ÐÂÀÕË÷Èí¼þMalasLockerÒªÇóÄ¿µÄÏò´ÈÉÆ»ú¹¹¾èÇ®

Ðû²¼Ê±¼ä 2023-05-19

1¡¢ÐÂÀÕË÷Èí¼þMalasLockerÒªÇóÄ¿µÄÏò´ÈÉÆ»ú¹¹¾èÇ®


¾ÝýÌå5ÔÂ17ÈÕ±¨µÀ£¬£¬£¬£¬£¬ÐÂÀÕË÷Èí¼þMalasLockerͨ¹ýÈëÇÖZimbraЧÀÍÆ÷À´ÇÔÈ¡Óʼþ²¢¼ÓÃÜÎļþ¡£¡£¡£¡£¡£¡£µ«¹¥»÷Õß²¢Ã»ÓÐÒªÇóÄ¿µÄ½»Êê½ð£¬£¬£¬£¬£¬¶øÊÇÒªÇóËûÃÇÏòÖ¸¶¨µÄ·ÇÓªÀû´ÈÉÆ»ú¹¹¾èÇ®¡£¡£¡£¡£¡£¡£¸Ã»î¶¯Ê¼ÓÚ3ÔÂ⣬£¬£¬£¬£¬ÔÚ¼ÓÃܵç×ÓÓʼþʱ£¬£¬£¬£¬£¬Ëü²»»áÔÚÎļþÃû¸½¼ÓÌØÁíÍâÀ©Õ¹Ãû¡£¡£¡£¡£¡£¡£µ«ËûÃÇÔÚÿ¸ö¼ÓÃÜÎļþµÄĩβ¶¼¸½¼ÓÁËÒ»¸ö"´ËÎļþÒѼÓÃÜ£¬£¬£¬£¬£¬ÇëÉó²éREADME.txtÏàʶ½âÃÜ˵Ã÷"µÄÐÅÏ¢¡£¡£¡£¡£¡£¡£ÏÖÔÚÉв»ÇåÎú¹¥»÷ÕßÊÇÔõÑùÈëÇÖZimbraЧÀÍÆ÷¡£¡£¡£¡£¡£¡£MalasLockerµÄÍøÕ¾Ä¿ÒѹûÕæÈý¼Ò¹«Ë¾µÄÊý¾ÝºÍÆäËû169¸ö±»¹¥»÷ÕßµÄZimbraÉèÖᣡ£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/malaslocker-ransomware-targets-zimbra-servers-demands-charity-donation/


2¡¢AppleÐÞ¸´iPhone¡¢MacºÍiPadÖÐÈý¸öÒѱ»Ê¹ÓõÄÎó²î


5ÔÂ18ÈÕ£¬£¬£¬£¬£¬AppleÐû²¼Çå¾²¸üУ¬£¬£¬£¬£¬ÐÞ¸´ÁËiPhone¡¢MacºÍiPadÖÐÈý¸öÒѱ»Ê¹ÓõÄÎó²î¡£¡£¡£¡£¡£¡£ÕâЩÎó²î¾ùÔÚ¶àÆ½Ì¨WebKitä¯ÀÀÆ÷ÒýÇæÖб»·¢Ã÷£¬£¬£¬£¬£¬»®·ÖÊÇ¿ÉÓÃÀ´Í»ÆÆWebÄÚÈÝɳÏäµÄɳÏäÌÓÒÝÎó²î£¨CVE-2023-32409£©¡¢»á¼ûÃô¸ÐÐÅÏ¢µÄÔ½½ç¶ÁÈ¡Îó²î£¨CVE-2023-28204£©ºÍÖ´ÐÐí§Òâ´úÂëµÄÊͷźóʹÓÃÎó²î£¨CVE-2023-32373£©¡£¡£¡£¡£¡£¡£Appleͨ¹ýˢнçÏß¼ì²é¡¢ÊäÈëÑéÖ¤ºÍÄÚ´æÖÎÃ÷È·¾öÁËÕâЩÎÊÌ⣬£¬£¬£¬£¬Ã»ÓйûÕæÓйØÕâЩ¹¥»÷µÄÏêϸÐÅÏ¢¡£¡£¡£¡£¡£¡£×ÔÄêÍ·ÒÔÀ´£¬£¬£¬£¬£¬AppleÒÑÐÞ¸´ÁË6¸öÁãÈÕÎó²î¡£¡£¡£¡£¡£¡£ 


