NCC³Æ½ü2000̨Citrix NetScaler·þÎñÆ÷Òѱ»Ö²ÈëºóÃÅ
°ä²¼¹¦·ò 2023-08-171¡¢NCC³Æ½ü2000̨Citrix NetScaler·þÎñÆ÷Òѱ»Ö²ÈëºóÃÅ
¾Ý8ÔÂ16ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬NCC Group·¢ÏÖÁËCitrix NetScaler·ì϶µÄ´ó¹æÄ£ÀûÓû¡£¡£¡£¡£¡£¹¥»÷ÕßÒÔ×Ô¶¯»¯·½Ê½ÀûÓÃÁË·ì϶£¨CVE-2023-3519£©£¬£¬£¬£¬£¬£¬ÔÚNetscaler·þÎñÆ÷ÖÐÖ²ÈëÁËWebshell¡£¡£¡£¡£¡£¼´±ãNetScalerÒÑ´ò²¹¶¡»ò³ÁÆô£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÒ²Äܹ»Ê¹ÓôËWebshellÖ´ÐÐËÁÒâºÅÁî¡£¡£¡£¡£¡£×êÑÐÈËÔ±×ܹ²ÔÚ1952¸ö·ÖÆçµÄNetScalerÖз¢ÏÖÁË2491¸öWebshell£¬£¬£¬£¬£¬£¬´óÎÞÊýλÓڵ¹ú¡¢·¨¹ú¡¢ÈðÊ¿¡¢ÈÕ±¾ºÍÒâ´óÀûµÈ¹ú¡£¡£¡£¡£¡£½ØÖÁ8ÔÂ14ÈÕ£¬£¬£¬£¬£¬£¬ÈÔÓÐ1828¸öNetScaler´æÔÚºóÃÅ£¬£¬£¬£¬£¬£¬ÆäÖÐÔ¼1248̨ÒѾÕë¶Ô¸Ã·ì϶½øÐÐÁ˽¨¸´¡£¡£¡£¡£¡£
https://thehackernews.com/2023/08/nearly-2000-citrix-netscaler-instances.html
2¡¢´óÁ¿LinkedInÓû§³ÆÆäÕË»§±»½Ù³Ö»òËø¶¨²¿ÃÅÒª½»Êê½ð
¾ÝýÌå8ÔÂ15ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬CyberintÔÚ×î½ü¼¸ÖÜ·¢ÏÖÁËÒ»³¡³ÖÐøµÄ¹¥»÷»î¶¯ÖØÒªÕë¶ÔLinkedInÕÊ»§¡£¡£¡£¡£¡£¸Ã»î¶¯µÄÓ°ÏìÁìÓò¸²¸ÇÈ«Çò£¬£¬£¬£¬£¬£¬µ¼Ö´óÁ¿Óû§ÎÞ·¨½Ó¼ûÆäÕÊ»§¡£¡£¡£¡£¡£ºÜ¶àLinkedInÓû§±§Ô¹ÆäÕË»§±»ÊÕÊÜ»òËø¶¨£¬£¬£¬£¬£¬£¬²¢ÇÒÎÞ·¨Í¨¹ýLinkedInµÄÖ§³Ö·þÎñ½â¾ö¡£¡£¡£¡£¡£ÓÐЩÈËÉõÖÁ±»ÆÈ½»Êê½ðÄÜÁ¦³ÁлñµÃ½ÚÔìȨ£¬£¬£¬£¬£¬£¬»òÕßÃæ¶ÔÕË»§±»ÓÀԶɾ³ýµÄÇé¿ö¡£¡£¡£¡£¡£¹ÌÈ»LinkedInÉÐδ°ä²¼Õýʽ²¼¸æ£¬£¬£¬£¬£¬£¬µ«ËûÃǵÄÖ§³ÖÏìÓ¦¹¦·òËÆºõÒѾµ¢¸é£¬£¬£¬£¬£¬£¬Óб¨Â·³ÆÖ§³ÖÒªÇóµÄÊýÁ¿ºÜ´ó¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/linkedin-accounts-hacked-in-widespread-hijacking-campaign/
