´óÁ¿QNAP NASÓû§³ÆÆäÉ豸Ôâµ½ech0raixµÄÀÕË÷¹¥»÷
°ä²¼¹¦·ò 2022-06-201¡¢´óÁ¿QNAP NASÓû§³ÆÆäÉ豸Ôâµ½ech0raixµÄÀÕË÷¹¥»÷
ýÌå6ÔÂ18ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬Æ¾¾ÝID Ransomwareƽ̨ÉÏÓû§Ìá½»µÄ»ã±¨ºÍÑù±¾£¬£¬£¬£¬£¬£¬ech0raixÀÕË÷Èí¼þÔÚÉÏÖÜÆðÍ·ÔÙ´ÎÕë¶ÔQNAP NASÉ豸¡£¡£¡£¡£¡£¡£Ô½À´Ô½¶àµÄÓû§³ÆÆäÔâµ½¹¥»÷£¬£¬£¬£¬£¬£¬×îÔç²úÉúÔÚ6ÔÂ8ÈÕ¡£¡£¡£¡£¡£¡£Ö»¹ÜÖ»Óм¸Ê®¸öech0raixÑù±¾£¬£¬£¬£¬£¬£¬µ«×êÑÐÈËÔ±°µÊ¾ÏÖʵµÄ³É¹¦¹¥»÷µÄÊýÁ¿ºÜ¿ÉÄܸü¸ß£¬£¬£¬£¬£¬£¬ÓÉÓÚÖ»Óв¿ÃÅÓû§»áʹÓÃID Ransomware·þÎñÀ´¼ø±ðÀÕË÷Èí¼þ¡£¡£¡£¡£¡£¡£QNAPÉÐδ°ä²¼ÓйØÕâ´Î¹¥»÷µÄ¸ü¶àÐÅÏ¢£¬£¬£¬£¬£¬£¬Õâ¸öech0raix»î¶¯Ê¹ÓõĹ¥»÷ý½éÒÀȻδ֪¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/qnap-nas-devices-targeted-by-surge-of-ech0raix-ransomware-attacks/
2¡¢ÃÀ¹úµ±¾Ö³ÆÒѵ·»ÙϰȾÊý°ÙÍòÉ豸µÄ½©Ê¬ÍøÂçRSOCKS
¾Ý6ÔÂ18ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬ÃÀ¹úµ±¾ÖÓëµÂ¹ú¡¢ºÉÀ¼ºÍÓ¢¹úµÄ·¨ÂÉ»ú¹¹ºÏ×÷£¬£¬£¬£¬£¬£¬³É¹¦²ð³ýÁËÓë¶íÂÞ˹½©Ê¬ÍøÂçRSOCKSÓйصĻù´¡ÉèÊ©¡£¡£¡£¡£¡£¡£RSOCKSÓÉÈ«ÇòÊý°ÙÍǫ̀±»Ï°È¾µÄÉ豸×é³É£¬£¬£¬£¬£¬£¬×Ô³ÆÄܹ»¹©¸¶·Ñ¿Í»§½Ó¼û±»ÈëÇÖµÄÉ豸µÄIPµØÖ·¡£¡£¡£¡£¡£¡£¸ÃÐж¯ÆðÍ·ÓÚ2017Ä꣬£¬£¬£¬£¬£¬Æäʱ·¨ÂÉÈËÔ±´ÓRSOCKS°ÂÃØµØ²É°ìÁËÆä·þÎñÒÔ¼ø±ðÆä»ù´¡ÉèÊ©ºÍÖ¸±ê£¬£¬£¬£¬£¬£¬È·¶¨ÁËԼĪ325000̨±»Ï°È¾µÄÉ豸¡£¡£¡£¡£¡£¡£½üÆÚµÄÁíÒ»Ïî·¨ÂÉÐж¯²é»ñÁËÒÑÏúÊÛ2400ÍòÈËÐÅÏ¢µÄ°µÍøÊг¡SSNDOB¡£¡£¡£¡£¡£¡£
https://securityaffairs.co/wordpress/132403/cyber-crime/police-dismantled-rsocks-bitnet.html
