°ÍÎ÷¿ç¹ú¹«Ë¾Andrade Gutierrez±»ºÚ3TBÊý¾Ýй¶

Ðû²¼Ê±¼ä 2023-03-09

1¡¢°ÍÎ÷¿ç¹ú¹«Ë¾Andrade Gutierrez±»ºÚÔ¼3TBÊý¾Ýй¶


¾ÝýÌå3ÔÂ7ÈÕ±¨µÀ£¬°ÍÎ÷µÄ¿ç¹ú¹«Ë¾Andrade GutierrezÔ¼3TBµÄÊý¾Ýй¶¡£ÕâÊÇÀ­¶¡ÃÀÖÞ×î´óµÄ¹¤³Ì¹«Ë¾Ö®Ò»£¬ÂôÁ¦¸ÃµØÓò»ù´¡ÉèÊ©¡¢ÄÜÔ´¡¢Ê¯ÓͺÍÌìÈ»ÆøÒÔ¼°ÔËÊäÁìÓòµÄÖØ´óÏîÄ¿¡£ºÚ¿ÍDark AngelsÉù³ÆÇÔÈ¡ÁË3TBµÄÓʼþºÍ¹«Ë¾Êý¾Ý£¬Éæ¼°Ô±¹¤ÐÕÃû¡¢»¤ÕÕÐÅÏ¢¡¢¸¶¿îÐÅÏ¢ºÍ˰ºÅµÈ¸öÈËÐÅÏ¢£¬ÒÔ¼°¼¸¸öÖªÃû½¨ÖþÏîÄ¿µÄÀ¶Í¼¡£¾ÝϤ£¬Ð¹Â¶Ê¼þ·¢ÉúÔÚÈ¥Äê9ÔÂÖÁ10Ô¡£


https://www.infosecurity-magazine.com/news/brazilian-conglomerate-3tb-data/ 


2¡¢FortinetÐÞ¸´Ó°ÏìFortiOSºÍFortiProxyµÄ©¶´


3ÔÂ7ÈÕ£¬FortinetÐû²¼¸üУ¬ÐÞ¸´ÁËÒ»¸öÓ°ÏìFortiOSºÍFortiProxyµÄ»º³åÇøÒç³ö©¶´¡£¸Ã©¶´£¨CVE-2023-25610£©µÄCVSSÆÀ·ÖΪ9.3£¬¿É±»Î´¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õßͨ¹ýʹÓÃÌØÖÆÇëÇó£¬À´ÔÚGUIÉÏÖ´ÐÐÈÎÒâ´úÂë»ò¾Ü¾ø·þÎñ(DoS)¡£Fortinetͨ¸æ³Æ£¬Ä¿Ç°ÉÐδ·¢ÏÖÈκÎÔÚÒ°ÍâÀûÓõÄÇé¿ö¡£¶ÔÓÚÎÞ·¨Ó¦ÓøüеÄÓû§£¬Fortinet½¨Òé½ûÓÃHTTP/HTTPS¹ÜÀí½çÃæ»òÏÞÖÆ¿ÉÔ¶³Ì·ÃÎʵÄIPµØÖ·¡£


https://www.bleepingcomputer.com/news/security/fortinet-warns-of-new-critical-unauthenticated-rce-vulnerability/


3¡¢Check Point·¢ÏÖSharp Panda¹¥»÷¶«ÄÏÑÇÕþ¸®»ú¹¹µÄ»î¶¯


3ÔÂ7ÈÕ£¬Check Point³ÆÆä·¢ÏÖÁËSharp PandaÕë¶Ô¶«ÄÏÑÇÕþ¸®»ú¹¹µÄ¹¥»÷»î¶¯¡£¸Ã»î¶¯´Ó2022Äêµ×¿ªÊ¼²¢Á¬Ðøµ½2023Ä꣬ʹÓÃÓã²æÊ½µöÓã¹¥»÷½øÐгõʼÈëÇÖ¡£µöÓãÓʼþµÄ¶ñÒ⸽¼þ°²×°RoyalRoad RTF¹¤¾ß°ü£¬±ýÊÔͼÀûÓé¶´ÔÚÖ÷»úÉÏ·Ö·¢¶ñÒâÈí¼þ¡£È»ºó°²×°²¢Ö´ÐÐÒ»¸öDLL¶ñÒâÈí¼þÏÂÔØ·¨Ê½£¬ËüÓÖ»á´ÓC2·þÎñÆ÷»ñÈ¡²¢Ö´Ðеڶþ¸öDLL£¬¼´SoulSearcher loader£¬×îÖÕ»á¼ÓÔØSoulÄ£¿é»¯¿ò¼Ü¡£


https://blog.checkpoint.com/2023/03/07/sharp-panda-check-point-research-puts-a-spotlight-on-chinese-origined-espionage-attacks-against-southeast-asian-government-entities/


