LATRODECTUS²»Ðݸüв¢·Ö·¢ICEDIDºÍÆäËû¶ñÒâÈí¼þ
°ä²¼¹¦·ò 2024-05-225ÔÂ21ÈÕ£¬£¬£¬£¬£¬LATRODECTUSÓÚ 2023 Äê 10 ÔÂÓÉÎÖ¶ûÂê×êÑÐÈËÔ±³õ´Î·¢ÏÖ£¬£¬£¬£¬£¬ÊÇÒ»ÖÖÔÚÍøÂç·¸×ï·Ö×ÓÖÐÔ½À´Ô½Ê¢ÐеĶñÒâÈí¼þ¼ÓÔØ·¨Ê½¡£¡£¡£¡£¡£¹ÌÈ»Õâ±»ÒÔΪÊÇÒ»¸öеļÒ×壬£¬£¬£¬£¬µ«ÓÉÓÚÐÐΪºÍ·¢Õ¹ÀàËÆÐÔ£¬£¬£¬£¬£¬LATRODECTUS ºÍICEDIDÖ®¼ä´æÔÚçÇÃÜÁªÏµ£¬£¬£¬£¬£¬Ô̺¬ÏÂÔØºÍÖ´ÐмÓÃܸºÔØ£¨Èç ICEDID£©µÄºÅÁî´¦Ö÷¨Ê½¡£¡£¡£¡£¡£Proofpoint ºÍ Team Cymru »ùÓÚÕâÖÖÁªÏµ£¬£¬£¬£¬£¬·¢ÏÖÁËICEDID ºÍ LATRODECTUS ÔËÓªÉÌʹÓõÄÍøÂç»ù´¡Éèʩ֮¼ä´æÔÚçÇÃÜÁªÏµ¡£¡£¡£¡£¡£LATRODECTUS ÌṩÁËһϵÁÐÈ«ÃæµÄ³ß¶ÈÖ°ÄÜ£¬£¬£¬£¬£¬ÍþвÐÐΪÕßÄܹ»ÀûÓÃÕâЩְÄÜÀ´²¿Êð¸ü¶àµÄÓÐЧ¸ºÔØ£¬£¬£¬£¬£¬ÔÚ³õ²½ÈëÇÖºóÖ´Ðи÷Àà»î¶¯¡£¡£¡£¡£¡£´úÂë¿âδ¾¹ý»ìºÏ£¬£¬£¬£¬£¬½öÔ̺¬ 11 ¸öרһÓÚö¾ÙºÍÖ´ÐеĺÅÁî´¦Ö÷¨Ê½¡£¡£¡£¡£¡£ÕâÖÖÀàÐ͵ļÓÔØÆ÷´ú±íÁËÎÒÃÇÍŶÓ×î½ü¹Û²ìµ½µÄº£³±£¬£¬£¬£¬£¬ÀýÈçPIKABOT£¬£¬£¬£¬£¬ÆäÖдúÂëÔ½·¢ÇáÁ¿¼¶ºÍÖ±½Ó£¬£¬£¬£¬£¬´¦Ö÷¨Ê½ÊýÁ¿ÓÐÏÞ¡£¡£¡£¡£¡£
https://www.elastic.co/security-labs/spring-cleaning-with-latrodectus?&web_view=true
2. Kinsing¹¥»÷Apache Tomcat²¿ÊðÍÚ¿ó·¨Ê½
5ÔÂ20ÈÕ£¬£¬£¬£¬£¬Kinsing ¶ñÒâÈí¼þÒÔÀûÓà Linux ÔÆ·þÎñÆ÷Éϵķì϶²¿ÊðºóÃźͼÓÃÜÇ®±ÒÍÚ¿ó·¨Ê½¶øÎÅÃû£¬£¬£¬£¬£¬×î½ü½«ÆäÖ¸±êÀ©´óµ½Ô̺¬ Apache Tomcat ·þÎñÆ÷¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þÀûÓÃÐÂÏʵļ¼ÊõÀ´Ìӱܼì²â£¬£¬£¬£¬£¬½«×ÔÉí°µ²ØÔÚ¿´ËÆÎÞº¦µÄϵͳÎļþÖУ¬£¬£¬£¬£¬Ê¹ÆäÔÚÊÜϰȾµÄϵͳÉÏÓÆ¾Ã´æÔÚ£¬£¬£¬£¬£¬Í¹ÆðÁË Kinsing ²»ÐÝ·¢Õ¹µÄÕ½Êõ£¬£¬£¬£¬£¬²¢Ç¿µ÷ϵͳÖÎÀíÔ±±ØÒª¶ÔÕâЩÐÂÐËÍþвά³Ö¾¯Ìè¡£¡£¡£¡£¡£Kinsing