Ò½ÁÆ»ú¹¹CHSÒòFortra·ì϶й¶100Íò»¼ÕßµÄÓ×ÎÒÐÅÏ¢
°ä²¼¹¦·ò 2023-02-16
¾Ý2ÔÂ14ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬£¬ÃÀ¹úÒ½ÁÆ»ú¹¹Community Health Systems(CHS)³ÆÆäÊܵ½ÁËÕë¶ÔFortraµÄGoAnywhere MFTƽ̨ÖÐÁãÈÕ·ì϶µÄ¹¥»÷µÄÓ°Ïì¡£¡£¡£¡£¡£¡£¡£¡£Õâ¼ÒÒ½ÁÆ·þÎñ¹«Ë¾ÖÜÒ»°µÊ¾£¬£¬£¬£¬£¬£¬£¬Fortra·¢³ö¾¯±¨³Æ¾ÀúÁËÒ»´Î°²È«ÊÂÎñ£¬£¬£¬£¬£¬£¬£¬µ¼ÖÂCHSµÄ²¿ÃÅÊý¾Ýй¶¡£¡£¡£¡£¡£¡£¡£¡£ËæºóµÄµ÷²éÏÔʾ£¬£¬£¬£¬£¬£¬£¬Õâ´Îй¶ӰÏìÁ˶à´ï100ÍòÃû»¼ÕßµÄÓ×ÎҺͽ¡È«ÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£ClopÍÅ»ïÐû³ÆÊÇÕâ´Î¹¥»÷µÄÄ»ºóºÚÊÖ£¬£¬£¬£¬£¬£¬£¬»¹³ÆÒÑÇÔÈ¡130¶à¸ö×éÖ¯µÄÊý¾Ý¡£¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/healthcare-giant-chs-reports-first-data-breach-in-goanywhere-hacks/
2¡¢Citrix½¨¸´Workspace AppsµÈ²úÆ·ÖеĶà¸ö·ì϶
¾ÝýÌå2ÔÂ15ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬£¬Citrix Systems°ä²¼°²È«¸üУ¬£¬£¬£¬£¬£¬£¬½¨¸´ÆäVirtual Apps and DesktopsºÍWorkspace Apps²úÆ·Öеķì϶¡£¡£¡£¡£¡£¡£¡£¡£ÆäÖÐ×îÑϳÁµÄÊÇȨÏÞÖÎÀí²»µ±·ì϶£¨CVE-2023-24483£©£¬£¬£¬£¬£¬£¬£¬¿É½«È¨ÏÞÌáÉýµ½NT AUTHORITY\SYSTEM¡£¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬»¹Óпɽ«ÈÕÖ¾ÎļþдÈëͨ³£Óû§ÎÞȨдÈëµÄĿ¼µÄ½Ó¼û½ÚÔì²»µ±·ì϶£¨CVE-2023-24484£©£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°µ¼ÖÂȨÏÞÌáÉýµÄ½Ó¼û½ÚÔì²»µ±·ì϶£¨CVE-2023-24485£©ºÍµ¼Ö»ỰÊÕÊܵĽӼû½ÚÔì²»µ±·ì϶£¨CVE-2023-24486£©¡£¡£¡£¡£¡£¡£¡£¡£CISA°ä²¼Á˹ØÓÚ¾¡¿ìÀûÓÃCitrix°²È«¸üеľ¯±¨¡£¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/citrix-fixes-severe-flaws-in-workspace-virtual-apps-and-desktops/
