×êÑÐÈËÔ±³Æ¶ñÒâÈí¼þAVreconÒÑϰȾ7Íò¶àSOHO·ÓÉÆ÷
°ä²¼¹¦·ò 2023-07-171¡¢×êÑÐÈËÔ±³Æ¶ñÒâÈí¼þAVreconÒÑϰȾ7Íò¶àSOHO·ÓÉÆ÷
Black Lotus LabsÔÚ7ÔÂ12Èճƣ¬£¬£¬£¬£¬£¬¶ñÒâÈí¼þAVreconÒÑϰȾ³¬¹ý70000¸ö»ùÓÚLinuxµÄSOHO·ÓÉÆ÷£¬£¬£¬£¬£¬£¬²¢½«ËüÃÇÔö³¤µ½½©Ê¬ÍøÂçÖС£¡£¡£¡£¡£³ýÁË2021Äê5Ô³õ´Î±»·¢ÏÖÖ®±í£¬£¬£¬£¬£¬£¬AVreconÒѾÔËÐÐÁËÁ½Äê¶à¶øÎ´±»¼ì²âµ½¡£¡£¡£¡£¡£×êÑÐÈËÔ±´§¶È£¬£¬£¬£¬£¬£¬¸Ã»î¶¯ËƺõÖ¼ÔÚ´´½¨Ò»¸ö°ÂÃØÍøÂ磬£¬£¬£¬£¬£¬ÒÔ͵͵µØ·¢Õ¹ÃÜÂëÅçÈ÷ºÍÊý×Ö¸æ°×ڲƵÈһϵÁй¥»÷»î¶¯¡£¡£¡£¡£¡£ÓÉÓÚ¶ñÒâÈí¼þµÄÒñ±ÎÐÔ£¬£¬£¬£¬£¬£¬±»Ï°È¾É豸µÄËùÓÐÕߺÜÉÙ°ÑÎȵ½¹¤×÷Öжϻò´ø¿íµÄËðʧ¡£¡£¡£¡£¡£°²È«ÍŶÓͨ¹ý½«½©Ê¬ÍøÂçµÄC2ÔÚÆäÖ÷¸ÉÍøÂçÉϽøÐÐÎÞЧ·ÓÉÀ´Ó¦¶Ô´ËÀàÍþв¡£¡£¡£¡£¡£
https://blog.lumen.com/routers-from-the-underground-exposing-avrecon/
2¡¢ÎÚ¿ËÀ¼CERT-UAÅû¶UAC-0010ÍÅ»ï½üÆÚ¹¥»÷»î¶¯µÄϸ½Ú
7ÔÂ13ÈÕ£¬£¬£¬£¬£¬£¬ÎÚ¿ËÀ¼CERT-UAÅû¶ÁËUAC-0010£¨ÓÖ³ÆGamaredon£©ÍÅ»ï½üÆÚ¹¥»÷»î¶¯µÄϸ½Ú¡£¡£¡£¡£¡£Gamaredon»á½øÐм±¾ç¹¥»÷£¬£¬£¬£¬£¬£¬ÔÚ³õ´ÎÈëÇÖºó30·ÖÖÓ¾ÍÆðÍ·ÇÔÈ¡Êý¾Ý¡£¡£¡£¡£¡£Ê×ÏÈÀûÓô¹µöÓʼþºÍÐÂÎÅ£¬£¬£¬£¬£¬£¬ÓÕʹָ±ê´ò¿ª¶øÒѸ½¼þ£¬£¬£¬£¬£¬£¬¶øºóÏÂÔØPowerShell¾ç±¾ºÍ¶ñÒâÈí¼þ£¨Í¨³£ÊÇGammaSteel£©¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÿÖÜÔÚ±»Ï°È¾µÄϵͳÉÏÖ²Èë¶à´ï120¸ö¶ñÒâÎļþ£¬£¬£¬£¬£¬£¬ÒÔÔö³¤ÔÙ´ÎϰȾµÄ¿ÉÄÜÐÔ¡£¡£¡£¡£¡£CERT-UA°µÊ¾£¬£¬£¬£¬£¬£¬ÕмܴËÀ๥»÷µÄ×î¼Ñ²½ÖèÊÇ×èÖ¹»òÏÞ¶Èmshta.exe¡¢wscript.exe¡¢cscript.exeºÍpowershell.exeµÄδ¾ÊÚȨִÐС£¡£¡£¡£¡£
https://cert.gov.ua/article/5160737
