NCC³Æ½ü2000̨Citrix NetScaler·þÎñÆ÷Òѱ»Ö²ÈëºóÃÅ

Ðû²¼Ê±¼ä 2023-08-17

1¡¢NCC³Æ½ü2000̨Citrix NetScaler·þÎñÆ÷Òѱ»Ö²ÈëºóÃÅ


¾Ý8ÔÂ16ÈÕ±¨µÀ £¬NCC Group·¢Ã÷ÁËCitrix NetScalerÎó²îµÄ´ó¹æģʹÓÃÔ˶¯ ¡£¹¥»÷ÕßÒÔ×Ô¶¯»¯·½·¨Ê¹ÓÃÁËÎó²î£¨CVE-2023-3519£© £¬ÔÚNetscaler·þÎñÆ÷ÖÐÖ²ÈëÁËWebshell ¡£×ÝÈ»NetScalerÒÑ´ò²¹¶¡»òÖØÆô £¬¹¥»÷ÕßÒ²¿ÉÒÔʹÓôËWebshellÖ´ÐÐí§ÒâÏÂÁî ¡£Ñо¿Ö°Ô±×ܹ²ÔÚ1952¸ö²î±ðµÄNetScalerÖз¢Ã÷ÁË2491¸öWebshell £¬´ó´ó¶¼Î»Óڵ¹ú¡¢·¨¹ú¡¢ÈðÊ¿¡¢ÈÕ±¾ºÍÒâ´óÀûµÈ¹ú ¡£×èÖ¹8ÔÂ14ÈÕ £¬ÈÔÓÐ1828¸öNetScaler±£´æºóÃÅ £¬ÆäÖÐÔ¼1248̨ÒѾ­Õë¶Ô¸ÃÎó²î¾ÙÐÐÁËÐÞ¸´ ¡£


https://thehackernews.com/2023/08/nearly-2000-citrix-netscaler-instances.html


2¡¢´ó×ÚLinkedInÓû§³ÆÆäÕË»§±»Ð®ÖÆ»òËø¶¨²¿·ÖÒª½»Êê½ð


¾ÝýÌå8ÔÂ15ÈÕ±¨µÀ £¬CyberintÔÚ×î½ü¼¸ÖÜ·¢Ã÷ÁËÒ»³¡Ò»Á¬µÄ¹¥»÷Ô˶¯Ö÷ÒªÕë¶ÔLinkedInÕÊ»§ ¡£¸ÃÔ˶¯µÄÓ°Ïì¹æÄ£ÁýÕÖÈ«Çò £¬µ¼Ö´ó×ÚÓû§ÎÞ·¨»á¼ûÆäÕÊ»§ ¡£Ðí¶àLinkedInÓû§Ëß¿àÆäÕË»§±»½ÓÊÜ»òËø¶¨ £¬²¢ÇÒÎÞ·¨Í¨¹ýLinkedInµÄÖ§³Ö·þÎñ½â¾ö ¡£ÓÐЩÈËÉõÖÁ±»ÆȽ»Êê½ð²Å»ªÖØлñµÃ¿ØÖÆȨ £¬»òÕßÃæÁÙÕË»§±»ÓÀÊÀɾ³ýµÄÇéÐÎ ¡£ËäÈ»LinkedInÉÐδÐû²¼Õýʽͨ¸æ £¬µ«ËûÃǵÄÖ§³ÖÏìӦʱ¼äËƺõÒѾ­ÑÓÉì £¬Óб¨µÀ³ÆÖ§³ÖÇëÇóµÄÊýÄ¿ºÜ´ó ¡£


https://www.bleepingcomputer.com/news/security/linkedin-accounts-hacked-in-widespread-hijacking-campaign/


3¡¢ÃÀ¹ú¸ßÀÖÊÏ(Clorox)Ôâµ½¹¥»÷µ¼ÖÂÔËÓªÔÝʱÖÐÖ¹


8ÔÂ16ÈÕ±¨µÀ³Æ £¬ÃÀ¹úÈÕÓÃÆ·Éú²úÉ̸ßÀÖÊÏ(Clorox)Ôâµ½¹¥»÷ £¬µ¼ÖÂÔËÓªÔÝʱÖÐÖ¹ ¡£¸Ã¹«Ë¾ÔÚ2022ÄêµÄÊÕÈëÁè¼Ý70ÒÚÃÀÔª ¡£´Ë´Î¹¥»÷ÓÚ8ÔÂ14ÈÕ±»¼ì²âµ½ £¬CloroxÁ¬Ã¦½ÓÄÉÐж¯ £¬¹Ø±ÕÁËÊÜÓ°ÏìµÄϵͳ ¡£¸ÃÊÂÎñµÄÊÓ²ìÈÔÔÚÔçÆڽ׶Î £¬Éв»ÇåÎúÊÇÄÄÖÖÀàÐ͵Ĺ¥»÷ ¡£È»¶øÏÖÓÐÐÅÏ¢Åú×¢ £¬Õâ¿ÉÄÜÊÇÀÕË÷¹¥»÷ ¡£´Ë´Î¹¥»÷Ó°ÏìÁËCloroxµÄÖÆÔìºÍÏúÊÛÁ÷³Ì £¬ÒÔ¼°ÆäÍÆÐж©µ¥ºÍά³ÖÕý³£ÔËÓªµÄÄÜÁ¦ ¡£


