×êÑÐÈËÔ±Åû¶SolarWinds ARM²úÆ·Öжà¸ö·ì϶µÄÏêÇé

°ä²¼¹¦·ò 2023-10-24

1¡¢×êÑÐÈËÔ±Åû¶SolarWinds ARM²úÆ·Öжà¸ö·ì϶µÄÏêÇé


¾ÝýÌå10ÔÂ20ÈÕ±¨Â·£¬£¬£¬ £¬£¬×êÑÐÈËÔ±³ÆÆäÔÚSolarWinds Access Rights Manager(ARM)²úÆ·Öз¢ÏÖÁË3¸öÔ¶³Ì´úÂëÖ´Ðзì϶ ¡£¡£¡£¡£¡£ÕâЩ·ì϶±ðÀëÊÇcreateGlobalServerChannelInternalÖв»³ÉÐÅÊý¾ÝµÄ·´ÐòÁл¯·ì϶£¨CVE-2023-35182£©¡¢ OpenFileÖжÔÓû§Ìṩõè¾¶ÑéÖ¤²»×ãµÄ·ì϶£¨CVE-2023-35185£©ÒÔ¼°OpenClientUpdateFileÖжÔÓû§Ìṩõè¾¶ÑéÖ¤²»×ãµÄ·ì϶£¨CVE-2023-35187£© ¡£¡£¡£¡£¡£ËüÃǵÄCVSSÆÀ·Ö¾ùΪ9.8£¬£¬£¬ £¬£¬ÒÑÓÚ10ÔÂ18ÈÕ½¨¸´ ¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/critical-rce-flaws-found-in-solarwinds-access-audit-solution/


2¡¢ÃÀ¹úÃÜЪ¸ù´óѧÔâµ½¹¥»÷ѧÉúºÍ¹¤×÷ÈËÔ±µÄÐÅϢй¶


¾Ý10ÔÂ23ÈÕ±¨Â·£¬£¬£¬ £¬£¬ÃÜЪ¸ù´óѧй©£¬£¬£¬ £¬£¬ºÚ¿ÍÔÚ8Ô·ÝÈëÇÔìäϵͳ²¢½Ó¼ûÁËÔ̺¬Ñ§Éú¡¢ÉêÇëÈË¡¢Ð£ÓÑ¡¢¾è¿îÈË¡¢Ô±¹¤¡¢»¼ÕߺÍ×êÑвμÓÕßµÄÐÅÏ¢ ¡£¡£¡£¡£¡£Î´¾­ÊÚȨµÄ½Ó¼û²úÉúÓÚ8ÔÂ23ÈÕÖÁ27ÈÕ£¬£¬£¬ £¬£¬ÔÚ¼ì²âµ½¿ÉÒɻºó£¬£¬£¬ £¬£¬¸ÃѧÌÃÁ¢¼´¶Â½ØÁËÕû¸öУ԰µÄÍøÂ磬£¬£¬ £¬£¬ÒÔ¾¡Á¿¼õÇáÓ°Ïì ¡£¡£¡£¡£¡£Õâ´ÎÊÂÎñ²»½öй¶ÁËÓ×ÎÒÐÅÏ¢£¬£¬£¬ £¬£¬»¹Ð¹Â¶Á˲ÆÕþºÍÒ½ÁƾßÌåÐÅÏ¢ ¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬ £¬£¬ÃÜЪ¸ù´óѧÒÑ֪ͨËùÓÐÊÜÓ°ÏìµÄÓ×ÎÒ£¬£¬£¬ £¬£¬²¢½«ÎªËûÃÇÌṩÃâ·ÑÐÅÓþ¼à¿Ø·þÎñ ¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/university-of-michigan-employee-student-data-stolen-in-cyberattack/


