´óÁ¿QNAP NASÓû§³ÆÆäÉ豸Ôâµ½ech0raixµÄÀÕË÷¹¥»÷

Ðû²¼Ê±¼ä 2022-06-20

1¡¢´óÁ¿QNAP NASÓû§³ÆÆäÉ豸Ôâµ½ech0raixµÄÀÕË÷¹¥»÷

      

ýÌå6ÔÂ18ÈÕ±¨µÀ£¬Æ¾¾ÝID Ransomwareƽ̨ÉÏÓû§Ìá½»µÄ³ÂËߺÍÑù±¾£¬ech0raixÀÕË÷Èí¼þÔÚÉÏÖÜ¿ªÊ¼ÔÙ´ÎÕë¶ÔQNAP NASÉ豸¡£Ô½À´Ô½¶àµÄÓû§³ÆÆäÔâµ½¹¥»÷£¬×îÔç·¢ÉúÔÚ6ÔÂ8ÈÕ¡£¾¡¹ÜÖ»Óм¸Ê®¸öech0raixÑù±¾£¬µ«Ñо¿ÈËÔ±ÌåÏÖʵ¼ÊµÄÀֳɹ¥»÷µÄÊýÁ¿ºÜ¿ÉÄܸü¸ß£¬ÒòΪֻÓв¿ÃÅÓû§»áʹÓÃID Ransomware·þÎñÀ´Ê¶±ðÀÕË÷Èí¼þ¡£QNAPÉÐδÐû²¼Óйش˴ι¥»÷µÄ¸ü¶àÐÅÏ¢£¬Õâ¸öech0raix»î¶¯Ê¹ÓõĹ¥»÷ý½éÈÔȻδ֪¡£


https://www.bleepingcomputer.com/news/security/qnap-nas-devices-targeted-by-surge-of-ech0raix-ransomware-attacks/


2¡¢ÃÀ¹úÕþ¸®³ÆÒѵ·»ÙѬȾÊý°ÙÍòÉ豸µÄ½©Ê¬ÍøÂçRSOCKS

      

¾Ý6ÔÂ18ÈÕ±¨µÀ£¬ÃÀ¹úÕþ¸®ÓëµÂ¹ú¡¢ºÉÀ¼ºÍÓ¢¹úµÄÖ´·¨»ú¹¹ºÏ×÷£¬Àֳɲð³ýÁËÓë¶íÂÞ˹½©Ê¬ÍøÂçRSOCKSÓйصĻù´¡ÉèÊ©¡£RSOCKSÓÉÈ«ÇòÊý°ÙÍǫ̀±»Ñ¬È¾µÄÉ豸×é³É£¬×ԳƿÉÒÔ¹©¸¶·Ñ¿Í»§·ÃÎʱ»ÈëÇÖµÄÉ豸µÄIPµØÖ·¡£¸ÃÐж¯¿ªÊ¼ÓÚ2017Ä꣬Æäʱִ·¨ÈËÔ±´ÓRSOCKSÃØÃܵعºÖÃÁËÆä·þÎñÒÔʶ±ðÆä»ù´¡ÉèÊ©ºÍÄ¿±ê£¬È·¶¨ÁËԼĪ325000̨±»Ñ¬È¾µÄÉ豸¡£½üÆÚµÄÁíÒ»ÏîÖ´·¨Ðж¯²é»ñÁËÒѳöÊÛ2400ÍòÈËÐÅÏ¢µÄ°µÍøÊг¡SSNDOB¡£


https://securityaffairs.co/wordpress/132403/cyber-crime/police-dismantled-rsocks-bitnet.html


3¡¢VolexityÅû¶DriftingCloudÍÅ»ï½üÆÚ¹¥»÷»î¶¯µÄϸ½Ú

      

VolexityÔÚ6ÔÂ15ÈÕÐû²¼³ÂËߣ¬Åû¶ÁËDriftingCloudÍÅ»ï½üÆÚ¹¥»÷»î¶¯µÄϸ½Ú¡£Ñо¿ÈËÔ±·¢ÏÖ£¬×Ô3Ô³õ¿ªÊ¼£¬¸ÃÍÅ»ï¾ÍÀûÓÃÁËSophos FirewallÖеÄÉí·ÝÑéÖ¤ÈÆ¹ý©¶´£¨CVE-2022-1040£¬CVSSÆÀ·Ö9.8£©À´ÈëÇÖÄ¿±ê£¬È»ºó°²×°Ò»¸öºóÃÅ¡£Volexity³Æ¹¥»÷Õß»áÀûÓ÷À»ðǽµÄ·ÃÎÊȨÏÞÀ´¸Ä¶¯Õë¶ÔÌØ¶¨Ä¿±êÍøÕ¾µÄDNSÏìÓ¦£¬ÒÔÖ´ÐÐMITM¹¥»÷¡£Ò»µ©»ñµÃ¶ÔÄ¿±êÍøÂç·þÎñÆ÷µÄ·ÃÎÊȨÏÞ£¬¹¥»÷Õ߾ͻᰲװ¶à¸ö¿ªÔ´¶ñÒâÈí¼þ£¬°üÂÞPupyRAT¡¢PanteganaºÍSliver¡£


https://www.volexity.com/blog/2022/06/15/driftingcloud-zero-day-sophos-firewall-exploitation-and-an-insidious-breach/


