̨»ýµçй©Æä¹©¸øÉÌÔâµ½¹¥»÷±»LockBitÀÕË÷7000ÍòÃÀÔª
°ä²¼¹¦·ò 2023-07-031¡¢Ì¨»ýµçй©Æä¹©¸øÉÌÔâµ½¹¥»÷±»LockBitÀÕË÷7000ÍòÃÀÔª
¾ÝýÌå7ÔÂ1ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬£¬£¬LockBitÐû³ÆÒÑÈëÇÖÖйų́ÍåоƬÔì×÷ÉĮ̀»ýµç(TSMC)£¬£¬£¬£¬£¬£¬£¬£¬²¢ÀÕË÷7000ÍòÃÀÔªÊê½ð¡£¡£¡£¡£¡£¡£Ì¨»ýµçÊÇÈ«Çò×î´óµÄоƬºÏÔ¼Ôì×÷ÉÌ£¬£¬£¬£¬£¬£¬£¬£¬ÎªÆ»¹ûºÍ¸ßͨµÈ¿Æ¼¼¾ÞÍ·ÌṩоƬ¡£¡£¡£¡£¡£¡£Ì¨»ýµç·ñ¶¨ÆäÔâµ½ºÚ¿Í¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬²¢°µÊ¾ÊÇËûÃǵÄITÓ²¼þ¹©¸øÉÌÖ®Ò»Kinmax TechnologyµÄϵͳÔâµ½¹¥»÷¡£¡£¡£¡£¡£¡£Kinmaxй©ËüÓÚ6ÔÂ29ÈÕÒâʶµ½¹¥»÷»î¶¯£¬£¬£¬£¬£¬£¬£¬£¬²¿ÃÅÐÅϢй¶£¬£¬£¬£¬£¬£¬£¬£¬ÖØÒªÉæ¼°¿Í»§µÄϵͳװÖúÍÅäÖÃÁìµ¼¡£¡£¡£¡£¡£¡£ÓÉÓÚKinmax²¢²»ÊÇ̨»ýµçÄÇÑùµÄ¾ÞÍ·£¬£¬£¬£¬£¬£¬£¬£¬Òò¶øLockBit 7000ÍòÃÀÔªÊê½ðµÄÒªÇó¿ÉÄܻᱻºöÂÔ¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/tsmc-denies-lockbit-hack-as-ransomware-gang-demands-70-million/
2¡¢Avast°ä²¼Windows°æ±¾µÄAkiraÀÕË÷Èí¼þÃâ·Ñ½âÃÜÆ÷
¾Ý7ÔÂ1ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬£¬£¬°²È«¹«Ë¾Avast°ä²¼ÁËAkiraÀÕË÷Èí¼þµÄÃâ·Ñ½âÃÜÆ÷£¬£¬£¬£¬£¬£¬£¬£¬ÎÞÐèÖ§¸¶Êê½ð¼´¿É¸´ÔÊý¾Ý¡£¡£¡£¡£¡£¡£AkiraÓÚ3Ô³õ´Î³öÏÖ £¬£¬£¬£¬£¬£¬£¬£¬²¢ÒòÕë¶ÔÈ«Çò¸÷¸öÁìÓòµÄ×éÖ¯¶øÃûÉù´óÔë¡£¡£¡£¡£¡£¡£6Ô£¬£¬£¬£¬£¬£¬£¬£¬AkiraÆðÍ··Ö·¢ÆäÕë¶ÔVMware ESXiÐé¹¹»úµÄLinux±äÌå¡£¡£¡£¡£¡£¡£Avast°ä²¼ÁËÁ½¸ö°æ±¾µÄAkira½âÃÜÆ÷£¬£¬£¬£¬£¬£¬£¬£¬Ò»ÖÖºÏÓÃÓÚ64λWindows¼Ü¹¹£¬£¬£¬£¬£¬£¬£¬£¬ÁíÒ»¸öºÏÓÃÓÚ32λ¡£¡£¡£¡£¡£¡£Ëü½¨ÒéʹÓÃ64λ°æ±¾£¬£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚÆÆ½âÃÜÂë±ØÒª´óÁ¿µÄϵͳÄÚ´æ¡£¡£¡£¡£¡£¡£¸Ã°²È«¹«Ë¾Ã»ÓÐÚ¹ÊÍËüÊÇÈôºÎÆÆ½âAkiraµÄ£¬£¬£¬£¬£¬£¬£¬£¬µ«¿ÉÄÜÀûÓÃÁËÀÕË÷Èí¼þµÄ²¿ÃÅÎļþ¼ÓÃܲ½Öè¡£¡£¡£¡£¡£¡£
https://securityaffairs.com/148007/cyber-crime/akira-ransomware-decryptor.html
3¡¢×êÑÐÈËÔ±·¢ÏÖÀûÓÃWP²å¼þUltimate Member·ì϶µÄ¹¥»÷
ýÌå7ÔÂ2Èճƣ¬£¬£¬£¬£¬£¬£¬£¬×êÑÐÈËÔ±·¢ÏÖÀûÓÃWordPress²å¼þUltimate MemberÖеķì϶µÄ¹¥»÷»î¶¯£¬£¬£¬£¬£¬£¬£¬£¬¸Ã²å¼þÒѱ»×°Öó¬¹ý200000´Î¡£¡£¡£¡£¡£¡£·ì϶׷×ÙΪCVE-2023-3460£¬£¬£¬£¬£¬£¬£¬£¬CVSSÆÀ·Ö9.8£¬£¬£¬£¬£¬£¬£¬£¬Ó°ÏìÁËÔ̺¬×îа汾v2.6.6ÔÚÄÚµÄËùÓÐUltimate Member°æ±¾¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÄܹ»ÀûÓô˷ì϶´´½¨ÓµÓÐÖÎÀíȨÏÞµÄÐÂÓû§ÕÊ»§£¬£¬£¬£¬£¬£¬£¬£¬´Ó¶øÆëÈ«½ÚÔìÍøÕ¾¡£¡£¡£¡£¡£¡£ÓÉÓڸ÷ì϶ÉÐ佨¸´ÇÒºÜÈÝÒ×±»ÀûÓ㬣¬£¬£¬£¬£¬£¬£¬×êÑÐÈËÔ±½¨ÒéÁ¢¼´Ð¶ÔØUltimate Member²å¼þ¡£¡£¡£¡£¡£¡£
https://securityaffairs.com/148030/hacking/wordpress-ultimate-member-plugin-attacks.html
4¡¢VolexityÅû¶APT35ºóÃÅPOWERSTARµÄ¸üа汾µÄϸ½Ú
VolexityÔÚ6ÔÂ28ÈÕÅû¶ÁËAPT35£¨±ðÃûCharming Kitten£©ºóÃÅPOWERSTARµÄ¸üа汾¡£¡£¡£¡£¡£¡£¹¥»÷Õß¼ÓÇ¿ÁËPOWERSTARµÄ·´·ÖÎö´ëÊ©¡£¡£¡£¡£¡£¡£2021Äê¼ì²âµ½µÄµÍ¼¶°æ±¾Ê¹ÓÃDOCMÎļþÖÐǶÈëµÄ¶ñÒâºê·Ö·¢£¬£¬£¬£¬£¬£¬£¬£¬¶øÔÚ½ñÄê5ÔµĹ¥»÷»î¶¯ÖÐÀûÓÃÁËÊÜÃÜÂë±£»£»£»£»£»£»¤µÄRARÎļþÄÚµÄLNKÎļþ£¬£¬£¬£¬£¬£¬£¬£¬´ÓBackblazeÏÂÔØºóÃÅ¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬£¬½ü¼¸¸öÔÂÀ´£¬£¬£¬£¬£¬£¬£¬£¬¸ÃÍŻﻹÓÃ˽ÓÐÍйܻù´¡ÉèÊ©BackblazeºÍIPFSÈ¡´úÁËËûÃÇ֮ǰµÄÔÆÍйÜÌṩÉÌ£¨OneDrive¡¢AWS S3ºÍDropbox£©¡£¡£¡£¡£¡£¡£
https://www.volexity.com/blog/2023/06/28/charming-kitten-updates-powerstar-with-an-interplanetary-twist/
