Atlassian½¨¸´Confluence·ì϶CVE-2023-22518
°ä²¼¹¦·ò 2023-11-021¡¢Atlassian½¨¸´Confluence·ì϶CVE-2023-22518
¾ÝýÌå10ÔÂ31Èճƣ¬£¬£¬£¬£¬£¬£¬£¬Atlassian½¨¸´ÁËÒ»¸öÑϳÁµÄ·ì϶£¨CVE-2023-22518£©£¬£¬£¬£¬£¬£¬£¬£¬ËüÓ°ÏìÁËËùÓа汾µÄConfluence Data CenterºÍConfluence Server¡£¡£¡£¡£¡£ÕâÊÇÒ»¸öÊÚȨ²»µ±·ì϶£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÀûÓø÷ì϶·ÛËéÊÜÓ°Ïì·þÎñÆ÷ÉϵÄÊý¾Ý£¬£¬£¬£¬£¬£¬£¬£¬µ¼ÖÂÊý¾ÝÃÔʧ£¬£¬£¬£¬£¬£¬£¬£¬µ«ÎÞ·¨±»ÓÃÀ´ÇÔÈ¡Êý¾Ý¡£¡£¡£¡£¡£Í¨¹ýatlassian.netÓò½Ó¼ûµÄAtlassian CloudÍøÕ¾²»ÊÜ´Ë·ì϶µÄÓ°Ïì¡£¡£¡£¡£¡£´Ë·ì϶ÉÐδ±»×Ô¶¯ÀûÓ㬣¬£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾½¨ÒéÓû§Á¢¼´ÀûÓøüС£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/atlassian-warns-of-critical-confluence-flaw-leading-to-data-loss/
2¡¢Avastɱ¶¾Èí¼þ½«Android GoogleÏóÕ÷Ϊ¶ñÒâÈí¼þ
¾Ý10ÔÂ31ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬£¬£¬°²È«¹«Ë¾Avast³Æ×ÔÖÜÁùÒÔÀ´£¬£¬£¬£¬£¬£¬£¬£¬Æäɱ¶¾Èí¼þ½«²¿ÃÅÐͺŵÄÖÇÄÜÊÖ»úÉϵÄGoogle AndroidÀûÓÃÏóÕ÷Ϊ¶ñÒâÈí¼þ¡£¡£¡£¡£¡£ÔÚÊÜÓ°ÏìÉ豸ÉÏ£¬£¬£¬£¬£¬£¬£¬£¬Óû§±»ÌáÐÑÁ¢¼´Ð¶ÔØGoogleÀûÓ㬣¬£¬£¬£¬£¬£¬£¬ÓÉÓÚËü¿ÉÄÜ»á°ÂÃØ·¢ËͶÌÐÅ¡¢ÏÂÔØºÍ×°ÖÃÆäËüÀûÓûòÇÔÈ¡Óû§ÐÅÏ¢¡£¡£¡£¡£¡£»£»£»£»£»£»£»¹ÓÐÈË¿´µ½ÁË·ÖÆçµÄÌáÐÑ£¬£¬£¬£¬£¬£¬£¬£¬³ÆGoogleÀûÓÃÊÇÒ»¸öľÂí£¬£¬£¬£¬£¬£¬£¬£¬Äܹ»Ô¶³Ì½Ó¼ûËûÃǵÄÉ豸£¬£¬£¬£¬£¬£¬£¬£¬±»¹¥»÷ÕßÓÃÀ´×°ÖöñÒâÈí¼þ²¢ÇÔÈ¡Êý¾Ý¡£¡£¡£¡£¡£Avastй©£¬£¬£¬£¬£¬£¬£¬£¬Æäɱ¶¾SDKÎó½«Google¼±¾çËÑË÷¿òÀûÓ÷¨Ê½Æô¶¯Æ÷ÏóÕ÷Ϊ¶ñÒâÈí¼þ£¬£¬£¬£¬£¬£¬£¬£¬¸ÃÎÊÌâÒÑÓÚ10ÔÂ30ÈÕ½â¾ö¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/avast-confirms-it-tagged-google-app-as-malware-on-android-phones/
