Microsoft 365ÒòECS²¿ÊðÃýÎóÈ«ÇòÁìÓòÄÚÀï¶Ï5Ó×ʱ

°ä²¼¹¦·ò 2022-07-25
1¡¢Microsoft 365ÒòECS²¿ÊðÃýÎóÈ«ÇòÁìÓòÄÚÀï¶Ï5Ó×ʱ

      

¾Ý7ÔÂ23ÈÕ±¨Â· £¬£¬£¬£¬£¬ £¬Î¢Èíй©ÉÏÖܳ¤´ï5Ó×ʱµÄMicrosoft 365È«ÇòÁìÓòÄÚÀï¶ÏÊÇÓÉÆóÒµÅäÖ÷þÎñ(ECS)²¿ÊðÃýÎóµ¼ÖµÄ¡£¡£¡£¡£¡£¡£ ¡£¡£ECS·þÎñµÄ²¿Êð´æÔÚ´úÂëȱµã£¬£¬£¬£¬£¬ £¬Ó°ÏìÁËÆäÏòºó¼æÈÝÐÔ£¬£¬£¬£¬£¬ £¬µ¼ÖÂÀûÓÃECSµÄ·þÎñ£¬£¬£¬£¬£¬ £¬½«ÏòÆäËùÓеĺÏ×÷ͬ°é·µ»Ø²»ÕýÈ·µÄÅäÖᣡ£¡£¡£¡£¡£ ¡£¡£Ò£²âÅú×¢£¬£¬£¬£¬£¬ £¬Ô¼ÄªÓÐ30Íò¸öºô½ÐÊܵ½Ó°Ï죬£¬£¬£¬£¬ £¬ÓÉÓÚÒµÎñ¹¦·òÓëÓ°Ïì´°¿ÚÏàÎǺÏ£¬£¬£¬£¬£¬ £¬ÑÇÌ«µØÓòÊܵ½µÄÓ°Ïì×î´ó¡£¡£¡£¡£¡£¡£ ¡£¡£´Ë±í£¬£¬£¬£¬£¬ £¬Ö±½Ó·ÓɺÍSkype MFAÊÇÊÜÓ°Ïì×î´óµÄ·þÎñ¡£¡£¡£¡£¡£¡£ ¡£¡£ÖÐ¶ÏÆðÍ·ÓÚ7ÔÂ21ÈÕÁ賿1:05 UTCÆðÍ·£¬£¬£¬£¬£¬ £¬µ±ÈÕÔçÉÏ6:00 UTC֮ǰ´ó²¿ÃÅÒѱ»½¨¸´¡£¡£¡£¡£¡£¡£ ¡£¡£


https://www.bleepingcomputer.com/news/microsoft/massive-microsoft-365-outage-caused-by-faulty-ecs-deployment/


2¡¢¹¥»÷ÕßÔÚ°µÍøÒÔ3ÍòÃÀÔªÏúÊÛ540ÍòTwitterÓû§µÄÐÅÏ¢

      

¾ÝýÌå7ÔÂ24ÈÕ±¨Â·£¬£¬£¬£¬£¬ £¬ÃûΪdevilµÄºÚ¿Í³ÆÆäÀûÓ÷ì϶½Ó¼ûÁË5485636ÃûTwitterÓû§µÄÐÅÏ¢£¬£¬£¬£¬£¬ £¬²¢ÒÔÖÁÉÙ30000ÃÀÔªµÄ¼ÛÖµ½øÐÐÏúÊÛ¡£¡£¡£¡£¡£¡£ ¡£¡£ÓÃÓÚÍøÂçÊý¾ÝµÄ·ì϶ÓÚ1ÔÂ1±»Åû¶²¢ÓÚ1ÔÂ13ÈÕ½¨¸´£¬£¬£¬£¬£¬ £¬¿É±»Î´¾­Éí·ÝÑéÖ¤¹¥»÷ÕßÓÃÀ´Í¨¹ýµç»°ºÅÂëºÍÓʼþÀ´»ñÈ¡ËÁÒâÓû§µÄTwitter ID¡£¡£¡£¡£¡£¡£ ¡£¡£¹¥»÷Õß°µÊ¾ËûÃÇÔÚ2021Äê12ÔÂ¾ÍÆðÍ·ÀûÓ÷ìÏ¶ÍøÂçÊý¾Ý£¬£¬£¬£¬£¬ £¬´Ë¿ÌÒÑÓиÐÐËÖµÄÂò¼ÒÓëËûÃǽøÐнÓÇ¢¡£¡£¡£¡£¡£¡£ ¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬ £¬TwitterÉÐδȷÈÏÕâ´Îй¶ÊÂÎñ£¬£¬£¬£¬£¬ £¬¶øÂô¼ÒÒÑɾ³ý¸Ã¸æ°×¡£¡£¡£¡£¡£¡£ ¡£¡£


https://securityaffairs.co/wordpress/133593/data-breach/twitter-leaked-data.html


3¡¢Securonix·¢ÏÖAPT37ÀûÓÃKonni¹¥»÷Å·ÖÞ¶à¹úµÄ»î¶¯

      

