ºÚ¿ÍÀûÓþɰæMS Excel©¶´Á÷´«¶ñÒâÈí¼þAgent Tesla

Ðû²¼Ê±¼ä 2023-12-22

1. ºÚ¿ÍÀûÓþɰæMS Excel©¶´Á÷´«¶ñÒâÈí¼þAgent Tesla 


21ÈÕýÌ屨µÀ£¬¹¥»÷ÕßÕýÔÚÀûÓÃ¾ÉµÄ Microsoft Office ©¶´À´Á÷´«ÃûΪAgent TeslaµÄ¶ñÒâÈí¼þ ¡£ÒÔ·¢Æ±ÎªÖ÷ÌâµÄÏûÏ¢Öи½¼ÓµÄÓÕ¶ü Excel ÎĵµÀ´ÓÕÆ­Ç±ÔÚÄ¿±ê´ò¿ªËüÃDz¢ÀûÓÃCVE-2017-11882£¨CVSS ÆÀ·Ö£º7.8£©£¬ÕâÊÇ Office ¹«Ê½±à¼­Æ÷ÖеÄÄÚ´æËð»µÂ©¶´£¬¿ÉÄܻᵼÖ´úÂëÒÔÓû§È¨ÏÞÖ´ÐÐ ¡£Agent TeslaÊÇÒ»ÖÖ»ùÓÚ .NET µÄ¸ß¼¶¼üÅ̼ǼÆ÷ºÍÔ¶³Ì·ÃÎÊľÂí (RAT)£¬Äܹ»´ÓÊÜѬȾµÄÖ÷»ú»ñÈ¡Ãô¸ÐÐÅÏ¢ ¡£È»ºóÌáÈ¡ÊÕ¼¯µÄÊý¾Ý ¡£


https://thehackernews.com/2023/12/hackers-exploiting-old-ms-excel.html


2. FBI³ÆÀÕË÷ÍÅ»ïPlayÔÚ17¸öÔÂÄÚ·¢¶¯Á˽ü300´Î¹¥»÷»î¶¯


¾ÝýÌå19ÈÕ±¨µÀ£¬½ñÄêÕë¶ÔÃÀ¹úÊÐÕþ·þÎñµÄ¼¸ÆðÆÆ»µÐÔ¹¥»÷Ö»ÊÇÀÕË÷ÍÅ»ï Play µÄ±ùɽһ½Ç£¬¾Ý FBI ³Æ£¬¸ÃÍÅ»ïÔÚ 17 ¸öÔÂÄÚÏ®»÷Á˽ü 300 ¸ö×éÖ¯ ¡£¸Ã×éÖ¯£¨Ò²³ÆÎª Playcrypt£©Ó°ÏìÁ˱±ÃÀ¡¢ÄÏÃÀºÍÅ·Ö޵Ĺ㷺ÆóÒµºÍÒªº¦»ù´¡ÉèÊ© ¡£Play ÀÕË÷Èí¼þ¹¥»÷Õß½ÓÄÉË«ÖØÀÕË÷Ä£ÐÍ£¬ÔÚÇÔÈ¡Êý¾Ýºó¶Ôϵͳ½øÐмÓÃÜ ¡£Êê½ðƱ¾Ý²»°üÂÞ×î³õµÄÊê½ðÒªÇó»ò¸¶¿î˵Ã÷£¬¶øÊÇָʾÊܺ¦Õßͨ¹ýµç×ÓÓʼþÁªÏµÍþвÐÐΪÕß ¡£


https://www.scmagazine.com/news/play-ransomware-gang-tied-to-300-attacks-in-17-months


3. Äþ¾²Ñо¿ÈËÔ±·¢ÏÖ25%µÄ¸ßΣ©¶´ÔÚÐû²¼µÄµ±Ìì¾Í±»ÀûÓÃ


19ÈÕýÌ屨µÀÖУ¬ÔÚQualysÐû²¼µÄÑо¿²©¿ÍÖУ¬Ñо¿ÈËÔ±·¢ÏÖÁËһЩÓë¹ýÈ¥Ò»Äê³ÂËߵij£¼û©¶´ºÍCVEÐû²¼Ïà¹ØµÄÇ÷ÊÆ ¡£³ýÁ˺ڿÍÀûÓÃÒÑ֪©¶´µÄËÙ¶ÈÖ®Í⣬³ÂËß»¹Ö¸³ö£¬2023 Ä꣨Æù½ñΪֹ£©³ÂËߵĸ߷çÏÕ©¶´ÖÐÓÐ 97 ¸ö¿ÉÄÜÒѱ»ÀûÓ㬵«´Óδ·ºÆðÔÚ  CISA µÄÒÑÖª¿ÉÀûÓé¶´ (KEV) Ŀ¼ÖÐ ¡£³ÂËßÖл¹Ìá¼°²»µ½ 1% µÄ©¶´Ôì³É×î¸ß·çÏÕ£¬¶øÇÒ¾­³£±»¹ã·ºÀûÓà ¡£


https://www.scmagazine.com/news/1-in-4-high-risk-cves-are-exploited-within-24-hours-of-going-public


