Ò½ÁÆ»ú¹¹CHSÒòFortra©¶´Ð¹Â¶100Íò»¼ÕߵĸöÈËÐÅÏ¢
Ðû²¼Ê±¼ä 2023-02-16
¾Ý2ÔÂ14ÈÕ±¨µÀ£¬ÃÀ¹úÒ½ÁÆ»ú¹¹Community Health Systems(CHS)³ÆÆäÊܵ½ÁËÕë¶ÔFortraµÄGoAnywhere MFTƽ̨ÖÐÁãÈÕ©¶´µÄ¹¥»÷µÄÓ°Ïì¡£Õâ¼ÒÒ½ÁÆ·þÎñ¹«Ë¾ÖÜÒ»ÌåÏÖ£¬Fortra·¢³ö¾¯±¨³Æ¾ÀúÁËÒ»´ÎÄþ¾²Ê¼þ£¬µ¼ÖÂCHSµÄ²¿ÃÅÊý¾Ýй¶¡£ËæºóµÄÊÓ²ìÏÔʾ£¬´Ë´Îй¶ӰÏìÁ˶à´ï100ÍòÃû»¼ÕߵĸöÈ˺ͽ¡¿µÐÅÏ¢¡£ClopÍÅ»ïÉù³ÆÊÇÕâ´Î¹¥»÷µÄÄ»ºóºÚÊÖ£¬»¹³ÆÒÑÇÔÈ¡130¶à¸ö×éÖ¯µÄÊý¾Ý¡£
https://www.bleepingcomputer.com/news/security/healthcare-giant-chs-reports-first-data-breach-in-goanywhere-hacks/
2¡¢CitrixÐÞ¸´Workspace AppsµÈ²úÎïÖеĶà¸ö©¶´
¾ÝýÌå2ÔÂ15ÈÕ±¨µÀ£¬Citrix SystemsÐû²¼Äþ¾²¸üУ¬ÐÞ¸´ÆäVirtual Apps and DesktopsºÍWorkspace Apps²úÎïÖеÄ©¶´¡£ÆäÖÐ×îÑÏÖصÄÊÇȨÏÞ¹ÜÀí²»Íש¶´£¨CVE-2023-24483£©£¬¿É½«È¨ÏÞÌáÉýµ½NT AUTHORITY\SYSTEM¡£´ËÍ⣬»¹Óпɽ«ÈÕÖ¾ÎļþдÈëÆÕͨÓû§ÎÞȨдÈëµÄĿ¼µÄ·ÃÎÊ¿ØÖƲ»Íש¶´£¨CVE-2023-24484£©£¬ÒÔ¼°µ¼ÖÂȨÏÞÌáÉýµÄ·ÃÎÊ¿ØÖƲ»Íש¶´£¨CVE-2023-24485£©ºÍµ¼Ö»Ự½Ó¹ÜµÄ·ÃÎÊ¿ØÖƲ»Íש¶´£¨CVE-2023-24486£©¡£CISAÐû²¼Á˹ØÓÚ¾¡¿ìÓ¦ÓÃCitrixÄþ¾²¸üеľ¯±¨¡£
https://www.bleepingcomputer.com/news/security/citrix-fixes-severe-flaws-in-workspace-virtual-apps-and-desktops/
3¡¢CiscoÅû¶·Ö·¢MortalKombatºÍLaplas ClipperµÄ»î¶¯
Cisco TalosÔÚ2ÔÂ14ÈÕÅû¶ÁËÒ»Æð·Ö·¢ÀÕË÷Èí¼þMortalKombatºÍ¶ñÒâÈí¼þLaplas ClipperµÄ»î¶¯¡£Ñо¿ÈËÔ±×Ô2022Äê12Ô¿ªÊ¼ÊӲ쵽Á˸û£¬Ö÷ÒªÕë¶ÔÃÀ¹ú¡¢Ó¢¹ú¡¢ÍÁ¶úÆäºÍ·ÆÂɱöµÈµØÓò¡£¹¥»÷»î¶¯Ê¼ÓÚµöÓãµç×ÓÓʼþ£¬²¢Æô¶¯¶à½×¶Î¹¥»÷Á´£¬»á·Ö·¢¶ñÒâÈí¼þ»òÀÕË÷Èí¼þ£¬È»ºóɾ³ý¶ñÒâÎļþµÄÖ¤¾Ý£¬ÑÚ¸ÇÆä×Ù¼£²¢Èƹý·ÖÎö¡£MortalKombatÊÇXoristµÄÒ»ÖÖ±äÌ壬ÓÚ2023Äê1ÔÂÊ״α»·¢ÏÖ¡£Laplas ClipperÊÇÏà¶Ô½ÏеļôÌù°åÇÔÈ¡·¨Ê½£¬ÓÃÓÚÇÔÈ¡Ä¿±êµÄ¼ÓÃÜ»õ±Ò¡£
https://blog.talosintelligence.com/new-mortalkombat-ransomware-and-laplas-clipper-malware-threats/
