ResecurityÅû¶ͨ¹ý±øÆ÷»¯OfficeÎĵµ·Ö·¢µÄEscanor
°ä²¼¹¦·ò 2022-08-231¡¢ResecurityÅû¶ͨ¹ý±øÆ÷»¯OfficeÎĵµ·Ö·¢µÄEscanor
8ÔÂ21ÈÕ£¬£¬£¬£¬£¬£¬£¬Resecurity³ÆÔÚ°µÍøºÍTelegramÖз¢ÏÖÁËÒ»ÖÖÃûΪEscanorµÄÐÂRAT¡£¡£¡£¡£¡£¡£¸Ã¹¤¾ßÓÚ½ñÄê1ÔÂ26ÈÕ°ä²¼£¬£¬£¬£¬£¬£¬£¬×î³õÊÇ×÷Ϊ½ô´ÕÐÍHVNCÖ²È뷨ʽ£¬£¬£¬£¬£¬£¬£¬¿ÉÓÃÀ´³ÉÁ¢ÓëÖ¸±êÍÆËã»úµÄÔ¶³Ì¾²Ä¬Ïνӣ¬£¬£¬£¬£¬£¬£¬ºóÀ´×ª±äΪӵÓжàÖÖÖ°Äܼ¯µÄóÒ×RAT¡£¡£¡£¡£¡£¡£×î½ü¼ì²âµ½µÄ´óÎÞÊýÑù±¾¶¼ÊÇʹÓÃEscanor Exploit Builder·Ö·¢µÄ£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßʹÓÃÁ˵ö¶üÎÄ£¬£¬£¬£¬£¬£¬£¬·ÂÕÕÊ¢ÐÐÔÚÏß·þÎñµÄ·¢Æ±ºÍ֪ͨ¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬ÓòÃûescanor[.]live´ËǰÒѱ»È·ÈÏÓëAridViperµÄ»ù´¡ÉèÊ©Óйء£¡£¡£¡£¡£¡£
https://resecurity.com/blog/article/escanor-malware-delivered-in-weaponized-microsoft-office-documents
2¡¢ÃÀ¹úNovant HealthµÄ130Íò»¼ÕßµÄÓ×ÎÒÐÅϢй¶
¾Ý8ÔÂ22ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬£¬ÃÀ¹úÒ½ÁƱ£½¡ÌṩÉÌNovant HealthÅû¶ÁËһ·Êý¾Ýй¶ÊÂÎñ£¬£¬£¬£¬£¬£¬£¬Ó°ÏìÁË1362296¸ö»¼Õß¡£¡£¡£¡£¡£¡£¸ÃÊÂÎñʼÓÚ2020Äê5Ô£¬£¬£¬£¬£¬£¬£¬ÆäʱNovant·¢Õ¹ÁËÉæ¼°Facebook¸æ°×µÄCOVID-19ÒßÃç½ÓÖÖÐû´«»î¶¯¡£¡£¡£¡£¡£¡£ÎªÁ˸ú×ÙÕâЩ¸æ°×£¬£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾ÔÚÍøÕ¾ÉÏÔö³¤ÁËMeta Pixel´úÂ룬£¬£¬£¬£¬£¬£¬À´Åжϸæ°×µÄ³ÉЧ¡£¡£¡£¡£¡£¡£µ«ÊÇ£¬£¬£¬£¬£¬£¬£¬Novant HealthµÄÍøÕ¾ºÍMyChartÃÅ»§ÉϵÄMeta PixelÅäÖÃÃýÎ󣬣¬£¬£¬£¬£¬£¬µ¼Ö»¼ÕßµÄÐÅÏ¢»á±»·¢Ë͸øMeta¼°Æä¸æ°×ºÏ×÷ͬ°é¡£¡£¡£¡£¡£¡£NovantÔÚ2022Äê5ÔÂ´ÓÆäÍøÕ¾ºÍÃÅ»§ÖÐɾ³ýÁËMeta Pixel¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/misconfigured-meta-pixel-exposed-healthcare-data-of-13m-patients/