3¡¢CiscoÅû¶·Ö·¢MortalKombatºÍLaplas ClipperµÄ»î¶¯
Cisco TalosÔÚ2ÔÂ14ÈÕÅû¶ÁËһ··Ö·¢ÀÕË÷Èí¼þMortalKombatºÍ¶ñÒâÈí¼þLaplas ClipperµÄ»î¶¯¡£¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±×Ô2022Äê12ÔÂÆðÍ·¹Û²ìµ½Á˸û£¬£¬£¬£¬£¬£¬£¬ÖØÒªÕë¶ÔÃÀ¹ú¡¢Ó¢¹ú¡¢ÍÁ¶úÆäºÍ·ÆÂɱöµÈµØÓò¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷»î¶¯Ê¼ÓÚ´¹µöµç×ÓÓʼþ£¬£¬£¬£¬£¬£¬£¬²¢Æô¶¯¶à½×¶Î¹¥»÷Á´£¬£¬£¬£¬£¬£¬£¬»á·Ö·¢¶ñÒâÈí¼þ»òÀÕË÷Èí¼þ£¬£¬£¬£¬£¬£¬£¬¶øºóɾ³ý¶ñÒâÎļþµÄÖ¤¾Ý£¬£¬£¬£¬£¬£¬£¬¸²¸ÇÆä×ÙÓ°²¢Èƹý¶ÈÎö¡£¡£¡£¡£¡£¡£¡£¡£MortalKombatÊÇXoristµÄÒ»ÖÖ±äÌ壬£¬£¬£¬£¬£¬£¬ÓÚ2023Äê1Ô³õ´Î±»·¢ÏÖ¡£¡£¡£¡£¡£¡£¡£¡£Laplas ClipperÊÇÏà¶Ô½ÏеļôÌù°åÇÔÈ¡·¨Ê½£¬£¬£¬£¬£¬£¬£¬ÓÃÓÚÇÔȡָ±êµÄ¼ÓÃÜÇ®±Ò¡£¡£¡£¡£¡£¡£¡£¡£
https://blog.talosintelligence.com/new-mortalkombat-ransomware-and-laplas-clipper-malware-threats/
4¡¢16¸ö¶ñÒâNPM°ü¼Ù×°³ÉÍøËÙ²âÊÔÆ÷Ö¼ÔÚÍÚ¾ò¼ÓÃÜÇ®±Ò
2ÔÂ14ÈÕ£¬£¬£¬£¬£¬£¬£¬Check Point³ÆÆäÔÚNPMÉϼì²âµ½16¸ö¶ñÒâ°ü¡£¡£¡£¡£¡£¡£¡£¡£ËüÃǼÙ×°³ÉÍøËÙ²âÊÔÆ÷£¬£¬£¬£¬£¬£¬£¬Ö¼ÔÚ½Ù³ÖÖ¸±êµÄÍÆËã»ú×ÊÔ´ÒÔÍÚ¾ò¼ÓÃÜÇ®±Ò¡£¡£¡£¡£¡£¡£¡£¡£ËùÓаü¾ùÓÉÓû§trendavaÉÏ´«µ½NPM£¬£¬£¬£¬£¬£¬£¬Ö»¹ÜËüÃÇÓµÓÐÒ»ÑùµÄÖ¸±ê£¬£¬£¬£¬£¬£¬£¬µ«×êÑÐÈËÔ±·¢ÏÖÿ¸ö°ü¶¼Ñ¡È¡·ÖÆçµÄ±àÂëºÍ²½ÖèÀ´ÊµÏ֯乤×÷¡£¡£¡£¡£¡£¡£¡£¡£¿£¿£¿£¿£Äܹ»ÒÔΪÕâЩ²î¾à´ú±íÁ˹¥»÷ÕßËù×öµÄÊÔÑ飬£¬£¬£¬£¬£¬£¬ËûÊÂÏȲ»ÖªÂ·Äĸö°æ±¾»á±»°²È«¹¤¾ß¼ì²âµ½£¬£¬£¬£¬£¬£¬£¬Òò¶ø³¢ÊÔÓÃ·ÖÆçµÄ·½Ê½À´°µ²Ø¶ñÒâÒâͼ¡£¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±ÓÚ1ÔÂ17ÈÕ·¢ÏÖÁËÕâЩ°ü£¬£¬£¬£¬£¬£¬£¬NPMÓÚ´ÎÈÕɾ³ýÁËËüÃÇ¡£¡£¡£¡£¡£¡£¡£¡£
