º«¹úÒÆ¶¯ÔËÓªÉÌLG UplusÊý¾Ýй¶ӰÏìÔ¼29ÍòÓû§

°ä²¼¹¦·ò 2023-02-07
1¡¢º«¹úÒÆ¶¯ÔËÓªÉÌLG UplusÊý¾Ýй¶ӰÏìÔ¼29ÍòÓû§

      

¾Ýº«ÁªÉç2ÔÂ3ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬LG UplusÉϸöÔµÄÊý¾Ýй¶ÊÂÎñ¹²Ó°ÏìÁË290000¸öÓû§¡£¡£¡£ ¡£¡£1ÔÂ10ÈÕ£¬£¬£¬£¬£¬£¬¸ÃÒÆ¶¯ÔËÓªÉÌÔøÐ¹Â©180000¸ö¿Í»§ÐÅϢй¶£¬£¬£¬£¬£¬£¬Ô̺¬ÐÕÃû¡¢µ®ÉúÈÕÆÚºÍµç»°ºÅÂëµÈ£¬£¬£¬£¬£¬£¬µ«²»Éæ¼°²ÆÕþÐÅÏ¢¡£¡£¡£ ¡£¡£ÉÏÖÜÎ壬£¬£¬£¬£¬£¬¸Ã¹«Ë¾ÔÚÆäÍøÕ¾ÉϰµÊ¾£¬£¬£¬£¬£¬£¬·¢ÏÖÁËÁí±í110000¸öÒÑÖÕÖ¹¶©ÔĵĿͻ§µÄÊý¾ÝÒ²Êܵ½ÁËÓ°Ïì¡£¡£¡£ ¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬£¬LG UplusÔÚ»ý¼«¹²Í¬µ±¾ÖµÄµ÷²é£¬£¬£¬£¬£¬£¬ÒÔÈ·¶¨ÕâЩÊý¾ÝÊǺÎʱÒÔ¼°ÈôºÎй¶µÄ¡£¡£¡£ ¡£¡£


https://en.yna.co.kr/view/AEN20230203008600325


2¡¢×êÑÐÈËԱй©GoAnywhere MFTÖеÄRCE·ì϶Õý±»ÀûÓÃ

      

¾Ý2ÔÂ4ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬FortraµÄGoAnywhere MFTÎļþ´«ÊäÀûÓÃÖеÄ0 dayÔÚ±»»ý¼«ÀûÓᣡ£¡£ ¡£¡£×êÑÐÈËÔ±Brian Krebsй©ÕâÊÇÒ»¸öÔ¶³Ì´úÂë×¢Èë·ì϶£¬£¬£¬£¬£¬£¬¹¥»÷Õß±ØÒª½Ó¼ûÖÎÀí½ÚÔį̀ÄÜÁ¦ÀûÓø÷ì϶¡£¡£¡£ ¡£¡£Òò¶ø±ØÐëÈ·±£ÏµÍ³²»ÔÚ¹«¹²ÍøÂçÉÏ£¬£¬£¬£¬£¬£¬µ«×êÑÐÈËÔ±·¢ÏÖÁË1008̨GoAnywhereÊ·ý¶³öÔÚ»¥ÁªÍøÉÏ£¬£¬£¬£¬£¬£¬ÖØÒªÎ»ÓÚÃÀ¹ú£¬£¬£¬£¬£¬£¬ÆäÖдó²¿ÃÅʹÓÃÁ˶˿Ú8000ºÍ8001¡£¡£¡£ ¡£¡£Ä¿Ç°Ã»ÓÐÕë¶Ô¸Ã·ì϶µÄ²¹¶¡£¡£¡£ ¡£¡£¬£¬£¬£¬£¬£¬µ«FortraÌṩÁË»º½â´ëÊ©¡£¡£¡£ ¡£¡£


https://thehackernews.com/2023/02/warning-hackers-actively-exploiting.html


3¡¢ÃÀ¹ú¸¥ÂÞÀï´ïTMHÒ½ÔºÔÚÔâµ½ÍøÂç¹¥»÷ºóITϵͳ¹Ø¹Ø

      