3¡¢Scarred ManticoreÀûÓÃLIONTAIL¹¥»÷Öж«µÄ¹ú¶È
Check PointÓÚ10ÔÂ31ÈÕÅû¶ÁËScarred ManticoreÕë¶ÔÖж«¹ú¶È¾üÕþ»ú¹¹ºÍµçÐŹ«Ë¾µÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£¸ÃÍÅ»ï´Ó2019ÄêÆðÒ»Ïò»îÔ¾£¬£¬£¬£¬£¬£¬£¬£¬Ä¿Ç°µÄ»î¶¯ÔÚ2023ÄêÖÐÆÚ´ïµ½¶¥·å¡£¡£¡£¡£¡£×îлÀûÓÃÁËLIONTAIL£¬£¬£¬£¬£¬£¬£¬£¬ÕâÊÇÒ»ÖÖ×°ÖÃÔÚWindows·þÎñÆ÷Éϵı»¶¯¶ñÒâÈí¼þ¿ò¼Ü¡£¡£¡£¡£¡£³öÓÚÒñ±ÎÐÔ£¬£¬£¬£¬£¬£¬£¬£¬LIONTIALÖ²È뷨ʽÀûÓöÔWindows HTTPÕ»Çý¶¯·¨Ê½HTTP.sysµÄÖ±½ÓŲÓÃÀ´¼ÓÔØ³£×¤ÄÚ´æµÄpayload¡£¡£¡£¡£¡£×êÑÐÈËÔ±»¹³Æ£¬£¬£¬£¬£¬£¬£¬£¬Scarred ManticoreÓëOilRig£¨±ðÃûAPT34£©ÓйØÁª¡£¡£¡£¡£¡£
https://research.checkpoint.com/2023/from-albania-to-the-middle-east-the-scarred-manticore-is-listening/
4¡¢Mandiant¼ì²âµ½¶àÆðÀûÓÃCitrix Bleed·ì϶µÄ»î¶¯
10ÔÂ31ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬Mandiant³ÆÆä¼ì²âµ½¶àÆðÀûÓÃCitrix Bleed·ì϶£¬£¬£¬£¬£¬£¬£¬£¬À´¹¥»÷ÃÀÖÞ¡¢Å·ÖÞ¡¢·ÇÖÞºÍÑÇÌ«µØÓòµÄ»î¶¯¡£¡£¡£¡£¡£ÕâÊÇNetScaler ADCºÍNetScaler GatewayÉ豸ÖеÄÐÅϢй¶·ì϶£¨CVE-2023-4966£©£¬£¬£¬£¬£¬£¬£¬£¬×Ô8ÔÂÏÂÑ®ÒÔÀ´Ò»ÏòÔÚ±»ÀûÓᣡ£¡£¡£¡£ÀûÓ÷ì϶ºó£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß»á½øÐÐÍøÂç¿úËÅ¡¢ÇÔÈ¡ÕÊ»§Í´´¦²¢Í¨¹ýRDP½øÐкáÏòÒÆ¶¯¡£¡£¡£¡£¡£Mandiant°µÊ¾£¬£¬£¬£¬£¬£¬£¬£¬ÔÚ¸÷Àà»î¶¯ÖÐÀûÓÃCVE-2023-4966µÄ4¸ö¹¥»÷ÍŻ£¬£¬£¬£¬£¬£¬£¬ÔÚPost-Exploitation½×¶Î´æÔÚһЩ³Áµþ¡£¡£¡£¡£¡£
https://www.mandiant.com/resources/blog/session-hijacking-citrix-cve-2023-4966
