×êÑÐÈËÔ±Åû¶SolarWinds ARM²úÆ·Öжà¸ö·ì϶µÄÏêÇé
°ä²¼¹¦·ò 2023-10-241¡¢×êÑÐÈËÔ±Åû¶SolarWinds ARM²úÆ·Öжà¸ö·ì϶µÄÏêÇé
¾ÝýÌå10ÔÂ20ÈÕ±¨Â·£¬£¬£¬£¬£¬×êÑÐÈËÔ±³ÆÆäÔÚSolarWinds Access Rights Manager(ARM)²úÆ·Öз¢ÏÖÁË3¸öÔ¶³Ì´úÂëÖ´Ðзì϶¡£¡£¡£¡£¡£ÕâЩ·ì϶±ðÀëÊÇcreateGlobalServerChannelInternalÖв»³ÉÐÅÊý¾ÝµÄ·´ÐòÁл¯·ì϶£¨CVE-2023-35182£©¡¢ OpenFileÖжÔÓû§Ìṩõè¾¶ÑéÖ¤²»×ãµÄ·ì϶£¨CVE-2023-35185£©ÒÔ¼°OpenClientUpdateFileÖжÔÓû§Ìṩõè¾¶ÑéÖ¤²»×ãµÄ·ì϶£¨CVE-2023-35187£©¡£¡£¡£¡£¡£ËüÃǵÄCVSSÆÀ·Ö¾ùΪ9.8£¬£¬£¬£¬£¬ÒÑÓÚ10ÔÂ18ÈÕ½¨¸´¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/critical-rce-flaws-found-in-solarwinds-access-audit-solution/
2¡¢ÃÀ¹úÃÜЪ¸ù´óѧÔâµ½¹¥»÷ѧÉúºÍ¹¤×÷ÈËÔ±µÄÐÅϢй¶
¾Ý10ÔÂ23ÈÕ±¨Â·£¬£¬£¬£¬£¬ÃÜЪ¸ù´óѧй©£¬£¬£¬£¬£¬ºÚ¿ÍÔÚ8Ô·ÝÈëÇÔìäϵͳ²¢½Ó¼ûÁËÔ̺¬Ñ§Éú¡¢ÉêÇëÈË¡¢Ð£ÓÑ¡¢¾è¿îÈË¡¢Ô±¹¤¡¢»¼ÕߺÍ×êÑвμÓÕßµÄÐÅÏ¢¡£¡£¡£¡£¡£Î´¾ÊÚȨµÄ½Ó¼û²úÉúÓÚ8ÔÂ23ÈÕÖÁ27ÈÕ£¬£¬£¬£¬£¬ÔÚ¼ì²âµ½¿ÉÒɻºó£¬£¬£¬£¬£¬¸ÃѧÌÃÁ¢¼´¶Â½ØÁËÕû¸öУ԰µÄÍøÂ磬£¬£¬£¬£¬ÒÔ¾¡Á¿¼õÇáÓ°Ïì¡£¡£¡£¡£¡£Õâ´ÎÊÂÎñ²»½öй¶ÁËÓ×ÎÒÐÅÏ¢£¬£¬£¬£¬£¬»¹Ð¹Â¶Á˲ÆÕþºÍÒ½ÁƾßÌåÐÅÏ¢¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬ÃÜЪ¸ù´óѧÒÑ֪ͨËùÓÐÊÜÓ°ÏìµÄÓ×ÎÒ£¬£¬£¬£¬£¬²¢½«ÎªËûÃÇÌṩÃâ·ÑÐÅÓþ¼à¿Ø·þÎñ¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/university-of-michigan-employee-student-data-stolen-in-cyberattack/
