MOVEit Transfer½¨¸´ÆäwebÀûÓÃÖеĶà¸öSQL×¢Èë·ì϶

°ä²¼¹¦·ò 2023-06-12

1¡¢MOVEit Transfer½¨¸´ÆäwebÀûÓÃÖеĶà¸öSQL×¢Èë·ì϶


¾Ý6ÔÂ10ÈÕ±¨Â·£¬ £¬£¬£¬ £¬£¬£¬£¬Progress SoftwareÔÚÆäMOVEit TransferÍйÜÎļþ´«Êä(MFT)½â¾ö¹æ»®ÖÐз¢ÏÖÁ˶à¸öÑϳÁµÄSQL×¢Èë·ì϶¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÄܹ»Í¨¹ýÏòMOVEit TransferÀûÓ÷¨Ê½Ìá½»ÌØÔìµÄpayload£¬ £¬£¬£¬ £¬£¬£¬£¬À´Åú¸ÄºÍй¶MOVEitÊý¾Ý¿âµÄÄÚÈÝ¡£¡£¡£¡£¡£¡£ÕâЩ·ì϶ÊÇͨ¹ý´úÂ밲ȫÉ󼯷¢Ïֵģ¬ £¬£¬£¬ £¬£¬£¬£¬Ó°ÏìÁËËùÓÐMOVEit Transfer°æ±¾£¬ £¬£¬£¬ £¬£¬£¬£¬Ä¿Ç°ÉÐδ·¢ÏÖ±»ÀûÓõļ£Ï󡣡£¡£¡£¡£¡£¸Ã¹«Ë¾ÓÚ6ÔÂ9ÈÕ°ä²¼Á˰²È«²¹¶¡£¡£¡£¡£¡£¡£¬ £¬£¬£¬ £¬£¬£¬£¬²¢°µÊ¾ËùÓÐMOVEit Transfer¿Í»§¶¼±ØÐëÀûÓô˲¹¶¡¡£¡£¡£¡£¡£¡£


https://thehackernews.com/2023/06/new-critical-moveit-transfer-sql.html


2¡¢¶íÂÞË¹ÒøÐÐÓйصĵçÐŹ«Ë¾Infotel JSCÔâµ½´ó¹æÄ£¹¥»÷


¾ÝýÌå6ÔÂ9ÈÕ±¨Â·£¬ £¬£¬£¬ £¬£¬£¬£¬ÎÚ¿ËÀ¼ºÚ¿ÍÍÅ»ïCyber.Anarchy.SquadÐû³Æ¹¥»÷Á˶íÂÞ˹µçÐÅÌṩÉÌInfotel JSC²¢µ¼ÖÂÆäå´»ú¡£¡£¡£¡£¡£¡£InfotelÖØÒªÕÆ¹Ü¶íÂÞ˹ÑëÐÐÓëÆäËü¶íÂÞË¹ÒøÐÓ×¢ÍøÉÏÉ̵êºÍÐÅ´û»ú¹¹Ö®¼äµÄÏνӷþÎñ¡£¡£¡£¡£¡£¡£Infotel JSCй©Õâ´Î´ó¹æÄ£ºÚ¿Í¹¥»÷Ó°ÏìÁËÆä²¿ÃÅÍøÂçÉ豸£¬ £¬£¬£¬ £¬£¬£¬£¬Ä¿Ç°ÔÚÖÂÁ¦¸´Ô­ÊÜÓ°ÏìµÄϵͳ£¬ £¬£¬£¬ £¬£¬£¬£¬ÊµÏÖÈÕÆÚ½«ÁíÐÐ֪ͨ¡£¡£¡£¡£¡£¡£IODA³Æ·þÎñÓÚUTC 6ÔÂ8ÈÕÉÏÎç11:00×óÓÒÖжÏ¡£¡£¡£¡£¡£¡£ºÚ¿Í»¹°ä²¼ÁËInfotelϵͳµÄ½ØÍ¼×÷Ϊ¹¥»÷Ö¤¾Ý£¬ £¬£¬£¬ £¬£¬£¬£¬Ô̺¬ÍøÂç»ù´¡ÉèʩͼºÍ±»ÈëÇÖµç×ÓÓʼþÕÊ»§¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/ukrainian-hackers-take-down-service-provider-for-russian-banks/