7ÔÂ20ÈÕ£¬£¬£¬£¬£¬ £¬Securonix³ÆÆä·¢ÏÖÁ˳¯Ïʹ¥»÷ÕßAPT37ÀûÓÃKonniÕë¶Ô½Ý¿ËºÍ²¨À¼µÈÅ·ÖÞ¹ú¶ÈµÄ¹¥»÷¡£¡£¡£¡£¡£¡£ ¡£¡£Ôڴ˻ÖУ¬£¬£¬£¬£¬ £¬¹¥»÷ÕßʹÓÃÁËÔ¶³Ì½Ó¼ûľÂíKonni£¬£¬£¬£¬£¬ £¬¹¥»÷ʼÓÚÒ»·âÔ̺¬WordÎĵµ(missile.docx)ºÍWindows¿ì½Ý·½Ê½Îļþ(weapons.doc.lnk.lnk)¸½¼þµÄ´¹µöÓʼþ¡£¡£¡£¡£¡£¡£ ¡£¡£´ò¿ªLNKºó»áÖ´ÐдúÂëÀ´ÔÚDOCXÎļþÖвéÕÒbase64±àÂëµÄPowerShell¾ç±¾£¬£¬£¬£¬£¬ £¬¶øºó³ÉÁ¢C2ͨѶ²¢ÏÂÔØÁ½¸öÎļþ¡°weapons.doc¡±ºÍ¡°wp.vbs¡±¡£¡£¡£¡£¡£¡£ ¡£¡£ÕâЩÎļþÖ»Êǵö¶ü£¬£¬£¬£¬£¬ £¬Í¬Ê±£¬£¬£¬£¬£¬ £¬ºó¶Ü»á¾²Ä¬µØÔËÐÐVBSÎļþ£¬£¬£¬£¬£¬ £¬×îÖÕÏÂÔØKonni¡£¡£¡£¡£¡£¡£ ¡£¡£


https://www.securonix.com/blog/stiffbizon-detection-new-attack-campaign-observed/


4¡¢Êý×Ö°²È«¹«Ë¾EntrustÔâµ½¹¥»÷ºóÄÚ²¿ÏµÍ³Êý¾Ý±»µÁ

     

ýÌå7ÔÂ22ÈÕ±¨Â·£¬£¬£¬£¬£¬ £¬Entrust³ÆÆäÔâµ½ÁËÍøÂç¹¥»÷£¬£¬£¬£¬£¬ £¬ÄÚ²¿ÏµÍ³ÖеÄÊý¾Ý±»µÁ¡£¡£¡£¡£¡£¡£ ¡£¡£EntrustÊÇÒ»¼ÒרһÓÚÔÚÏßÐÅÀµºÍÉí·ÝÖÎÀíµÄ°²È«¹«Ë¾£¬£¬£¬£¬£¬ £¬ÌṩÔ̺¬¼ÓÃÜͨѶ¡¢°²È«Êý×ÖÖ§¸¶ºÍÉí·ÝÖ¤Ã÷½â¾ö¹æ»®µÈ·þÎñ¡£¡£¡£¡£¡£¡£ ¡£¡£¹¥»÷²úÉúÔÚ6ÔÂ18ÈÕ£¬£¬£¬£¬£¬ £¬¸Ã¹«Ë¾²¢Î´Ìṩ¹ØÓÚ¸ÃÊÂÎñµÄ¸ü¶àϸ½Ú£¬£¬£¬£¬£¬ £¬µ«×êÑÐÈËÔ±Ïàʶµ½Ò»¸ö³ÛÃûµÄÀÕË÷ÍÅ»ïÊÇÄ»ºóºÚÊÖ¡£¡£¡£¡£¡£¡£ ¡£¡£±»µÁÊý¾ÝÏÔʾ£¬£¬£¬£¬£¬ £¬Õâ´ÎÊÂÎñ¿ÉÄÜ»áÓ°Ïì´óÁ¿Ê¹ÓÃEntrust½øÐÐÉí·ÝÖÎÀíºÍÉí·ÝÑéÖ¤µÄ×éÖ¯£¬£¬£¬£¬£¬ £¬Ô̺¬ÃÀ¹úµ±¾Ö»ú¹¹£¬£¬£¬£¬£¬ £¬ÈçÄÜÔ´²¿¡¢ºÓɽ°²È«Êý¡¢²ÆÕþ²¿¡¢ÎÀÉúÓ빫¼Ò·þÎñ²¿¡¢ÍËÒÛÎäÊ¿ÊÂÎñ²¿ºÍũҵ²¿µÈµÈ¡£¡£¡£¡£¡£¡£ ¡£¡£


https://www.bleepingcomputer.com/news/security/digital-security-giant-entrust-breached-by-ransomware-gang/