3¡¢WordPress²å¼þAIOS¼Í¼Ã÷ÎÄÃÜÂëÓ°Ïì100¶àÍò¸öÍøÕ¾
¾ÝýÌå7ÔÂ14ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬WordPress²å¼þAll-In-One Security(AIOS)±»·¢ÏÖ»áÒÔÃ÷ÎÄ´ó¾Ö´æ´¢Óû§ÃÜÂ룬£¬£¬£¬£¬£¬´Ó¶øÊ¹ÕÊ»§°²È«Ãæ¶Ô·çÏÕ¡£¡£¡£¡£¡£¸Ã²å¼þ±»³¬¹ý100Íò¸öÍøÕ¾Ê¹Ó㬣¬£¬£¬£¬£¬ÓÐЧ»§»ã±¨³Æ£¬£¬£¬£¬£¬£¬Ëü²»½ö½«Óû§µÇ¼³¢ÊԼͼµ½aiowps_audit_logÊý¾Ý¿â±í£¨ÓÃÓÚ¸ú×ٵǼ¡¢×¢ÏúºÍµÇ¼ʧ°Ü¶Îñ£©£¬£¬£¬£¬£¬£¬»¹¼Í¼ÁËÊäÈëµÄÃÜÂë¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬£¬AIOS¹©¸øÉÌÒÑÓÚ7ÔÂ11ÈÕ°ä²¼ÁË5.2.0°æ±¾£¬£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬Ô¤·À±£ÁôÃ÷ÎÄÃÜÂë²¢¶Ï¸ù¾ÉÌõ¿î±ê½¨¸´·¨Ê½¡£¡£¡£¡£¡£Í³¼ÆÊý¾ÝÏÔʾ£¬£¬£¬£¬£¬£¬½ØÖÁĿǰ»¹Óг¬¹ý750000¸öÍøÕ¾Î´¸üУ¬£¬£¬£¬£¬£¬ÈÝÒ×Ôâµ½¹¥»÷¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/wordpress-aios-plugin-used-by-1m-sites-logged-plaintext-passwords/
4¡¢Ð½×Ê·þÎñ¹«Ë¾UKGÔÞ³ÉÒÔ600ÍòÃÀÔªºÍ½âÊý¾Ýй¶µÄËßËÏ
ýÌå7ÔÂ12Èճƣ¬£¬£¬£¬£¬£¬Ð½×Ê·þÎñÌṩÉÌUKGÔÞ³ÉÒÔ600ÍòÃÀÔªºÍ½â2021ÄêÊý¾Ýй¶µÄËßËÏ¡£¡£¡£¡£¡£2021Äê12ÔµÄÀÕË÷¹¥»÷µ¼ÖÂUKGµÄKronos˽ÓÐÔÆ²¿ÃŲúÆ·ÀëÏߣ¬£¬£¬£¬£¬£¬»¹µ¼Ö²¿ÃÅÔ±¹¤ºÍ³Ð°üÉ̵ÄÐÅϢй¶¡£¡£¡£¡£¡£Õâ´ÎÊÂÎñÓ°ÏìÁ˰Ùʹ«Ë¾¡¢Å¦Ô¼Êн»Í¨¾Ö¡¢Ó¢¹ú³¬ÊÐSainsburyºÍ¶à¸öÒ½ÁÆ»ú¹¹¡£¡£¡£¡£¡£UKGÓÚ2022Äê1Ô±»¸æ×´£¬£¬£¬£¬£¬£¬ÆäʱÌá³öÁ˾ÅÏîËßËÏÀíÓÉ£¬£¬£¬£¬£¬£¬Ô̺¬ºöÂÔ¡¢²»µ±µÃÀû¡¢Î¥Ô¼ºÍÎ¥·´¼ÓÖÝÒþÖÔ·¨µÈ¡£¡£¡£¡£¡£UKGÔÞ³ÉÖ§¸¶550ÍòÃÀÔªÓÃÓÚË÷Å⣬£¬£¬£¬£¬£¬²¢³ÐŵÔÚ±ØÒªÊ±×·¼Ó50ÍòÃÀÔª¡£¡£¡£¡£¡£