ÀûÓÃÈÝÆ÷ºÍ·þÎñÆ÷Öеķì϶À´²¿ÊðºóÃźͼÓÃÜÍÚ¿ó·¨Ê½£¬£¬£¬£¬£¬µ÷²éÁ˾ÖÏÔʾ¶à¸ö·þÎñÆ÷Êܵ½Ï°È¾£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬ÓµÓÐÑϳÁȱµãµÄ Apache Tomcat¡£¡£¡£¡£¡£Tomcat ÊÇÒ»¿î¿É¹«¿ª½Ó¼ûµÄ¾²Ì¬ÄÚÈÝ¿ªÔ´·þÎñÆ÷£¬£¬£¬£¬£¬ÓÉÓÚÆäÔÚ»¥ÁªÍøÉϵͳö¶ø³ÉÎªÖØÒª¹¥»÷Ö¸±ê£¬£¬£¬£¬£¬ÕâʹµÃ Kinsing Äܹ»ÉøÈ뵽ϵͳÖв¢³ÉÁ¢°µ²ØµÄºóÃÅÒÔʵÏÖÓÆ¾ÃÐÔ£¬£¬£¬£¬£¬Í¬Ê±²¿Êð¼ÓÃÜ¿ó¹¤À´ÇÔÈ¡ÍÆËã×ÊÔ´ÒÔ½øÐмÓÃÜÇ®±ÒÍÚ¾ò¡£¡£¡£¡£¡£
https://gbhackers.com/kinsing-malware-apache-tomcat-servers/
3. SECÒªÇó½ðÈÚ×éÖ¯±ØÒªÔÚ 30 ÌìÄÚÅû¶Êý¾Ýй¶ÊÂÎñ
5ÔÂ21ÈÕ£¬£¬£¬£¬£¬ÃÀ¹ú֤ȯÂòÂôίԱ»á£¨SEC£©¶Ô SP ÂÉÀý½øÐÐÁËÅú¸Ä£¬£¬£¬£¬£¬ÒªÇó½ðÈÚ¹«Ë¾ÔÚ 30 ÌìÄڻ㱨Êý¾Ýй¶Çé¿ö¡£¡£¡£¡£¡£ÕâÊDZ£»£»£»£»£»£»£»£»¤Ïû·ÑÕßµÄÒ»ÃͽøÈ¡¡£¡£¡£¡£¡£ÕâÏîл®¶¨½«ÓÚ 2024 Äê 5 Ô 15 ÈÕÉúЧ£¬£¬£¬£¬£¬Ö¼ÔÚ¼ÓÇ¿ºÍ¸üжÔÏû·ÑÕß½ðÈÚÐÅÏ¢µÄ±£»£»£»£»£»£»£»£»¤¡£¡£¡£¡£¡£×Ô 2000 ÄêÍÆ³öÒÔÀ´£¬£¬£¬£¬£¬SEC ¼à¹Ü SPÒªÇó¾¼ÍÂòÂôÉÌ¡¢Í¶×ʹ«Ë¾ºÍ³ÖÅÆÍ¶×ÊÕÕ·÷ͨ¹ýÊéÃæÕþ²ßºÍ·¨Ê½±£»£»£»£»£»£»£»£»¤¿Í»§¼Í¼ºÍÐÅÏ¢¡£¡£¡£¡£¡£¸Ã¹æ¶¨»¹Ú¹ÊÏçËÈôºÎÕýȷɾ³ýÏû·ÑÕ߻㱨ÐÅÏ¢£¬£¬£¬£¬£¬²¢ÒªÇóÒþÖÔÕþ²ß֪ͨºÍÑ¡ÔñÍ˳öÑ¡Ïî¡£¡£¡£¡£¡£¶àÄêÀ´£¬£¬£¬£¬£¬¼¼ÊõµÄ½øÈ¡Ê¹µÃÊý¾Ýй¶µÄ¿ÉÄÜÐÔ¸ü´ó£¬£¬£¬£¬£¬Õâ¾ÍÊDZØÒªÕâЩŤתµÄÔÒò¡£¡£¡£¡£¡£
https://gbhackers.com/financial-organizations-data-breach/
4. Git Ô¶³Ì´úÂëÖ´Ðзì϶CVE-2024-32002