https://securityaffairs.com/146411/security/apple-3-new-zero-day-bugs.html


3¡¢BatLoaderÔÚ½üÆÚ¹¥»÷ÖÐð³äChatGPTºÍMidjourney


eSentireÔÚ5ÔÂ16ÈÕ³ÆÆä·¢Ã÷ÁËBatLoaderð³äChatGPTºÍMidjourneyµÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±³Æ£¬£¬£¬£¬£¬ÕâÁ½ÖÖAIЧÀͶ¼ºÜÊÇÊܽӴý£¬£¬£¬£¬£¬¿ÉÊÇûÓйٷ½µÄ×ÔÁ¦Ó¦ÓóÌÐò£¬£¬£¬£¬£¬Óû§Ö»ÄÜͨ¹ýÍøÂç½çÃæºÍDiscordÓëChatGPTºÍMidjourney½»»¥¡£¡£¡£¡£¡£¡£¹¥»÷ÕßʹÓÃÁËÕâÖÖ¿Õȱ£¬£¬£¬£¬£¬½«ËÑË÷AIÓ¦ÓóÌÐòµÄÓû§Òýµ½Ã°ÅÆÍøÒ³¡£¡£¡£¡£¡£¡£ÔÚð³äChatGPTµÄ»î¶¯ÖУ¬£¬£¬£¬£¬BatLoaderͨ¹ýMSIX Windows App InstallerÎļþºÍRedline StealerÀ´Ñ¬È¾×°±¸¡£¡£¡£¡£¡£¡£ÔÚð³äMidjourneyµÄ»î¶¯ÖУ¬£¬£¬£¬£¬»áÏÂÔØÓÉAshana Global Ltd.ÊðÃûµÄWindowsÓ¦ÓóÌÐò°ü¡£¡£¡£¡£¡£¡£


https://www.esentire.com/blog/batloader-impersonates-midjourney-chatgpt-in-drive-by-cyberattacks


4¡¢ÊÖÒÕÌṩÉÌScanSourceÔâµ½ÀÕË÷¹¥»÷ÍøÕ¾ÔÝʱÎÞ·¨»á¼û


¾Ý5ÔÂ17ÈÕ±¨µÀ£¬£¬£¬£¬£¬ÊÖÒÕÌṩÉÌScanSource͸¶ÆäÔâµ½ÀÕË÷¹¥»÷£¬£¬£¬£¬£¬²¿·Öϵͳ¡¢ÓªÒµÔËÓªºÍ¿Í»§ÃÅ»§Êܵ½Ó°Ïì¡£¡£¡£¡£¡£¡£5ÔÂ15ÈÕ×îÏÈ£¬£¬£¬£¬£¬ScanSourceµÄ¿Í»§³ÆÎÞ·¨»á¼û¹«Ë¾µÄÍøÕ¾¡£¡£¡£¡£¡£¡£Ö®ºó£¬£¬£¬£¬£¬¸Ã¹«Ë¾Ö¤ÊµËûÔÚ5ÔÂ14ÈÕÔâµ½ÁËÀÕË÷¹¥»÷¡£¡£¡£¡£¡£¡£´Ë´Î¹¥»÷µÄÓ°ÏìÊÇÖØ´óµÄ£¬£¬£¬£¬£¬ÓÉÓڸù«Ë¾Ëµ£¬£¬£¬£¬£¬ÔÚδÀ´Ò»¶Îʱ¼äÄÚ£¬£¬£¬£¬£¬Ïò¿Í»§ÌṩµÄЧÀͽ«»á·ºÆðÑÓ³Ù£¬£¬£¬£¬£¬Ô¤¼Æ½«Ó°Ïì±±ÃÀºÍ°ÍÎ÷µÄÓªÒµ¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬Æä¹É¼ÛÔÚ5ÔÂ17ÈÕϵøÁË1.42%£¬£¬£¬£¬£¬Õâ¿ÉÄÜÊǹ¥»÷Ôì³ÉµÄÓ°Ïì¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/scansource-says-ransomware-attack-behind-multi-day-outages/