3¡¢VolexityÅû¶DriftingCloudÍÅ»ï½üÆÚ¹¥»÷»î¶¯µÄϸ½Ú
VolexityÔÚ6ÔÂ15ÈÕ°ä²¼»ã±¨£¬£¬£¬£¬£¬£¬Åû¶ÁËDriftingCloudÍÅ»ï½üÆÚ¹¥»÷»î¶¯µÄϸ½Ú¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±·¢ÏÖ£¬£¬£¬£¬£¬£¬×Ô3Ô³õÆðÍ·£¬£¬£¬£¬£¬£¬¸ÃÍÅ»ï¾ÍÀûÓÃÁËSophos FirewallÖеÄÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶£¨CVE-2022-1040£¬£¬£¬£¬£¬£¬CVSSÆÀ·Ö9.8£©À´ÈëÇÖÖ¸±ê£¬£¬£¬£¬£¬£¬¶øºó×°ÖÃÒ»¸öºóÃÅ¡£¡£¡£¡£¡£¡£Volexity³Æ¹¥»÷Õß»áÀûÓ÷À»ðǽµÄ½Ó¼ûȨÏÞÀ´´Û¸ÄÕë¶ÔÌØ¶¨Ö¸±êÍøÕ¾µÄDNSÏìÓ¦£¬£¬£¬£¬£¬£¬ÒÔÖ´ÐÐMITM¹¥»÷¡£¡£¡£¡£¡£¡£Ò»µ©»ñµÃ¶ÔÖ¸±êÍøÂç·þÎñÆ÷µÄ½Ó¼ûȨÏÞ£¬£¬£¬£¬£¬£¬¹¥»÷Õ߾ͻá×°Ööà¸ö¿ªÔ´¶ñÒâÈí¼þ£¬£¬£¬£¬£¬£¬Ô̺¬PupyRAT¡¢PanteganaºÍSliver¡£¡£¡£¡£¡£¡£
https://www.volexity.com/blog/2022/06/15/driftingcloud-zero-day-sophos-firewall-exploitation-and-an-insidious-breach/
4¡¢ÉϰÙÍòWordPressÍøÕ¾µÄ²å¼þNinja Forms±»Ç¿Ôì¸üÐÂ
¾ÝýÌå6ÔÂ17Èճƣ¬£¬£¬£¬£¬£¬ÉϰÙÍò¸öWordPressÍøÕ¾Òѱ»Ç¿Ôì¸üУ¬£¬£¬£¬£¬£¬ÒÔ½¨¸´Æä²å¼þNinja FormsÖеķì϶¡£¡£¡£¡£¡£¡£ÕâÊÇÒ»¸ö´úÂë×¢Èë·ì϶£¬£¬£¬£¬£¬£¬CVSSÆÀ·ÖΪ9.8£¬£¬£¬£¬£¬£¬Ó°ÏìÁË´Ó3.0ÆðÍ·µÄ¶à¸öNinja Forms°æ±¾¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±°µÊ¾£¬£¬£¬£¬£¬£¬Î´¾Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÄܹ»Ô¶³ÌÀûÓô˷ì϶À´Å²Óø÷ÀàNinja±íµ¥À࣬£¬£¬£¬£¬£¬¶øºóͨ¹ý¶à¸öÀûÓÃÁ´ÆëÈ«ÊÕÊÜWordPressÍøÕ¾¡£¡£¡£¡£¡£¡£Wordfence·¢ÏÖµÄÖ¤¾ÝÅú×¢£¬£¬£¬£¬£¬£¬¸Ã·ì϶ÒÑÔÚ¹¥»÷Öб»ÀûÓ㬣¬£¬£¬£¬£¬WordPressΪ´Ë²å¼þÖ´ÐÐÁËÇ¿Ôì×Ô¶¯¸üС£¡£¡£¡£¡£¡£
