AnimkerÊý¾Ý¿âÅäÖôíÎóÁè¼Ý70ÍòÓû§µÄÐÅϢй¶
Ðû²¼Ê±¼ä 2023-03-021¡¢AnimkerÊý¾Ý¿âÅäÖôíÎóÁè¼Ý70ÍòÓû§µÄÐÅϢй¶
¾Ý3ÔÂ1ÈÕ±¨µÀ£¬Ñо¿ÈËÔ±ÔÚShodanÉÏ·¢ÏÖÁËÒ»¸öÅäÖôíÎóµÄÊý¾Ý¿â£¬Ð¹Â¶ÁËgetshow.ioºÍanimaker.comÍøÕ¾Áè¼Ý700000Óû§µÄ²âÊԺ͸öÈËÊý¾Ý¡£Getshow.ioÊôÓÚAnimker.com£¬ÓÐÎÊÌâµÄ·þÎñÆ÷×¢²áÔÚÓòÃûgetshow.ioÏ£¬ÓÉanimaker.com¹ÜÀí¡£¸ÃÊý¾Ý¿âÄ¿Ç°°üÂÞ5.3GBµÄÊý¾Ý£¬¶øÇÒËæ×ÅÿÌìÐÂÌí¼ÓµÄÊý¾ÝÔÚ²»Í£Ôö³¤£¬Éæ¼°Óû§ÐÕÃû¡¢É豸ÀàÐÍ¡¢IPµØÖ·ºÍÊÖ»úºÅÂëµÈ¡£Ä¿Ç°£¬AnimkerÒÑ»ñÖª´ËÊ£¬µ«ÈÔδ½øÐлØÓ¦¡£
https://www.hackread.com/video-marketing-software-animker-data-leak/
2¡¢Aruba Networks¸üÐÂÐÞ¸´ÆäArubaOSÖеÄ6¸ö©¶´
ýÌå3ÔÂ1ÈÕ±¨µÀ³Æ£¬Aruba NetworksÐû²¼Äþ¾²¸üУ¬ÐÞ¸´ÁËÓ°ÏìÆäרÓÐÍøÂç²Ù×÷ϵͳArubaOS¶à¸ö°æ±¾µÄ6¸ö©¶´¡£´Ë´ÎÐÞ¸´µÄ©¶´¿ÉÒÔ·ÖΪÁ½ÀࣺPAPIÐÒ飨Aruba Networks½ÓÈëµã¹ÜÀíÐÒ飩ÖеÄÃüÁî×¢È멶´£¨CVE-2023-22747¡¢CVE-2023-22748¡¢CVE-2023-22749ºÍCVE-2023-22750£©ºÍ»ùÓÚ¶ÑÕ»µÄ»º³åÇøÒç³ö©¶´£¨CVE-2023-22751ºÍCVE-2023-22752£©¡£ËüÃǵÄCVSSÆÀ·Ö¾ùΪ9.8£¬¿Éͨ¹ýUDP¶Ë¿Ú8211ÏòPAPI·¢ËÍÌØÖÆÊý¾Ý°üÀ´ÀûÓ㬴ӶøÒÔÌØȨÓû§Éí·ÝÖ´ÐÐÈÎÒâ´úÂë¡£
https://www.bleepingcomputer.com/news/security/aruba-networks-fixes-six-critical-vulnerabilities-in-arubaos/
3¡¢Sysdig·¢ÏÖÖ÷ÒªÕë¶ÔÔÆ»·¾³µÄSCARLETEEL¹¥»÷»î¶¯
SysdigÔÚ2ÔÂ28ÈÕ³ÆÆä·¢ÏÖÁËÒ»¸öÃûΪSCARLETEELµÄ¹¥»÷»î¶¯¡£¹¥»÷ʼÓÚ»ñµÃÍйÜÔÚAWSÉϵÄKubernetes¼¯ÈºµÄÃæÏò¹«ÖڵķþÎñµÄ³õʼ·ÃÎÊȨÏÞ£¬Àֳɺ󹥻÷Õ߾ͻáÏÂÔØÒ»¸öXMRig coinminerºÍÒ»¸ö½Å±¾£¬ÓÃÓÚ´ÓKubernetes podÖÐÇÔÈ¡ÕÊ»§Æ¾¾Ý¡£¹¥»÷Õß»áʹÓÃLambdaº¯Êýö¾ÙºÍ¼ìË÷ËùÓÐרÓдúÂëºÍÈí¼þ£¬ÒÔ¼°ÆäÖ´ÐÐÃÜÔ¿ºÍLambdaº¯Êý»·¾³±äÁ¿£¬ÒÔÕÒµ½IAMÓû§Æ¾Ö¤¡£SysdigÈÏΪ¼ÓÃܽٳֹ¥»÷±»ÓÃ×÷ÓÕ¶ü£¬Ö¼ÔÚµ½´ï¹¥»÷ÕßµÄÕæÕýÄ¿µÄ£¬¼´ÍµÈ¡×¨ÓÐÈí¼þ¡£