5¡¢¶ñÒâNuGet°üÀûÓÃMSBuild¼¯³ÉÀ´·Ö·¢¶ñÒâÈí¼þ
ReversingLabsÔÚ10ÔÂ31ÈÕÅû¶ÁËͨ¹ý¶ñÒâNuGet°üÀ´·Ö·¢¶ñÒâÈí¼þµÄ»î¶¯¡£¡£¡£¡£¡£×êÑÐÈËÔ±ÓÚ10ÔÂ15ÈÕ·¢ÏÖÁË×îÐÂNuGet»î¶¯£¬£¬£¬£¬£¬£¬£¬£¬ÀûÓÃ·ÖÆçµÄƴдÃýÎóµÄÈí¼þ°üÀ´×°ÖöñÒâÈí¼þ¡£¡£¡£¡£¡£´Ë»î¶¯µÄÐÂÏÊÖ®´¦ÔÚÓÚ£¬£¬£¬£¬£¬£¬£¬£¬ÕâЩÈí¼þ°üûÓÐʹÓÃÔÚ×°Öþ籾ÖÐÖ²ÈëÏÂÔØ·¨Ê½µÄ³£Óò½Ö裬£¬£¬£¬£¬£¬£¬£¬¶øÊÇÀûÓÃNuGetµÄMSBuild¼¯³ÉÀ´Ö´ÐдúÂë¡£¡£¡£¡£¡£ÕâÊÇ8Ô³õÒÔÀ´µÄ³ÖÐø»î¶¯µÄÒ»²¿ÃÅ£¬£¬£¬£¬£¬£¬£¬£¬Ö±µ½10ÔÂÖÐÑ®£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õ߲ůðÍ·ÀûÓÃMSBuild¼¯³É¡£¡£¡£¡£¡£ÔçÆÚ°æ±¾ÀûÓÃPowerShell¾ç±¾£¨init.ps1£©´ÓGitHub´æ´¢¿â»ñÈ¡¶ñÒâÈí¼þpayload¡£¡£¡£¡£¡£
https://www.reversinglabs.com/blog/iamreboot-malicious-nuget-packages-exploit-msbuild-loophole
6¡¢Cisco°ä²¼¹ØÓÚArid Viper¹¥»÷»î¶¯µÄ·ÖÎö»ã±¨
10ÔÂ31ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬Cisco Talos°ä²¼Á˹ØÓÚArid Viper¹¥»÷»î¶¯µÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¸Ã»î¶¯×Ô2022Äê4ÔÂÆðÍ·»îÔ¾£¬£¬£¬£¬£¬£¬£¬£¬Ò»Ö¹Øë¶Ô°¢À²®ÓïµØÓò¡£¡£¡£¡£¡£¹¥»÷ÕßÀûÓÃαÔìµÄ¶ñÒâAndroidÀûÓ㬣¬£¬£¬£¬£¬£¬£¬Ö¼ÔÚ´ÓÖ¸±êÊÖ»úÖÐÍøÂçÊý¾Ý¡£¡£¡£¡£¡£ÓÐȤµÄÊÇ£¬£¬£¬£¬£¬£¬£¬£¬¸Ã¶ñÒâÈí¼þÓëÔ¼»áÈí¼þSkippedµÄÔ´´úÂëÀàËÆ£¬£¬£¬£¬£¬£¬£¬£¬ÕâÅú×¢ÔËÓªÍÅ»ïҪôÓëSkippedµÄ¿ª·¢ÈËÔ±ÓÐÁªÏµ£¬£¬£¬£¬£¬£¬£¬£¬ÒªÃ´·¸·¨»ñµÃÁËÏîÖ÷ÕŽӼûȨÏÞ¡£¡£¡£¡£¡£¹¥»÷Õß»á·Ö·¢¼Ù×°³ÉÔ¼»áÀûÓøüеĶñÒâÁ´½Ó£¬£¬£¬£¬£¬£¬£¬£¬´Ó¶ø½«¶ñÒâÈí¼þ×°Öõ½Óû§µÄÉ豸¡£¡£¡£¡£¡£
https://blog.talosintelligence.com/arid-viper-mobile-spyware/


¾©¹«Íø°²±¸11010802024551ºÅ