https://www.wsj.com/articles/payroll-services-provider-ukg-agrees-to-6-million-settlement-in-data-breach-lawsuit-8ea87f01
5¡¢Uptycs·¢ÏÖ¼ÙµÄCVE-2023-35829µÄPoC·Ö·¢¶ñÒâÈí¼þ
UptycsÔÚ7ÔÂ12ÈÕ³ÆÆä·¢ÏÖÁËÒ»¸öαÔìµÄ·ì϶PoC£¬£¬£¬£¬£¬£¬»á·Ö·¢LinuxÃÜÂëÇÔÈ¡¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¸ÃPoCÐû³ÆÊÇÕë¶ÔCVE-2023-35829µÄ·ì϶ÀûÓ㬣¬£¬£¬£¬£¬ÕâÊÇÒ»¸öÓ°Ïì6.3.2֮ǰµÄLinuxÄں˵ĿªÊͺóʹÓ÷ì϶¡£¡£¡£¡£¡£µ«ÏÖʵÉÏ£¬£¬£¬£¬£¬£¬ËüÊÇÁíÒ»¸öLinuxÄں˷ì϶CVE-2022-34918µÄ¾É°æºÏ·¨·ì϶ÀûÓᣡ£¡£¡£¡£¸Ã¶ñÒâÈí¼þ¿ÉÄÜÇÔÈ¡Ö÷»úÃû¡¢Óû§ÃûºÍÖ÷Ŀ¼ÄÚÈÝµÄÆëÈ«ÁбíµÈ¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬¹¥»÷Õß»¹Í¨¹ý½«SSHÃÜÔ¿Ôö³¤µ½authorized_keysÎļþÖУ¬£¬£¬£¬£¬£¬ÒÔʵÏÖ¶ÔÖ¸±êϵͳµÄÆëÈ«½ÚÔì¡£¡£¡£¡£¡£
https://www.uptycs.com/blog/new-poc-exploit-backdoor-malware
6¡¢SlashNext°ä²¼»ùÓÚAIµÄºÚ¿Í¹¤¾ßWormGPTµÄ·ÖÎö»ã±¨
7ÔÂ13ÈÕ£¬£¬£¬£¬£¬£¬SlashNext°ä²¼ÁËÐÂÐÍÌìÉúʽÈËΪÖÇÄܺڿ͹¤¾ßWormGPTµÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¸Ã¹¤¾ß½«×Ô¼ºÊÓΪGPTÄ£Ð͵ĺÚñ´úÌæÆ·£¬£¬£¬£¬£¬£¬×¨Îª¶ñÒâ»î¶¯¶øÉè¼Æ¡£¡£¡£¡£¡£WormGPTÊÇÒ»¿î»ùÓÚGPTJ˵»°Ä£Ð͵ÄAIÄ£¿£¿£¿£¿£¿£¿£¿é£¬£¬£¬£¬£¬£¬ÓÚ2021Ä꿪·¢£¬£¬£¬£¬£¬£¬ÓµÓÐÎÞÏÞ×Ö·ûÖ§³Ö¡¢Ì¸ÌìÄÚ´æ±£ÁôºÍ´úÂëÌåʽ»¯µÈÖ°ÄÜ¡£¡£¡£¡£¡£¹¥»÷ÕßÄܹ»ÀûÓô˹¤¾ßÌìÉúÓÐ˵·þÁ¦µÄµç×ÓÓʼþ£¬£¬£¬£¬£¬£¬½øÐи´ÔӵĴ¹µö¹¥»÷ºÍBEC¹¥»÷¡£¡£¡£¡£¡£
https://slashnext.com/blog/wormgpt-the-generative-ai-tool-cybercriminals-are-using-to-launch-business-email-compromise-attacks/


¾©¹«Íø°²±¸11010802024551ºÅ