6ÔÂWindows¸üпÉÄܵ¼Ö²¿ÃÅÓ¦ÓÃÎÞ·¨Ê¹ÓÃVSS±¸·Ý

Ðû²¼Ê±¼ä 2022-06-17
1¡¢6Ô·ÝWindows¸üпÉÄܵ¼Ö²¿ÃÅÓ¦ÓÃÎÞ·¨Ê¹ÓÃVSS±¸·Ý

      

¾Ý6ÔÂ15ÈÕ±¨µÀ £¬Î¢ÈíÌåÏÖ £¬ÔÚ°²×°2022Äê6ÔµÄWindows¸üкó £¬Ä³Ð©Ó¦Ó÷¨Ê½¿ÉÄÜÎÞ·¨Ê¹ÓþíÓ°¸´ÖÆ·þÎñ(VSS)À´±¸·ÝÊý¾Ý¡£¸ÃÎÊÌâÊÇÐÞ¸´MicrosoftÎļþ·þÎñÆ÷¾íÓ°¸´ÖÆÊðÀí·þÎñ(RVSS)ÖеÄÌáȨ©¶´(CVE-2022-30154)µ¼Öµġ£´æÔÚÎÊÌâµÄϵͳÖÐ £¬Windows±¸·ÝÓ¦Ó÷¨Ê½ÔÚ¾íÓ°¸´ÖÆ´´½¨¹ý³ÌÖпÉÄÜ»áÊÕµ½E_ACCESSDENIED´íÎó £¬ÇÒ»áÔÚÎļþ·þÎñÆ÷ÖмǼΪ"FileShareShadowCopyAgent Event 1013"¡£


https://www.bleepingcomputer.com/news/microsoft/microsoft-june-windows-server-updates-may-cause-backup-issues/


2¡¢F5 LabsÅû¶ÐÂAndroidľÂíMaliBotµÄϸ½ÚÐÅÏ¢

      

6ÔÂ15ÈÕ £¬F5 Labs×îгÂËßÅû¶ÁËAndroidľÂíMaliBotµÄϸ½ÚÐÅÏ¢¡£MaliBotרעÓÚÇÔÈ¡½ðÈÚÐÅÏ¢ £¬ÀýÈçµç×ÓÒøÐзþÎñƾ֤¡¢¼ÓÃÜÇ®°üÃÜÂëºÍ¸öÈËÏêϸÐÅÏ¢ £¬»¹¿ÉÒÔÇÔÈ¡ºÍÈÆ¹ý¶àÒòËØ(2FA/MFA)´úÂë £¬Ö÷ÒªÕë¶ÔÒâ´óÀûºÍÎ÷°àÑÀµÄ½ðÈÚ»ú¹¹¡£¸Ã¶ñÒâÈí¼þ»áαװ³É¼ÓÃÜ»õ±ÒÍÚ¾òÓ¦Ó÷¨Ê½¡°Mining X¡±ºÍ¡°The CryptoApp¡± £¬ÓÐʱҲαװ³É¡°MySocialSecurity¡±ºÍ¡°Chrome¡±¡£´ËÍâ £¬Ñо¿ÈËÔ±ÌåÏÖÆäC2·þÎñÆ÷λÓÚ¶íÂÞ˹ £¬ËƺõÓë·Ö·¢SalityµÄ»î¶¯Ê¹ÓõÄÊÇͬһ¸ö·þÎñÆ÷ £¬×Ô2020Äê6ÔÂÒÔÀ´ £¬Ðí¶à»î¶¯¶¼Ô´×Ô´ËIP¡£


https://www.f5.com/labs/articles/threat-intelligence/f5-labs-investigates-malibot


3¡¢Citrix ADM¿ÉÖØÖùÜÀíÔ±ÃÜÂëµÄ©¶´CVE-2022-27511

      

¾ÝýÌå6ÔÂ15ÈÕ±¨µÀ £¬CitrixÓ¦Óý»¸¶¹ÜÀí(ADM)´æÔÚ¿ÉÖØÖùÜÀíÔ±ÃÜÂëµÄ©¶´¡£¸Ã©¶´×·×ÙΪCVE-2022-27511 £¬ÊÇÓɲ»ÕýÈ·µÄ·ÃÎÊ¿ØÖƵ¼Ö嵀 £¬Ó°ÏìËùÓÐÊÜÖ§³ÖµÄCitrix ADM·þÎñÆ÷ºÍCitrix ADMÊðÀí°æ±¾¡£Citrix½âÊ͵À £¬ÀûÓøÃ©¶´¿ÉÄÜÔÚÏ´ÎÉè±¸ÖØÆôÊ±ÖØÖùÜÀíÔ±ÃÜÂë £¬¾ßÓÐssh·ÃÎÊȨÏ޵Ĺ¥»÷ÕßÔÚÉè±¸ÖØÆôºó¿ÉÒÔʹÓÃĬÈϹÜÀíԱƾ¾Ý½øÐÐÁ¬½Ó¡£Ä¿Ç° £¬Â©¶´Òѱ»ÐÞ¸´ £¬¸Ã¹«Ë¾½¨Òé¹ÜÀíÔ±Á¢¼´°²×°²¹¶¡¡£


https://www.bleepingcomputer.com/news/security/citrix-warns-critical-bug-can-let-attackers-reset-admin-passwords/


4¡¢Ñо¿ÈËÔ±·¢ÏÖBeanVPN½ü20GBµÄÁ¬½ÓÈÕÖ¾¿É¹ûÈ»·ÃÎÊ

      

