¼ÓÄôóÍøÂçÔËÓªÉÌRogers´ó¹æÄ£Öжϲ¨¼°¶à¸öÁìÓò
°ä²¼¹¦·ò 2022-07-111¡¢¼ÓÄôóÍøÂçÔËÓªÉÌRogers´ó¹æÄ£Öжϲ¨¼°¶à¸öÁìÓò
¾ÝýÌå7ÔÂ8ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬¼ÓÄôóÍøÂçÔËÓªÉÌÂÞ½Ü˹£¨Rogers£©²úÉúÁË´ó¹æÄ£·þÎñÖжϡ£¡£¡£¡£¡£¡£¡£¡£DownDetector³Æ£¬£¬£¬£¬£¬£¬ÖÐ¶ÏÆðÍ·×ÔÃÀ¹ú¶«²¿¹¦·òÔçÉÏ5µã×óÓÒ£¬£¬£¬£¬£¬£¬¿Í»§·´Ó³ºöÈ»ÎÞ·¨²¦´òµç»°»òÏνӵ½»¥ÁªÍø¡£¡£¡£¡£¡£¡£¡£¡£ÁªÍø¼à¿Ø×éÖ¯NetBlocks°µÊ¾£¬£¬£¬£¬£¬£¬¸ÃÊÂÎñµ¼Ö¼ÓÄôóµÄÍøÂçÏνÓÏ÷¼õÁË25%¡£¡£¡£¡£¡£¡£¡£¡£ÖжÏÓ°ÏìÁ˼ÓÄôóµÄÒøÐкͽðÈÚÂòÂô£¬£¬£¬£¬£¬£¬×Ô¶¯¹ñÔ±»úºÍÐÅÓþ¿¨ÂòÂôÎÞ·¨Õý³£¹¤×÷£¬£¬£¬£¬£¬£¬¶ø²¿ÃŵØÓòµÄ911·þÎñÒ²Êܵ½Ó°Ïì¡£¡£¡£¡£¡£¡£¡£¡£½ØÖÁ7ÔÂ9ÈÕÉÏÎç8:00£¬£¬£¬£¬£¬£¬Roger°ä²¼ÉêÃ÷³Æ£¬£¬£¬£¬£¬£¬ÒÑΪ¾ø´óÎÞÊý¿Í»§¸´ÔÁË·þÎñ£¬£¬£¬£¬£¬£¬µ«ÒÀȻûÓÐÚ¹Ê͵¼ÖÂÖжϵÄÔÒò¡£¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/technology/massive-rogers-outage-disrupts-mobile-service-payments-in-canada/
2¡¢MangatoonÊý¾Ý¿âÅäÖÃÃýÎóй¶2300ÍòÓû§µÄÐÅÏ¢
¾Ý7ÔÂ9ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬Êý¾Ýй¶֪ͨ·þÎñHave I Been Pwned(HIBP)ÔÚÆäÆ½Ì¨ÉÏй©2300Íò¸öMangatoonÕÊ»§Ð¹Â¶¡£¡£¡£¡£¡£¡£¡£¡£MangatoonÊÇÒ»¿îÊÜ»¶ÓµÄÔÚÏßÂþ»ÀûÓ㬣¬£¬£¬£¬£¬Õâ´Îй¶ÁËÓû§µÄÐÕÃû¡¢ÓʼþµØÖ·¡¢É罻ýÌåÕË»§¡¢Éí·ÝÑéÖ¤ÁîÅÆºÍÃÜÂë¡£¡£¡£¡£¡£¡£¡£¡£¾ÝºÚ¿Ípompompurin³Æ£¬£¬£¬£¬£¬£¬ËûÃÇ´ÓʹÓÃÁËÈõÃÜÂë"password"µÄElasticsearch·þÎñÆ÷ÉÏÇÔÈ¡ÁËÊý¾Ý¡£¡£¡£¡£¡£¡£¡£¡£¸ÃºÚ¿Í»¹°µÊ¾£¬£¬£¬£¬£¬£¬¹«Ë¾ÔÚÊÕµ½Ð¹Â¶Í¨Öªºó¸ü¸ÄÁËÃÜÂ룬£¬£¬£¬£¬£¬µ«²¢Î´Í¨Öª¿Í»§£¬£¬£¬£¬£¬£¬Ò²Î´¶Ô´ËÊÂ×÷³ö»ØÓ¦¡£¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/mangatoon-data-breach-exposes-data-from-23-million-accounts/