3¡¢Donot TeamΪÆä¶ñÒâÈí¼þ¿ò¼ÜJacaÔö³¤ÐµÄÖ°ÄÜ
ýÌå8ÔÂ22ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬£¬Donot Team£¨±ðÃûAPT-C-35£©ÒÑΪÆäWindows¶ñÒâÈí¼þ¿ò¼ÜJacaÔö³¤ÁËеÄÖ°ÄÜ¡£¡£¡£¡£¡£¡£¸ÃÍÅ»ï×Ô2016ÄêÆðÍ·»îÔ¾£¬£¬£¬£¬£¬£¬£¬ÖØÒªÕë¶ÔÓ¡¶È¡¢°Í»ù˹̹¡¢Ë¹ÀïÀ¼¿¨¡¢ÃϼÓÀ¹úµÈÄÏÑǹú¶ÈÈ·µ±¾Ö»ú¹¹¡¢¾üÊÂ×éÖ¯¡¢±í½»²¿ºÍ´óʹ¹Ý¡£¡£¡£¡£¡£¡£Ð°汾¼ÓÇ¿ÁËä¯ÀÀÆ÷ÇÔȡģ¿£¿£¿£¿£¿é£¬£¬£¬£¬£¬£¬£¬Ê¹ÓÃǰһ½×¶ÎÏÂÔØµÄ4¸ö¸½¼Ó¿ÉÖ´ÐÐÎļþ(WavemsMp.dll)ʵÏÖÇÔȡְÄÜ£¬£¬£¬£¬£¬£¬£¬¶ø²»ÊÇÔÚDLLÖУ¬£¬£¬£¬£¬£¬£¬Ã¿¸ö¸½¼ÓµÄ¿ÉÖ´ÐÐÎļþ¶¼Äܹ»´ÓChrome»òFirefoxÖÐÇÔÊØÐÅÏ¢¡£¡£¡£¡£¡£¡£
https://securityaffairs.co/wordpress/134674/apt/donot-team-improves-jaca-framework.html
4¡¢APT29ÔÚÕë¶Ô±±Ô¼µÄ¹¥»÷»î¶¯ÖÐʹÓÃеÄTTPÈÆ¹ý¼ì²â
8ÔÂ18ÈÕ£¬£¬£¬£¬£¬£¬£¬MandiantÅû¶Á˶íÂÞ˹APT29£¨Cozy Bear£©Õë¶Ô±±Ô¼¹ú¶ÈµÄÐÂÒ»ÂÖ¹¥»÷»î¶¯¡£¡£¡£¡£¡£¡£ÔÚ¹¥»÷ÖУ¬£¬£¬£¬£¬£¬£¬APT29ʹÓÃÁËеÄÕ½Êõ¡¢¼¼ÊõºÍ·¨Ê½£¨TTP£©À´Èƹý¼ì²â£¬£¬£¬£¬£¬£¬£¬Ô̺¬ÔÚÔÚϰȾµÄÖ¸±êÕÊ»§ÉϽûÓÃPurview AuditÖ°ÄÜ£¬£¬£¬£¬£¬£¬£¬¶øºóÍøÂçÊÕ¼þÏäÖеĵç×ÓÓʼþ£»£»£»£»£»£»ÀûÓÃAzure Active DirectoryºÍÆäËüƽ̨ÖеÄMFA×ÔÎÒ×¢²á¹ý³Ì£¬£¬£¬£¬£¬£¬£¬¸ÃÍÅ»ï¿É±©Á¦ÆÆ½â´ÓδµÇ¼¹ýµÄÓòµÄÕÊ»§²¢½«ÆäÉ豸ע²áµ½MFA£»£»£»£»£»£»×êÑÐÈËԱǿµ÷APT29ѡȡÁ˵ÄÌØÊâµÄÔËÓª°²È«ºÍÈÆ¹ýÕ½Êõ£¬£¬£¬£¬£¬£¬£¬ËüʹÓÃÁËAzureÐé¹¹»ú¡£¡£¡£¡£¡£¡£
https://www.mandiant.com/resources/blog/apt29-continues-targeting-microsoft