¾ÝýÌå2ÔÂ3ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬·ðÂÞÀï´ïÖÝÒ½ÔºTallahassee Memorial HealthCare(TMH)Ôâµ½ÁËÍøÂç¹¥»÷¡£¡£¡£ ¡£¡£¹¥»÷²úÉúÔÚÉÏÖÜËÄ£¬£¬£¬£¬£¬£¬ÔÚ·¢ÏÖ°²È«ÎÊÌâºóÒ½ÔºÁ¢¿Ì¹Ø¹ØÁËÆäITϵͳÒÔ¼õÇáÓ°Ï죬£¬£¬£¬£¬£¬²¢½«±ØÒª´¹Î£Ò½ÁÆ·þÎñ(EMS)µÄ»¼Õß×ªÒÆµ½ÆäËüÒ½Ôº¡£¡£¡£ ¡£¡£TMHй©£¬£¬£¬£¬£¬£¬ËûÃÇÔÚÉó²éÿһ¸öITϵͳ£¬£¬£¬£¬£¬£¬È·¶¨ËüÃǵÄÓÅÏÈÖÈÐò£¬£¬£¬£¬£¬£¬²¢Ê¹ËüÃÇÖðÒ»¸´Ô­ÔÚÏß¡£¡£¡£ ¡£¡£¾Ý±¾µØÃ½Ì屨·£¬£¬£¬£¬£¬£¬ÕâÒÉËÆÊÇһ·ÀÕË÷¹¥»÷ÊÂÎñ¡£¡£¡£ ¡£¡£


https://www.bleepingcomputer.com/news/security/florida-hospital-takes-it-systems-offline-after-cyberattack/


4¡¢TrendMicro·¢ÏÖ¶ñÒâÈí¼þTgToxicÕë¶Ô¶«ÄÏÑǵĹ¥»÷

      

Trend MicroÔÚ2ÔÂ3ÈÕÅû¶Á˶ñÒâÈí¼þTgToxicÕë¶Ô¶«ÄÏÑǵĹ¥»÷¡£¡£¡£ ¡£¡£¸Ã»î¶¯Ê¼ÓÚ2022Äê7Ô£¬£¬£¬£¬£¬£¬ÖØÒªÕë¶Ǫ̂Í塢̩¹úºÍÓ¡¶ÈÄáÎ÷ÑǵÄAndroidÓû§¡£¡£¡£ ¡£¡£¹¥»÷Õßͨ¹ý½«ÒøÐÐľÂíTgToxicǶÈë¶à¸öÐéαÀûÓ÷¨Ê½£¬£¬£¬£¬£¬£¬À´´Ó½ðÈÚºÍÒøÐÐÀûÓ÷¨Ê½ÖÐÇÔȡָ±êµÄ×ʲú¡£¡£¡£ ¡£¡£TgToxicʹÓÃÁ½ÖÖ²½ÖèÀ´Èƹý¼ì²âºÍ·ÖÎö£¬£¬£¬£¬£¬£¬±ðÀëΪ´úÂë»ìºÏºÍpayload¼ÓÃÜ¡£¡£¡£ ¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬TgToxicÄܹ»½Ù³ÖϵͳÀûÓÃ×Ô¶¯ÊÚÓè×Ô¼ºÈ¨ÏÞ£¬£¬£¬£¬£¬£¬²¢ÔÚÖ¸±ê³¢ÊÔÐ¶ÔØ¶ñÒâÈí¼þʱ×èÖ¹Ð¶ÔØ¡£¡£¡£ ¡£¡£


https://www.trendmicro.com/en_us/research/23/b/tgtoxic-malware-targets-southeast-asia-android-users.html


5¡¢Î¢Èí³Æ·¨¹ú²éÀíÖÜ¿¯Ôâµ½µÄ¹¥»÷ÓëNEPTUNIUMÍÅ»ïÓйØ

      