https://sysdig.com/blog/cloud-breach-terraform-data-theft/
4¡¢Blind Eagleð³äÕþ¸®Ë°Îñ»ú¹¹Õë¶Ô¸çÂ×±ÈÑǵĻú¹¹
2ÔÂ27ÈÕ£¬BlackberryÅû¶ÁËBlind EagleÕë¶Ô¸çÂ×±ÈÑÇÒªº¦ÐÐÒµµÄÐÂÒ»ÂÖ¹¥»÷»î¶¯¡£BlackberryÓÚ2ÔÂ20ÈÕ¼ì²âµ½´Ë´Î¹¥»÷»î¶¯£¬¹¥»÷Õßð³äÕþ¸®Ë°Îñ»ú¹¹¹ú¼ÒË°ÎñºÍº£¹Ø×ÜÊð(DIAN)£¬Ö÷ÒªÕë¶Ô¸çÂ×±ÈÑǵÄÎÀÉú¡¢½ðÈÚ¡¢Ö´·¨¡¢ÒÆÃñºÍÂôÁ¦Ì¸ÅеĻú¹¹¡£µöÓãÓʼþ´øÓÐÒ»¸öÖ¸ÏòPDFÎļþµÄÁ´½Ó£¬¸ÃÎļþ¾Ý³ÆÍйÜÔÚDIANÍøÕ¾ÉÏ£¬Êµ¼ÊÉϻᰲװ¶ñÒâÈí¼þ¡£PayloadÊÇÒ»¸ö»ìÏýµÄVBS£¬ËüÀûÓÃPowerShell¼ìË÷»ùÓÚ.NETµÄDLLÎļþ£¬×îÖÕ½«AsyncRAT¼ÓÔص½ÄÚ´æÖС£
https://blogs.blackberry.com/en/2023/02/blind-eagle-apt-c-36-targets-colombia
5¡¢FortiGuardÅû¶LockBitÐÂÒ»ÂÖ¹¥»÷µÄѬȾÁ´ºÍTTP
FortiGuardÓÚ2ÔÂ28ÈÕÐû²¼³ÂËßÏêÊöÁËLockBitÐÂÒ»ÂÖÀÕË÷¹¥»÷µÄѬȾÁ´ºÍTTP¡£Ñо¿ÈËÔ±ÔÚ2022Äê12ÔºÍ2023Äê1Ô·¢ÏÖLockBitµÄ»î¶¯£¬Ö÷ÒªÕë¶ÔÄ«Î÷¸çºÍÎ÷°àÑÀµÄ×ÉѯºÍÖ´·¨ÐÐÒµµÄ¹«Ë¾¡£¸Ã»î¶¯Ê¹ÓÃÁË¿ÉÓÐЧ·´¿¹AVºÍEDR½â¾ö·½°¸µÄ·½Ê½£¬Í¨¹ý.imgÈÝÆ÷·Ö·¢ÈƹýÁËWeb±êÖ¾(MOTW)±£»¤»úÖÆ£¬¶à½×¶Î½Å±¾ÌáÈ¡ÊÜÃÜÂë±£»¤µÄÀÕË÷Èí¼þ¿ÉÖ´ÐÐÎļþ£¨Ö»ÓÐÔÚʹÓÃÆæÌØÃÜÂëÔËÐÐʱ²Å»á±»½âѹ£©¿ÉÈƹý»ùÓÚÇ©ÃûµÄ¼ì²â¡£VirusTotalÖÐÑù±¾µÄ¼ì²âÂʺܵͣ¬±íÃ÷¸Ã»î¶¯Ê¹ÓõÄÒªÁìÔÚ¼ì²âÈƹý·½ÃæÊÇÓÐЧµÄ¡£
https://www.fortinet.com/blog/threat-research/emerging-lockbit-campaign
6¡¢SonicWallÐû²¼2023ÄêÍøÂçÍþв̬ÊƵķÖÎö³ÂËß
ýÌå2ÔÂ28Èճƣ¬SonicWallÐû²¼ÁË2023ÄêÍøÂçÍþв̬ÊƵķÖÎö³ÂËß¡£³ÂËßÖ¸³ö£¬SonicWallÔÚ2022Äê×ܹ²¼Ç¼ÁË55ÒڴζñÒâÈí¼þ¹¥»÷£¬Í¬±ÈÔö³¤2%¡£ÀÕË÷Èí¼þÔÚ2022Äê¼ÌÐøϽµ£¬ÊýÁ¿Ï½µÖÁ4.933ÒÚ£¬Í¬±ÈϽµ21%¡£ÎïÁªÍø¶ñÒâÈí¼þÊýÁ¿ÔÚ´ó·ùÔ¾Éý£¬Ê×´ÎÍ»ÆÆ1ÒÚ´ó¹Ø£¬¹²1.123Òڴι¥»÷£¬Í¬±ÈÔö³¤87%¡£¼ÓÃܽٳֹ¥»÷Ϊ1.393ÒڴΣ¬±È2021ÄêÔö³¤ÁË43%¡£È¥Äê·¢ÏÖÁË465501¸öеĶñÒâÈí¼þ±äÌ壬ƽ¾ùÿÌì1279¸ö¡£
https://www.sonicwall.com/2023-cyber-threat-report/