4¡¢16¸ö¶ñÒâNPM°üαװ³ÉÍøËÙ²âÊÔÆ÷Ö¼ÔÚÍÚ¾ò¼ÓÃÜ»õ±Ò
2ÔÂ14ÈÕ£¬Check Point³ÆÆäÔÚNPMÉϼì²âµ½16¸ö¶ñÒâ°ü¡£ËüÃÇαװ³ÉÍøËÙ²âÊÔÆ÷£¬Ö¼ÔÚ½Ù³ÖÄ¿±êµÄ¼ÆËã»ú×ÊÔ´ÒÔÍÚ¾ò¼ÓÃÜ»õ±Ò¡£ËùÓаü¾ùÓÉÓû§trendavaÉÏ´«µ½NPM£¬¾¡¹ÜËüÃǾßÓÐÏàͬµÄÄ¿±ê£¬µ«Ñо¿ÈËÔ±·¢ÏÖÿ¸ö°ü¶¼½ÓÄɲîÒìµÄ±àÂëºÍÒªÁìÀ´Íê³ÉÆäÈÎÎñ¡£¿ÉÒÔÈÏΪÕâЩ²îÒì´ú±íÁ˹¥»÷ÕßËù×öµÄÊÔÑ飬ËûÊÂÏȲ»ÖªµÀÄĸö°æ±¾»á±»Äþ¾²¹¤¾ß¼ì²âµ½£¬Òò´ËʵÑéÓòîÒìµÄ·½Ê½À´Òþ²Ø¶ñÒâÒâͼ¡£Ñо¿ÈËÔ±ÓÚ1ÔÂ17ÈÕ·¢ÏÖÁËÕâЩ°ü£¬NPMÓÚÔ½ÈÕɾ³ýÁËËüÃÇ¡£
https://blog.checkpoint.com/2023/02/14/check-point-cloudguard-spectral-detects-malicious-crypto-mining-packages-on-npm-the-leading-registry-for-javascript-open-source-packages/
5¡¢BlackCat³ÆÒÑÇÔÈ¡°®¶ûÀ¼Ã÷˹ÌؿƼ¼´óѧ6GBµÄÊý¾Ý
ýÌå2ÔÂ14Èճƣ¬BlackCat£¨Ò²³ÆALPHV£©ÔÚÆäÍøÕ¾ÁгöÁË´Ó°®¶ûÀ¼Ã÷˹ÌؿƼ¼´óѧ(MTU)ÇÔÈ¡µÄÁè¼Ý6 GBµÄÊý¾Ý¡£¸ÃÍÅ»ïÔÚ.onionÍøÕ¾ÉÏÉù³Æй¶ÐÅÏ¢°üÂÞÔ±¹¤¼Ç¼ºÍÈËΪµ¥ÏêϸÐÅÏ¢£¬ÕâÁ½¸öÊý¾Ý¼¯¶¼¿ÉÄܵ¼ÖÂÆÛÕ©ºÍɧÈŻ¡£MTUÔøÓÚ2ÔÂ6Èճƣ¬ÓÉÓÚÖØ´óITÎÊÌâºÍµç»°Öжϣ¬ÆäλÓڿƿ˵ÄУÇø¹Ø±ÕÇҿγÌÈ¡Ïû£¬µ«²¢Î´½«´Ë´Î¹¥»÷¹é¾ÌÓÚÌض¨µÄ¹¥»÷ÍŻ
https://therecord.media/alphv-blackcat-posted-data-ireland-munster-technical-university/
6¡¢MinervaÐû²¼ÇÔÈ¡ÐÅÏ¢µÄ¶ñÒâÈí¼þBeepµÄ·ÖÎö³ÂËß
2ÔÂ13ÈÕ£¬MinervaÐû²¼Á˹ØÓÚÇÔÈ¡ÐÅÏ¢µÄ¶ñÒâÈí¼þBeepµÄ·ÖÎö³ÂËß¡£BeepʹÓÃÈý¸ö¶ÀÁ¢µÄ×é¼þ£ºÖ²È뷨ʽ¡¢×¢È뷨ʽºÍpayload¡£¸Ã¶ñÒâÈí¼þËƺõÈÔÔÚ¿ª·¢ÖУ¬Ñо¿ÈËÔ±ÔÚÑù±¾Öз¢ÏÖÁ˺ܶàÓÉC2ÃüÁî´¥·¢µÄ¹¦Ð§ÉÐδʵʩ¡£BeepÖ®ËùÒÔÍÑÓ±¶ø³ö£¬ÊÇÒòΪÔÚÕû¸öÖ´ÐÐÁ÷³ÌÖÐʹÓÃÁ˶àÖÖ¼¼ÊõÀ´ÈƹýÄþ¾²Èí¼þºÍÑо¿ÈËÔ±µÄ¼ì²âºÍ·ÖÎö£¬°üÂÞ¶¯Ì¬×Ö·û´®È¥»ìÏý¡¢ÏµÍ³ÓïÑÔ¼ì²é¡¢IsDebuggerPresent APIº¯ÊýµÄ·¨Ê½¼¯ºÍNtGlobalFlag×ֶη´µ÷ÊԵȡ£
https://www.bleepingcomputer.com/news/security/new-stealthy-beep-malware-focuses-heavily-on-evading-detection/