5ÔÂ21ÈÕ£¬£¬£¬£¬£¬×êÑÐÍŶӷ¢ÏÖÁËÒ»¸öÑϳÁµÄÔ¶³Ì´úÂëÖ´Ðзì϶£¬£¬£¬£¬£¬¸Ã·ì϶±»Ö¸¶¨Îª CVE-2024-32002£¬£¬£¬£¬£¬ÑϳÁˮƽΪ 9.0£¨ÑϳÁ£©¡£¡£¡£¡£¡£Õâ¸öÌØÊâµÄ·ì϶´æÔÚÓÚ¿í·ºÊ¹ÓõÄcloneºÅÁîÖÓ×£¡£¡£¡£¡£Git ÉÏÖܰ䲼ÁËÒ»·Ý°²È«²¼¸æ£¬£¬£¬£¬£¬ÆäÖÐÖ¸³öÁËÓйØÔ¶³Ì´úÂëÖ´ÐеÄÎÊÌâ¡£¡£¡£¡£¡£³ý´ËÖ®±í£¬£¬£¬£¬£¬¸Ã·ì϶±»ÃèÊöΪÓÉÓÚÄܹ»ÒÔÌØ¶¨·½Ê½²ÝÄâµÄ×ÓÄ£¿£¿£¿£¿£¿£¿é¶ø´æÔÚ£¬£¬£¬£¬£¬´Ó¶ø¿ÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐÓ×£¡£¡£¡£¡£²»ÍâÕâ¸ö·ì϶ÒѾ±»git½¨¸´£¬£¬£¬£¬£¬²¢ÇÒ°ä²¼Á˽¨²¹°æ±¾¡£¡£¡£¡£¡£Æ¾¾ÝÍøÂ簲ȫÐÂÎÅ·ÖÏíµÄ»ã±¨£¬£¬£¬£¬£¬git ʹÓÃ×ÓÄ£¿£¿£¿£¿£¿£¿é£¬£¬£¬£¬£¬ÕâЩ×ÓÄ£¿£¿£¿£¿£¿£¿éÊÇǶÌ×ÔÚÆäËû´æ´¢¿âÖеĴ洢¿â¡£¡£¡£¡£¡£Ã¿¸ö×ÓÄ£¿£¿£¿£¿£¿£¿éÔÚÖ÷Ŀ¼Öж¼ÓÐÒ»¸öÖ¸¶¨µÄĿ¼õè¾¶£¬£¬£¬£¬£¬¸ÃĿ¼õè¾¶»á±»¸ú×ÙÒÔÈ·±£ÕýÈ·¼Í¼¸ü¸Ä¡£¡£¡£¡£¡£½øÒ»²½¹Û²ì·¢ÏÖ£¬£¬£¬£¬£¬Windows£¨A/modules/x£©ºÍmacOS£¨a/modules/x£©µÄĬÈÏÉèÖÃÖдæÔÚ²»·Ö±æ´óÓ×дµÄÎļþϵͳ¡£¡£¡£¡£¡£ÕâÁ½¸öõè¾¶µÄ´¦Ö÷½Ê½Ò»Ñù£¬£¬£¬£¬£¬ÕâÊÇÔ¶³Ì´úÂëÖ´Ðб³ºóµÄÖØÒªÔÒò¡£¡£¡£¡£¡£
https://gbhackers.com/git-flaw-remote-code-execution/
5. Fluent Bit ÑϳÁȱµãÓ°ÏìËùÓÐÖØÒªÔÆÌṩÉÌ
5ÔÂ21ÈÕ£¬£¬£¬£¬£¬¿ÉÔڻؾø·þÎñºÍÔ¶³Ì´úÂëÖ´Ðй¥»÷ÖÐÀûÓõĹؼü Fluent Bit ·ì϶ӰÏìÁËËùÓÐÖØÒªÔÆÌṩÉ̺ͺܶ༼Êõ¾ÞÍ·¡£¡£¡£¡£¡£Fluent Bit ÊÇÒ»ÖÖ¼«¶ÈÊ¢ÐеÄÈÕÖ¾¼Í¼ºÍÖ¸±ê½â¾ö¹æ»®£¬£¬£¬£¬£¬ºÏÓÃÓÚ Windows¡¢Linux ºÍ macOS£¬£¬£¬£¬£¬Ç¶ÈëÔÚÖØÒª Kubernetes ¿¯ÐаæÖУ¬£¬£¬£¬£¬Ô̺¬À´×Ô Amazon AWS¡¢Google GCP ºÍ Microsoft Azure µÄ¿¯Ðа档¡£¡£¡£¡£½ØÖÁ 2024 Äê 3 Ô£¬£¬£¬£¬£¬Fluent Bit µÄÏÂÔØºÍ²¿Êð´ÎÊý³¬¹ý 130 ÒڴΣ¬£¬£¬£¬£¬½Ï 2022 Äê 10 Ô±¨Â·µÄ30 ÒÚ´ÎÏÂÔØÁ¿´ó·ùÔö³¤¡£¡£¡£¡£¡£Fluent Bit Ò²±» Crowdstrike ºÍ Trend Micro µÈÍøÂ簲ȫ¹«Ë¾ÒÔ¼°Ë¼¿Æ¡¢VMware¡¢Ó¢Ìضû¡¢Adobe ºÍ´÷¶ûµÈºÜ¶à¿Æ¼¼¹«Ë¾Ê¹Óᣡ£¡£¡£¡£Õâ¸öÑϳÁµÄÄÚ´æ°Ü»µ·ì϶±»¸ú×ÙΪCVE-2024-4323£¬£¬£¬£¬£¬²¢±»·¢Ïָ÷ì϶µÄ Tenable °²È«×êÑÐÈËÔ±³ÆÎªLinguistic Lumberjack£¬£¬£¬£¬£¬ËüÊÇÔÚ°æ±¾ 2.0.7 ÖÐÒýÈëµÄ£¬£¬£¬£¬£¬ÊÇÓÉ Fluent Bit µÄǶÈëʽ HTTP ·þÎñÆ÷½âÎö¸ú×ÙÒªÇóÖеĶѻº³åÇøÒç¶Âí½ÅÒýÆðµÄ¡£¡£¡£¡£¡£Ö»¹Üδ¾Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÄܹ»ÇáËÉÀûÓøð²È«·ì϶À´´¥·¢»Ø¾ø·þÎñ»òÔ¶³Ì²¶»ñÃô¸ÐÐÅÏ¢£¬£¬£¬£¬£¬µ«ÈôÊÇÓÐÊʵ±µÄǰÌáºÍ×ã¹»µÄ¹¦·òÀ´´´½¨¿¿µÃסµÄ·ì϶£¬£¬£¬£¬£¬ËûÃÇÒ²Äܹ»Ê¹ÓÃËüÀ´»ñµÃÔ¶³Ì´úÂëÖ´ÐÓ×£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/critical-fluent-bit-flaw-impacts-all-major-cloud-providers/
6. AntidotľÂí¼Ù×°³ÉGoogle Play¸üУ¬£¬£¬£¬£¬ÇÔÈ¡ÒøÐÐÊý¾Ý
5ÔÂ22ÈÕ£¬£¬£¬£¬£¬CybleµÄ×êÑÐÈËÔ±·¢ÏÖÁËÒ»ÖÖÕë¶Ô Android É豸µÄÐÂÒøÐÐľÂí¡£¡£¡£¡£¡£ÕâÖÖ¸´ÔӵĶñÒâÈí¼þÓµÓжàÖÖΣÏÕÖ°ÄÜ£¬£¬£¬£¬£¬Ô̺¬¸²¸Ç¹¥»÷¡¢¼üÅ̼ͼºÍ»ìºÏ¼¼Êõ¡£¡£¡£¡£¡£¸ÃľÂíÆ¾¾ÝÆäÔ´´úÂëÖеÄ×Ö·û´®¶¨ÃûΪ¡°Antidot¡±£¬£¬£¬£¬£¬ÒÔ¼Ù×°³É¹Ù·½ Google Play ¸üв¢Ö§³Ö¶àÖÖ˵»°¶øÎÅÃû£¬£¬£¬£¬£¬Ô̺¬Ó¢Óï¡¢µÂÓï¡¢·¨Óï¡¢Î÷°àÑÀÓï¡¢ÆÏÌÑÑÀÓï¡¢ÂÞÂíÄáÑÇÓ£¬£¬£¬£¬ÉõÖÁ¶íÓï¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þ×÷Ϊ Google Play µÄ¸üнøÐзַ¢£¬£¬£¬£¬£¬²¢ÒÔ¡°Ð°汾¡±µÄÃû³Æ³Ê´Ë¿ÌÊܺ¦ÕßµÄÉ豸ÉÏ¡£¡£¡£¡£¡£×°Öúͳõ´ÎÆô¶¯ºó£¬£¬£¬£¬£¬Óû§»á¿´µ½Ò»¸ö¼ÙÒ³Ãæ£¬£¬£¬£¬£¬¾Ý³ÆÀ´×Ô Google Play£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬ÊµÏÖ¸üÐÂËùÐè²Ù×÷µÄ¾ßÌå×¢Ã÷¡£¡£¡£¡£¡£
https://meterpreter.org/new-antidot-trojan-masquerades-as-google-play-update-steals-banking-data/


¾©¹«Íø°²±¸11010802024551ºÅ