Ó¡¶È×î´óµÄµçÁ¦¹«Ë¾Tata PowerµÄIT»ù´¡ÉèÊ©Ôâµ½¹¥»÷

°ä²¼¹¦·ò 2022-10-17

1¡¢Ó¡¶È×î´óµÄµçÁ¦¹«Ë¾Tata PowerµÄIT»ù´¡ÉèÊ©Ôâµ½¹¥»÷

      

¾ÝýÌå10ÔÂ15ÈÕ±¨Â·£¬£¬ £¬ £¬£¬£¬Ó¡¶È×î´óµÄ×ۺϵçÁ¦¹«Ë¾Tata PowerµÄIT»ù´¡ÉèÊ©Ôâµ½ÍøÂç¹¥»÷¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬ £¬ £¬£¬£¬¸Ã¹«Ë¾ÉÐδÌṩÓйع¥»÷»î¶¯µÄ¾ßÌåÐÅÏ¢£¬£¬ £¬ £¬£¬£¬µ«Æäй©ÒѾ­²ÉÈ¡Ðж¯ÒÔÓ¦¶Ô¸ÃÊÂÎñ²¢¸´Ô­ÊÜÓ°ÏìµÄϵͳ¡£¡£¡£¡£¡£¾Ý³Æ£¬£¬ £¬ £¬£¬£¬¹¥»÷»î¶¯Õë¶ÔµÄÊÇÖÁÉÙ7¸öÓ¡¶È¹ú¶ÈµçÁ¦µ÷¶ÈÖÐÐÄ(sldc)£¬£¬ £¬ £¬£¬£¬ËüÃÇÕÆ¹ÜÔÚ¸÷×ÔµÄÖÝÄÚÖ´ÐÐʵʱµçÍø½ÚÔìºÍµçÁ¦µ÷¶È²Ù×÷¡£¡£¡£¡£¡£×êÑÐÈËÔ±½«Õâ´Î»î¶¯¹éÒòÓÚºÚ¿ÍÍÅ»ïTAG-38¡£¡£¡£¡£¡£


https://thehackernews.com/2022/10/indian-energy-company-tata-powers-it.html


2¡¢Î¢Èí·¢ÏÖÖØÒªÕë¶ÔÎÚ¿ËÀ¼ºÍ²¨À¼µÄÐÂÀÕË÷Èí¼þPrestige

      

10ÔÂ14ÈÕ£¬£¬ £¬ £¬£¬£¬Î¢ÈíMSTICй©ÐµÄÀÕË÷Èí¼þPrestigeÕý±»ÓÃÓÚÕë¶ÔÎÚ¿ËÀ¼ºÍ²¨À¼µÄÔËÊäºÍÎïÁ÷×éÖ¯µÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þÓÚ10ÔÂ11ÈÕ³õ´ÎÔÚÒ°±íʹÓ㬣¬ £¬ £¬£¬£¬ÓëFoxBlade£¨Ò²³ÆÎªHermeticWiper£©µÄ±»¹¥»÷Ö¸±êÓгÁµþ¡£¡£¡£¡£¡£Î¢Èí²¹³ä·£¬£¬ £¬ £¬£¬£¬´Ë»î¶¯ÓëËüÔÚ¸ú×ÙµÄ94¸öµ±Ç°»îÔ¾µÄÀÕË÷»î¶¯Ã»ÓÐÈκθÉÁª£¬£¬ £¬ £¬£¬£¬ÔÚ´Ë֮ǰ²¢Î´¼û¹ýPrestigeÀÕË÷Èí¼þ¡£¡£¡£¡£¡£MSTIC»¹Ç¿µ÷ÁËÓÃÓÚ·Ö·¢PrestigeµÄÈýÖÖ²½Ö裬£¬ £¬ £¬£¬£¬²¢¹«¿ªÁËһϵÁеÄIOCºÍ¸ß¼¶ËÑË÷²éÎÊ£¬£¬ £¬ £¬£¬£¬ÒÔÔ®ÊÖÓû§ÕмܴËÀ๥»÷¡£¡£¡£¡£¡£


https://www.microsoft.com/security/blog/2022/10/14/new-prestige-ransomware-impacts-organizations-in-ukraine-and-poland/


