Symantec³ÆBillbug¹¥»÷ÑÇÖÞµØÇøµÄÊý×ÖÖ¤Êé½ÒÏþ»ú¹¹
Ðû²¼Ê±¼ä 2022-11-17SymantecÔÚ11ÔÂ15ÈÕ³ÆÆä·¢Ã÷Billbug¹¥»÷ÁËÑÇÖ޵Ķà¸öÕþ¸®»ú¹¹£¬£¬£¬£¬£¬£¬ÆäÖаüÀ¨Ò»¸öÊý×ÖÖ¤Êé½ÒÏþ»ú¹¹¡£¡£¡£¡£¡£¸ÃÍÅ»ï×Ô2009ÄêÒÔÀ´Ò»Ö±»îÔ¾£¬£¬£¬£¬£¬£¬Symantec 2019ÄêË꼵ĻÖÐÏêϸÏÈÈÝÁ˸ÃÍÅ»ïÔõÑùʹÓúóÃÅHannotogºÍSagerunexµÄ£¬£¬£¬£¬£¬£¬ÕâЩ¹¤¾ßÔÚ×î½üµÄ»î¶¯ÖÐÒ²ÓзºÆð¡£¡£¡£¡£¡£´Ë´Î»î¶¯ÖÁÉÙ´Ó3Ô¾ÍÒÑ×îÏÈ£¬£¬£¬£¬£¬£¬Óм£ÏóÅú×¢¹¥»÷ÕßÕýÔÚʹÓÃÃæÏò¹«ÖÚµÄÓ¦ÓóÌÐòÀ´»ñµÃ¶ÔÄ¿µÄÍøÂçµÄ³õʼ»á¼ûȨÏÞ¡£¡£¡£¡£¡£Óë֮ǰµÄ»î¶¯Ò»Ñù£¬£¬£¬£¬£¬£¬¹¥»÷ÕßҲʹÓÃÁ˶àÖÖÁ½Óù¤¾ß¼°×Ô½ç˵¶ñÒâÈí¼þ£¬£¬£¬£¬£¬£¬ÈçAdFind¡¢Directory¡¢Winmail¡¢WinRAR¡¢PingºÍTracertµÈ¡£¡£¡£¡£¡£
https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/espionage-asia-governments-cert-authority
2¡¢VaronisÅû¶Zendesk ExploreÖÐSQL×¢ÈëµÈÎó²îµÄϸ½Ú
VaronisÔÚ11ÔÂ15ÈÕÅû¶ÁËZendesk ExploreÖÐÁ½¸öÎó²îµÄϸ½Ú¡£¡£¡£¡£¡£ÆäÖÐÒ»¸öÊÇSQL×¢ÈëÎó²î£¬£¬£¬£¬£¬£¬¸ÃÎó²îÉæ¼°ÆäGraphQL APIÖеÄSQL×¢È룬£¬£¬£¬£¬£¬¿É±»ÓÃÀ´Ð¹Â¶×÷ΪÖÎÀíÔ±´æ´¢ÔÚÊý¾Ý¿âÖеÄËùÓÐÐÅÏ¢£¬£¬£¬£¬£¬£¬°üÀ¨ÓʼþµØµã¡¢¹¤µ¥ÒÔ¼°ÓëʵʱÊðÀíµÄ¶Ô»°µÈ¡£¡£¡£¡£¡£ÁíÒ»¸öÎó²îÊÇÉæ¼°ÓëÅÌÎÊÖ´ÐÐAPIÏà¹ØµÄÂß¼»á¼ûÎÊÌ⣬£¬£¬£¬£¬£¬¸ÃAPI±»ÉèÖÃΪÔËÐÐÅÌÎÊ£¬£¬£¬£¬£¬£¬¶ø²»¼ì²é¾ÙÐÐŲÓõÄÓû§ÊÇ·ñÓÐ×ã¹»µÄȨÏÞÕâÑù×ö¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬£¬ÕâЩÎó²îÒѱ»ÐÞ¸´¡£¡£¡£¡£¡£
https://securityaffairs.co/wordpress/138579/hacking/zendesk-explore-critical-flaws.html