3¡¢FacebookºÍInstagramÓë·¨Âɲ¿ÃÅÁª¶¯µÄÕ˺ű»ÏúÊÛ


ýÌå10ÔÂ21Èճƣ¬£¬£¬ £¬£¬ºÚ¿ÍÔÚ°µÍøÏúÊÛFacebookºÍInstagramµÄPolice PortalµÄ½Ó¼ûȨÏÞ ¡£¡£¡£¡£¡£¸ÃÃÅ»§¿É±»·¨ÂÉ»ú¹¹ÓÃÓÚÒªÇóÓëÓû§ÓйصÄÊý¾Ý£¨IP¡¢µç»°¡¢Ë½ÐźÍÉ豸ÐÅÏ¢£©»òÒªÇóɾ³ýÌû×ӺͽûÓÃÕÊ»§ ¡£¡£¡£¡£¡£¹¥»÷ÕßÒÔ700ÃÀÔªµÄ¼ÛÖµÌṩ½Ó¼ûȨÏÞ£¬£¬£¬ £¬£¬²¢ÇÒËÆºõÕ¼Óв»Ö¹Ò»¸öÃÅ»§µÄÕË»§ ¡£¡£¡£¡£¡£×êÑÐÈËÔ±´§Ä¦£¬£¬£¬ £¬£¬ÒªÃ´ÊÇMetaÔâµ½ÁËÉ繤¹¥»÷µ¼Ö½ӼûȨÏÞй¶£¬£¬£¬ £¬£¬ÒªÃ´¾ÍÊǹ¥»÷ÕßÕ¼ÓкϷ¨µÄ·¨ÂÉÕÊ»§µÄÍ´´¦ ¡£¡£¡£¡£¡£


https://securityaffairs.com/152811/cyber-crime/facebook-and-instagrams-police-portal-access.html


4¡¢Cadre ServicesÔ¼100GBÊý¾Ýй¶²¢±»ÀÕË÷30ÍòÃÀÔª


10ÔÂ19ÈÕ±¨Â·³Æ£¬£¬£¬ £¬£¬AlphVÐû³Æ¹¥»÷Á˾ÍÒµºÍÈËÊ·þÎñCadre Services²¢ÒÑÇÔÈ¡100 GBµÄÎļþ ¡£¡£¡£¡£¡£¹¥»÷ÍÅ»ïÔÚ9ÔÂ19ÈÕ³õ´ÎÁªÏµÁËCadre£¬£¬£¬ £¬£¬²¢ÓÚ9ÔÂ22ÈÕÊÕµ½»Ø¸´ ¡£¡£¡£¡£¡£½»ÉæµÄ̸Ìì½ØÍ¼ÏÔʾ£¬£¬£¬ £¬£¬AlphVÒªÇó30ÍòÃÀÔªÊê½ð£¬£¬£¬ £¬£¬¸Ã¹«Ë¾×î³õ°µÊ¾Ô¸Òâ³ö¼Û25000ÃÀÔª£¬£¬£¬ £¬£¬²¢³Æ×î¸ß±¨¼ÛΪ35000ÃÀÔª ¡£¡£¡£¡£¡£×î½ü¼¸ÈÕ£¬£¬£¬ £¬£¬AlphVÔÙ´ÎÏò¸Ã¹«Ë¾£¬£¬£¬ £¬£¬ÒÔ¼°¿Í»§ºÍDataBreaches·¢ËÍÓʼþ£¬£¬£¬ £¬£¬ÌṩÁ˽«ÒªÐ¹Â¶µÄÊý¾ÝµÄÑù±¾£¬£¬£¬ £¬£¬Ô̺¬Ô±¹¤Êý¾ÝºÍÉêÇëÈËÊý¾Ý ¡£¡£¡£¡£¡£


https://www.databreaches.net/another-small-firm-suffers-a-serious-ransomware-attack-cadre-services-gets-mauled-by-alphv/


