Winter Vivern ͨ¹ý Roundcube ȱÏÝÃé×¼ 80 ¶à¸ö×éÖ¯
Ðû²¼Ê±¼ä 2024-02-202ÔÂ19ÈÕ£¬£¬£¬£¬£¬Óë°×¶íÂÞ˹ºÍ¶íÂÞ˹ÀûÒæÒ»ÖµÄÍþвÐÐΪÕßÓëÒ»ÏîеÄÍøÂçÌØ¹¤»î¶¯Óйأ¬£¬£¬£¬£¬¸Ã»î¶¯¿ÉÄÜʹÓà Roundcube ÍøÂçÓʼþЧÀÍÆ÷ÖеĿçÕ¾¾ç±¾ (XSS) Îó²îÀ´Õë¶Ô 80 ¶à¸ö×éÖ¯¡£¡£¡£¡£¡£¡£¾Ý Recorded Future ³Æ£¬£¬£¬£¬£¬ÕâЩʵÌåÖ÷ҪλÓÚ¸ñ³¼ªÑÇ¡¢²¨À¼ºÍÎÚ¿ËÀ¼£¬£¬£¬£¬£¬¸Ã¹«Ë¾½«Õâ´ÎÈëÇÖ¹éÒòÓÚÃûΪ Winter Vivern µÄÍþвÐÐΪÕߣ¬£¬£¬£¬£¬¸ÃÍþвÕßÒ²±»³ÆÎª TA473 ºÍ UAC0114¡£¡£¡£¡£¡£¡£¸ÃÍøÂçÇå¾²¹«Ë¾ÕýÔÚ×·×ÙÃûΪ¡°Íþв»î¶¯×éÖ¯ 70¡±(TAG-70) µÄºÚ¿Í×éÖ¯¡£¡£¡£¡£¡£¡£Recorded Future ·¢Ã÷µÄÕⳡ»î¶¯´Ó 2023 Äê 10 ÔÂ×îÏÈÒ»Ö±Ò»Á¬µ½±¾ÔÂÖÐÑ®£¬£¬£¬£¬£¬Ä¿µÄÊÇÍøÂçÓйØÅ·ÖÞÕþÖκ;üÊ»µÄÇ鱨¡£¡£¡£¡£¡£¡£ÕâЩ¹¥»÷Óë 2023 Äê 3 Ô¼ì²âµ½µÄÕë¶ÔÎÚ×ȱð¿Ë˹̹Õþ¸®ÓʼþЧÀÍÆ÷µÄÆäËû TAG-70 »î¶¯Öصþ¡£¡£¡£¡£¡£¡£Recorded FutureÌåÏÖ£¬£¬£¬£¬£¬»¹·¢Ã÷ÁËTAG-70Õë¶ÔÒÁÀÊפ¶íÂÞ˹ºÍºÉÀ¼´óʹ¹ÝÒÔ¼°¸ñ³¼ªÑÇפÈðµä´óʹ¹ÝµÄÖ¤¾Ý¡£¡£¡£¡£¡£¡£
https://thehackernews.com/2024/02/russian-linked-hackers-breach-80.html
2.ÒÁÀʺڿÍʹÓÃÐ嵀 BASICSTAR ºóÃÅÃé×¼Öж«Õþ²ßר¼Ò
2ÔÂ19ÈÕ£¬£¬£¬£¬£¬ÃûΪ Charming Kitten µÄÒÁÀÊÒáÍþвÐÐΪÕßͨ¹ý½¨ÉèÒ»¸öÐéαµÄÍøÂç×êÑлáÃÅ»§£¬£¬£¬£¬£¬Í¨¹ýÃûΪBASICSTARµÄкóÃÅ£¬£¬£¬£¬£¬ÓëһϵÁÐÕë¶ÔÖж«Õþ²ßר¼ÒµÄй¥»÷Óйء£¡£¡£¡£¡£¡£Charming Kitten£¬£¬£¬£¬£¬Ò²³ÆÎª APT35¡¢CharmingCypress¡¢Mint Sandstorm¡¢TA453 ºÍ Yellow Garuda£¬£¬£¬£¬£¬ÓÐ×Ų߻®ÖÖÖÖÉç»á¹¤³Ì»î¶¯µÄÀúÊ·£¬£¬£¬£¬£¬ÕâЩ»î¶¯ÔÚÆäÄ¿µÄÉÏÈöÏÂÁËÆÕ±éµÄÍøÂ磬£¬£¬£¬£¬Í¨³£×¨ÃÅÕë¶ÔÖǿ⡢·ÇÕþ¸®×éÖ¯ºÍ¼ÇÕß¡£¡£¡£¡£¡£¡£¸Ã×éÖ¯±»ÆÀ¹ÀΪÁ¥ÊôÓÚÒÁÀÊÒÁ˹À¼¸ïÃüÎÀ¶Ó (IRGC)£¬£¬£¬£¬£¬ÔÚÒÑÍùÒ»ÄêÖл¹·Ö·¢ÁËÆäËû¼¸¸öºóÃÅ£¬£¬£¬£¬£¬ÀýÈçPowerLess¡¢BellaCiao¡¢POWERSTAR£¨ÓÖÃû GorjolEcho£©ºÍNokNok £¬£¬£¬£¬£¬Ç¿µ÷Æä¼ÌÐø¾ÙÐÐÍøÂç¹¥»÷µÄ¿ÌÒâÖ»¹Ü¹ûÕæÆØ¹â£¬£¬£¬£¬£¬µ«ÈÔµ÷½âÆäÕ½ÂÔºÍÒªÁì¡£¡£¡£¡£¡£¡£2023 Äê 9 ÔÂÖÁ 10 ÔÂʱ´úÊӲ쵽µÄÍøÂç´¹ÂÚ¹¥»÷Éæ¼° Charming Kitten ÔËÓªÉÌð³ä Rasanah ¹ú¼ÊÒÁÀÊÑо¿Ëù (IIIS) Ìᳫ¹¥»÷²¢ÓëÄ¿µÄ½¨ÉèÐÅÈΡ£¡£¡£¡£¡£¡£¹¥»÷Á´Í¨³£Ê¹ÓðüÀ¨ LNK ÎļþµÄ RAR ´æµµ×÷Ϊ·Ö·¢¶ñÒâÈí¼þµÄÆðµã£¬£¬£¬£¬£¬²¢Í¨¹ýÐÂÎű޲ßDZÔÚÄ¿µÄ¼ÓÈëÓйØËûÃǸÐÐËȤµÄÖ÷ÌâµÄÐéÎ±ÍøÂç×êÑлᡣ¡£¡£¡£¡£¡£ÒÑÊӲ쵽°²ÅÅ BASICSTAR ºÍ KORKULOADER£¨Ò»ÖÖ PowerShell ÏÂÔØÆ÷¾ç±¾£©µÄ´ËÀà¶à½×¶ÎѬȾÐòÁС£¡£¡£¡£¡£¡£
https://thehackernews.com/2024/02/iranian-hackers-target-middle-east.html
3.ºÚ¿ÍÉù³ÆÈËÁ¦×ÊÔ´¾ÞÍ· Robert Half Êý¾Ýй¶²¢³öÊÛÃô¸ÐÊý¾Ý
2ÔÂ18ÈÕ£¬£¬£¬£¬£¬ÕâЩÎÛÃûÕÑÖøµÄºÚ¿Í»®·ÖÊÇ IntelBroker ºÍ Sanggiero£¬£¬£¬£¬£¬ËûÃÇÉù³ÆÓµÓÐ Robert Half µÄ´ó×ÚÊý¾Ý£¬£¬£¬£¬£¬ÕâЩÊý¾ÝÕýÔÚÒÔÃÅÂÞ±Ò (XMR) ¼ÓÃÜÇ®±ÒµÄ¼ÛÇ®³öÊÛ£¬£¬£¬£¬£¬ÊÛ¼ÛΪ 20,000 ÃÀÔª¡£¡£¡£¡£¡£¡£2022 Äê 6 Ô£¬£¬£¬£¬£¬È«ÇòÈËÁ¦×ÊÔ´ºÍÉÌÒµ×ÉѯЧÀ͹«Ë¾ Robert Half International