Symantec³ÆBillbug¹¥»÷ÑÇÖÞµØÓòµÄÊý×ÖÖ¤ÊéÐû¸æ»ú¹¹
°ä²¼¹¦·ò 2022-11-17SymantecÔÚ11ÔÂ15ÈÕ³ÆÆä·¢ÏÖBillbug¹¥»÷ÁËÑÇÖ޵Ķà¸öµ±¾Ö»ú¹¹£¬£¬£¬£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬Ò»¸öÊý×ÖÖ¤ÊéÐû¸æ»ú¹¹¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÍÅ»ï×Ô2009ÄêÒÔÀ´Ò»Ïò»îÔ¾£¬£¬£¬£¬£¬£¬£¬£¬Symantec 2019Äê¼Í¼µÄ»î¶¯ÖоßÌå½éÉÜÁ˸ÃÍÅ»ïÈôºÎʹÓúóÃÅHannotogºÍSagerunexµÄ£¬£¬£¬£¬£¬£¬£¬£¬ÕâЩ¹¤¾ßÔÚ×î½üµÄ»î¶¯ÖÐÒ²ÓгöÏÖ¡£¡£¡£¡£¡£¡£¡£¡£Õâ´Î»î¶¯ÖÁÉÙ´Ó3Ô¾ÍÒÑÆðÍ·£¬£¬£¬£¬£¬£¬£¬£¬Óм£ÏóÅú×¢¹¥»÷ÕßÔÚÀûÓÃÃæÏò¹«¼ÒµÄÀûÓ÷¨Ê½À´»ñµÃ¶ÔÖ¸±êÍøÂçµÄ³õʼ½Ó¼ûȨÏÞ¡£¡£¡£¡£¡£¡£¡£¡£Óë֮ǰµÄ»î¶¯Ò»Ñù£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßҲʹÓÃÁ˶àÖÖÁ½Óù¤¾ß¼°×Ô½ç˵¶ñÒâÈí¼þ£¬£¬£¬£¬£¬£¬£¬£¬ÈçAdFind¡¢Directory¡¢Winmail¡¢WinRAR¡¢PingºÍTracertµÈ¡£¡£¡£¡£¡£¡£¡£¡£
https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/espionage-asia-governments-cert-authority
2¡¢VaronisÅû¶Zendesk ExploreÖÐSQL×¢ÈëµÈ·ì϶µÄϸ½Ú
VaronisÔÚ11ÔÂ15ÈÕÅû¶ÁËZendesk ExploreÖÐÁ½¸ö·ì϶µÄϸ½Ú¡£¡£¡£¡£¡£¡£¡£¡£ÆäÖÐÒ»¸öÊÇSQL×¢Èë·ì϶£¬£¬£¬£¬£¬£¬£¬£¬¸Ã·ìÏ¶Éæ¼°ÆäGraphQL APIÖеÄSQL×¢È룬£¬£¬£¬£¬£¬£¬£¬¿É±»ÓÃÀ´Ð¹Â¶×÷ΪÖÎÀíÔ±´æ´¢ÔÚÊý¾Ý¿âÖеÄËùÓÐÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬£¬Ô̺¬ÓʼþµØÖ·¡¢¹¤µ¥ÒÔ¼°ÓëʵʱÆÚÀíµÄ¶Ô»°µÈ¡£¡£¡£¡£¡£¡£¡£¡£ÁíÒ»¸ö·ì϶ÊÇÉæ¼°Óë²éÎÊÖ´ÐÐAPIÓйصÄÂß¼½Ó¼ûÎÊÌ⣬£¬£¬£¬£¬£¬£¬£¬¸ÃAPI±»ÅäÖÃΪÔËÐвéÎÊ£¬£¬£¬£¬£¬£¬£¬£¬¶ø²»²é³½øÐÐŲÓõÄÓû§ÊÇ·ñÓÐ×ã¹»µÄȨÏÞÕâÑù×ö¡£¡£¡£¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬£¬£¬£¬ÕâЩ·ì϶Òѱ»½¨¸´¡£¡£¡£¡£¡£¡£¡£¡£
