з¢ÏÖµÄ RustDoor ¶ñÒâÈí¼þð³ä Visual Studio ¸üÐÂ

Ðû²¼Ê±¼ä 2024-02-22
1. з¢ÏÖµÄ RustDoor ¶ñÒâÈí¼þð³ä Visual Studio ¸üÐÂ


2ÔÂ20ÈÕ £¬Ð·¢ÏÖµÄ Apple macOS ºóÃÅÃûΪ RustDoor £¬Ëüͨ¹ýÅÓ´óµÄ¶ñÒâÈí¼þ»î¶¯Õë¶Ô¼ÓÃÜ»õ±ÒÁìÓòµÄ¶à¼Ò¹«Ë¾¡£¸Ã¶ñÒâÈí¼þ½ÓÄÉ Rust ¿ª·¢ £¬¿ÉÔÚ»ùÓÚ Intel µÄ¼Ü¹¹ºÍ ARM ¼Ü¹¹ÉÏÔËÐС£Bitdefender µÄÑо¿ÈËÔ±ÖÁÉÙ´Ó 2023 Äê 11 ÔÂÆð¾ÍÒ»Ö±ÔÚ¸ú×ٸöñÒâÈí¼þ £¬·¢ÏÖËüÓëÓëÎÛÃûÕÑÖøµÄALPHV/BlackCat ÀÕË÷Èí¼þÍÅ»ïÏà¹ØµÄ C2 ·þÎñÆ÷½øÐÐͨÐÅ¡£RustDoor Ö÷Òª×÷Ϊ Visual Studio for Mac µÄ¸üз¨Ê½½øÐзַ¢ £¬¾ßÓвîÒìµÄÃû³Æ,Èç¡°zshrc2¡±¡¢¡°Previewers¡±¡¢¡°VisualStudioUpdater¡±¡¢¡°VisualStudioUpdater_Patch¡±¡¢¡°VisualStudioUpdating¡±¡¢¡°visualstudioupdate¡±ºÍ¡°DO_NOT_RUN_ChromeUpdates¡±¡£Ñ¬È¾ÏµÍ³ºó £¬¶ñÒâÈí¼þÓë C2 ·þÎñÆ÷ͨÐÅÒÔ¿ØÖÆÊÜѬȾµÄϵͳ¡¢Ö´ÐÐÈÎÎñ²¢ÇÔÈ¡Êý¾Ý¡£


https://cyware.com/news/newly-discovered-rustdoor-malware-impersonates-visual-studio-update-148f6632/?web_view=true


2.Earth Preta Õë¶ÔÑÇÖ޵Ĺ¥»÷»î¶¯£ºDOPLUGS ¶ñÒâÈí¼þÍþв


2ÔÂ20ÈÕ £¬Check Point µÄÉîÈëÍþв·ÖÎö·ÖÎöÁ˸߼¶Á¬ÐøÍþв (APT) ×éÖ¯ Earth Preta µÄÁ¬ÐøÐж¯¡£¾¡¹ÜÆäÅ·Ö޻Êܵ½¹ã·º¼à¿Ø £¬µ«²»ÐзñÈϵÄÊÇ £¬Æä¶ÔÑÇÖÞÄ¿±êµÄ¸ß¶È¹Ø×¢¡£ÕâÒ»¶¨ÖƼÆÄ±µÄÒªº¦ÊÇÒ»ÖÖÃûΪ DOPLUGS µÄ¶¨ÖƶñÒâÈí¼þ £¬ËüÊÇ×î½üһϵÁÐÈëÇÖÖÐÀûÓõÄÒªº¦¹¤¾ß¡£·ÖÎö±íÃ÷ £¬ÕâÖÖ¶¨ÖÆµÄ PlugX ±äÌåÔ¶·ÇµäÐÍ¡£Check Point µÄÑо¿ÈËÔ±ÈÏʶµ½ÆäÆæÌØµÄÊôÐÔ £¬²¢½«ÆäÃüÃûΪ DOPLUGS¡£Óë¾ßÓÐÈ«Ì׺óÃÅÃüÁîµÄ´«Í³ PlugX ¶ñÒâÈí¼þ²îÒì¡£ÓÐȤµÄÊÇ £¬Check Point ·¢ÏÖÁËÄܹ»ÀûÓá°KillSomeOne¡±USB È䳿²¡¶¾µÄ DOPLUGS ±äÌ壨×î³õÓÚ 2020 ÄêÆØ¹â£©¡£ÕâÒ»Ôö¼ÓµÄά¶ÈÓÐÖúÓÚÔÚÊÜѬȾµÄÍøÂçÖпìËÙÒÆ¶¯ £¬Í¹ÏÔÁËÍþв×é֯׷Çó¸ü¹ã·ºµÄÉøÍ¸¡£


https://securityonline.info/earth-pretas-targeted-asian-campaigns-the-doplugs-malware-threat/


