Kaspersky·¢Ã÷APT41ʹÓÃMoonBounceµÄ¹¥»÷»î¶¯
Ðû²¼Ê±¼ä 2022-01-24Kaspersky·¢Ã÷APT41ʹÓÃMoonBounceµÄ¹¥»÷»î¶¯
1ÔÂ20ÈÕ£¬£¬£¬£¬KasperskyÐû²¼Á˹ØÓÚ¶ñÒâÈí¼þMoonBounceµÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±³Æ£¬£¬£¬£¬MoonBounceÊÇÆù½ñΪֹÔÚÒ°Íâ·¢Ã÷µÄ×îÏȽøµÄUEFI¹Ì¼þ¶ñÒâÈí¼þ£¬£¬£¬£¬ÓëºÚ¿Í×éÖ¯APT41£¨Ò²³ÆÎªWinnti£©Óйء£¡£¡£¡£¡£¡£MoonBounceÖ²ÈëÔÚÖ÷°åµÄSPIÉÁ´æÉÏ£¬£¬£¬£¬Òò´Ë×ÝÈ»Ìæ»»Ó²ÅÌÒ²ÎÞ·¨½«Æä¸ù³ý¡£¡£¡£¡£¡£¡£ÕâÊǽüÆÚ·¢Ã÷µÄµÚÈý¸öUEFI¶ñÒâÈí¼þ£¬£¬£¬£¬Ö®Ç°Á½¸öΪFinFisherºÍESPecter¡£¡£¡£¡£¡£¡£KasperskyÌåÏִ˴ι¥»÷¾ßÓи߶ÈÕë¶ÔÐÔ£¬£¬£¬£¬Ä³¸ö¿ØÖÆ×ż¸¼ÒÔËÊäÊÖÒÕÏà¹ØÆóÒµµÄ×éÖ¯ÒѳÉΪ¹¥»÷Ä¿µÄ¡£¡£¡£¡£¡£¡£
https://securelist.com/moonbounce-the-dark-side-of-uefi-firmware/105468/
ContiÍÅ»ïÉù³Æ¶ÔÓ¡¶ÈÄáÎ÷ÑÇÑëÐеÄÀÕË÷¹¥»÷ÈÏÕæ
¾ÝýÌå1ÔÂ20ÈÕ±¨µÀ£¬£¬£¬£¬Ó¡¶ÈÄáÎ÷ÑÇÒøÐУ¨BI£©ÈÏ¿ÉÆäÔâµ½ÀÕË÷¹¥»÷¡£¡£¡£¡£¡£¡£¸ÃÐн²»°ÈËÌåÏÖ£¬£¬£¬£¬¹¥»÷±¬·¢ÔÚÉϸöÔ£¬£¬£¬£¬¹¥»÷ÕßÇÔÈ¡Á˲¿·ÖÔ±¹¤µÄÐÅÏ¢£¬£¬£¬£¬²¢ÔÚÊ®¼¸¸öϵͳÉÏ×°ÖÃÁËÀÕË÷Èí¼þ£¬£¬£¬£¬µ«ÆäÔËÓª²¢Î´Êܵ½Ó°Ïì¡£¡£¡£¡£¡£¡£ContiÍÅ»ïÉù³Æ¶Ô´ËÊÂÈÏÕæ£¬£¬£¬£¬ÈôÊÇÓ¡ÄáÒøÐв»Ö§¸¶Êê½ð£¬£¬£¬£¬ËûÃǽ«¹ûÕæ¸ÃÒøÐÐ13.88 GBµÄÎļþ¡£¡£¡£¡£¡£¡£Ç°²»¾Ã£¬£¬£¬£¬Conti»¹¹¥»÷Á˰®¶ûÀ¼DoH¡¢HSE£¬£¬£¬£¬ºÍÓªÏú¹«Ë¾RR Donnelly¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/indonesias-central-bank-confirms-ransomware-attack-conti-leaks-data/
Ñо¿Ö°Ô±³ÆÊýÊ®¸öWordPressÖ÷ÌâºÍ²å¼þÒѱ»Ö²ÈëºóÃÅ