3¡¢LazarusʹÓúóÃÅDTrack¹¥»÷Å·ÖÞºÍÀ¶¡ÃÀÖÞµÄ×éÖ¯
¾Ý11ÔÂ15ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬³¯ÏʺڿÍÍÅ»ïLazarusÕýÔÚʹÓÃа汾µÄDTrackºóÃÅÀ´¹¥»÷Å·ÖÞºÍÀ¶¡ÃÀÖÞµÄ×éÖ¯¡£¡£¡£¡£¡£Ä¿µÄÐÐÒµ°üÀ¨Ñо¿ÖÐÐÄ¡¢Õþ²ß»ú¹¹¡¢»¯Ñ§Æ·ÖÆÔìÉÌ¡¢ITЧÀÍÌṩÉÌ¡¢µçÐÅÌṩÉÌ¡¢¹«ÓÃÊÂҵЧÀÍÌṩÉ̺ͽÌÓý¡£¡£¡£¡£¡£ÔÚеĻÖУ¬£¬£¬£¬£¬£¬DTrackͨ³£Ê¹ÓÃÓëÕýµ±ÎļþÏà¹ØµÄÎļþÃû¾ÙÐзַ¢£¬£¬£¬£¬£¬£¬ÈçÒ»¸öÑù±¾ÒÔ¡°NvContainer.exe¡±ÎªÃû·Ö·¢£¬£¬£¬£¬£¬£¬ËüÓëÕýµ±µÄNVIDIAÎļþͬÃû¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬DTrackÈÔ¼ÌÐøÍ¨¹ýÇÔÈ¡µÄƾ֤ÈëÇÖÍøÂç»òʹÓÃÍøÉÏ̻¶µÄЧÀÍÆ÷À´¾ÙÐзַ¢¡£¡£¡£¡£¡£
https://securelist.com/dtrack-targeting-europe-latin-america/107798/
4¡¢Ñо¿ÍŶӷ¢Ã÷¿ÉÓ°Ï캽ÌìÆ÷ºÍ·É»úµÄ¹¥»÷·½·¨PCspooF
ýÌå11ÔÂ15ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬Ñо¿ÍŶӷ¢Ã÷ÁËÒ»ÖÖÕë¶Ôʱ¼ä´¥·¢ÒÔÌ«Íø(TTE)µÄÐÂÐ͹¥»÷ÒªÁì¡£¡£¡£¡£¡£TTEÊôÓÚ»ìÏýÒªº¦ÐÔÍøÂçµÄÍøÂçÊÖÒÕÖ®Ò»£¬£¬£¬£¬£¬£¬ÆäÖоßÓвî±ðʱÐòºÍÈÝ´íÒªÇóµÄÁ÷Á¿¹²´æÓÚͳһÎïÀíÍøÂçÖС£¡£¡£¡£¡£¸ÃÊÖÒÕÓÃÓÚÇå¾²»ù´¡ÉèÊ©£¬£¬£¬£¬£¬£¬¿Éµ¼ÖÂΪº½ÌìÆ÷ºÍ·É»úÌṩ¶¯Á¦µÄϵͳ·ºÆð¹ÊÕÏ¡£¡£¡£¡£¡£ÕâÊÇʹÓöñÒâ×°±¸Í¨¹ýÒÔÌ«ÍøµçÀ½«µç´Å×ÌÈÅ(EMI)×¢ÈëTTE½»Á÷»úÀ´ÊµÏֵ쬣¬£¬£¬£¬£¬¿ÉÓÐÓõØÓÕʹ½»Á÷»ú·¢ËÍ¿´ËÆÕæÊµµÄͬ²½ÐÂÎŲ¢ÈÃËüÃDZ»ÆäËûTTE×°±¸½ÓÊÜ¡£¡£¡£¡£¡£×÷Ϊ»º½â²½·¥£¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±½¨ÒéʹÓùâñîºÏÆ÷»òÀËÓ¿±£»£»£»£»£»£»¤Æ÷À´×èÖ¹µç´Å×ÌÈÅ¡£¡£¡£¡£¡£