3¡¢×êÑÐÍŶÓй©ºÚ¿ÍÒÑÀûÓÃZimbra·ì϶¹¥»÷½ü900̨·þÎñÆ÷

      

¾Ý10ÔÂ15ÈÕ±¨Â·£¬£¬ £¬ £¬£¬£¬ºÚ¿ÍÒÑÀûÓÃZCSÖеķì϶£¨CVE-2022-41352£©ÈëÇÖÁ˽ü900̨·þÎñÆ÷¡£¡£¡£¡£¡£Kaspersky³Æ£¬£¬ £¬ £¬£¬£¬µÚÒ»ÂÖ¹¥»÷ʼÓÚ9Ô£¬£¬ £¬ £¬£¬£¬ÖØÒªÕë¶ÔÓ¡¶ÈºÍÍÁ¶úÆäµÄһЩÒ×±»¹¥»÷µÄZimbra·þÎñÆ÷¡£¡£¡£¡£¡£×î³õµÄÕâ´Î¹¥»÷¿ÉÄÜÊÇÓÃÓÚ²âÊÔ¹¥»÷µÄÓÐЧÐÔ£¬£¬ £¬ £¬£¬£¬½öÈëÇÖÁË44̨·þÎñÆ÷¡£¡£¡£¡£¡£·ì϶ÒѾ­¹«¿ª£¬£¬ £¬ £¬£¬£¬¹¥»÷Õß¾ÍÆðÍ·Ö´Ðдó¹æÄ£¹¥»÷¡£¡£¡£¡£¡£µÚ¶þÂֻÖкڿÍÓöñÒâwebshellϰȾÁË832̨·þÎñÆ÷£¬£¬ £¬ £¬£¬£¬µ«ÕâЩ¹¥»÷±È֮ǰµÄ¹¥»÷Ô½·¢Ëæ»ú¡£¡£¡£¡£¡£×êÑÐÈËÔ±½¨ÒéÓû§Á¢¼´ÀûÓÃZimbra°²È«¸üлò±äͨ·¨×Ó¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/almost-900-servers-hacked-using-zimbra-zero-day-flaw/


4¡¢°Ä´óÀûÑDZ£ÏÕ¹«Ë¾Medibank±»¹¥»÷ºó¹ÉƱÔÝÍ£ÂòÂô

      

¾Ý·͸Éç10ÔÂ13ÈÕ±¨Â·£¬£¬ £¬ £¬£¬£¬°Ä´óÀûÑǽ¡È«±£ÏÕ¹«Ë¾Medibank Private(MPL.AX)Ôâµ½ÍøÂç¹¥»÷¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÔÚÉÏÖÜËݵʾ£¬£¬ £¬ £¬£¬£¬ËûÃǼì²âµ½ÆäÍøÂçÉÏÓÐÒì³£»£»£»£»£»£»£»î¶¯£¬£¬ £¬ £¬£¬£¬½«¸ôÀ벢ɾ³ý¶ÔÒ»Ð©ÃæÏò¿Í»§µÄϵͳµÄ½Ó¼û¡£¡£¡£¡£¡£Òò¶ø£¬£¬ £¬ £¬£¬£¬ÆäAHM£¨°Ä´óÀûÑǽ¡È«ÖÎÀí£©ºÍ¹ú¼ÊѧÉúÕþ²ßÖÎÀíϵͳÒÑÏÂÏߣ¬£¬ £¬ £¬£¬£¬µ«ÊÇÆäÒ½ÁÆ·þÎñ½«³ÖÐøÏòÆä¿Í»§Ìṩ·þÎñ¡£¡£¡£¡£¡£¾ÝϤ£¬£¬ £¬ £¬£¬£¬ÔÚÍøÂçÊÂÎñ°ä²¼Ö®Ç°£¬£¬ £¬ £¬£¬£¬MedibankµÄ¹ÉƱÒѾ­ÔÝÍ£ÂòÂô£¬£¬ £¬ £¬£¬£¬²¢ÔÚµ÷²é¸ÃÊÂÎñʱ½«³ÖÐø¹Ø¹ØÂòÂô¡£¡£¡£¡£¡£


https://www.reuters.com/technology/australias-medibank-reports-cyber-incident-2022-10-13/