3¡¢FacebookºÍInstagramÓë·¨Âɲ¿ÃÅÁª¶¯µÄÕ˺ű»ÏúÊÛ
ýÌå10ÔÂ21Èճƣ¬£¬£¬£¬£¬ºÚ¿ÍÔÚ°µÍøÏúÊÛFacebookºÍInstagramµÄPolice PortalµÄ½Ó¼ûȨÏÞ¡£¡£¡£¡£¡£¸ÃÃÅ»§¿É±»·¨ÂÉ»ú¹¹ÓÃÓÚÒªÇóÓëÓû§ÓйصÄÊý¾Ý£¨IP¡¢µç»°¡¢Ë½ÐźÍÉ豸ÐÅÏ¢£©»òÒªÇóɾ³ýÌû×ӺͽûÓÃÕÊ»§¡£¡£¡£¡£¡£¹¥»÷ÕßÒÔ700ÃÀÔªµÄ¼ÛÖµÌṩ½Ó¼ûȨÏÞ£¬£¬£¬£¬£¬²¢ÇÒËÆºõÕ¼Óв»Ö¹Ò»¸öÃÅ»§µÄÕË»§¡£¡£¡£¡£¡£×êÑÐÈËÔ±´§Ä¦£¬£¬£¬£¬£¬ÒªÃ´ÊÇMetaÔâµ½ÁËÉ繤¹¥»÷µ¼Ö½ӼûȨÏÞй¶£¬£¬£¬£¬£¬ÒªÃ´¾ÍÊǹ¥»÷ÕßÕ¼ÓкϷ¨µÄ·¨ÂÉÕÊ»§µÄÍ´´¦¡£¡£¡£¡£¡£
https://securityaffairs.com/152811/cyber-crime/facebook-and-instagrams-police-portal-access.html
4¡¢Cadre ServicesÔ¼100GBÊý¾Ýй¶²¢±»ÀÕË÷30ÍòÃÀÔª
10ÔÂ19ÈÕ±¨Â·³Æ£¬£¬£¬£¬£¬AlphVÐû³Æ¹¥»÷Á˾ÍÒµºÍÈËÊ·þÎñCadre Services²¢ÒÑÇÔÈ¡100 GBµÄÎļþ¡£¡£¡£¡£¡£¹¥»÷ÍÅ»ïÔÚ9ÔÂ19ÈÕ³õ´ÎÁªÏµÁËCadre£¬£¬£¬£¬£¬²¢ÓÚ9ÔÂ22ÈÕÊÕµ½»Ø¸´¡£¡£¡£¡£¡£½»ÉæµÄ̸Ìì½ØÍ¼ÏÔʾ£¬£¬£¬£¬£¬AlphVÒªÇó30ÍòÃÀÔªÊê½ð£¬£¬£¬£¬£¬¸Ã¹«Ë¾×î³õ°µÊ¾Ô¸Òâ³ö¼Û25000ÃÀÔª£¬£¬£¬£¬£¬²¢³Æ×î¸ß±¨¼ÛΪ35000ÃÀÔª¡£¡£¡£¡£¡£×î½ü¼¸ÈÕ£¬£¬£¬£¬£¬AlphVÔÙ´ÎÏò¸Ã¹«Ë¾£¬£¬£¬£¬£¬ÒÔ¼°¿Í»§ºÍDataBreaches·¢ËÍÓʼþ£¬£¬£¬£¬£¬ÌṩÁ˽«ÒªÐ¹Â¶µÄÊý¾ÝµÄÑù±¾£¬£¬£¬£¬£¬Ô̺¬Ô±¹¤Êý¾ÝºÍÉêÇëÈËÊý¾Ý¡£¡£¡£¡£¡£
https://www.databreaches.net/another-small-firm-suffers-a-serious-ransomware-attack-cadre-services-gets-mauled-by-alphv/
5¡¢WithSecure·¢ÏÖÕë¶ÔÓ¢ÃÀµÈ¹úµÄDarkGate¹¥»÷»î¶¯
