-4-high-risk-cves-are-exploited-within-24-hours-of-going-public
4. ŦԼij·¿µØ²ú¹«Ë¾ÔÆ·þÎñÆ÷ÅäÖôíÎóй¶15ÒÚÌõµØ²ú¼Ç¼
20ÈÕýÌ屨µÀ£¬ÍøÂçÄþ¾²Ñо¿Ô± Jeremiah Fowler ·¢ÏÖÁËÒ»¸öÓëŦԼÔÚÏ߯½Ì¨ Real Estate Wealth Network Ïà¹ØµÄδÊܱ£»¤µÄÊý¾Ý¿â£¬Êý¾Ý¿âÉú´æÁË 15 ÒÚÌõ¼Ç¼£¬ÆäÖаüÂÞÊý°ÙÍòÈ˵ķ¿µØ²úËùÓÐȨÊý¾Ý¡£¸ÃÊý¾Ý¿â¾ÞϸΪ 1.16 TB£¨×ܹ² 1,523,776,691 Ìõ¼Ç¼£©£¬¾ßÓÐ×éÖ¯ÓÐÐòµÄÎļþ¼Ð£¬ÆäÖаüÂÞÓйØÒµÖ÷¡¢Âô¼Ò¡¢Í¶×ÊÕߺÍÄÚ²¿Óû§ÈÕÖ¾Êý¾ÝµÄÐÅÏ¢¡£Ëü°üÂÞ´Ó 2023 Äê 4 Ô 22 ÈÕµ½ 23 Äê 10 Ô 23 ÈÕµÄÿÈÕÈÕÖ¾¼Ç¼£¬½ÒʾÁËÄÚ²¿Óû§ËÑË÷Êý¾Ý¡£
https://www.hackread.com/data-leak-exposes-real-estate-records-elon-musk-trump/
5. ¶ñÒâÈí¼þJaskaGO¿É¿çMacºÍWindowsÇÔÈ¡Óû§Êý¾Ý
20ÈÕýÌ屨µÀ£¬AT&T Alien Labs µÄÍøÂçÄþ¾²Ñо¿ÈËÔ±·¢ÏÖÁËÒ»ÖÖÃûΪ JaskaGO µÄÅÓ´ó¶ñÒâÈí¼þ£¬ËüÊÇÓà Go ( Golang ) ±à³ÌÓïÑÔ±àдµÄ£¬²¢¾ßÓÐÔÚÊÜѬȾϵͳÖб£³Ö³Ö¾ÃÐÔµÄÄÜÁ¦¡£Ëü¿ÉÒÔй¶ÓмÛÖµµÄÐÅÏ¢£¬°üÂÞä¯ÀÀÆ÷ƾ¾ÝºÍ¼ÓÃÜ»õ±ÒÇ®°üÏêϸÐÅÏ¢¡£Æ¾¾Ý AT&T Alien Labs µÄ³ÂËߣ¬JaskaGO ÊÇÒ»ÖÖÆÛÆÐÔ¹¤¾ß£¬Ëü»áÏÔʾһÌõÐé¼ÙµÄ´íÎóÏûÏ¢£¬Éù³ÆÎļþ¶ªÊ§£¬ÒÔÎóµ¼Óû§ÏàÐŶñÒâ´úÂëÎÞ·¨ÔËÐС£´ËÍ⣬ËüʹÓÃÀàËÆÓÚÖªÃûÓ¦Ó÷¨Ê½µÄÎļþÃû£¬ÀýÈç¡°Capcut_Installer_Intel_M1.dmg¡±ºÍ¡°Anyconnect.exe¡±£¬Õâ±íÃ÷ÔÚµÁ°æÓ¦Ó÷¨Ê½ÍøÒ³ÖÐÒԺϷ¨Èí¼þΪ»Ï×Ó²¿Êð¶ñÒâÈí¼þµÄ³£¼û¼ÆÄ±¡£
https://www.hackread.com/jaskago-malware-mac-windows-crypto-browser-data/
6. IvantiÐû²¼¸üУ¬ÐÞ¸´13¸öÑÏÖØAvalanche RCE©¶´
20ÈÕ£¬Ivanti Ðû²¼ÁËÄþ¾²¸üУ¬ÐÞ¸´Á˸ù«Ë¾ Avalanche ÆóÒµÒÆ¶¯É豸¹ÜÀí (MDM) ½â¾ö·½°¸ÖÐµÄ 13 ¸öÒªº¦Äþ¾²Â©¶´¡£Avalanche ÔÊÐí¹ÜÀíԱͨ¹ý»¥ÁªÍø´ÓÒ»ÆäÖÐÑëλÖùÜÀíÁè¼Ý 100,000 Ì¨ÒÆ¶¯É豸¡¢²¿ÊðÈí¼þ²¢°²×°¸üС£Î´¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔÔÚµÍÅÓ´óÐÔ¹¥»÷ÖÐÀûÓÃËüÃÇ£¬ÕâЩ¹¥»÷²»ÐèÒªÓû§½»»¥¼´¿ÉÔÚδÐÞ²¹µÄϵͳÉÏ»ñµÃÔ¶³Ì´úÂëÖ´ÐС£CISAÆäʱ¾¯¸æËµ£¬Òƶ¯É豸¹ÜÀí (MDM) ϵͳ¶ÔÓÚÍþвÐÐΪÕßÀ´ËµÊÇÓÐÎüÒýÁ¦µÄÄ¿±ê£¬ÒòΪËüÌṩÁ˶ÔÊýǧ¸öÒÆ¶¯É豸µÄ¸ü¸ß·ÃÎÊȨÏÞ£¬¶øÇÒ APT ÐÐΪÕßÒѾÀûÓÃÁË֮ǰµÄ MobileIron ©¶´¡£
https://www.bleepingcomputer.com/news/security/ivanti-releases-patches-for-13-critical-avalanche-rce-flaws/