3¡¢ÃÀ¹ú¸ßÀÖÊÏ(Clorox)Ôâµ½¹¥»÷µ¼ÖÂÔËÓªÁÙʱÖжÏ
8ÔÂ16ÈÕ±¨Â·³Æ£¬£¬£¬£¬£¬£¬ÃÀ¹úÈÕÓÃÆ·³ö²úÉ̸ßÀÖÊÏ(Clorox)Ôâµ½¹¥»÷£¬£¬£¬£¬£¬£¬µ¼ÖÂÔËÓªÁÙʱÖжϡ£¡£¡£¡£¡£¸Ã¹«Ë¾ÔÚ2022ÄêµÄÊÕÈ볬¹ý70ÒÚÃÀÔª¡£¡£¡£¡£¡£Õâ´Î¹¥»÷ÓÚ8ÔÂ14ÈÕ±»¼ì²âµ½£¬£¬£¬£¬£¬£¬CloroxÁ¢¼´²ÉÈ¡Ðж¯£¬£¬£¬£¬£¬£¬¹Ø¹ØÁËÊÜÓ°ÏìµÄϵͳ¡£¡£¡£¡£¡£¸ÃÊÂÎñµÄµ÷²éÈÔÔÚÔçÆÚ½×¶Î£¬£¬£¬£¬£¬£¬Éв»Ã÷ÏÔÊÇÄÄÖÖÀàÐ͵Ĺ¥»÷¡£¡£¡£¡£¡£È»¶øÏÖÓÐÐÅÏ¢Åú×¢£¬£¬£¬£¬£¬£¬Õâ¿ÉÄÜÊÇÀÕË÷¹¥»÷¡£¡£¡£¡£¡£Õâ´Î¹¥»÷Ó°ÏìÁËCloroxµÄÔì×÷ºÍÏúÊÛÁ÷³Ì£¬£¬£¬£¬£¬£¬ÒÔ¼°ÆäÍÆ¹ã¶©µ¥ºÍά³ÖÕý³£ÔËÓªµÄÄÜÁ¦¡£¡£¡£¡£¡£
https://www.infosecurity-magazine.com/news/clorox-disrupted-cyber-attack/
4¡¢´Óǰ°ëÄêCloudflare R2ÍйܵĴ¹µöÍøÒ³Á÷Á¿Ôö³¤61±¶
NetskopeÔÚ8ÔÂ14Èճƣ¬£¬£¬£¬£¬£¬´Ó½ñÄê2Ôµ½7Ô£¬£¬£¬£¬£¬£¬Cloudflare R2ÖÐÍйܵĴ¹µöÒ³ÃæÁ÷Á¿Ôö³¤ÁË61±¶¡£¡£¡£¡£¡£´óÎÞÊý´¹µö»î¶¯¶¼Õë¶ÔMicrosoftµÇ¼ʹ´¦£¬£¬£¬£¬£¬£¬µ«Ò²ÓÐһЩÕë¶ÔAdobe¡¢DropboxºÍÆäËüÔÆÀûÓ÷¨Ê½¡£¡£¡£¡£¡£ÕâЩ¹¥»÷ÖØÒªÕë¶Ô±±ÃÀºÍÑÇÖÞ£¬£¬£¬£¬£¬£¬Éæ¼°¸÷ÀàÁìÓò£¬£¬£¬£¬£¬£¬ÒÔ¼¼Êõ¡¢½ðÈÚ·þÎñºÍÒøÐÐҵΪÊס£¡£¡£¡£¡£ÕâЩ´¹µö»î¶¯²»½öÀûÓÃCloudflare R2·Ö·¢¾²Ì¬´¹µöÒ³Ãæ£¬£¬£¬£¬£¬£¬»¹ÀûÓøù«Ë¾µÄTurnstile²úÆ·À´Èƹý¼ì²â¡£¡£¡£¡£¡£
https://www.netskope.com/blog/evasive-phishing-campaign-steals-cloud-credentials-using-cloudflare-r2-and-turnstile