3.DNS ©¶´ KeyTrap ¿Éµ¼Ö»¥ÁªÍø´ó·¶Î§µÄÖжÏ


2ÔÂ21ÈÕ £¬¾¡¹ÜËü×Ô 2000 ÄêÒÔÀ´¾ÍÒ»Ö±´æÔÚ £¬µ«Ñо¿ÈËÔ±×î½ü²Å·¢ÏÖÓòÃûϵͳ (DNS) Äþ¾²À©Õ¹ÖеÄÒ»¸ö»ù±¾Éè¼ÆÈ±ÏÝ £¬¸ÃȱÏÝÔÚijЩÇé¿öÏ¿ÉÄܻᱻÀûÓÃÀ´´Ý»Ù´ó·¶Î§µÄ»¥ÁªÍø¡£DNS ·þÎñÆ÷½«ÍøÕ¾ URL ת»»Îª IP µØÖ· £¬¶øÇÒÔÚ´ó¶àÊýÇé¿öϲ»ÐмûµØ³ÐÔØËùÓл¥ÁªÍøÁ÷Á¿¡£ÕâÒ»·¢ÏÖ±³ºóµÄÍŶÓÀ´×Ե¹ú ATHENE ¹ú¼ÒÓ¦ÓÃÍøÂçÄþ¾²Ñо¿ÖÐÐÄ¡£ËûÃǽ«¸ÃÄþ¾²Â©¶´ÃüÃûΪ¡°KeyTrap¡± £¬±àºÅΪCVE-2023-50387¡£Æ¾¾ÝËûÃǹØÓÚ KeyTrap DNS ´íÎóµÄгÂËß £¬Ñо¿ÈËÔ±·¢ÏÖ £¬Ê¹Óà DNSSEC À©Õ¹·¢Ë͵½ DNS ·þÎñÆ÷ʵÏÖÀ´ÑéÖ¤Á÷Á¿µÄµ¥¸öÊý¾Ý°ü¿ÉÄÜ»áÆÈʹ·þÎñÆ÷½øÈë½âÎöÑ­»· £¬´Ó¶øµ¼ÖÂÆäÏûºÄËùÓÐ×Ô¼ºµÄ¼ÆËãÄÜÁ¦¡£Æ¾¾Ý¸Ã³ÂËßºÍ ISC µÄ˵·¨ £¬ºÃÏûÏ¢ÊÇ £¬µ½Ä¿Ç°ÎªÖ¹ £¬»¹Ã»ÓÐÈκÎÖ÷¶¯ÀûÓõÄÖ¤¾Ý¡£


https://www.darkreading.com/cloud-security/keytrap-dns-bug-threatens-widespread-internet-outages


4. Joomla Ô¶³Ì´úÂëÖ´ÐЩ¶´ CVE-2024-21726


2ÔÂ20ÈÕ £¬Ñо¿ÍŶÓ×î½üµÄÒ»Ïî·¢ÏÖ̻¶ÁËÁ÷ÐеÄJoomlaÄÚÈݹÜÀíϵͳ (CMS)ÖеÄÒ»¸öÖØÒªµÄÄþ¾²ÎÊÌâ¡£´Ë©¶´Ö¸¶¨ÎªCVE-2024-21726 £¬Îª¶àÖÖ¿çÕ¾½Å±¾ (XSS) ¹¥»÷´ò¿ªÁË´óÃÅ £¬¹¥»÷Õß¿ÉÒÔÀûÓôËȨÏÞÇÔÈ¡Ãô¸ÐÊý¾Ý¡¢Öض¨ÏòÍøÕ¾Á÷Á¿¡¢ÆÆ»µÍøÕ¾»ò°²×°³Ö¾ÃÐÔ¶ñÒâÈí¼þÒÔ½øÒ»²½Î£º¦¡£Joomla Ðж¯Ñ¸ËÙ £¬Ðû²¼Á˲¹¶¡°æ±¾£¨5.0.3¡¢4.4.3¡¢3.10.15-elts£©£©¡£¿ÉÔö¼Ó Web Ó¦Ó÷¨Ê½·À»ðǽ (WAF) ºÍ¶¨ÆÚ¶ñÒâÈí¼þɨÃè £¬ÒÔÔö¼ÓÕë¶Ô¹¥»÷µÄÌØ±ðÆÁÕÏ¡£Ç¿ÖÆÖ´ÐС°×îСȨÏÞ¡±¼ÆÄ± £¬½öÏòÐèÒªÍêÈ«ÍøÕ¾¿ØÖƵÄÈËÔ±ÊÚÓè¹ÜÀí·ÃÎÊȨÏÞ¡£


https://securityonline.info/cve-2024-21726-patch-now-to-stop-joomla-remote-code-execution/


