ConnectWise½¨¸´¿ÉÓ°ÏìÊýǧ̨·þÎñÆ÷µÄRCE·ì϶

°ä²¼¹¦·ò 2022-11-01

1¡¢ConnectWise½¨¸´¿ÉÓ°ÏìÊýǧ̨·þÎñÆ÷µÄRCE·ì϶

      

ýÌå10ÔÂ28Èճƣ¬£¬£¬ £¬ £¬£¬£¬£¬ConnectWiseÒѰ䲼°²È«¸üУ¬£¬£¬ £¬ £¬£¬£¬£¬½¨¸´ÁËConnectWise RecoverºÍR1Soft Server Backup Manager(SBM)°²È«±¸·Ý½â¾ö¹æ»®Öеķì϶¡£¡£¡£¡£¡£¡£¸Ã·ì϶ÊÇÏÂÓÎ×é¼þʹÓõÄÊä³öÖÐÌØÊâÔªËØµÄÖкͲ»µ±ÎÊÌ⣬£¬£¬ £¬ £¬£¬£¬£¬¿É±»¹¥»÷ÕßÓÃÀ´½Ó¼û»úÃÜÊý¾Ý»òÔ¶³ÌÖ´ÐдúÂë¡£¡£¡£¡£¡£¡£Æ¾¾ÝShodanɨÃ裬£¬£¬ £¬ £¬£¬£¬£¬³¬¹ý4800̨R1Soft·þÎñÆ÷¿ÉÄÜ»áÔâµ½´ËÀ๥»÷¡£¡£¡£¡£¡£¡£¸Ã·ì϶±»ÏóÕ÷Ϊ¸ßÓÅÏȼ¶£¬£¬£¬ £¬ £¬£¬£¬£¬¼´ÔÚ¹¥»÷Öб»ÀûÓõķçÏպܸߡ£¡£¡£¡£¡£¡£¸Ã¹«Ë¾³Æ£¬£¬£¬ £¬ £¬£¬£¬£¬ÊÜÓ°ÏìµÄConnectWise Recover sbmÒÑ×Ô¶¯¸üе½×îа汾(v2.9.9)¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/connectwise-fixes-rce-bug-exposing-thousands-of-servers-to-attacks/


2¡¢Ó¢¹úǰÊ×ÏàLiz TrussµÄÊÖ»ú¾Ý³Æ±»ÍøÂç¼äµýÈëÇÖ

      

¾ÝÓ¢¹ú¡¶ÖðÈÕÓʱ¨¡·10ÔÂ29ÈÕ±¨Â·£¬£¬£¬ £¬ £¬£¬£¬£¬Ó¢¹úǰÊ×ÏàÀû×È¡¤ÌØÀ­Ë¹£¨Liz Truss£©µÄ¸öÈËÊÖ»úÔâµ½ÒÉËÆÀ´×Ô¶íÂÞ˹µÄÈëÇÖ¡£¡£¡£¡£¡£¡£¾ÝϤ£¬£¬£¬ £¬ £¬£¬£¬£¬¹¥»÷ÕßÒѾ­»ñµÃÁËÓëÖØÒª¹ú¼ÊºÏ×÷ͬ°éµÄ¾øÃÜ»¥»»£¬£¬£¬ £¬ £¬£¬£¬£¬ÒÔ¼°ÓëËýµÄÖØÒªÕþÖÎÃËÓÑ¿äÎ÷¡¤¿ËÎÖëøµÄ¸öÈË·¢ÑÔ¡£¡£¡£¡£¡£¡£ÓÐÐÂÎųƣ¬£¬£¬ £¬ £¬£¬£¬£¬¸ÃÊÖ»úÒѱ»ÑϳÁ°Ü»µ£¬£¬£¬ £¬ £¬£¬£¬£¬Ä¿Ç°¸éÖÃÔÚµ±¾Ö°²È«µãµÄÒ»¸ö±£ÏÕÏäÖÓ×£¡£¡£¡£¡£¡£¹¥»÷ÕßÔÚÏļ¾Êؾɵ³¸¨µ¼¾ºÑ¡ÆÚ¼äÈëÇÖÁËÌØÀ­Ë¹µÄÊÖ»ú£¬£¬£¬ £¬ £¬£¬£¬£¬ÆäʱµÄÊ×Ï౫Àï˹¡¤Ô¼º²Ñ·ºÍÄÚ¸óÃØÊéÎ÷ÃÉ¡¤¿­Ë¹¾ö¶¨È«Ãæ¹Ø±Õ¸ÃÊÂÎñ¡£¡£¡£¡£¡£¡£¡¶ÐÇÆÚÈÕÓʱ¨¡·Ð¹Â©£¬£¬£¬ £¬ £¬£¬£¬£¬ÌØÀ­Ë¹¼°25λÄڸ󲿳¤µÄÊÖ»úºÅÂëһ·ÔÚÍøÉÏÏúÊÛ£¬£¬£¬ £¬ £¬£¬£¬£¬ÊÛ¼Û½öΪ6.49Ó¢°÷¡£¡£¡£¡£¡£¡£