4¡¢Ñо¿ÈËÔ±Åû¶DJIÎÞÈË»úÖÐ16¸öÄþ¾²Â©¶´µÄÏêϸÐÅÏ¢


ýÌå3ÔÂ7Èճƣ¬Ñо¿ÈËÔ±·¢ÏÖÁËDJIÎÞÈË»úÖеÄ16¸öÄþ¾²Â©¶´¡£ÕâЩ©¶´µÄÓ°Ï췶ΧºÜ¹ã£¬´Ó¾Ü¾ø·þÎñµ½ÈÎÒâ´úÂëÖ´ÐС£ÖµµÃ×¢ÒâµÄÊÇ£¬ÆäÖÐÓÐ14¸ö©¶´¿ÉÒÔͨ¹ýÖÇÄÜÊÖ»úÔ¶³Ì´¥·¢£¬¿ÉÄܵ¼ÖÂÎÞÈË»úÔÚ·ÉÐÐ;ÖÐ×¹»Ù¡£¹¥»÷Õß»¹¿ÉÒÔ¸üËûÈÕÖ¾Êý¾Ý»òÐòÁкÅÀ´Î±×°Éí·Ý£¬»òÕßÈÆ¹ý¶ÔËٶȺ͸߶ȷ½ÃæµÄÏÞÖÆ£¬ÒÔ¼°Í¨¹ýµØÀíΧÀ¸ºÍÐéÄâ½çÏÞ¶Ô½û·ÉÇøÓòµÄÏÞÖÆ¡£Ä¿Ç°£¬DJIÒÑÐÞ¸´ÕâЩ©¶´¡£


https://www.hackread.com/dji-drones-flaw-crash-drones-mid-flight/


5¡¢TrendMicroÐû²¼2022Äê¶ÈÍøÂçÄþ¾²Ì¬ÊƵķÖÎö³ÂËß


3ÔÂ7ÈÕ£¬Trend MicroÐû²¼ÁË2022Äê¶ÈÍøÂçÄþ¾²Ì¬ÊƵķÖÎö³ÂËß¡£2022Ä꣬Trend Micro¼ì²âµ½ÁË1464ÒÚ´ÎÍþв£¬±ÈÉÏÒ»ÄêÔö³¤ÁË55.3%¡£¹¥»÷Õß×î³£ÓõÄATT&CK¼¼ÊõΪԶ³Ì·þÎñ¡¢ÓÐЧÕÊ»§ºÍ²Ù×÷ϵͳƾ¾Ýת´¢¡£2022Ä꣬Microsoft×èÖ¹ÁËOfficeÎĵµÖк귨ʽµÄÖ´ÐУ¬´Ë¾Ùµ¼ÖÂOfficeºêµÄʹÓÃϽµ£¬µ«¹¥»÷Õß¿ªÊ¼Ñ°ÕÒÌæ´ú·½°¸£¬ÀýÈçHTML×ß˽µÈ¼ÆÄ±¡£¹¥»÷ÕßÕë¶ÔÔÆ·þÎñ£¬°üÂÞÎÞ·þÎñÆ÷ƽ̨ÉϵũӦÁ´¹¥»÷£¬ÒÔ¼°ÔÚLinuxϵͳÉÏÌᳫ¼ÓÃÜ»õ±ÒÍÚ¾ò¹¥»÷¡£


https://www.trendmicro.com/en_us/research/23/c/expanding-attack-blueprints-2022-annual-cybersecurity-report-.html


6¡¢MorphisecÐû²¼¶ñÒâÈí¼þSYS01ÇÔÈ¡ÐÅÏ¢µÄ·ÖÎö³ÂËß


3ÔÂ7ÈÕ£¬MorphisecÐû²¼Á˹ØÓÚ¶ñÒâÈí¼þSYS01µÄ·ÖÎö³ÂËß¡£×Ô2022Äê11ÔÂÒÔÀ´£¬¸Ã¶ñÒâÈí¼þ±»ÓÃÓÚÕë¶ÔÒªº¦Õþ¸®»ù´¡ÉèÊ©¡¢ÖÆÔ칫˾ºÍÆäËüÐÐÒµµÄ¹¥»÷¡£¹¥»÷Õßͨ¹ýʹÓùȸè¹ã¸æºÍÐé¼ÙµÄFacebook¸öÈË×ÊÁÏÀ´Õë¶ÔFacebookÉÌÒµÕË»§£¬ÓÕʹĿ±êÏÂÔØ¶ñÒâÎļþ¡£¸Ã¹¥»÷Ö¼ÔÚÇÔÈ¡Ãô¸ÐÐÅÏ¢£¬°üÂ޵ǼÊý¾Ý¡¢cookieÒÔ¼° Facebook¹ã¸æºÍÆóÒµÕÊ»§ÐÅÏ¢¡£ 


https://blog.morphisec.com/sys01stealer-facebook-info-stealer