5¡¢WithSecure·¢ÏÖÕë¶ÔÓ¢ÃÀµÈ¹úµÄDarkGate¹¥»÷»î¶¯


10ÔÂ20ÈÕ£¬£¬£¬ £¬£¬WithSecureÅû¶ÁËÕë¶ÔÓ¢¹ú¡¢ÃÀ¹úºÍÓ¡¶ÈµÄDarkGate¹¥»÷»î¶¯ ¡£¡£¡£¡£¡£¸Ã»î¶¯ÓëÈ¥Äê³õ´Î·¢ÏÖµÄDucktail»î¶¯µÄÔ½ÄϹ¥»÷ÕßÓйأ¬£¬£¬ £¬£¬³õʼϰȾý½éÊÇLinkedInÐÂÎźÍÓ²¼þÔì×÷ÉÌCorsairµÄFacebook¸æ°×רԱְ룬£¬£¬ £¬£¬»á½«Ö¸±ê³Á¶¨Ïòµ½Google DriveÉÏÍйܵÄÎļþ ¡£¡£¡£¡£¡£ÏÂÔØµÄÎĵµÔ̺¬Ò»¸öVBS¾ç±¾£¬£¬£¬ £¬£¬¿ÉÄÜǶÈëÔÚDOCXÎļþÖУ¬£¬£¬ £¬£¬»áÏÂÔØautoit3.exeºÍÒ»¸ö±àÒëºóµÄAutoit3¾ç±¾ ¡£¡£¡£¡£¡£¿£¿£¿£¿£¿ÉÖ´ÐÐÎļþºó»áÀûÓþ籾ÖеÄ×Ö·û´®»ú¹ØDarkGate£¬£¬£¬ £¬£¬×°ÖÃÈýÊ®Ãëºó£¬£¬£¬ £¬£¬¶ñÒâÈí¼þ»á³¢ÊÔ´ÓÖ¸±êϵͳÖÐÐ¶ÔØ°²È«²úÆ· ¡£¡£¡£¡£¡£


https://labs.withsecure.com/publications/darkgate-malware-campaign


6¡¢Fortinet°ä²¼¶ñÒâÈí¼þExelaStealerµÄ·ÖÎö»ã±¨


10ÔÂ19ÈÕ£¬£¬£¬ £¬£¬Fortinet°ä²¼Á˹ØÓÚ¶ñÒâÈí¼þExelaStealerµÄ·ÖÎö»ã±¨ ¡£¡£¡£¡£¡£ExelaStealerÊÇÒ»¸ö¸ù»ùÉÏ¿ªÔ´µÄÐÅÏ¢ÇÔÈ¡·¨Ê½£¬£¬£¬ £¬£¬Äܹ»Ìṩ¸¶·Ñ¶¨Ôì·þÎñ ¡£¡£¡£¡£¡£Æä¸¶·Ñ°æ±¾Ã¿ÔÂ20ÃÀÔª£¬£¬£¬ £¬£¬Èý¸öÔÂ45ÃÀÔª£¬£¬£¬ £¬£¬Æ½Éú°æ±¾120ÃÀÔª ¡£¡£¡£¡£¡£ËüÓÉPython¿ª·¢²¢Ö§³ÖJavaScript£¬£¬£¬ £¬£¬ÓµÓÐÇÔÈ¡ÃÜÂë¡¢DiscordÁîÅÆ¡¢ÐÅÓþ¿¨¡¢cookieºÍ»á»°Êý¾Ý¡¢»÷¼ü¡¢ÆÁÄ»½ØÍ¼ºÍ¼ôÌù°åÄÚÈݵÄÖ°ÄÜ ¡£¡£¡£¡£¡£ExelaStealer¿ÉÄÜÊÇͨ¹ý¼Ù×°³ÉPDFÎĵµµÄ¿ÉÖ´ÐÐÎļþ½øÐзַ¢µÄ£¬£¬£¬ £¬£¬Æô¶¯¶þ½øÔìÎļþºó£¬£¬£¬ £¬£¬»áÏÔʾһ·ÝÒýÓÕÎļþ£¬£¬£¬ £¬£¬Í¬Ê±ÔÚºó¶Ü͵͵Æô¶¯ÇÔÈ¡·¨Ê½ ¡£¡£¡£¡£¡£


https://www.fortinet.com/blog/threat-research/exelastealer-infostealer-enters-the-field