JetPackÔÚ1ÔÂ18ÈÕÐû²¼±¨¸æ£¬£¬£¬£¬³ÆÒÑÔÚÊýÊ®¸öWordPressÖ÷ÌâºÍ²å¼þÖз¢Ã÷ºóÃÅ¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±³Æ£¬£¬£¬£¬¹¥»÷ÕßÒÑÔÚAccessPress ThemesµÄ40¸öÖ÷ÌâºÍ53¸ö²å¼þÖÐÖ²ÈëºóÃÅ¡£¡£¡£¡£¡£¡£¾ÓÉÊÓ²ìµÃÖª£¬£¬£¬£¬AccessPress ThemesÓÚ2021Äê9ÔÂÉϰëÔÂÔâµ½¹¥»÷£¬£¬£¬£¬ÆäÊ±ÍøÕ¾ÉϵÄÀ©Õ¹³ÌÐò±»×¢ÈëÁ˺óÃÅ¡£¡£¡£¡£¡£¡£ÊÜѬȾµÄÀ©Õ¹³ÌÐò°üÀ¨Ò»¸öwebshell dropper£¬£¬£¬£¬Ê¹¹¥»÷Õß¿ÉÒÔÍêÈ«»á¼ûÄ¿µÄÍøÕ¾£¬£¬£¬£¬¸ÃÎó²î×·×ÙΪCVE-2021-24867¡£¡£¡£¡£¡£¡£
https://thehackernews.com/2022/01/hackers-planted-secret-backdoor-in.html
ʹÓÃCWPµÄÎļþ°üÀ¨ºÍí§ÒâдÈëÎó²î¿ÉʵÏÖÔ¶³Ì´úÂëÖ´ÐÐ
ýÌå1ÔÂ22ÈÕ±¨µÀ£¬£¬£¬£¬Control Web PanelÖб£´æ2¸öÑÏÖØµÄÎó²î¡£¡£¡£¡£¡£¡£Control Web Panel£¨ÒÔǰµÄCentOS Web Panel£©ÊÇÒ»¸ö¿ªÔ´µÄLinux¿ØÖÆÃæ°åÈí¼þ£¬£¬£¬£¬ÓÃÓÚ°²ÅÅWebÍйÜÇéÐΡ£¡£¡£¡£¡£¡£µÚÒ»¸öÊÇÎļþ°üÀ¨Îó²î£¨CVE-2021-45467£©£¬£¬£¬£¬¹¥»÷ÕßÖ»ÐèÐÞ¸ÄincludeÓï¾ä¾Í¿ÉÒÔÔ¶³Ì×¢Èë¶ñÒâ´úÂë»òʵÏÖ´úÂëÖ´ÐС£¡£¡£¡£¡£¡£µÚ¶þ¸öΪí§ÒâÎļþдÈëÎó²î£¨CVE-2021-45466£©£¬£¬£¬£¬Á¬ÏµÊ¹ÓÃÕâÁ½¸öÎó²î¿ÉÒÔÔÚÒ×Êܹ¥»÷µÄLinuxЧÀÍÆ÷ÉÏʵÏÖÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£¡£
https://securityaffairs.co/wordpress/127058/hacking/control-web-panel-flaws.html
MoleratsÍÅ»ïʹÓöà¸öÔÆÐ§ÀͶÔÖж«µØÇø¾ÙÐÐÌØ¹¤¹¥»÷
¾ÝýÌå1ÔÂ22ÈÕ±¨µÀ£¬£¬£¬£¬Çå¾²¹«Ë¾Zscaler·¢Ã÷MoleratsÍÅ»ïÕë¶ÔÖж«µØÇøµÄÌØ¹¤»î¶¯¡£¡£¡£¡£¡£¡£¾ÝϤ£¬£¬£¬£¬¹¥»÷´Ó2021Äê7Ô¾ÍÒÑ×îÏÈ£¬£¬£¬£¬¹¥»÷ÕßʹÓÃÕýµ±µÄÔÆÐ§ÀÍ£¨ÈçGoogle DriveºÍDropbox£©ÍйܶñÒâÈí¼þpayload£¬£¬£¬£¬´ÓÖж«µØÇøµÄÄ¿µÄÖÐÇÔÈ¡Êý¾Ý¡£¡£¡£¡£¡£¡£´Ë´Î»î¶¯Ê¹ÓÃÓëÒÔÉ«ÁкͰÍÀÕ˹̹³åÍ»Ïà¹ØµÄÓÕ¶ü£¬£¬£¬£¬ÔÚÄ¿µÄϵͳÉÏ×°ÖÃ.NETºóÃÅ£¬£¬£¬£¬Ö÷ҪĿµÄ°üÀ¨°ÍÀÕË¹Ì¹ÒøÐÐÒµÔ±¹¤¡¢°ÍÀÕ˹̹Õþµ³³ÉÔ±£¬£¬£¬£¬ÒÔ¼°ÍÁ¶úÆä¼ÇÕߵȡ£¡£¡£¡£¡£¡£
https://thehackernews.com/2022/01/molerats-hackers-hiding-new-espionage.html