4. ŦԼij·¿µØ²ú¹«Ë¾ÔÆ·þÎñÆ÷ÅäÖôíÎóй¶15ÒÚÌõµØ²ú¼Ç¼


20ÈÕýÌ屨µÀ£¬ÍøÂçÄþ¾²Ñо¿Ô± Jeremiah Fowler ·¢ÏÖÁËÒ»¸öÓëŦԼÔÚÏ߯½Ì¨ Real Estate Wealth Network Ïà¹ØµÄδÊܱ £»¤µÄÊý¾Ý¿â£¬Êý¾Ý¿âÉú´æÁË 15 ÒÚÌõ¼Ç¼£¬ÆäÖаüÂÞÊý°ÙÍòÈ˵ķ¿µØ²úËùÓÐȨÊý¾Ý ¡£¸ÃÊý¾Ý¿â¾ÞϸΪ 1.16 TB£¨×ܹ² 1,523,776,691 Ìõ¼Ç¼£©£¬¾ßÓÐ×éÖ¯ÓÐÐòµÄÎļþ¼Ð£¬ÆäÖаüÂÞÓйØÒµÖ÷¡¢Âô¼Ò¡¢Í¶×ÊÕߺÍÄÚ²¿Óû§ÈÕÖ¾Êý¾ÝµÄÐÅÏ¢ ¡£Ëü°üÂÞ´Ó 2023 Äê 4 Ô 22 ÈÕµ½ 23 Äê 10 Ô 23 ÈÕµÄÿÈÕÈÕÖ¾¼Ç¼£¬½ÒʾÁËÄÚ²¿Óû§ËÑË÷Êý¾Ý ¡£


https://www.hackread.com/data-leak-exposes-real-estate-records-elon-musk-trump/


5. ¶ñÒâÈí¼þJaskaGO¿É¿çMacºÍWindowsÇÔÈ¡Óû§Êý¾Ý


20ÈÕýÌ屨µÀ£¬AT&T Alien Labs µÄÍøÂçÄþ¾²Ñо¿ÈËÔ±·¢ÏÖÁËÒ»ÖÖÃûΪ JaskaGO µÄÅÓ´ó¶ñÒâÈí¼þ£¬ËüÊÇÓà Go ( Golang ) ±à³ÌÓïÑÔ±àдµÄ£¬²¢¾ßÓÐÔÚÊÜѬȾϵͳÖб£³Ö³Ö¾ÃÐÔµÄÄÜÁ¦ ¡£Ëü¿ÉÒÔй¶ÓмÛÖµµÄÐÅÏ¢£¬°üÂÞä¯ÀÀÆ÷ƾ¾ÝºÍ¼ÓÃÜ»õ±ÒÇ®°üÏêϸÐÅÏ¢ ¡£Æ¾¾Ý AT&T Alien Labs µÄ³ÂËߣ¬JaskaGO ÊÇÒ»ÖÖÆÛÆ­ÐÔ¹¤¾ß£¬Ëü»áÏÔʾһÌõÐé¼ÙµÄ´íÎóÏûÏ¢£¬Éù³ÆÎļþ¶ªÊ§£¬ÒÔÎóµ¼Óû§ÏàÐŶñÒâ´úÂëÎÞ·¨ÔËÐÐ ¡£´ËÍ⣬ËüʹÓÃÀàËÆÓÚÖªÃûÓ¦Ó÷¨Ê½µÄÎļþÃû£¬ÀýÈç¡°Capcut_Installer_Intel_M1.dmg¡±ºÍ¡°Anyconnect.exe¡±£¬Õâ±íÃ÷ÔÚµÁ°æÓ¦Ó÷¨Ê½ÍøÒ³ÖÐÒԺϷ¨Èí¼þΪ»Ï×Ó²¿Êð¶ñÒâÈí¼þµÄ³£¼û¼ÆÄ± ¡£


https://www.hackread.com/jaskago-malware-mac-windows-crypto-browser-data/


6. IvantiÐû²¼¸üУ¬ÐÞ¸´13¸öÑÏÖØAvalanche RCE©¶´


20ÈÕ£¬Ivanti Ðû²¼ÁËÄþ¾²¸üУ¬ÐÞ¸´Á˸ù«Ë¾ Avalanche ÆóÒµÒÆ¶¯É豸¹ÜÀí (MDM) ½â¾ö·½°¸ÖÐµÄ 13 ¸öÒªº¦Äþ¾²Â©¶´ ¡£Avalanche ÔÊÐí¹ÜÀíԱͨ¹ý»¥ÁªÍø´ÓÒ»ÆäÖÐÑëλÖùÜÀíÁè¼Ý 100,000 Ì¨ÒÆ¶¯É豸¡¢²¿ÊðÈí¼þ²¢°²×°¸üР¡£Î´¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔÔÚµÍÅÓ´óÐÔ¹¥»÷ÖÐÀûÓÃËüÃÇ£¬ÕâЩ¹¥»÷²»ÐèÒªÓû§½»»¥¼´¿ÉÔÚδÐÞ²¹µÄϵͳÉÏ»ñµÃÔ¶³Ì´úÂëÖ´ÐÐ ¡£CISAÆäʱ¾¯¸æËµ£¬Òƶ¯É豸¹ÜÀí (MDM) ϵͳ¶ÔÓÚÍþвÐÐΪÕßÀ´ËµÊÇÓÐÎüÒýÁ¦µÄÄ¿±ê£¬ÒòΪËüÌṩÁ˶ÔÊýǧ¸öÒÆ¶¯É豸µÄ¸ü¸ß·ÃÎÊȨÏÞ£¬¶øÇÒ APT ÐÐΪÕßÒѾ­ÀûÓÃÁË֮ǰµÄ MobileIron ©¶´ ¡£


https://www.bleepingcomputer.com/news/security/ivanti-releases-patches-for-13-critical-avalanche-rce-flaws/