Inc. ÏòÃåÒòÖÝ×ÜÉó²é³¤°ì¹«ÊÒÌá½»ÁËÊý¾Ýй¶֪ͨ¡£¡£¡£¡£¡£¡£Í¨Öª³Æ£¬£¬£¬£¬£¬¸Ã¹«Ë¾ÔâÓöÊý¾Ýй¶£¬£¬£¬£¬£¬ºÚ¿ÍÕë¶Ô 1000 ¶àÃû¿Í»§£¬£¬£¬£¬£¬ÀֳɻñÈ¡ÁËËûÃǵÄÐÕÃû¡¢µØµã¡¢Éç»áÇå¾²ºÅÂëºÍ˰ÎñÐÅÏ¢¡£¡£¡£¡£¡£¡£ºÚ¿Í»¹·ÖÏíÁ˾ݳÆÏÔʾ±»µÁÊý¾Ý¡¢Git ´æ´¢¿âºÍ AWS Ïà¹ØÏµÍ³ÉèÖÃµÄÆÁÄ»½ØÍ¼¡£¡£¡£¡£¡£¡£Ò»ÕÅÆÁÄ»½ØÍ¼ËƺõÏÔʾÁËÒ»·Ý¿Í»§ÁÐ±í£¬£¬£¬£¬£¬¡°ÕÊ»§Ãû³Æ¡±ÏÂÁгöÁ˹«Ë¾£¬£¬£¬£¬£¬²¢¸½ÓÐÈ«Ãû¡¢Ö÷ÒªÖ°ÄܽÇÉ«¡¢Í·Ïκ͵绰ºÅÂë¡£¡£¡£¡£¡£¡£
https://www.hackread.com/hackers-claim-robert-half-data-breach/
4.Turla APT ʹÓÃTinyTurla-NGÖ¼ÔÚÇÔÈ¡µÇ¼ƾ֤
https://gbhackers.com/turla-aptc-new-tool/
5.ESET ÐÞ¸´ WINDOWS ²úÆ·ÖеÄÑÏÖØÐÔÍâµØÈ¨ÏÞÉý¼¶Îó²î
2ÔÂ18ÈÕ£¬£¬£¬£¬£¬ESET ½â¾öÁËÆä Windows ²úÆ·ÖеÄÒ»¸ö¸ßÑÏÖØÐÔÎó²î£¬£¬£¬£¬£¬±àºÅΪ CVE-2024-0353£¨CVSS ÆÀ·Ö 7.8£©¡£¡£¡£¡£¡£¡£¸ÃÎó²îÊÇÒ»¸öÍâµØÈ¨ÏÞÉý¼¶ÎÊÌ⣬£¬£¬£¬£¬ÓÉÁãÈÕÍýÏë (ZDI) Ìá½»¸ø¸Ã¹«Ë¾¡£¡£¡£¡£¡£¡£Æ¾Ö¤¸Ãת´ï£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔÀÄÓà ESET µÄÎļþ²Ù×÷£¨ÓÉʵʱÎļþϵͳ±£»£»£»£»¤Ö´ÐУ©£¬£¬£¬£¬£¬ÔÚûÓÐÊʵ±È¨ÏÞµÄÇéÐÎÏÂɾ³ýÎļþ¡£¡£¡£¡£¡£¡£ÓÉ Windows ²Ù×÷ϵͳÉϵÄʵʱÎļþϵͳ±£»£»£»£»¤¹¦Ð§Ö´ÐеÄÎļþ²Ù×÷´¦Öóͷ£ÖеÄÎó²î£¬£¬£¬£¬£¬¿ÉÄÜÔÊÐíÄܹ»ÔÚÄ¿µÄϵͳÉÏÖ´ÐеÍÌØÈ¨´úÂëµÄ¹¥»÷Õßɾ³ý NT AUTHORITY\SYSTEM ϵÄí§ÒâÎļþ£¬£¬£¬£¬£¬ÌáÉýËûÃǵÄÌØÈ¨¡£¡£¡£¡£¡£¡£ESET ÉÐδ·¢Ã÷ʹÓôËÎó²î¾ÙÐеÄÒ°Íâ¹¥»÷»î¶¯¡£¡£¡£¡£¡£¡£