3¡¢Ó¢¹úÂü³¹Ë¹ÌØ´óѧÔâµ½¹¥»÷Ô±¹¤ºÍѧÉúÊý¾Ý¿ÉÄÜй¶


ýÌå6ÔÂ9ÈÕ±¨Â·£¬ £¬£¬£¬ £¬£¬£¬£¬Ó¢¹úÂü³¹Ë¹ÌØ´óѧÔâµ½¹¥»÷£¬ £¬£¬£¬ £¬£¬£¬£¬Ô±¹¤ºÍѧÉúµÄÊý¾Ý¿ÉÄÜÒѾ­Ð¹Â¶¡£¡£¡£¡£¡£¡£¸ÃУ³ÆËüÔÚ6ÔÂ6ÈÕ·¢ÏÖÁËÕâÒ»ÎÊÌ⣬ £¬£¬£¬ £¬£¬£¬£¬²¢Á¢¼´·¢Õ¹µ÷²é¡£¡£¡£¡£¡£¡£¾­È·Èϲ¿ÃÅϵͳÒѱ»Î´¾­ÊÚȨµÄµÚÈý·½½Ó¼û£¬ £¬£¬£¬ £¬£¬£¬£¬Êý¾Ý¿ÉÄÜÒѱ»¸´Ôì¡£¡£¡£¡£¡£¡£´Ë±í£¬ £¬£¬£¬ £¬£¬£¬£¬Âü³¹Ë¹ÌØ´óѧ°µÊ¾Õâ´Î°²È«ÊÂÎñÓë×î½üµÄMOVEit TransferÊý¾Ýй¶¹¥»÷ºÍZellisÓйع¥»÷Î޹ء£¡£¡£¡£¡£¡£¸Ã´óѧûÓÐÌṩ¹ØÓÚ¹¥»÷µÄ½øÒ»²½ÐÅÏ¢£¬ £¬£¬£¬ £¬£¬£¬£¬µ«×êÑÐÈËÔ±´ÓÐÂÎÅÆðÔ´»ñϤÕâÊÇһ·ÀÕË÷¹¥»÷¡£¡£¡£¡£¡£¡£


https://securityaffairs.com/147290/data-breach/university-of-manchester-cyber-attack.html


4¡¢Elastic·¢ÏÖÖØÒªÕë¶ÔÔ½ÄÏÆóÒµµÄкóÃÅSPECTRALVIPER 


ElasticÔÚ6ÔÂ9ÈÕ³ÆÆä·¢ÏÖÁËÒ»¸öÐÂÐͺóÃÅSPECTRALVIPER£¬ £¬£¬£¬ £¬£¬£¬£¬ÖØÒªÓÃÓÚÕë¶ÔÔ½ÄÏÉÏÊй«Ë¾µÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£¡£PECTRALVIPERÊÇÒ»¸ö»ìºÏµÄx64ºóÃÅ£¬ £¬£¬£¬ £¬£¬£¬£¬ËüÓµÓÐPE¼ÓÔØºÍ×¢Èë¡¢ÎļþÉÏ´«ºÍÏÂÔØ¡¢ÎļþºÍĿ¼½ÚÔìÒÔ¼°ÁîÅÆÄ£ÄâÖ°ÄÜ¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±½«¸Ã»î¶¯¹éÒòÓÚÔ½ÄϵĹ¥»÷ÍÅ»ïREF2754¡£¡£¡£¡£¡£¡£×îÐÂϰȾÁ´ÖУ¬ £¬£¬£¬ £¬£¬£¬£¬ÀûÓÃÁËSysInternals ProcDumpʵÓ÷¨Ê½¼ÓÔØÔ̺¬DONUTLOADERµÄδÊðÃûDLLÎļþ£¬ £¬£¬£¬ £¬£¬£¬£¬¶øºóÕßÓÖ±»ÅäÖÃΪ¼ÓÔØSPECTRALVIPERºÍÆäËü¶ñÒâÈí¼þ£¬ £¬£¬£¬ £¬£¬£¬£¬ÀýÈçP8LOADER»òPOWERSEAL¡£¡£¡£¡£¡£¡£