5¡¢ZscalerÅû¶Ducktail InfostealerеÄPHP±äÌåµÄÏêÇé

      

ZscalerÔÚ10ÔÂ13ÈÕÅû¶ÁËÕë¶ÔFacebookÆóÒµÕÊ»§µÄDucktail InfostealerÐÂPHP±äÌå¡£¡£¡£¡£¡£Ducktail×Ô2021ÄêÒÔÀ´Ò»Ïò´æÔÚ£¬£¬ £¬ £¬£¬£¬²¢¹éÒòÓÚÔ½ÄϵÄÒ»¸ö¹¥»÷ÍŻ¡£¡£¡£¡£ZscalerÔÚ2022Äê8Ô·¢ÏÖÁËÒ»¸öеĻ£¬£¬ £¬ £¬£¬£¬Í¨¹ý¼Ù×°³É¸÷ÀàÃâ·Ñ»òÆÆ½âµÄÀûÓÃ×°Ö÷¨Ê½£¬£¬ £¬ £¬£¬£¬ÈçÓÎÏ·¡¢Microsoft OfficeÀûÓ÷¨Ê½ºÍTelegramµÈ£¬£¬ £¬ £¬£¬£¬»ý¼«·Ö·¢DucktailµÄбäÌå¡£¡£¡£¡£¡£Óë¾É°æ±¾(.NetCore)Ò»Ñù£¬£¬ £¬ £¬£¬£¬¸Ã±äÌåÒ²Ö¼ÔÚй¶±£ÁôµÄä¯ÀÀÆ÷Í´´¦ºÍFacebookÕÊ»§ÐÅÏ¢µÈÐÅÏ¢¡£¡£¡£¡£¡£


https://www.zscaler.com/blogs/security-research/new-php-variant-ducktail-infostealer-targeting-facebook-business-accounts


6¡¢Cisco°ä²¼¹ØÓÚÐµĹ¥»÷¿ò¼ÜAlchimistµÄ·ÖÎö»ã±¨

      

10ÔÂ13ÈÕ£¬£¬ £¬ £¬£¬£¬Cisco Talos°ä²¼Á˹ØÓÚеĵ¥ÎļþC2¿ò¼ÜAlchimistµÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¸Ã¿ò¼ÜËÆºõ±»ÓÃÓÚÕë¶ÔWindows¡¢LinuxºÍmacOSϵͳµÄ¹¥»÷£¬£¬ £¬ £¬£¬£¬ËüÓë¹¥»÷¿ò¼ÜManjusaka¼«¶ÈÀàËÆ¡£¡£¡£¡£¡£AlchimistÓÃGoLang±àд£¬£¬ £¬ £¬£¬£¬²¢¸¨ÒÔÒ»¸öÃûΪInsektµÄbeaconÖ²È뷨ʽ£¬£¬ £¬ £¬£¬£¬ËüÓµÓпÉÓÉC2·þÎñÆ÷¼ì²âµÄÔ¶³Ì½Ó¼ûÖ°ÄÜ¡£¡£¡£¡£¡£Alchimist¿É±»ÓÃÀ´ÌìÉúºÍÅäÖÃpayload£¬£¬ £¬ £¬£¬£¬À´Ô¶³Ì½ØÆÁ¡¢Ö´ÐÐËÁÒâºÅÁîºÍÔ¶³Ìshellcode£¬£¬ £¬ £¬£¬£¬»¹Ö§³Ö³ÉÁ¢×Ô½ç˵ϰȾ»úÔ죬£¬ £¬ £¬£¬£¬ÔÚÉ豸ÉÏ×°ÖÃInsekt£¬£¬ £¬ £¬£¬£¬²¢Í¨¹ýÌìÉúPowerShellºÍwget´úÂëÆ¬¶ÎÀ´×°ÖÃRATs¡£¡£¡£¡£¡£


https://blog.talosintelligence.com/2022/10/alchimist-offensive-framework.html