https://securityaffairs.co/wordpress/137826/intelligence/liz-truss-phone-hacked.html


3¡¢AndroidľÂíDrinikбäÌå¹¥»÷Ó¡¶ÈµÄ18¼Ò½ðÈÚ»ú¹¹

      

CybleÔÚ10ÔÂ27ÈÕ³ÆÆä·¢ÏÖDrinikµÄбäÌåÕë¶ÔÓ¡¶ÈµÄ18¼Ò½ðÈÚ»ú¹¹¡£¡£¡£¡£¡£¡£2016Ä꣬£¬£¬ £¬ £¬£¬£¬£¬Drinik¶ñÒâÈí¼þµÄÔçÆÚ±äÖÖ³õ´Î±»·¢ÏÖÊÇSMSÇÔÈ¡·¨Ê½£¬£¬£¬ £¬ £¬£¬£¬£¬Ô¼ÄªÔÚ2021Äê8ÔÂÆäÔٴλîÔ¾£¬£¬£¬ £¬ £¬£¬£¬£¬ÕâÒ»´ÎÑݱäΪAndroidÒøÐÐľÂí¡£¡£¡£¡£¡£¡£×îа汾µÄ¶ñÒâÈí¼þ¼Ù×°³ÉÃûΪiAssistµÄAPK£¬£¬£¬ £¬ £¬£¬£¬£¬Ðû³ÆÊÇÓ¡¶È˰Îñ²¿ÃŵĹٷ½Ë°ÎñÖÎÀí¹¤¾ß¡£¡£¡£¡£¡£¡£×îÖջὫָ±ê³Á¶¨Ïòµ½´¹µöÍøÕ¾£¬£¬£¬ £¬ £¬£¬£¬£¬²¢ÓÕʹËûÃÇÊäÈë²ÆÕþÐÅÏ¢£¬£¬£¬ £¬ £¬£¬£¬£¬ÈçÕʺš¢ÐÅÓþ¿¨ºÅ¡¢CVVºÍPINµÈ¡£¡£¡£¡£¡£¡£


https://blog.cyble.com/2022/10/27/drinik-malware-returns-with-advanced-capabilities-targeting-indian-taxpayers/


4¡¢BlackByteÐû³ÆÒѹ¥»÷Asahi Group²¢ÀÕË÷60ÍòÃÀÔª

      

¾Ý10ÔÂ30ÈÕ±¨Â·£¬£¬£¬ £¬ £¬£¬£¬£¬ÀÕË÷ÍÅ»ïBlackByteÐû³ÆÒÑÈëÇÖÁ˾«ÃܽðÊôÔì×÷ºÍ½ðÊô½â¾ö¹æ»®ÌṩÉÌAsahi Group Holdings¡£¡£¡£¡£¡£¡£BlackByte°µÊ¾ÒѴӸù«Ë¾ÇÔÈ¡ÁËÊýǧÕ××Ö½ÚµÄÎļþ£¬£¬£¬ £¬ £¬£¬£¬£¬Ô̺¬²ÆÕþºÍÏúÊۻ㱨¡£¡£¡£¡£¡£¡£¸ÃÍÅ»ïÒªÇó50ÍòÃÀÔª²É°ìÊý¾Ý£¬£¬£¬ £¬ £¬£¬£¬£¬²¢ÒªÇó60ÍòÃÀԪɾ³ý±»µÁÊý¾Ý¡£¡£¡£¡£¡£¡£BlackByte×Ô2021Äê9ÔÂÒÔÀ´Ò»Ïò»îÔ¾£¬£¬£¬ £¬ £¬£¬£¬£¬FBIÔÚ2Ô·Ýй©¸ÃÍÅ»ïÒÑÈëÇÖÁËÃÀ¹úÖÁÉÙ3¸öÉæ¼°¹Ø¼ü»ù´¡ÉèÊ©ÁìÓòµÄ×éÖ¯¡£¡£¡£¡£¡£¡£


https://securityaffairs.co/wordpress/137803/cyber-crime/blackbyte-ransomware-asahi-group-holdings.html