ýÌå2ÔÂ5ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬Î¢Èíй©·¨¹ú²éÀíÖÜ¿¯£¨Charlie Hebdo£©Ôâµ½µÄ¹¥»÷ÓëÒÁÀÊNEPTUNIUMÍÅ»ïÓйØ¡£¡£¡£ ¡£¡£1Ô³õ£¬£¬£¬£¬£¬£¬×Ô³ÆHoly SoulsµÄ¹¥»÷ÕßÐû³ÆÈëÇÖÁ˸ÃÔÓÖ¾µÄÊý¾Ý¿â²¢»ñµÃÁ˳¬¹ý200000Ãû¿Í»§µÄÐÅÏ¢£¬£¬£¬£¬£¬£¬»¹°ä²¼ÁËÒ»¸öÑù±¾×÷ΪÈëÇÖÖ¤¾Ý¡£¡£¡£ ¡£¡£Ö®ºó£¬£¬£¬£¬£¬£¬Holy SoulsÒÔ20 BTC£¨Ô¼ºÏ340000ÃÀÔª£©µÄ¼ÛÖµÏúÊÛ´óÁ¿Êý¾Ý¡£¡£¡£ ¡£¡£·¨¹ú¡¶ÊÀ½ç±¨¡·Ö¤ÊµÁËй¶Êý¾ÝµÄÕæÊµÐÔ¡£¡£¡£ ¡£¡£Î¢Èí»ùÓÚ´óÁ¿µÄ¿ÉÓõý±¨£¬£¬£¬£¬£¬£¬½«Õâ´Î¹¥»÷»î¶¯¹éÒòÓÚNEPTUNIUM£¬£¬£¬£¬£¬£¬²éÀíÖÜ¿¯ÉÐδ¶Ô΢ÈíµÄµ÷²éÁ˾ְ䷢ÆÀÂÛ¡£¡£¡£ ¡£¡£


https://securityaffairs.com/141855/apt/charlie-hebdo-data-leak-iran.html


6¡¢WithSecure°ä²¼LazarusÕë¶ÔZimbraÉ豸µÄ·ÖÎö»ã±¨

      

WithSecureÔÚ2ÔÂ2ÈÕ°ä²¼Á˹ØÓÚLazarusÀûÓÃ佨¸´ZimbraÉ豸µÄ¹¥»÷»î¶¯µÄ»ã±¨¡£¡£¡£ ¡£¡£¸Ã»î¶¯±»¶¨ÃûΪNo Pineapple£¬£¬£¬£¬£¬£¬ÖØÒªÕë¶Ô×êÑлú¹¹¡¢Ò½Ñ§ºÍÄÜÔ´ÐÐÒµ×éÖ¯¼°Æä¹©¸øÁ´¡£¡£¡£ ¡£¡£ÓÃÓÚ³õʼ½Ó¼ûµÄ·ì϶ÊÇCVE-2022-27925ºÍCVE-2022-37042£¬£¬£¬£¬£¬£¬ËüÃǶ¼¿ÉÓÃÀ´Ôڵײã·þÎñÆ÷ÉÏÔ¶³ÌÖ´ÐдúÂë¡£¡£¡£ ¡£¡£¹¥»÷ÕßʹÓÃÏֳɵÄwebshellºÍ×Ô½ç˵¶þ½øÔìÎļþ£¬£¬£¬£¬£¬£¬ÒÔ¼°ÀûÓúϷ¨µÄWindowsºÍUnix¹¤¾ß¡£¡£¡£ ¡£¡£×îÖÕ£¬£¬£¬£¬£¬£¬¹¥»÷Õß×°ÖÃÁËDtrackºÍ¸üа汾µÄGREASEµÈºóÃÅ¡£¡£¡£ ¡£¡£ 


https://labs.withsecure.com/publications/no-pineapple-dprk-targeting-of-medical-research-and-technology-sector