https://thehackernews.com/2022/11/pcspoof-new-vulnerability-affects.html
5¡¢ÒÁÀÊÏà¹ØºÚ¿ÍʹÓÃLog4ShellÎó²îÈëÇÖÃÀ¹úÕþ¸®»ú¹¹
11ÔÂ16ÈÕ£¬£¬£¬£¬£¬£¬FBIºÍCISAÁªºÏÐû²¼ÁËÒ»·Ýͨ¸æ£¬£¬£¬£¬£¬£¬³ÆÓëÒÁÀÊÏà¹ØµÄºÚ¿ÍÈëÇÖÁËÒ»¸öÕþ¸®»ú¹¹²¢×°ÖÃÁËXMRig¿ó¹¤¶ñÒâÈí¼þ¡£¡£¡£¡£¡£Í¨¸æ³Æ£¬£¬£¬£¬£¬£¬´Ó2022Äê6ÔÂÖÐÑ®µ½7Ô£¬£¬£¬£¬£¬£¬CISAÔÚÁª°îÃñÓÃÐÐÕþ²¿·Ö(FCEB)×éÖ¯ÖÐÊӲ쵽ÁË¿ÉÒɵÄAPT»î¶¯¡£¡£¡£¡£¡£¹¥»÷ÕßʹÓÃδÐÞ¸´µÄVMware HorizonЧÀÍÆ÷ÖеÄLog4ShellÎó²î£¬£¬£¬£¬£¬£¬×°ÖÃXMRig¿ó¹¤Èí¼þ£¬£¬£¬£¬£¬£¬ºáÏòÒÆ¶¯µ½Óò¿ØÖÆÆ÷(DC)£¬£¬£¬£¬£¬£¬ÇÔȡƾ֤£¬£¬£¬£¬£¬£¬È»ºóÖ²ÈëNgrok·´ÏòÊðÀíÀ´ÔÚ¶à¸ö×°±¸Éϼá³Ö³¤ÆÚÐÔ¡£¡£¡£¡£¡£CISA ºÍ FBI Ðû²¼´ËCSAÌṩºÚ¿ÍµÄTTPºÍIOC£¬£¬£¬£¬£¬£¬ÒÔ×ÊÖú×éÖ¯¼ì²âºÍ·ÀÓùÏà¹ØµÄ¹¥»÷¡£¡£¡£¡£¡£
https://www.cisa.gov/uscert/ncas/alerts/aa22-320a
6¡¢KasperskyÐû²¼¹ØÓÚ2023ÄêAPT¹¥»÷»î¶¯µÄÕ¹Íû±¨¸æ
KasperskyÔÚ11ÔÂ14ÈÕÐû²¼Á˹ØÓÚ2023ÄêAPT¹¥»÷»î¶¯µÄÕ¹Íû±¨¸æ¡£¡£¡£¡£¡£±¨¸æÕ¹ÍûÔÚ2023Ä꣬£¬£¬£¬£¬£¬½«·ºÆð´ó×򵀮ÆËðÐÔÍøÂç¹¥»÷£¬£¬£¬£¬£¬£¬Ó°ÏìÕþ¸®²¿·ÖºÍÒªº¦ÐÐÒµ£»£»£»£»£»£»ÓʼþЧÀÍÆ÷½«³ÉΪÖ÷ҪĿµÄ£¬£¬£¬£¬£¬£¬ºÜ¿ÉÄÜËùÓÐÖ÷Òªµç×ÓÓʼþÈí¼þ¶¼·ºÆð0-day£»£»£»£»£»£»Ò»Ð©¾ßÓÐÓ°ÏìÁ¦µÄ²¡¶¾Ã¿6-7Ä걬·¢Ò»´Î£¬£¬£¬£¬£¬£¬¿ÉÄÜ·ºÆðÏÂÒ»¸öWannaCry£»£»£»£»£»£»APT¹¥»÷ÍŻォĿµÄתÏòÎÀÐÇÊÖÒÕ¡¢Éú²úÉ̺ÍÔËÓªÉÌ£»£»£»£»£»£»¸ü¶àAPT×éÖ¯½«´ÓCobaltStrike×ªÒÆµ½ÆäËüÌæ»»¼Æ»®µÈ¡£¡£¡£¡£¡£
https://securelist.com/advanced-threat-predictions-for-2023/107939/


¾©¹«Íø°²±¸11010802024551ºÅ