https://securityaffairs.com/159280/breaking-news/eset-local-privilege-escalation-windows.html
6. SOLARWINDS ÐÞ¸´ ACCESS RIGHTS MANAGER ÖеÄÒªº¦ RCE
2ÔÂ19ÈÕ£¬£¬£¬£¬£¬SolarWinds ½â¾öÁËÆä»á¼ûȨÏÞÖÎÀíÆ÷ (ARM) ½â¾ö¼Æ»®ÖеÄÈý¸öÒªº¦Îó²î£¬£¬£¬£¬£¬ÆäÖаüÀ¨Á½¸ö RCE ¹ýʧ¡£¡£¡£¡£¡£¡£»á¼ûȨÏÞÖÎÀíÆ÷ (ARM) ÊÇÒ»¿îÈí¼þ½â¾ö¼Æ»®£¬£¬£¬£¬£¬Ö¼ÔÚ×ÊÖú×éÖ¯ÖÎÀíºÍ¼à¿ØÆä IT »ù´¡ÉèÊ©ÄڵĻá¼ûȨÏÞºÍȨÏÞ¡£¡£¡£¡£¡£¡£´ËÀ๤¾ß¹ØÓÚά»¤Óû§¶ÔÖÖÖÖ×ÊÔ´¡¢ÏµÍ³ºÍÊý¾ÝµÄ»á¼ûµÄÇå¾²ÐÔ¡¢ºÏ¹æÐԺ͸ßЧÖÎÀíÖÁ¹ØÖ÷Òª¡£¡£¡£¡£¡£¡£Èý¸öÑÏÖØµÄÔ¶³Ì´úÂëÖ´ÐÐȱÏÝÊÇ£ºCVE-2023-40057£¨CVSS ÆÀ·Ö 9.0£©£º²»ÊÜÐÅÈÎÊý¾ÝµÄ·´ÐòÁл¯ÎÊÌâ¡£¡£¡£¡£¡£¡£¾ÓÉÉí·ÝÑéÖ¤µÄÓû§¿ÉÒÔʹÓôËÎó²îÀÄÓà SolarWinds ЧÀÍ£¬£¬£¬£¬£¬´Ó¶øµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£¡£CVE-2024-23479£¨CVSS ÆÀ·Ö 9.6£©£ºÄ¿Â¼±éÀúÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£¡£Î´¾Éí·ÝÑéÖ¤µÄÓû§¿ÉÒÔʹÓôËÎÊÌâʵÏÖÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£¡£CVE-2024-23476£¨CVSS ÆÀ·Ö 9.6£©Ä¿Â¼±éÀúÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£¡£ÈôÊDZ»Ê¹Ó㬣¬£¬£¬£¬Î´¾Éí·ÝÑéÖ¤µÄÓû§¿ÉÒÔʵÏÖÔ¶³ÌÖ´ÐдúÂë¡£¡£¡£¡£¡£¡£
https://securityaffairs.com/159294/security/solarwinds-access-rights-manager-flaws.html


¾©¹«Íø°²±¸11010802024551ºÅ