5¡¢Ciscoй©Õë¶ÔÎÚ¿ËÀ¼Ä³´óÐÍÈí¼þ¹«Ë¾µÄ¹¥»÷µÄϸ½Ú

      

CiscoÔÚ7ÔÂ21ÈÕÅû¶ÁËÕë¶ÔÎÚ¿ËÀ¼Ä³´óÐÍÈí¼þ¹«Ë¾µÄ¹¥»÷»î¶¯µÄϸ½Ú¡£¡£¡£¡£¡£¡£ ¡£¡£Õâ¼ÒÈí¼þ¹«Ë¾³ö²úµÄÈí¼þ¹©ÎÚ¿ËÀ¼¶à¸ö¹ú¶È»ú¹¹ËùʹÓ㬣¬£¬£¬£¬ £¬×êÑÐÈËÔ±ÒÔΪ£¬£¬£¬£¬£¬ £¬¸ÃÊÂÎñ¿ÉÄÜÓë¶íÂÞ˹ÓйØ£¬£¬£¬£¬£¬ £¬ÒԸù«Ë¾ÎªÖ¸±ḛ̂ͼ·¢Æð¹©¸øÁ´¹¥»÷¡£¡£¡£¡£¡£¡£ ¡£¡£¹¥»÷»î¶¯Ê¹ÓÃÁËÒ»¸öÃûΪGoMetµÄ¿ªÔ´ºóÃŵÄ×Ô½ç˵±äÌ壬£¬£¬£¬£¬ £¬Ö»ÓÐÁ½Æð¼Í¼ÔÚ°¸µÄ»î¶¯ÀûÓùý¸ÃºóÃÅ£º2020Äê¹¥»÷ÕßÀûÓÃF5 BIG-IPÖзì϶£¨CVE-2020-5902£©ÈëÇÖϵͳ²¢×°ÖÃÕâ¸öºóÃÅ£»£»£»£» £»£»£»½üÆÚ£¬£¬£¬£¬£¬ £¬¹¥»÷ÕßÔÚÀûÓÃSophos FirewallÖзì϶£¨CVE-2022-1040£©ºó×°ÖúóÃÅ¡£¡£¡£¡£¡£¡£ ¡£¡£


https://blog.talosintelligence.com/2022/07/attackers-target-ukraine-using-gomet.html


6¡¢SonicWal°ä²¼SQL×¢Èë·ì϶CVE-2022-22280µÄ°²È«²¼¸æ

      

SonicWallÔÚ7ÔÂ22ÈÕ°ä²¼°²È«²¼¸æ£¬£¬£¬£¬£¬ £¬ÌáÐÑÓ°ÏìGMS£¨È«ÇòÖÎÀíϵͳ£©ºÍAnalytics On-Prem²úÆ·µÄSQL×¢Èë·ì϶¡£¡£¡£¡£¡£¡£ ¡£¡£¸Ã·ì϶׷×ÙΪCVE-2022-22280£¬£¬£¬£¬£¬ £¬ÊǶÔSQLºÅÁîÖÐʹÓõÄÌØÊâÔªËØµÄ²»ÕýÈ·Öк͵¼ÖµÄ£¬£¬£¬£¬£¬ £¬CVSSÆÀ·ÖΪ9.4£¬£¬£¬£¬£¬ £¬ÎÞÐèÉí·ÝÑéÖ¤»òÓû§½»»¥¼´¿ÉÀûÓᣡ£¡£¡£¡£¡£ ¡£¡£SonicWall°µÊ¾Ëµ£¬£¬£¬£¬£¬ £¬¸Ã·ì϶ÉÐδ±»ÔÚÒ°ÀûÓ㬣¬£¬£¬£¬ £¬Ò²Ã»ÓÐÕë¶Ô´Ë·ì϶µÄ¸ÅÏëÖ¤Ã÷(PoC)¡£¡£¡£¡£¡£¡£ ¡£¡£´Ë·ìϼû»ÓпÉÓõĽâ¾ö²½Ö裬£¬£¬£¬£¬ £¬Òò¶øSonicWallÇ¿ÁÒ½¨ÒéʹÓÃÊÜÓ°Ïì²úÆ·µÄ×éÖ¯Á¢¼´Éý¼¶µ½ÏàÓ¦µÄ½¨¸´°æ±¾¡£¡£¡£¡£¡£¡£ ¡£¡£


https://www.bleepingcomputer.com/news/security/sonicwall-patch-critical-sql-injection-bug-immediately/