https://securityaffairs.co/wordpress/138579/hacking/zendesk-explore-critical-flaws.html
3¡¢LazarusÀûÓúóÃÅDTrack¹¥»÷Å·ÖÞºÍÀ¶¡ÃÀÖÞµÄ×éÖ¯
¾Ý11ÔÂ15ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬£¬£¬³¯ÏʺڿÍÍÅ»ïLazarusÔÚʹÓÃа汾µÄDTrackºóÃÅÀ´¹¥»÷Å·ÖÞºÍÀ¶¡ÃÀÖÞµÄ×éÖ¯¡£¡£¡£¡£¡£¡£¡£¡£Ö¸±êÐÐÒµÔ̺¬×êÑÐÖÐÐÄ¡¢Õþ²ß»ú¹¹¡¢»¯Ñ§Æ·Ôì×÷ÉÌ¡¢IT·þÎñÌṩÉÌ¡¢µçÐÅÌṩÉÌ¡¢¹«ÓÃÊÂÒµ·þÎñÌṩÉ̺ͽÌÓý¡£¡£¡£¡£¡£¡£¡£¡£ÔÚеĻÖУ¬£¬£¬£¬£¬£¬£¬£¬DTrackͨ³£Ê¹ÓÃÓëºÏ·¨ÎļþÓйصÄÎļþÃû½øÐзַ¢£¬£¬£¬£¬£¬£¬£¬£¬ÈçÒ»¸öÑù±¾ÒÔ¡°NvContainer.exe¡±ÎªÃû·Ö·¢£¬£¬£¬£¬£¬£¬£¬£¬ËüÓëºÏ·¨µÄNVIDIAÎļþͬÃû¡£¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬£¬DTrackÈÔ³ÖÐøÍ¨¹ýÇÔÈ¡µÄƾ֤ÈëÇÖÍøÂç»òÀûÓÃÍøÉ϶³öµÄ·þÎñÆ÷À´½øÐзַ¢¡£¡£¡£¡£¡£¡£¡£¡£
https://securelist.com/dtrack-targeting-europe-latin-america/107798/
4¡¢×êÑÐÍŶӷ¢ÏÖ¿ÉÓ°Ï캽ÌìÆ÷ºÍ·É»úµÄ¹¥»÷·½Ê½PCspooF
ýÌå11ÔÂ15ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬£¬£¬×êÑÐÍŶӷ¢ÏÖÁËÒ»ÖÖÕë¶Ô¹¦·ò´¥·¢ÒÔÌ«Íø(TTE)µÄÐÂÐ͹¥»÷²½Öè¡£¡£¡£¡£¡£¡£¡£¡£TTEÊôÓÚ»ìºÏ¹Ø¼üÐÔÍøÂçµÄÍøÂç¼¼ÊõÖ®Ò»£¬£¬£¬£¬£¬£¬£¬£¬ÆäÖÐÓµÓÐ·ÖÆçʱÐòºÍÈÝ´íÒªÇóµÄÁ÷Á¿¹²´æÓÚͳһÎïÀíÍøÂçÖС£¡£¡£¡£¡£¡£¡£¡£¸Ã¼¼ÊõÓÃÓÚ°²È«»ù´¡ÉèÊ©£¬£¬£¬£¬£¬£¬£¬£¬¿Éµ¼ÖÂΪº½ÌìÆ÷ºÍ·É»úÌṩ¶¯Á¦µÄϵͳ³öÏÖ¹ÊÕÏ¡£¡£¡£¡£¡£¡£¡£¡£ÕâÊÇʹÓöñÒâÉ豸ͨ¹ýÒÔÌ«ÍøµçÀ½«µç´Å×ÌÈÅ(EMI)×¢ÈëTTE»¥»»»úÀ´ÊµÏֵ쬣¬£¬£¬£¬£¬£¬£¬¿ÉÓÐЧµØÓÕʹ»¥»»»ú·¢ËÍ¿´ËÆÕæÊµµÄͬ²½ÐÂÎŲ¢ÈÃËüÃDZ»ÆäËûTTEÉ豸½ÓÊÜ¡£¡£¡£¡£¡£¡£¡£¡£×÷Ϊ»º½â´ëÊ©£¬£¬£¬£¬£¬£¬£¬£¬×êÑÐÈËÔ±½¨ÒéʹÓùâñîºÏÆ÷»òÀËÓ¿±£»£»£»£»£»¤Æ÷À´×èÖ¹µç´Å×ÌÈÅ¡£¡£¡£¡£¡£¡£¡£¡£
https://thehackernews.com/2022/11/pcspoof-new-vulnerability-affects.html