ýÌå6ÔÂ15ÈÕ³Æ £¬CybernewsµÄÊӲ췢ÏÖÌṩÉÌBeanVPN 18.5 GBµÄÁ¬½ÓÈÕÖ¾¿É±»¹ûÈ»·ÃÎÊ¡£¸Ã»º´æÈÕÖ¾°üÂÞÁè¼Ý2500ÍòÌõ¼Ç¼ £¬Éæ¼°Óû§É豸ºÍPlay·þÎñID¡¢Á¬½Óʱ¼ä´ÁºÍIPµØÖ·µÈ¡£Ñо¿ÈËÔ±ÌåÏÖ £¬Play·þÎñID¿ÉÓÃÓÚ²éÕÒÓû§µÇ¼É豸ʱʹÓõĵç×ÓÓʼþµØÖ·¡£´ËÍâ £¬¸ÃÌṩÉÌÌåÏÖ²»ÊÕ¼¯Óû§IPµØÖ·¡¢´«³öIPµØÖ·¡¢Á¬½Óʱ¼ä´ÁºÍ»á»°Á¬ÐøÊ±¼äµÈÐÅÏ¢¡£µ«Õâһ˵·¨Óëй¶µÄÐÅÏ¢²¢·×ÆçÖ £¬ºóÕß¼¸ºõ°üÂÞÁËBeanVPNÉù³Æ²»»áÊÕ¼¯µÄËùÓÐÊý¾Ý¡£Ä¿Ç° £¬Ð¹Â¶µÄÊý¾ÝÒѱ»±£»¤ÆðÀ´¡£


https://www.infosecurity-magazine.com/news/beanvpn-leaks-user-records/


5¡¢ÃÀ¹úTransact CampusÅäÖôíÎóй¶3Íò¶àѧÉúµÄÐÅÏ¢

      

ýÌå6ÔÂ15ÈÕ±¨µÀ £¬SafetyDetectives·¢ÏÖÁËÒ»¸öÅäÖôíÎóµÄElasticsearch·þÎñÆ÷ £¬ÆäÖаüÂÞTransact CampusµÄÓ¦Ó÷¨Ê½µÄÊý¾Ý¡£¸ÃÓ¦ÓÃÓÃÓڸߵȽÌÓý»ú¹¹µÄѧÉúµÄÖ§¸¶Á÷³Ì £¬´Ë´Îʼþй¶ÁËÔ¼100ÍòÌõ¼Ç¼ £¬Éæ¼°3ÖÁ4ÍòÃûѧÉú¡£ÖµµÃ×¢ÒâµÄÊÇ £¬Óû§ÃûºÍÃÜÂëµÈµÇ¼Êý¾Ý¾ùÒÔ´¿Îı¾¸ñʽ´æ´¢ £¬ÇÒй¶µÄÐÅÓÿ¨ÐÅÏ¢°üÂÞÒøÐÐʶ±ðºÅ¡¢ÐÅÓÿ¨ºÅµÄǰÁùλºÍºóËÄλºÍµ½ÆÚÈÕÆÚµÈ¡£Ä¿Ç° £¬Êý¾Ý¿âÒѱ»±£»¤ÆðÀ´ £¬µ«¸Ã¹«Ë¾Éù³Æ·þÎñÆ÷²»ÔÚËûÃǵĿØÖÆÖ®ÏÂÇÒÊý¾ÝÊǼٵġ£µ«Ñо¿ÈËÔ±ÌåÏÖ¾­¹ý¿ªÔ´¹¤¾ßµÄ¼ì²é £¬ÕâЩÊý¾ÝÊôÓÚÕæÊµµÄÓû§¡£


https://www.hackread.com/elasticsearch-database-expose-login-pii-data-students/


6¡¢Blue MockingbirdÍÅ»ïÀÄÓÃTelerik UIÖеÄ©¶´ÍÚ¿ó

      

6ÔÂ15ÈÕ £¬SophosÐû²¼ÁËBlue Mockingbird½üÆÚ¹¥»÷»î¶¯µÄ·ÖÎö³ÂËß¡£¸ÃÍÅ»ïÀûÓÃÁËTelerik UI WebÓ¦Ó÷¨Ê½¿ò¼ÜÖеÄ©¶´À´ÈëÇÖ·þÎñÆ÷ £¬°²×°Cobalt Strike beacons £¬È»ºó½Ù³Öϵͳ×ÊÔ´À´ÍÚ¾òMonero¡£¹¥»÷ÕßÀûÓõÄÊÇÒÑ´æÔÚ3ÄêµÄ.NET·´ÐòÁл¯Â©¶´£¨CVE-2019-18935 £¬CVSSÆÀ·Ö9.8£© £¬¿ÉÔÚTelerik UI¿âÖÐÔ¶³ÌÖ´ÐÐASP.NET AJAXµÄ´úÂë¡£´ËÍâ £¬ÔÚ¹¥»÷¹ý³ÌÖÐ £¬¸ÃÍÅ»ïʹÓÃÁËÒ»ÖÖÏֳɵÄPoC £¬¿É´¦ÖüÓÃÜÂß¼­²¢×Ô¶¯Ö´ÐÐDLL±àÒë¡£


https://www.bleepingcomputer.com/news/security/hackers-exploit-three-year-old-telerik-flaws-to-deploy-cobalt-strike/