5¡¢Apple½¨¸´SafariÖÐÒѱ»ÀûÓõķì϶CVE-2022-32893
8ÔÂ18ÈÕ£¬£¬£¬£¬£¬£¬£¬AppleΪmacOS Big SurºÍCatalina°ä²¼ÁËSafari 15.6.1£¬£¬£¬£¬£¬£¬£¬ÒÔ½¨¸´Ò»¸ö±»ÓÃÀ´ÈëÇÖMacµÄ·ì϶¡£¡£¡£¡£¡£¡£ÕâÊÇWebKitÖеÄÒ»¸öÔ½½çдÈë·ì϶(CVE-2022-32893)£¬£¬£¬£¬£¬£¬£¬¿ÉÓÃÀ´ÔÚÖ¸±êÉ豸ÉÏÔ¶³ÌÖ´ÐдúÂë¡£¡£¡£¡£¡£¡£¸Ã·ì϶ÓëApple֮ǰ½¨¸´µÄmacOS MontereyºÍiPhone/iPadÖеķì϶һÑù£¬£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾²¢Î´ÌṩÓйØÈôºÎ±»ÀûÓõľßÌåÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬Ö»ÊÇ˵Ëü¿ÉÄÜÒѱ»»ý¼«ÀûÓᣡ£¡£¡£¡£¡£ÕâÊÇAppleÔÚ2022Ä꽨¸´µÄµÚ7¸ö0 day¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/apple-releases-safari-1561-to-fix-zero-day-bug-used-in-attacks/
6¡¢Unit42°ä²¼2022Äê2ÔÂÖÁ4ÔÂÍøÂç°²È«Ì¬ÊÆµÄ·ÖÎö»ã±¨
Unit42ÔÚ8ÔÂ19ÈÕ°ä²¼ÁË2022Äê2ÔÂÖÁ4ÔÂÍøÂç°²È«Ì¬ÊÆµÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£´Ó½ñÄê2ÔÂÖÁ4Ô£¬£¬£¬£¬£¬£¬£¬Unit42¹²¼Í¼ÁË5962¸öеÄCVE£¬£¬£¬£¬£¬£¬£¬ÆäÖÐ26.4%±»¹éÀàΪ±¾µØ·ì϶£¬£¬£¬£¬£¬£¬£¬Ôü×ÒµÄ73.6%ÊÇ¿Éͨ¹ýÍøÂçÀûÓõÄÔ¶³Ì·ì϶¡£¡£¡£¡£¡£¡£XSS·ì϶ÈÔÊǻ㱨×î¶àµÄ·ì϶£¬£¬£¬£¬£¬£¬£¬Æä´ÎÊÇÔ½½çдÈë¡¢ÐÅϢй¶ºÍSQL×¢Èë·ì϶¡£¡£¡£¡£¡£¡£¶ÔÍøÂç¹¥»÷½øÐзÖÀ࣬£¬£¬£¬£¬£¬£¬×î¶àµÄÊÇÔ¶³Ì´úÂëÖ´Ðй¥»÷£¬£¬£¬£¬£¬£¬£¬Æä´ÎÊDZéÀú¹¥»÷¡¢ÐÅϢй¶¹¥»÷¡¢¿çÕ¾¾ç±¾¹¥»÷ºÍSQL×¢Èë¹¥»÷¡£¡£¡£¡£¡£¡£´óÎÞÊý¹¥»÷ËÆºõÀ´×ÔÃÀ¹ú£¬£¬£¬£¬£¬£¬£¬Æä´ÎÊǵ¹úºÍ¶íÂÞ˹¡£¡£¡£¡£¡£¡£
https://unit42.paloaltonetworks.com/recent-exploits-network-security-trends/


¾©¹«Íø°²±¸11010802024551ºÅ