10ÔÂ20ÈÕ£¬£¬£¬£¬£¬WithSecureÅû¶ÁËÕë¶ÔÓ¢¹ú¡¢ÃÀ¹úºÍÓ¡¶ÈµÄDarkGate¹¥»÷»î¶¯¡£¡£¡£¡£¡£¸Ã»î¶¯ÓëÈ¥Äê³õ´Î·¢ÏÖµÄDucktail»î¶¯µÄÔ½ÄϹ¥»÷ÕßÓйأ¬£¬£¬£¬£¬³õʼϰȾý½éÊÇLinkedInÐÂÎźÍÓ²¼þÔì×÷ÉÌCorsairµÄFacebook¸æ°×רԱְ룬£¬£¬£¬£¬»á½«Ö¸±ê³Á¶¨Ïòµ½Google DriveÉÏÍйܵÄÎļþ¡£¡£¡£¡£¡£ÏÂÔØµÄÎĵµÔ̺¬Ò»¸öVBS¾ç±¾£¬£¬£¬£¬£¬¿ÉÄÜǶÈëÔÚDOCXÎļþÖУ¬£¬£¬£¬£¬»áÏÂÔØautoit3.exeºÍÒ»¸ö±àÒëºóµÄAutoit3¾ç±¾¡£¡£¡£¡£¡£¿£¿£¿£¿£¿ÉÖ´ÐÐÎļþºó»áÀûÓþ籾ÖеÄ×Ö·û´®»ú¹ØDarkGate£¬£¬£¬£¬£¬×°ÖÃÈýÊ®Ãëºó£¬£¬£¬£¬£¬¶ñÒâÈí¼þ»á³¢ÊÔ´ÓÖ¸±êϵͳÖÐÐ¶ÔØ°²È«²úÆ·¡£¡£¡£¡£¡£
https://labs.withsecure.com/publications/darkgate-malware-campaign
6¡¢Fortinet°ä²¼¶ñÒâÈí¼þExelaStealerµÄ·ÖÎö»ã±¨
10ÔÂ19ÈÕ£¬£¬£¬£¬£¬Fortinet°ä²¼Á˹ØÓÚ¶ñÒâÈí¼þExelaStealerµÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£ExelaStealerÊÇÒ»¸ö¸ù»ùÉÏ¿ªÔ´µÄÐÅÏ¢ÇÔÈ¡·¨Ê½£¬£¬£¬£¬£¬Äܹ»Ìṩ¸¶·Ñ¶¨Ôì·þÎñ¡£¡£¡£¡£¡£Æä¸¶·Ñ°æ±¾Ã¿ÔÂ20ÃÀÔª£¬£¬£¬£¬£¬Èý¸öÔÂ45ÃÀÔª£¬£¬£¬£¬£¬Æ½Éú°æ±¾120ÃÀÔª¡£¡£¡£¡£¡£ËüÓÉPython¿ª·¢²¢Ö§³ÖJavaScript£¬£¬£¬£¬£¬ÓµÓÐÇÔÈ¡ÃÜÂë¡¢DiscordÁîÅÆ¡¢ÐÅÓþ¿¨¡¢cookieºÍ»á»°Êý¾Ý¡¢»÷¼ü¡¢ÆÁÄ»½ØÍ¼ºÍ¼ôÌù°åÄÚÈݵÄÖ°ÄÜ¡£¡£¡£¡£¡£ExelaStealer¿ÉÄÜÊÇͨ¹ý¼Ù×°³ÉPDFÎĵµµÄ¿ÉÖ´ÐÐÎļþ½øÐзַ¢µÄ£¬£¬£¬£¬£¬Æô¶¯¶þ½øÔìÎļþºó£¬£¬£¬£¬£¬»áÏÔʾһ·ÝÒýÓÕÎļþ£¬£¬£¬£¬£¬Í¬Ê±ÔÚºó¶Ü͵͵Æô¶¯ÇÔÈ¡·¨Ê½¡£¡£¡£¡£¡£
https://www.fortinet.com/blog/threat-research/exelastealer-infostealer-enters-the-field


¾©¹«Íø°²±¸11010802024551ºÅ