https://www.elastic.co/cn/security-labs/elastic-charms-spectralviper


5¡¢Sorgu Paneli¿É¹«¿ª¼ìË÷Ô¼8500ÍòÍÁ¶úÆä¾ÓÃñµÄÐÅÏ¢


6ÔÂ10ÈÕ±¨Â·£¬ £¬£¬£¬ £¬£¬£¬£¬8500ÍòÍÁ¶úÆä¾ÓÃñµÄÃô¸ÐÐÅϢй¶¡£¡£¡£¡£¡£¡£ÍÁ¶úÆäµÄƽ̨Free Web TurkeyÆØ¹âÁËÒ»¸öÃûΪSorgu PaneliµÄÍøÕ¾£¬ £¬£¬£¬ £¬£¬£¬£¬¿É²»ÊÜÏ޶ȵؽӼûÓ×ÎÒÐÅÏ¢£¬ £¬£¬£¬ £¬£¬£¬£¬ÀýÈçÉí·ÝÖ¤ºÅÂë¡¢ÐÕÃû¡¢µØÖ·¡¢µç»°ºÅÂëÉõÖÁÒøÐÐÕË»§¾ßÌåÐÅÏ¢£¬ £¬£¬£¬ £¬£¬£¬£¬ÒÔ»»È¡Ãâ·Ñ»áÔ±×ʸñ¡£¡£¡£¡£¡£¡£¸¶·Ñ»áÔ±Äܹ»»ñµÃ¸ü¶àÐÅÏ¢£¬ £¬£¬£¬ £¬£¬£¬£¬ÀýÈç·¿Æõ¡£¡£¡£¡£¡£¡£¸ÃÍøÕ¾ÔÚÓòÃûSorgu.liveÏÂÔËÓª£¬ £¬£¬£¬ £¬£¬£¬£¬Ä¿Ç°¹²ÓÐ5195ÃûÓû§£¬ £¬£¬£¬ £¬£¬£¬£¬²¢ÔÚTelegramºÍDiscordÉÏÌṩÀàËÆµÄ·þÎñ¡£¡£¡£¡£¡£¡£¾Ý¹À¼Æ£¬ £¬£¬£¬ £¬£¬£¬£¬Ô¼ÓÐ8500ÍòÍÁ¶úÆä¹«ÃñµÄÐÅÏ¢Êܵ½Ó°Ïì¡£¡£¡£¡£¡£¡£


https://medyanews.net/website-leak-exposes-sensitive-data-of-85-million-turkish-residents-report/


6¡¢Check Point¹«¿ªÀûÓÃStealth Soldier¹¥»÷±±·ÇµÄ»î¶¯


6ÔÂ8ÈÕ£¬ £¬£¬£¬ £¬£¬£¬£¬Check Point¹«¿ªÁËһ·Õë¶ÔÐÔºÜÇ¿µÄ¼äµý¹¥»÷£¬ £¬£¬£¬ £¬£¬£¬£¬ÀûÓÃÁËÐµĶ¨ÔìÄ £¿ £¿£¿£¿£¿£¿ £¿£¿é»¯ºóÃÅStealth Soldier¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þÖØÒªÔËÐмලְÄÜ£¬ £¬£¬£¬ £¬£¬£¬£¬ÀýÈçÎļþй¶¡¢ÆÁÄ»ºÍÂó¿Ë·ç¼Ôì¡¢¼üÅ̼ͼºÍÇÔÈ¡ä¯ÀÀÆ÷ÐÅÏ¢¡£¡£¡£¡£¡£¡£Stealth SoldierÓëThe Eye on the NileµÄ»ù´¡ÉèÊ©Óв¿ÃųÁµþ£¬ £¬£¬£¬ £¬£¬£¬£¬¹¥»÷ÕßʹÓÃÁ˼Ù×°³ÉÀû±ÈÑÇ±í½»²¿ÍøÕ¾µÄC2Óò¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±³Æ£¬ £¬£¬£¬ £¬£¬£¬£¬Ï°È¾Á´´ÓºÜ¸´ÔÓ£¬ £¬£¬£¬ £¬£¬£¬£¬Éæ¼°´ÓC&C·þÎñÆ÷ÏÂÔØµÄÁù¸öÎļþ£¬ £¬£¬£¬ £¬£¬£¬£¬Ô̺¬Loader( MSDataV5.16945.exe)¡¢Watchdog(MSCheck.exe)ºÍPayload(MShc.txt)µÈ¡£¡£¡£¡£¡£¡£


https://research.checkpoint.com/2023/stealth-soldier-backdoor-used-in-targeted-espionage-attacks-in-north-africa/