΢Èí°ä²¼11Ô°²È«¸üн¨¸´3¸öÒѱ»ÀûÓõķì϶
°ä²¼¹¦·ò 2023-11-15΢ÈíÔÚ11ÔÂ14ÈÕ°ä²¼Á˱¾ÔµÄÖܶþ²¹¶¡£¡£¡£¡£¡£¡£¡£¡£¬£¬£¬£¬£¬×ܼƽ¨¸´ÁË58¸ö·ì϶£¬£¬£¬£¬£¬Ô̺¬5¸ö0day¡£¡£¡£¡£¡£¡£¡£¡£Õâ´Î½¨¸´µÄ0dayÖУ¬£¬£¬£¬£¬WindowsÔÆÎļþ΢ÐÍɸѡÆ÷Çý¶¯·¨Ê½ÌáȨ·ì϶£¨CVE-2023-36036£©¡¢Windows DWMÖ÷Ìâ¿âÌáȨ·ì϶£¨CVE-2023-36033£©ºÍWindows SmartScreen°²È«Ö°ÄÜÈÆ¹ý·ì϶£¨CVE-2023-36025£©Òѱ»ÀûÓ㬣¬£¬£¬£¬Microsoft Office°²È«Ö°ÄÜÈÆ¹ý·ì϶£¨CVE-2023-36413£©ºÍASP.NET Core»Ø¾ø·þÎñ·ì϶£¨CVE-2023-36038£©Ò²Òѱ»¹«¿ªÅû¶¡£¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/microsoft/microsoft-november-2023-patch-tuesday-fixes-5-zero-days-58-flaws/
2¡¢SektorCERTÅû¶µ¤ÂóµÄ»ù´¡ÉèÊ©Ôâµ½´ó¹æÄ£¹¥»÷
¾Ý11ÔÂ14ÈÕ±¨Â·£¬£¬£¬£¬£¬µ¤Â󹨼ü²¿ÃŵķÇͶ»úÍøÂ簲ȫÖÐÐÄSektorCERTÅû¶£¬£¬£¬£¬£¬Æä¹Ø¼ü»ù´¡ÉèÊ©Ôâµ½ÁËÓÐÊ·ÒÔÀ´×î´ó¹æÄ£µÄÍøÂç¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£µÚÒ»²¨¹¥»÷ÓÚ5ÔÂ11ÈÕÌáÒ飬£¬£¬£¬£¬¶ÌÔÝͣϢºó£¬£¬£¬£¬£¬µÚ¶þ²¨¹¥»÷ÓÚ5ÔÂ22ÈÕÆðÍ·£¬£¬£¬£¬£¬SektorCERTÓÚ5ÔÂ22ÈÕÒâʶµ½ÕâЩ¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÀûÓÃZyxel·À»ðǽÖеķì϶£¨CVE-2023-28771£©£¬£¬£¬£¬£¬ÈëÇÖÁË22¼Ò´ÓÊÂÄÜÔ´»ù´¡ÉèÊ©ÔËÓªµÄ¹«Ë¾¡£¡£¡£¡£¡£¡£¡£¡£SektorCERTÒÔΪ£¬£¬£¬£¬£¬¹¥»÷Õß°ÑÎÕÁËÖ¸±êµÄ¾ßÌåÐÅÏ¢£¬£¬£¬£¬£¬ºÜ¿ÉÄÜÊÇͨ¹ý֮ǰδ±»·¢ÏֵĿúËÅ»î¶¯ÍøÂçµÄ¡£¡£¡£¡£¡£¡£¡£¡£²¢ÇÒÕâЩ¹¥»÷¿ÉÄÜÊǶà¸öÍÅ»ïÖ´Ðе쬣¬£¬£¬£¬ÆäÖÐÖÁÉÙÓÐÒ»¸ö¿É¹éÒòÓÚSandworm¡£¡£¡£¡£¡£¡£¡£¡£
https://securityaffairs.com/154156/apt/denmark-critical-infrastructure-record-attacks.html
3¡¢RoyalÒÑÈëÇÖÖÁÉÙ350¸öÖ¸±ê²¢ÀÕË÷³¬¹ý2.75ÒÚÃÀÔª
11ÔÂ13ÈÕ£¬£¬£¬£¬£¬FBIºÍCISA°ä²¼Á˹ØÓÚÀÕË÷Èí¼þRoyalµÄ½áºÏÍøÂ簲ȫÕ÷ѯ(CSA)¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÕ÷ѯָ³ö£¬£¬£¬£¬£¬×Ô2022Äê9ÔÂÒÔÀ´£¬£¬£¬£¬£¬RoyalÒѹ¥»÷È«Çò350¶à¸öÖ¸±ê£¬£¬£¬£¬£¬Ìá³öÁ˳¬¹ý2.75ÒÚÃÀÔªµÄÀÕË÷ÒªÇ󡣡£¡£¡£¡£¡£¡£¡£´¹µöÓʼþÊÇRoyal½øÐгõʼ½Ó¼ûµÄ×î³É¹¦µÄÔØÌåÖ®Ò»¡£¡£¡£¡£¡£¡£¡£¡£Óм£ÏóÅú×¢£¬£¬£¬£¬£¬Royal¿ÉÄÜÔÚ뻮ၮ³ÁËܺÍ/»òÑÜÉú±äÌå×ö³ï±¸£¬£¬£¬£¬£¬ÀÕË÷Èí¼þBlacksuitÓµÓкܶàÓëRoyalÀàËÆµÄ±àÂëÌØµã¡£¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/fbi-royal-ransomware-asked-350-victims-to-pay-275-million/
4¡¢HuntersÐû³ÆÒÑÍøÂçHomeland¹«Ë¾³¬¹ý200GBµÄÊý¾Ý