https://thehackernews.com/2022/06/over-million-wordpress-sites-forcibly.html
5¡¢×êÑÐÈËÔ±·¢ÏÖÀûÓÃÀ¬»øÓʼþ·Ö·¢MatanbuchusµÄ»î¶¯
¾Ý6ÔÂ18ÈÕµÄýÌ屨·£¬£¬£¬£¬£¬£¬×êÑÐÈËÔ±·¢ÏÖÁË·Ö·¢¶ñÒâÈí¼þMatanbuchusµÄÀ¬»øÓʼþ»î¶¯¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÊ×ÏÈʹÓüÙ×°ÊǶÔÏÈǰµç×ÓÓʼþµÄ»Ø¸´×÷Ϊµö¶ü£¬£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬Ò»¸öZIP¸½¼þ£¬£¬£¬£¬£¬£¬¿ÉÏÂÔØÒ»¸öMSI°ü£¬£¬£¬£¬£¬£¬¸Ã°üʹÓÃÓÉDigiCertΪ¡°Westeast Tech Consulting, Corp.¡±Ðû¸æµÄÓÐЧ֤Êé½øÐÐÊðÃû¡£¡£¡£¡£¡£¡£Ö®ºó£¬£¬£¬£¬£¬£¬»áÏÂÔØÁ½¸öMatanbuchus DLL payload£¬£¬£¬£¬£¬£¬¸Ã¶ñÒâÈí¼þ×îÖÕ»á´ÓC2·þÎñÆ÷ÏÂÔØCobalt Strike£¬£¬£¬£¬£¬£¬ÎªºóÐø¹¥»÷×ö³ï±¸¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/new-phishing-attack-infects-devices-with-cobalt-strike/
6¡¢¿ý±±¿Ë·¨ÔºÅоöDesjardins¾ÍÊý¾Ýй¶ÊÂÎñÖ§¸¶2ÒÚ¼ÓÔª
6ÔÂ18ÈÕ±¨Â·³Æ£¬£¬£¬£¬£¬£¬¿ý±±¿Ë·¨ÔºÒÑÅоöDesjardinsÖ§¸¶2.009ÒÚ¼ÓÔªÒÔ½â¾ö¶ÔÊý¾Ýй¶ÊÂÎñµÄ¼¯ÌåËßËÏ¡£¡£¡£¡£¡£¡£¼à¹Ü»ú¹¹°µÊ¾£¬£¬£¬£¬£¬£¬DesjardinsµÄÎ¥¹æÊÂÎñÊÇÓÉһϵÁзì϶Ôì³ÉµÄ£¬£¬£¬£¬£¬£¬Ð¹Â¶ÁË420Íò¸öÕ¼ÓлîÔ¾ÕË»§µÄÓû§µÄÊý¾Ý¡£¡£¡£¡£¡£¡£¾ÝϤ£¬£¬£¬£¬£¬£¬Ã¿¸öÊÜÓ°ÏìµÄÓû§¶¼ÓÐ×ʸñÌá³öË÷Åâ¡£¡£¡£¡£¡£¡£Ôڴ˽׶Σ¬£¬£¬£¬£¬£¬Óû§²»ÓòÉÈ¡ÈκδëÊ©£¬£¬£¬£¬£¬£¬Ô̺¬Ë÷Åâ×¢Ã÷ÔÚÄÚµÄ֪ͨ½«ÔÚ×Ô7ÔÂ21ÈÕÆðÍ·µÄ¼¸¸öÔÂÄÚ·Ö·¢¡£¡£¡£¡£¡£¡£
https://www.databreaches.net/quebec-court-approves-200-9m-settlement-against-desjardins-over-data-breach/


¾©¹«Íø°²±¸11010802024551ºÅ