3¡¢Fortinet·¢ÏÖÀûÓÃDiscord·Ö·¢ºóÃÅRozenaµÄ»î¶¯
7ÔÂ6ÈÕ£¬£¬£¬£¬£¬£¬FortinetÅû¶ÁË·Ö·¢¶ñÒâÈí¼þRozenaµÄ¹¥»÷»î¶¯µÄ¼¼Êõϸ½Ú¡£¡£¡£¡£¡£¡£¡£¡£RozenaÊÇÒ»¸öеĺóÃÅ£¬£¬£¬£¬£¬£¬Äܹ»½«Ô¶³ÌshellÏνÓ×¢Èë¹¥»÷ÕßµÄÍÆËã»ú¡£¡£¡£¡£¡£¡£¡£¡£Õâ´Î»î¶¯ÀûÓÃÁËMSDTÔ¶³Ì´úÂëÖ´Ðзì϶Follina£¨CVE-2022-30190£©£¬£¬£¬£¬£¬£¬Ê¼ÓÚÒ»¸ö±øÆ÷»¯µÄOfficeÎĵµ£¬£¬£¬£¬£¬£¬¸ÃÎĵµÔÚ´ò¿ªÊ±»áÏνӵ½Discord CDN URLÒÔ¼ìË÷HTMLÎļþ£¨¡°index.htm¡±£©¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÎļþʹÓÃPowerShellºÅÁîŲÓÃÕï¶Ï¹¤¾ß£¬£¬£¬£¬£¬£¬´Óͳһ¸öCDN¸½¼þ¿Õ¼äÏÂÔØÏÂÒ»½×¶ÎµÄpayload£¬£¬£¬£¬£¬£¬ÕâÔ̺¬RozenaÖ²È뷨ʽ£¨¡°Word.exe¡±£©ºÍÒ»¸öÅú´¦ÖÃÎļþ£¨¡°cd.bat¡±£©¡£¡£¡£¡£¡£¡£¡£¡£
https://www.fortinet.com/blog/threat-research/follina-rozena-leveraging-discord-to-distribute-a-backdoor
4¡¢QNAPÌáÐѳÆÐÂÀÕË÷Èí¼þCheckmatÖØÒªÕë¶ÔÆäNASÉ豸
QNAPÔÚ7ÔÂ7ÈÕ°ä²¼²¼¸æ³Æ£¬£¬£¬£¬£¬£¬ÐÂÀÕË÷Èí¼þCheckmatÖØÒªÕë¶ÔÆäNASÉ豸¡£¡£¡£¡£¡£¡£¡£¡£³õ´ëÊ©²éÅú×¢£¬£¬£¬£¬£¬£¬Checkmate»áͨ¹ý¶³öÔÚ»¥ÁªÍøÉϵÄSMB·þÎñ½øÐй¥»÷£¬£¬£¬£¬£¬£¬²¢Ê¹ÓÃ×ֵ乥»÷À´ÆÆ½âÈõÃÜÂëµÄÕÊ»§¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÒ»µ©³É¹¦µÇ¼É豸£¬£¬£¬£¬£¬£¬¾Í»á¶Ô¹²ÏíÎļþ¼ÐÖеÄÊý¾Ý½øÐмÓÃÜ£¬£¬£¬£¬£¬£¬²¢ÔÚÿ¸öÎļþ¼ÐÖÐÁôÏÂÒ»¸öÎļþ¡°£¡CHECKMATE_DECRYPTION_README¡±×÷ΪÀÕË÷¼Í¼¡£¡£¡£¡£¡£¡£¡£¡£CheckmateÓÚ5ÔÂ28ÈÕ×óÓÒ³õ´ÎÔÚ¹¥»÷Öб»Ê¹Ó㬣¬£¬£¬£¬£¬QNAP½¨Ò鏿Óû§²»Òª½«SMB·þÎñ¶³öÔÚ»¥ÁªÍøÉÏ£¬£¬£¬£¬£¬£¬²¢Ê¹ÓÃVPN½Ó¼ûNASÀ´Ï÷¼õ¹¥»÷Ãæ¡£¡£¡£¡£¡£¡£¡£¡£
https://securityaffairs.co/wordpress/132989/malware/checkmate-ransomware-targets-qnap-nas.html