5¡¢Î¢Èí°ä²¼¹ØÓÚRaspberry RobinÈ䳿µÄ·ÖÎö»ã±¨

      

΢ÈíÔÚ10ÔÂ27ÈÕ°ä²¼Á˹ØÓÚRaspberry RobinÈ䳿µÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£Î¢Èí°µÊ¾£¬£¬£¬ £¬ £¬£¬£¬£¬±»×·×ÙΪDEV-0950µÄ×é֯ʹÓÃClopÀÕË÷Èí¼þÀ´¼ÓÃÜÏÈǰϰȾÁËRaspberry RobinÈ䳿µÄÍøÂ磬£¬£¬ £¬ £¬£¬£¬£¬DEV-0950µÄ»î¶¯ÓëFIN11ºÍTA505ÍÅ»ï³Áµþ¡£¡£¡£¡£¡£¡£³ýÁËÀÕË÷Èí¼þ£¬£¬£¬ £¬ £¬£¬£¬£¬Raspberry Robin»¹±»ÓÃÓÚ½«×°ÖÃÆäËüµÚ¶þ½×¶Îpayload£¬£¬£¬ £¬ £¬£¬£¬£¬Ô̺¬IcedID¡¢BumblebeeºÍTruebot¡£¡£¡£¡£¡£¡£Î¢Èí»¹Ö¸³ö£¬£¬£¬ £¬ £¬£¬£¬£¬Ô¼1000¸ö×éÖ¯µÄ½ü3000̨É豸ÔÚ´Óǰ30ÌìÄÚ³öÏÖÁËÖÁÉÙÒ»´ÎÓëRaspberry Robin payloadÓйصľ¯±¨¡£¡£¡£¡£¡£¡£


https://www.microsoft.com/en-us/security/blog/2022/10/27/raspberry-robin-worm-part-of-larger-ecosystem-facilitating-pre-ransomware-activity/


6¡¢NSAµÈ»ú¹¹°ä²¼Èí¼þ¹©¸øÉÌÈôºÎ±£»£»£»£» £»£»£»£»¤¹©¸øÁ´°²È«µÄÖ¸ÄÏ

      

¾ÝýÌå10ÔÂ31ÈÕ±¨Â·£¬£¬£¬ £¬ £¬£¬£¬£¬NSA¡¢CISAºÍ¹ú¶Èµý±¨×ܼà°ì¹«ÊÒ(ODNI)°ä²¼¹ØÓÚÈí¼þ¹©¸øÉÌÈôºÎ±£»£»£»£» £»£»£»£»¤¹©¸øÁ´°²È«µÄÖ¸ÄÏ£¬£¬£¬ £¬ £¬£¬£¬£¬Ô̺¬°²È«ÐèÒª¹æ»®ºÍÈí¼þ°²È«ÊØ»¤¡£¡£¡£¡£¡£¡£Èí¼þ¹©¸øÉÌÕÆ¹ÜÁªÏµ¿Í»§ºÍÈí¼þ¿ª·¢ÈËÔ±£¬£¬£¬ £¬ £¬£¬£¬£¬Í¨Äܹ»Í¨¹ýºÏͬºÍ̸¡¢Èí¼þ°ä²¼ºÍ¸üС¢Í¨ÖªºÍ·ì϶»º½âµÈ·½Ê½ÀûÓöî±íµÄ°²È«Ö°ÄÜ¡£¡£¡£¡£¡£¡£¸ÃÖ¸ÄÏÊÇÔÚ×î½üÂŴα¸ÊÜÖõÖ÷ÕÅÍøÂç¹¥»÷Ö®ºó°ä²¼µÄ£¬£¬£¬ £¬ £¬£¬£¬£¬ÕâЩ¹¥»÷͹ÏÔÁ˹ú¶ÈÖ§³ÖµÄ¹¥»÷ÕßÄܹ»ÇáËɵØÀûÓÃÈí¼þ¹©¸øÁ´Öеķì϶¡£¡£¡£¡£¡£¡£


https://media.defense.gov/2022/Oct/31/2003105368/-1/-1/0/SECURING_THE_SOFTWARE_SUPPLY_CHAIN_SUPPLIERS.PDF