×ÖÄ»ÍøÕ¾OpenSubtitles½ü700ÍòÓû§µÄÐÅϢй¶
¾Ý1ÔÂ23ÈÕ±¨µÀ£¬£¬£¬£¬×ÖÄ»ÍøÕ¾OpenSubtitlesÔâµ½¹¥»÷£¬£¬£¬£¬6783158¸öÓû§µÄÐÅÏ¢ÒѾй¶¡£¡£¡£¡£¡£¡£2021Äê8Ô£¬£¬£¬£¬ÍøÕ¾ÖÎÀíÔ±ÊÕµ½Êê½ð֪ͨºó²ÅÒâʶµ½ÆäÒÑÔâµ½¹¥»÷¡£¡£¡£¡£¡£¡£¹¥»÷Õß»¹ÌåÏÖ»áÌṩ֧³ÖÒÔÐÞ¸´ÍøÕ¾ÖеÄÎó²î£¬£¬£¬£¬µ«ÔÚÖ§¸¶Êê½ðºó¹¥»÷Õß´Óδ×ÊÖúËûÃǼӹÌÍøÕ¾£¬£¬£¬£¬²¢ÔÚ1ÔÂ11ÈÕ¹ûÕæÁ˱»µÁÊý¾Ý¡£¡£¡£¡£¡£¡£¾ÝϤ£¬£¬£¬£¬ºÚ¿Íͨ¹ýSQL×¢Èë¹¥»÷»á¼ûÁËÍøÕ¾µÄÊý¾Ý¿â£¬£¬£¬£¬ÇÔÈ¡ÁËÓû§Óʼþ¡¢IPµØµã¡¢Óû§Ãû¡¢ËùÔÚ¹ú¼ÒºÍÃÜÂëµÈÐÅÏ¢¡£¡£¡£¡£¡£¡£
https://securityaffairs.co/wordpress/127092/data-breach/opensubtitles-data-breach.html
Çå¾²¹¤¾ß
Narthex
ÊÇÒ»¸öÄ£¿£¿£¿é»¯ºÍ×îСµÄ×ÖµäÌìÉúÆ÷£¬£¬£¬£¬ÓÃÓÚÓà C ºÍ Shell ±àдµÄ Unix ºÍÀà Unix ²Ù×÷ϵͳ¡£¡£¡£¡£¡£¡£
https://github.com/MichaelDim02/Narthex
Iptable_Evil
IptablesµÄºóÃÅ£¬£¬£¬£¬Ê¹¶ñÒâÊý¾Ý°üͨ¹ýiptables£¬£¬£¬£¬ÎÞÂÛ·À»ðǽ¹æÔòÔõÑù¡£¡£¡£¡£¡£¡£
https://github.com/FlamingSpork/iptable_evil
iMonitor
ÊÇÒ»¿î»ùÓÚiMonitorSDKµÄ¶ËµãÐÐΪ¼à¿ØÆÊÎöÈí¼þ¡£¡£¡£¡£¡£¡£
https://github.com/wecooperate/iMonitor/releases
Çå¾²ÆÊÎö
΢ÈíÐÞ¸´ÁË Windows 10 µÄ Outlook ËÑË÷ÎÊÌâ
΢ÈíÐÞ¸´ÁË×°ÖÃ2021 Äê 11 ÔÂÐû²¼µÄ Windows 10 Çå¾²¸üкóµ¼Ö Outlook Óû§·ºÆðËÑË÷ÎÊÌâµÄÎÊÌâ¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/microsoft/microsoft-fixes-outlook-search-issues-for-windows-10-users/
WordPress²å¼þ±£´æÎó²î
WP HTML MailÖб£´æÒ»¸öÑÏÖØµÄ¿çÕ¾µã¾ç±¾(XSS)Îó²î£¬£¬£¬£¬Ó°ÏìÁè¼Ý20,000¸öWordPressÍøÕ¾¡£¡£¡£¡£¡£¡£
https://threatpost.com/wordpress-insecure-plugin-rest-api/177866/