4¡¢ÉϰÙÍòWordPressÍøÕ¾µÄ²å¼þNinja Forms±»Ç¿ÖƸüÐÂ

      

¾ÝýÌå6ÔÂ17Èճƣ¬ÉϰÙÍò¸öWordPressÍøÕ¾Òѱ»Ç¿ÖƸüУ¬ÒÔÐÞ¸´Æä²å¼þNinja FormsÖеÄ©¶´¡£ÕâÊÇÒ»¸ö´úÂë×¢Èë©¶´£¬CVSSÆÀ·ÖΪ9.8£¬Ó°ÏìÁË´Ó3.0¿ªÊ¼µÄ¶à¸öNinja Forms°æ±¾¡£Ñо¿ÈËÔ±ÌåÏÖ£¬Î´¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔÔ¶³ÌÀûÓôË©¶´À´µ÷ÓÃÖÖÖÖNinja±íµ¥À࣬Ȼºóͨ¹ý¶à¸öÀûÓÃÁ´ÍêÈ«½Ó¹ÜWordPressÍøÕ¾¡£Wordfence·¢ÏÖµÄÖ¤¾Ý±íÃ÷£¬¸Ã©¶´ÒÑÔÚ¹¥»÷Öб»ÀûÓã¬WordPressΪ´Ë²å¼þÖ´ÐÐÁËÇ¿ÖÆ×Ô¶¯¸üС£


https://thehackernews.com/2022/06/over-million-wordpress-sites-forcibly.html


5¡¢Ñо¿ÈËÔ±·¢ÏÖÀûÓÃÀ¬»øÓʼþ·Ö·¢MatanbuchusµÄ»î¶¯

      

¾Ý6ÔÂ18ÈÕµÄýÌ屨µÀ£¬Ñо¿ÈËÔ±·¢ÏÖÁË·Ö·¢¶ñÒâÈí¼þMatanbuchusµÄÀ¬»øÓʼþ»î¶¯¡£¹¥»÷ÕßÊ×ÏÈʹÓüÙ×°ÊǶÔÏÈǰµç×ÓÓʼþµÄ»Ø¸´×÷ΪÓÕ¶ü£¬ÆäÖаüÂÞÒ»¸öZIP¸½¼þ£¬¿ÉÏÂÔØÒ»¸öMSI°ü£¬¸Ã°üʹÓÃÓÉDigiCertΪ¡°Westeast Tech Consulting, Corp.¡±·¢±íµÄÓÐЧ֤Êé½øÐÐÇ©Ãû¡£Ö®ºó£¬»áÏÂÔØÁ½¸öMatanbuchus DLL payload£¬¸Ã¶ñÒâÈí¼þ×îÖÕ»á´ÓC2·þÎñÆ÷ÏÂÔØCobalt Strike£¬ÎªºóÐø¹¥»÷×ö×¼±¸¡£


https://www.bleepingcomputer.com/news/security/new-phishing-attack-infects-devices-with-cobalt-strike/


6¡¢¿ý±±¿Ë·¨ÔºÅоöDesjardins¾ÍÊý¾Ýй¶Ê¼þÖ§¸¶2ÒÚ¼ÓÔª

      

6ÔÂ18ÈÕ±¨µÀ³Æ£¬¿ý±±¿Ë·¨ÔºÒÑÅоöDesjardinsÖ§¸¶2.009ÒÚ¼ÓÔªÒÔ½â¾ö¶ÔÊý¾Ýй¶Ê¼þµÄ¼¯ÌåËßËÏ¡£¼à¹Ü»ú¹¹ÌåÏÖ£¬DesjardinsµÄÎ¥¹æÊ¼þÊÇÓÉһϵÁЩ¶´Ôì³ÉµÄ£¬Ð¹Â¶ÁË420Íò¸öÓµÓлîÔ¾ÕË»§µÄÓû§µÄÊý¾Ý¡£¾ÝϤ£¬Ã¿¸öÊÜÓ°ÏìµÄÓû§¶¼ÓÐ×ʸñÌá³öË÷Åâ¡£Ôڴ˽׶Σ¬Óû§²»±Ø½ÓÄÉÈκδëÊ©£¬°üÂÞË÷Åâ˵Ã÷ÔÚÄÚµÄ֪ͨ½«ÔÚ×Ô7ÔÂ21ÈÕ¿ªÊ¼µÄ¼¸¸öÔÂÄÚ·Ö·¢¡£


https://www.databreaches.net/quebec-court-approves-200-9m-settlement-against-desjardins-over-data-breach/