5¡¢KasperskyÅû¶¶ñÒâ¿ó¹¤Minas¹¥»÷»î¶¯µÄÊÖÒÕϸ½Ú   

 

KasperskyÓÚ5ÔÂ17ÈÕÅû¶Á˶ñÒâ¿ó¹¤Minas¹¥»÷»î¶¯µÄÊÖÒÕϸ½Ú¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±´ÓÖ´ÐÐPowerShell×îÏÈÖØÐÞÁËËüµÄѬȾÁ´£ºPowerShell¾ç±¾Í¨¹ýʹÃüÍýÏë³ÌÐòÔËÐУ¬£¬£¬£¬£¬²¢´ÓÔ¶³ÌЧÀÍÆ÷ÏÂÔØlgntoerr.gifÎļþ£¬£¬£¬£¬£¬½âÃܺóÌìÉú.NET DLL£¬£¬£¬£¬£¬²¢´ÓÆä×ÊÔ´ÖÐÌáȡϢÕùÃÜÈý¸öÎļþ£¬£¬£¬£¬£¬×îºó»áÔÚÄÚ´æÖÐÌáÈ¡²¢Æô¶¯¿ó¹¤DLL¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±³Æ£¬£¬£¬£¬£¬MinasÊÇÒ»¸öʹÓñê׼ʵÏֵĿ󹤣¬£¬£¬£¬£¬Ö¼ÔÚÒþ²ØÆä±£´æ¡£¡£¡£¡£¡£¡£ÏÖÔÚÎÞ·¨Íêȫȷ¶¨×î³õµÄPowerShellÏÂÁîÊÇÔõÑùÖ´Ðе쬣¬£¬£¬£¬µ«ÖÖÖÖ¼£ÏóÅú×¢ÊÇͨ¹ýGPOÖ´Ðеġ£¡£¡£¡£¡£¡£


https://securelist.com/minas-miner-on-the-way-to-complexity/109692/


6¡¢Trend MicroÐû²¼¹ØÓÚ8220 GangÐÂÕ½ÂÔµÄÆÊÎö±¨¸æ


5ÔÂ16ÈÕ£¬£¬£¬£¬£¬Trend MicroÐû²¼Á˹ØÓÚ8220 GangÐÂÕ½ÂÔµÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¡£¸ÃÍÅ»ï×î½ü¼¸¸öÔÂÒ»Ö±ºÜ»îÔ¾£¬£¬£¬£¬£¬ËüʹÓÃÁËOracle WebLogic ServerÖеÄÎó²î£¨CVE-2017-3506£©À´·Ö·¢PowerShell£¬£¬£¬£¬£¬È»ºóÔÚÄÚ´æÖн¨ÉèÁíÒ»¸ö»ìÏýµÄPowerShell¾ç±¾¡£¡£¡£¡£¡£¡£Õâ¸öеľ籾»á½ûÓÃWindows AMSI¼ì²â²¢Æô¶¯Ò»¸öWindows¶þ½øÖÆÎļþ£¬£¬£¬£¬£¬ËüËæºó»áÅþÁ¬µ½Ô¶³ÌЧÀÍÆ÷ÒÔ¼ìË÷payload¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬¹¥»÷»¹Ê¹ÓÃÁËÒ»ÖÖÕýµ±Linux¹¤¾ßlwp-download£¬£¬£¬£¬£¬ÓÃÓÚÔÚÄ¿µÄÖ÷»úÉÏÉúÑÄí§ÒâÎļþ¡£¡£¡£¡£¡£¡£ 


https://www.trendmicro.com/en_us/research/23/e/8220-gang-evolution-new-strategies-adapted.html