5¡¢IBM X-Force°ä²¼¹ØÓÚTrickbotÕë¶ÔÎÚ¿ËÀ¼µÄ·ÖÎö»ã±¨
7ÔÂ7ÈÕ£¬£¬£¬£¬£¬£¬IBM Security X-Force°ä²¼Á˹ØÓÚTrickbotÍÅ»ïÆðÍ·Õë¶ÔÎÚ¿ËÀ¼µÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£¡£¡£ÔÚ2022Äê4ÔÂÖÁ6Ô£¬£¬£¬£¬£¬£¬Trickbot²ß¶¯ÁËÖÁÉÙ6´ÎÕë¶ÔÎÚ¿ËÀ¼µÄ¹¥»÷»î¶¯£¬£¬£¬£¬£¬£¬²¢ÔÚÕâЩ»î¶¯ÖÐ×°ÖÃÁ˶ñÒâÈí¼þIcedID¡¢CobaltStrike¡¢AnchorMailºÍMeterpreter¡£¡£¡£¡£¡£¡£¡£¡£ÔÚµ÷²éÕâЩ»î¶¯Ê±£¬£¬£¬£¬£¬£¬X-Force»¹·¢ÏÖÁ˸ÃÍÅ»ïÔÚʹÓõÄеĶñÒâÈí¼þºÍ¹¤¾ß£ºÓÃÓÚ´«µÝpayloadµÄ¶ñÒâExcelÏÂÔØ·¨Ê½¡¢ÓÃÓÚͶ·ÅºÍ¹¹½¨payload£¨ÈçAnchorMail£©µÄ×Ô½âѹ´æµµ£¨SFX£©£¬£¬£¬£¬£¬£¬ÒÔ¼°Ò»¸ö±»³ÆÎªForestµÄ¶ñÒâÈí¼þ¼ÓÃÜ·¨Ê½¡£¡£¡£¡£¡£¡£¡£¡£
https://securityintelligence.com/posts/trickbot-group-systematically-attacking-ukraine/
6¡¢×êÑÐÈËÔ±ÑÝʾÈôºÎͨ¹ýRolling-PWN¹¥»÷½âËø±¾ÌïÆû³µ
ýÌå7ÔÂ10Èճƣ¬£¬£¬£¬£¬£¬Star-V³¢ÊÔÊÒµÄÒ»×é×êÑÐÈËÔ±³ÆÆäÄܹ»Í¨¹ýRolling-PWN¹¥»÷½âËø¶à¸ö±¾Ìï³µÐÍ¡£¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±ÔÚ±¾ÌïÖз¢ÏÖÁËÒ»¸ö·ì϶(CVE-2021-46145)£¬£¬£¬£¬£¬£¬¿ÉÓÃÀ´½âËø³µÁ¾£¬£¬£¬£¬£¬£¬ÉõÖÁÆô¶¯³µÁ¾·¢Æð»ú¡£¡£¡£¡£¡£¡£¡£¡£¾ÝϤ£¬£¬£¬£¬£¬£¬¸ÃÎÊÌâÓ°ÏìÊг¡ÉÏ´Ó2012Äêµ½2022ÄêµÄËùÓб¾ÌïÆû³µ¡£¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶´æÔÚÓÚÓÃÀ´Ô¤·À³Á·Å¹¥»÷µÄ¹ö¶¯´úÂë»úÔìÖУ¬£¬£¬£¬£¬£¬×êÑÐÈËÔ±»¹°ä²¼ÁËÒ»×éPoCÊÓÆµ£¬£¬£¬£¬£¬£¬À´ÑÝʾÀûÓø÷ì϶¶Ô±¾ÌïCRVµÄ¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£
https://securityaffairs.co/wordpress/133090/hacking/honda-rolling-pwn-attack.html


¾©¹«Íø°²±¸11010802024551ºÅ