https://blog.checkpoint.com/2023/02/14/check-point-cloudguard-spectral-detects-malicious-crypto-mining-packages-on-npm-the-leading-registry-for-javascript-open-source-packages/
5¡¢BlackCat³ÆÒÑÇÔÈ¡°®¶ûÀ¼Ã÷Ë¹ÌØ¿Æ¼¼´óѧ6GBµÄÊý¾Ý
ýÌå2ÔÂ14Èճƣ¬£¬£¬£¬£¬£¬£¬BlackCat£¨Ò²³ÆALPHV£©ÔÚÆäÍøÕ¾ÁгöÁË´Ó°®¶ûÀ¼Ã÷Ë¹ÌØ¿Æ¼¼´óѧ(MTU)ÇÔÈ¡µÄ³¬¹ý6 GBµÄÊý¾Ý¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÍÅ»ïÔÚ.onionÍøÕ¾ÉÏÐû³ÆÐ¹Â¶ÐÅÏ¢Ô̺¬Ô±¹¤¼Í¼ºÍ¹¤×ʵ¥¾ßÌåÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬ÕâÁ½¸öÊý¾Ý¼¯¶¼¿ÉÄܵ¼ÖÂڲƺÍɧÈŻ¡£¡£¡£¡£¡£¡£¡£¡£MTUÔøÓÚ2ÔÂ6Èճƣ¬£¬£¬£¬£¬£¬£¬ÓÉÓÚ³Á´óITÎÊÌâºÍµç»°Öжϣ¬£¬£¬£¬£¬£¬£¬ÆäλÓڿƿ˵ÄÐ£Çø¹Ø¹ØÇҿγÌÈ¡µÞ£¬£¬£¬£¬£¬£¬£¬µ«²¢Î´½«Õâ´Î¹¥»÷¹é×ïÓÚÌØ¶¨µÄ¹¥»÷ÍŻ¡£¡£¡£¡£¡£¡£¡£
https://therecord.media/alphv-blackcat-posted-data-ireland-munster-technical-university/
6¡¢Minerva°ä²¼ÇÔÊØÐÅÏ¢µÄ¶ñÒâÈí¼þBeepµÄ·ÖÎö»ã±¨
2ÔÂ13ÈÕ£¬£¬£¬£¬£¬£¬£¬Minerva°ä²¼Á˹ØÓÚÇÔÊØÐÅÏ¢µÄ¶ñÒâÈí¼þBeepµÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£¡£¡£BeepʹÓÃÈý¸ö¶ÀÁ¢µÄ×é¼þ£ºÖ²È뷨ʽ¡¢×¢È뷨ʽºÍpayload¡£¡£¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þËÆºõÈÔÔÚ¿ª·¢ÖУ¬£¬£¬£¬£¬£¬£¬×êÑÐÈËÔ±ÔÚÑù±¾Öз¢ÏÖÁ˺öàÓÉC2ºÅÁî´¥·¢µÄÖ°ÄÜÉÐδʩÐÓ×£¡£¡£¡£¡£¡£¡£¡£BeepÖ®ËùÒÔÍÑÓ±¶ø³ö£¬£¬£¬£¬£¬£¬£¬ÊÇÓÉÓÚÔÚÕû¸öÖ´ÐÐÁ÷³ÌÖÐʹÓÃÁ˶àÖÖ¼¼ÊõÀ´Èƹý°²È«Èí¼þºÍ×êÑÐÈËÔ±µÄ¼ì²âºÍ·ÖÎö£¬£¬£¬£¬£¬£¬£¬Ô̺¬¶¯Ì¬×Ö·û´®È¥»ìºÏ¡¢ÏµÍ³Ëµ»°²é³¡¢IsDebuggerPresent APIº¯ÊýµÄ·¨Ê½¼¯ºÍNtGlobalFlag×ֶη´µ÷ÊԵȡ£¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/new-stealthy-beep-malware-focuses-heavily-on-evading-detection/


¾©¹«Íø°²±¸11010802024551ºÅ