¾ÝýÌå11ÔÂ13ÈÕ±¨Â·£¬£¬£¬£¬£¬Hunters International½«ÃÀ¹úÎïÒµÖÎÀí¹«Ë¾HomelandÔö³¤µ½ÁËÆäÍøÕ¾ÖС£¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÐû³ÆÒÑÍøÂç183793¸öÎļþ£¬£¬£¬£¬£¬¹²204.1GB£¬£¬£¬£¬£¬»¹ÔÚÍøÕ¾Éϰ䲼ÁËÒ»·ÝÎļþÑù±¾×÷ΪÀÕË÷Ö¤¾Ý¡£¡£¡£¡£¡£¡£¡£¡£Ñù±¾ÎļþÔ̺¬×â»§µÄµ®ÉúÈÕÆÚ¡¢µØÖ·¡¢ÄêÊÕÈëºÍ×â½ð¾ßÌåÐÅÏ¢µÈÓ×ÎÒÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£Huntersй©¹¥»÷²úÉúÓÚ10ÔÂ26ÈÕ£¬£¬£¬£¬£¬ËûÃÇÂú×ãHomelandµÄÒªÇóÌṩ½âÃܹ¤¾ßÑÝʾºÍй¶Êý¾ÝÑù±¾ºóûÓÐÊÕµ½Èκλظ´£¬£¬£¬£¬£¬»¹°µÊ¾¸Ã¹«Ë¾±ØÒªÔÚ11ÔÂ18ÈÕ֮ǰ×ö³ö»ØÓ¦¡£¡£¡£¡£¡£¡£¡£¡£
https://www.databreaches.net/property-management-firm-homeland-inc-allegedly-hacked-hackers-claim-to-have-hundreds-of-thousands-of-ssn-of-tenants/
5¡¢AhnLab¼ì²âµ½ÀûÓÃDdostf¹¥»÷MySQL·þÎñÆ÷µÄ»î¶¯
AhnLabÓÚ11ÔÂ14Èճƣ¬£¬£¬£¬£¬×î½ü·¢´Ë¿ÌMySQL·þÎñÆ÷ÉÏ×°ÖÃDdostfµÄ»î¶¯¡£¡£¡£¡£¡£¡£¡£¡£DDdostfÊÇÒ»ÖÖDDoS bot£¬£¬£¬£¬£¬¶ÔÌØ¶¨Ö¸±êÖ´ÐÐDDoS¹¥»÷£¬£¬£¬£¬£¬ÓÚ2016Äê×óÓÒ³õ´Î±»·¢ÏÖ¡£¡£¡£¡£¡£¡£¡£¡£Ôڿɹ«¿ª½Ó¼ûµÄϵͳÖУ¬£¬£¬£¬£¬É¨Ã跨ʽ»áËÑË÷ʹÓÃ3306/TCP¶Ë¿ÚµÄϵͳ£¬£¬£¬£¬£¬¶øºóÖ´Ðб©Á¦¹¥»÷»ò×ֵ乥»÷£¬£¬£¬£¬£¬»¹¿ÉÄܽӼûÖÎÀíÔ¹ØÊ»§Í´´¦¡£¡£¡£¡£¡£¡£¡£¡£ÈôÊÇϵͳÔËÐеÄÊÇ´æÔÚ·ì϶µÄ佨¸´°æ±¾£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶À´Ö´ÐкÅÁ£¬£¬£¬£¬¶øÎÞÐèÉÏÊö¹ý³Ì¡£¡£¡£¡£¡£¡£¡£¡£Ö¸±êϵͳµÄϰȾÈÕÖ¾Åú×¢£¬£¬£¬£¬£¬³ýÁËDdostfÖ®±í£¬£¬£¬£¬£¬Ö¸±êϵͳÉÏ»¹±»×°ÖÃÁ˶ñÒâUDF DLL¡£¡£¡£¡£¡£¡£¡£¡£
https://asec.ahnlab.com/en/58878/
6¡¢Cado·¢ÏÖÕë¶ÔDocker Engine APIµÄ½©Ê¬ÍøÂçOracleIV
11ÔÂ13ÈÕ£¬£¬£¬£¬£¬CadoÅû¶ÁË×î½ü·¢ÏÖµÄһ·Õë¶Ô¹«¿ªDocker Engine APIÊ·ýµÄл¡£¡£¡£¡£¡£¡£¡£¡£Ôڴ˻ÖУ¬£¬£¬£¬£¬¹¥»÷ÕßÀûÓÃDockerÈÝÆ÷ÖеÄÃýÎóÅäÖÃÀ´´«²¼±àÒëΪELF¿ÉÖ´ÐÐÎļþµÄPython¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þ×ÔÉí³äÈÎDDoS bot´úÀí£¬£¬£¬£¬£¬¿ÉÄÜͨ¹ý¶àÖÖ²½Öè½øÐÐDoS¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£ÔÚеÄOracleIV DDoS½©Ê¬ÍøÂç¶ñÒâÈí¼þÖУ¬£¬£¬£¬£¬¹¥»÷Õßͨ¹ýHTTP POSTÒªÇóÆô¶¯¶ÔDocker APIµÄ½Ó¼û¡£¡£¡£¡£¡£¡£¡£¡£Õâ»á´¥·¢docker pullºÅÁ£¬£¬£¬£¬´ÓDockerhub»ñȡָ¶¨¾µÏñ¡£¡£¡£¡£¡£¡£¡£¡£
https://www.cadosecurity.com/oracleiv-a-dockerised-ddos-botnet/


¾©¹«Íø°²±¸11010802024551ºÅ