5¡¢MITRE¹«¿ª2023ÄêCWE 25¸ö×îΣÏÕµÄÈí¼þ·ì϶µÄÇåµ¥
6ÔÂ29ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬MITRE¹«¿ªÁË2023ÄêCWE 25¸ö×îΣÏÕµÄÈí¼þ·ì϶µÄÇåµ¥¡£¡£¡£¡£¡£¡£MITRE·ÖÎöÁËNIST¹ú¶È·ì϶Êý¾Ý¿â£¨NVD£©ÖеÄ43996¸öCVE£¬£¬£¬£¬£¬£¬£¬£¬¼´2021ÄêºÍ2022ÄêÆÚ¼ä·¢Ïֺͻ㱨µÄ·ì϶£¬£¬£¬£¬£¬£¬£¬£¬Æ¾¾ÝÆäÑϳÁÐÔºÍÆÕ±éÐÔ¶Ôÿ¸ö·ì϶½øÐÐÁËÆÀ·Ö£¬£¬£¬£¬£¬£¬£¬£¬´Ó¶ø´´½¨Á˸ÃÁÐ±í¡£¡£¡£¡£¡£¡£ÆäÖÐ×îΪÑϳÁµÄÊÇÔ½½çдÈë¡¢ÍøÒ³ÌìÉúÆÚ¼äÊäÈëµÄ²»ÕýÈ·Öкͣ¨¿çÕ¾¾ç±¾£©¡¢SQLºÅÁîÖÐʹÓõÄÌØÊâÔªËØµÄ²»ÕýÈ·Öкͣ¨SQL×¢È룩ºÍ¿ªÊͺóʹÓ÷ì϶µÈ¡£¡£¡£¡£¡£¡£
https://cwe.mitre.org/top25/
6¡¢Elastic°ä²¼Õë¶ÔmacOSµÄRustBucketбäÌåµÄ·ÖÎö»ã±¨
6ÔÂ29ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬Elastic°ä²¼»ã±¨£¬£¬£¬£¬£¬£¬£¬£¬Åû¶ÁËÕë¶ÔmacOSµÄRustBucketбäÌå¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±·¢ÏÖÁËRustBucketϵÁÐÖÐÒÔǰûÓеÄÓÆ¾ÃÐÔÖ°ÄÜ£¬£¬£¬£¬£¬£¬£¬£¬²¢ÒÔΪ¸ÃϵÁÐÔÚ»ý¼«¿ª·¢ÖС£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬£¬½ØÖÁĿǰ£¬£¬£¬£¬£¬£¬£¬£¬¸ÃбäÖÖÔÚVirusTotalÉϵļì²âÂÊΪÁ㣬£¬£¬£¬£¬£¬£¬£¬²¢ÀûÓö¯Ì¬ÍøÂç»ù´¡ÉèÊ©µÄ²½Öè½øÐÐC2¡£¡£¡£¡£¡£¡£¹¥»÷µÄµÚÒ»½×¶Î£¬£¬£¬£¬£¬£¬£¬£¬»áÖ´ÐÐÒ»¸öAppleScript£¬£¬£¬£¬£¬£¬£¬£¬Æô¶¯Ê¹ÓÃcURL´ÓC2ÏÂÔØµÚ¶þ½×¶ÎpayloadµÄ¶þ½øÔìÎļþ¡£¡£¡£¡£¡£¡£µÚ¶þ½×¶Î¶þ½øÔìÎļþ(.pd)ÓÃSwift±àÒ룬£¬£¬£¬£¬£¬£¬£¬´ÓC2ÏÂÔØÖØÒª¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¡£µÚÈý½×¶ÎµÄ¶ñÒâÈí¼þÊÇÒ»¸öFAT macOS¶þ½øÔìÎļþ¡£¡£¡£¡£¡£¡£
https://www.elastic.co/cn/security-labs/DPRK-strikes-using-a-new-variant-of-rustbucket


¾©¹«Íø°²±¸11010802024551ºÅ