5. VMware ¶Ø´ÙÓû§Ð¶ÔØÒÑÆúÓõÄÔöÇ¿ÐÍÉí·ÝÑéÖ¤²å¼þ


2ÔÂ21ÈÕ £¬ÔÚ·¢ÏÖÑÏÖØÄþ¾²Â©¶´ºó £¬VMware ¶Ø´ÙÓû§Ð¶ÔØÒÑÆúÓõÄÔöÇ¿ÐÍÉí·ÝÑéÖ¤²å¼þ (EAP)¡£¸Ã©¶´±àºÅΪCVE-2024-22245£¨CVSS ÆÀ·Ö£º9.6£© £¬±»ÃèÊöΪÈÎÒâÉí·ÝÑéÖ¤Öм̴íÎó¡£¶ñÒâÐÐΪÕß¿ÉÄÜ»áÆÛÆ­ÔÚÍøÂçä¯ÀÀÆ÷Öа²×°ÁË EAP µÄÄ¿±êÓòÓû§ £¬ÇëÇó²¢×ª·¢ÈÎÒâ Active Directory ·þÎñÖ÷ÌåÃû³Æ (SPN) µÄ·þÎñƱ֤¡£EAPÊÇÒ»¸öÈí¼þ°ü £¬Ö¼ÔÚÔÊÐíͨ¹ý Web ä¯ÀÀÆ÷Ö±½ÓµÇ¼ vSphere µÄ¹ÜÀí½çÃæºÍ¹¤¾ß £¬×Ô 2021 Äê 3 ÔÂÆðÒÑÆúÓá£Ä¬ÈÏÇé¿öϲ»°üÂÞËü £¬Ò²²»ÊôÓÚ vCenter Server¡¢ESXi »ò Cloud Foundation¡£ÖµµÃÖ¸³öµÄÊÇ £¬ÕâЩȱÏݽöÓ°ÏìÒѽ« EAP Ìí¼Óµ½ Microsoft Windows ϵͳÒÔͨ¹ý vSphere Client Á¬½Óµ½ VMware vSphere µÄÓû§¡£


https://thehackernews.com/2024/02/vmware-alert-uninstall-eap-now-critical.html


6. Linux ¶ñÒâÈí¼þ»î¶¯ Migo Ãé×¼ Redis ½øÐÐÍÚ¿ó


2ÔÂ20ÈÕ £¬Äþ¾²Ñо¿ÈËÔ±·¢ÏÖÁËÕë¶ÔÁ÷ÐÐÊý¾Ý´æ´¢ÏµÍ³ Redis µÄÅÓ´ó¶ñÒâÈí¼þ»î¶¯¡£¸Ã»î¶¯±»³ÆÎª¡°Migo¡± £¬½ÓÄÉÐÂÓ±µÄ¼ÆÄ±À´ÆÆ»µ Redis ·þÎñÆ÷ £¬×îÖÕÄ¿±êÊÇÔÚ Linux Ö÷»úÉÏÍÚ¾ò¼ÓÃÜ»õ±Ò¡£ÌرðÊÇ £¬Cado Äþ¾²ÊµÑéÊÒÑо¿ÈËÔ±ÊӲ쵽 £¬Migo ÀûÓÃÐ嵀 Redis ϵͳÈõ»¯ÃüÁîÀ´ÀûÓÃÊý¾Ý´æ´¢½øÐмÓÃܽٳÖ¡£Óë֮ǰÕë¶Ô Redis µÄ¹¥»÷²îÒì £¬´Ë»î¶¯ÒýÈëÁËÆæÌصļ¼ÊõÀ´Î£º¦ÏµÍ³µÄÄþ¾²¡£¹¥»÷µÄ³õʼ·ÃÎʽ׶ÎÉæ¼°Ê¹ÓÃÌØ¶¨µÄ CLI ÃüÁî½ûÓà Redis µÄÖÖÖÖÅäÖÃÑ¡Ïî¡£ÀýÈç £¬¹¥»÷Õ߹رձ£»¤Ä£Ê½ºÍ¸±±¾Ö»¶ÁµÈ¹¦Ð§ÒÔ´Ù½øÆä¶ñÒâ»î¶¯¡£»ñµÃ·ÃÎÊȨÏÞºó £¬¹¥»÷ÕßÉèÖÃÁËһϵÁÐÃüÁîÀ´Ö´ÐÐ´Ó Transfer.sh ºÍ Pastebin µÈÍⲿÀ´Ô´¼ìË÷µ½µÄ¶ñÒâ¸ºÔØ¡£ÕâЩÓÐЧ¸ºÔØÖ¼ÔÚÔÚºǫ́ÍÚ¾ò¼ÓÃÜ»õ±Ò £¬Í¬Ê±±£³Ö²»±»·¢ÏÖ¡£


https://www.infosecurity-magazine.com/news/linux-malware-migo-targets-redis/