5¡¢AhnLab·¢ÏÖHakuna MatataÕë¶Ôº«¹úÆóÒµµÄ¹¥»÷»î¶¯
8ÔÂ16ÈÕ£¬£¬£¬£¬£¬£¬AhnLabй©ÀÕË÷Èí¼þHakuna MatataÕý±»ÓÃÀ´¹¥»÷º«¹úµÄÆóÒµ¡£¡£¡£¡£¡£Hakuna MatataÊǽüÆÚ¿ª·¢µÄÀÕË÷Èí¼þ£¬£¬£¬£¬£¬£¬ÓÚ7ÔÂ6ÈÕ³õ´Î±»Åû¶¡£¡£¡£¡£¡£Hakuna MatataÓëÆäËü´«Í³ÀÕË÷Èí¼þµÄ·ÖÆçÖ®´¦ÔÚÓÚ£¬£¬£¬£¬£¬£¬ËüÓµÓÐClipBankerÖ°ÄÜ¡£¡£¡£¡£¡£¼´±ãÔÚ¼ÓÃÜÖ®ºó£¬£¬£¬£¬£¬£¬ËüÒÀÈ»±£ÁôÔÚϵͳÖУ¬£¬£¬£¬£¬£¬½«±ÈÌØ±ÒÇ®°üµØÖ·¸ü¸ÄΪ¹¥»÷ÕߵĵØÖ·¡£¡£¡£¡£¡£¼ÓÃÜϵͳºó£¬£¬£¬£¬£¬£¬¹¥»÷Õß»áɾ³ý¹¥»÷ÖÐʹÓõÄÊÂÎñÈÕÖ¾ºÍ¶ñÒâÈí¼þ£¬£¬£¬£¬£¬£¬Òò¶øºÜÄÑ»ñµÃÈ·ÇеÄÐÅÏ¢¡£¡£¡£¡£¡£µ«ÊÇ£¬£¬£¬£¬£¬£¬Æ¾¾Ý¸÷ÀàÇé¿ö£¬£¬£¬£¬£¬£¬´§Ä¦Ô¶³Ì×ÀÃæºÍ̸£¨RDP£©±»×÷Ϊ³õʼ¹¥»÷ÔØÌå¡£¡£¡£¡£¡£
https://asec.ahnlab.com/en/56010/
6¡¢Group-IB°ä²¼¹ØÓÚ¶ñÒâÈí¼þGigabudµÄ·ÖÎö»ã±¨
8ÔÂ14ÈÕ£¬£¬£¬£¬£¬£¬Group-IB°ä²¼Á˹ØÓÚ¶ñÒâÈí¼þGigabudµÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£ËüÖØÒªÕë¶ÔÌ©¹ú¡¢Ó¡¶ÈÄáÎ÷ÑÇ¡¢Ô½ÄÏ¡¢·ÆÂɱöºÍÃØÂ³µÄ½ðÈÚ»ú¹¹¡£¡£¡£¡£¡£Gigabud RATÔÚÓû§±»ÊÚȨ½øÈë¶ñÒâÀûÓÃ֮ǰ²»»áÖ´ÐÐÈκζñÒâ»î¶¯£¬£¬£¬£¬£¬£¬Õâ¼Ó´óÁ˼ì²âµÄÄѶȡ£¡£¡£¡£¡£ËüÖØÒªÍ¨¹ýÆÁϼÔìÀ´ÍøÂçÃô¸ÐÐÅÏ¢£¬£¬£¬£¬£¬£¬¶ø²»ÊÇHTML¸²¸Ç¹¥»÷¡£¡£¡£¡£¡£³ÖÐøµ÷²é·¢ÏÖÁËÁíÒ»¸ö²»¾ß±¸RATÖ°ÄܵÄÑù±¾£¬£¬£¬£¬£¬£¬´úºÅΪGigabud.Loan£¬£¬£¬£¬£¬£¬ÕâÊÇÒ»¸öαÔìµÄ´û¿îÀûÓ㬣¬£¬£¬£¬£¬»áÇÔÈ¡Óû§ÊäÈëµÄÊý¾Ý¡£¡£¡£¡£¡£
https://www.group-ib.com/blog/gigabud-banking-malware/


¾©¹«Íø°²±¸11010802024551ºÅ