5¡¢ÒÁÀÊÓйغڿÍÀûÓÃLog4Shell·ì϶ÈëÇÖÃÀ¹úµ±¾Ö»ú¹¹
11ÔÂ16ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬FBIºÍCISA½áºÏ°ä²¼ÁËÒ»·Ý¹«¸æ£¬£¬£¬£¬£¬£¬£¬£¬³ÆÓëÒÁÀÊÓйصĺڿÍÈëÇÖÁËÒ»¸öµ±¾Ö»ú¹¹²¢×°ÖÃÁËXMRig¿ó¹¤¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¡£¡£¡£¹«¸æ³Æ£¬£¬£¬£¬£¬£¬£¬£¬´Ó2022Äê6ÔÂÖÐÑ®µ½7Ô£¬£¬£¬£¬£¬£¬£¬£¬CISAÔÚÁª¹úÃñÓÃÐÐÕþ²¿ÃÅ(FCEB)×éÖ¯Öй۲쵽ÁË¿ÉÒɵÄAPT»î¶¯¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÀûÓÃ佨¸´µÄVMware Horizon·þÎñÆ÷ÖеÄLog4Shell·ì϶£¬£¬£¬£¬£¬£¬£¬£¬×°ÖÃXMRig¿ó¹¤Èí¼þ£¬£¬£¬£¬£¬£¬£¬£¬ºáÏòÒÆ¶¯µ½Óò½ÚÔìÆ÷(DC)£¬£¬£¬£¬£¬£¬£¬£¬ÇÔȡʹ´¦£¬£¬£¬£¬£¬£¬£¬£¬¶øºóÖ²ÈëNgrok·´Ïò´úÀíÀ´ÔÚ¶à¸öÉ豸ÉÏά³ÖÓÆ¾ÃÐÔ¡£¡£¡£¡£¡£¡£¡£¡£CISA ºÍ FBI °ä²¼´ËCSAÌṩºÚ¿ÍµÄTTPºÍIOC£¬£¬£¬£¬£¬£¬£¬£¬ÒÔÔ®ÊÖ×éÖ¯¼ì²âºÍ·ÀÓùÓйصĹ¥»÷¡£¡£¡£¡£¡£¡£¡£¡£
https://www.cisa.gov/uscert/ncas/alerts/aa22-320a
6¡¢Kaspersky°ä²¼¹ØÓÚ2023ÄêAPT¹¥»÷»î¶¯µÄÔ¤²â»ã±¨
KasperskyÔÚ11ÔÂ14ÈÕ°ä²¼Á˹ØÓÚ2023ÄêAPT¹¥»÷»î¶¯µÄÔ¤²â»ã±¨¡£¡£¡£¡£¡£¡£¡£¡£»ã±¨Ô¤²âÔÚ2023Ä꣬£¬£¬£¬£¬£¬£¬£¬½«³öÏÖ´óÁ¿µÄ·ÛËéÐÔÍøÂç¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬Ó°Ïìµ±²¿ÃÅÃź͹ؼüÐÐÒµ£»£»£»£»£»Óʼþ·þÎñÆ÷½«³ÉΪ³ÁÒªÖ¸±ê£¬£¬£¬£¬£¬£¬£¬£¬ºÜ¿ÉÄÜËùÓÐÖØÒªµç×ÓÓʼþÈí¼þ¶¼³öÏÖ0-day£»£»£»£»£»Ò»Ð©ÓµÓÐÓ°ÏìÁ¦µÄ²¡¶¾Ã¿6-7Äê²úÉúÒ»´Î£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÄܳöÏÖÏÂÒ»¸öWannaCry£»£»£»£»£»APT¹¥»÷ÍŻォָ±êתÏòÎÀÐǼ¼Êõ¡¢³ö²úÉ̺ÍÔËÓªÉÌ£»£»£»£»£»¸ü¶àAPT×éÖ¯½«´ÓCobaltStrike×ªÒÆµ½ÆäËü´úÌæ¹æ»®µÈ¡£¡£¡£¡£¡£¡£¡£¡£
https://securelist.com/advanced-threat-predictions-for-2023/107939/


¾©¹«Íø°²±¸11010802024551ºÅ