https://www.infosecurity-magazine.com/news/clorox-disrupted-cyber-attack/


4¡¢ÒÑÍù°ëÄêCloudflare R2ÍйܵĴ¹ÂÚÍøÒ³Á÷Á¿ÔöÌí61±¶


NetskopeÔÚ8ÔÂ14ÈÕ³Æ £¬´Ó½ñÄê2Ôµ½7Ô £¬Cloudflare R2ÖÐÍйܵĴ¹ÂÚÒ³ÃæÁ÷Á¿ÔöÌíÁË61±¶ ¡£´ó´ó¶¼´¹ÂÚÔ˶¯¶¼Õë¶ÔMicrosoftµÇ¼ƾ֤ £¬µ«Ò²ÓÐһЩÕë¶ÔAdobe¡¢DropboxºÍÆäËüÔÆÓ¦ÓóÌÐò ¡£ÕâЩ¹¥»÷Ö÷ÒªÕë¶Ô±±ÃÀºÍÑÇÖÞ £¬Éæ¼°ÖÖÖÖÁìÓò £¬ÒÔÊÖÒÕ¡¢½ðÈÚ·þÎñºÍÒøÐÐҵΪÊ× ¡£ÕâЩ´¹ÂÚÔ˶¯²»µ«Ê¹ÓÃCloudflare R2·Ö·¢¾²Ì¬´¹ÂÚÒ³Ãæ £¬»¹Ê¹Óøù«Ë¾µÄTurnstile²úÆ·À´Èƹý¼ì²â ¡£


https://www.netskope.com/blog/evasive-phishing-campaign-steals-cloud-credentials-using-cloudflare-r2-and-turnstile


5¡¢AhnLab·¢Ã÷Hakuna MatataÕë¶Ôº«¹úÆóÒµµÄ¹¥»÷Ô˶¯


8ÔÂ16ÈÕ £¬AhnLab͸¶ÀÕË÷Èí¼þHakuna MatataÕý±»ÓÃÀ´¹¥»÷º«¹úµÄÆóÒµ ¡£Hakuna MatataÊǽüÆÚ¿ª·¢µÄÀÕË÷Èí¼þ £¬ÓÚ7ÔÂ6ÈÕÊ״α»Åû¶ ¡£Hakuna MatataÓëÆäËü¹Å°åÀÕË÷Èí¼þµÄ²î±ðÖ®´¦ÔÚÓÚ £¬Ëü¾ßÓÐClipBanker¹¦Ð§ ¡£×ÝÈ»ÔÚ¼ÓÃÜÖ®ºó £¬ËüÈÔÈ»±£±£´æϵͳÖÐ £¬½«±ÈÌرÒÇ®°üµØµã¸ü¸ÄΪ¹¥»÷Õߵĵصã ¡£¼ÓÃÜϵͳºó £¬¹¥»÷Õß»áɾ³ý¹¥»÷ÖÐʹÓõÄÊÂÎñÈÕÖ¾ºÍ¶ñÒâÈí¼þ £¬Òò´ËºÜÄÑ»ñµÃÈ·ÇеÄÐÅÏ¢ ¡£¿ÉÊÇ £¬Æ¾Ö¤ÖÖÖÖÇéÐÎ £¬ÍƲâÔ¶³Ì×ÀÃæЭÒ飨RDP£©±»×÷Ϊ³õʼ¹¥»÷ÔØÌå ¡£


https://asec.ahnlab.com/en/56010/


6¡¢Group-IBÐû²¼¹ØÓÚ¶ñÒâÈí¼þGigabudµÄÆÊÎö±¨¸æ


8ÔÂ14ÈÕ £¬Group-IBÐû²¼Á˹ØÓÚ¶ñÒâÈí¼þGigabudµÄÆÊÎö±¨¸æ ¡£ËüÖ÷ÒªÕë¶ÔÌ©¹ú¡¢Ó¡¶ÈÄáÎ÷ÑÇ¡¢Ô½ÄÏ¡¢·ÆÂɱöºÍÃسµÄ½ðÈÚ»ú¹¹ ¡£Gigabud RATÔÚÓû§±»ÊÚȨ½øÈë¶ñÒâÓ¦ÓÃ֮ǰ²»»áÖ´ÐÐÈκζñÒâÔ˶¯ £¬Õâ¼Ó´óÁ˼ì²âµÄÄÑ¶È ¡£ËüÖ÷Ҫͨ¹ýÆÁĻ¼ÖÆÀ´ÍøÂçÃô¸ÐÐÅÏ¢ £¬¶ø²»ÊÇHTMLÁýÕÖ¹¥»÷ ¡£¼ÌÐøÊӲ췢Ã÷ÁËÁíÒ»¸ö²»¾ß±¸RAT¹¦Ð§µÄÑù±¾ £¬´úºÅΪGigabud.Loan £¬ÕâÊÇÒ»¸öαÔìµÄ´û¿îÓ¦Óà £¬»áÇÔÈ¡Óû§ÊäÈëµÄÊý¾Ý ¡£


https://www.group-ib.com/blog/gigabud-banking-malware/