΢ÈíÅû¶CODESYS V3 SDKÖÐÓ°ÏìOTϵͳµÄ¶à¸ö©¶´
Ðû²¼Ê±¼ä 2023-08-151¡¢Î¢ÈíÅû¶CODESYS V3 SDKÖÐÓ°ÏìOTϵͳµÄ¶à¸ö©¶´
΢ÈíÓÚ8ÔÂ10ÈÕ³ÆÆäÔÚCODESYS V3Èí¼þ¿ª·¢Ì×¼þ(SDK)Öз¢ÏÖÁËͳ³ÆÎªCoDe16µÄ¶à¸ö©¶´¡£¸ÃÌ×¼þ±»ÓÃÓÚPLCµÄÈí¼þ¿ª·¢»·¾³£¬ÕâЩ©¶´Ó°ÏìÁË3.5.19.0֮ǰµÄËùÓÐCODESYS V3°æ±¾£¬Ê¹OT»ù´¡ÉèÊ©ÃæÁÙÔâµ½RCEºÍDoSµÈ¹¥»÷µÄ·çÏÕ¡£ÕâЩ©¶´·Ö±ðΪCVE-2022-47378¡¢CVE-2022-47379ºÍCVE-2022-47380µÈ¡£Î¢ÈíÓÚ2022Äê9ÔÂÏòCODESYS³ÂËßÁËÕâЩ©¶´£¬¹©Ó¦ÉÌÓÚ½ñÄê4ÔÂÐÞ¸´ÁËËüÃÇ¡£
https://www.microsoft.com/en-us/security/blog/2023/08/10/multiple-high-severity-vulnerabilities-in-codesys-v3-sdk-could-lead-to-rce-or-dos/
2¡¢Discord.ioÔ¼76ÍòÓû§µÄÊý¾ÝÔÚºÚ¿ÍÂÛ̳±»³öÊÛ
¾ÝýÌå8ÔÂ14ÈÕ±¨µÀ£¬Discord.ioÔ¼760000Ãû»áÔ±µÄÐÅϢй¶£¬µ¼Ö·þÎñÔÝʱ¹Ø±Õ¡£Discord.io²»Êǹٷ½DiscordÍøÕ¾¶øÊǵÚÈý·½·þÎñ£¬±»·þÎñÆ÷ËùÓÐÕßÓÃÀ´´´½¨×Ô½ç˵ÑûÇë¡£8ÔÂ13ÈÕ£¬ºÚ¿ÍAkhirahÔÚÂÛ̳BreachedÉϳöÊÛÁËDiscord.ioµÄÊý¾Ý¿â£¬²¢¹ûÈ»ÁËÆäÖеÄ4ÌõÓû§¼Ç¼×÷Ϊ¹¥»÷Ö¤¾Ý¡£¾Ý¹¥»÷Õ߳ƣ¬¸ÃÊý¾Ý¿â°üÂÞ760000ÃûDiscord.ioÓû§µÄÐÅÏ¢¡£²»¾Ãºó£¬Discord.io֤ʵÁËй¶Êý¾ÝµÄÕæÊµÐÔ£¬²¢¹Ø±ÕÆä·þÎñ£¬È¡ÏûËùÓи¶·Ñ»áÔ±µÄ×ʸñ¡£
https://www.bleepingcomputer.com/news/security/discordio-confirms-breach-after-hacker-steals-data-of-760k-users/
3¡¢Sophos·¢ÏÖαװ³ÉTripAdvisorͶËßµÄKnight·Ö·¢»î¶¯
¾Ý8ÔÂ12ÈÕ±¨µÀ£¬SophosÑо¿ÈËÔ±·¢ÏÖÁËÒ»¸öÐµĹ¥»÷»î¶¯£¬Î±×°³ÉTripAdvisorͶËߣ¬µ«È´·Ö·¢ÀÕË÷Èí¼þKnight¡£CyclopsÔÚ7Ôµ׸üÃûΪKnight£¬»¹¸üÐÂÁ˾«¼ò°æ¼ÓÃÜÆ÷ÒÔÖ§³ÖÅúÁ¿·Ö·¢£¬²¢ÍƳöеÄÐ¹Â¶ÍøÕ¾¡£µöÓãÓʼþ°üÂÞZIP¸½¼þTripAdvisorComplaint.zip£¬È»ºóÓÕʹĿ±êÏÂÔØÍ¨¹ýExcel-DNA´´½¨µÄÒ»¸öXLLÎļþ¡£´ò¿ªXLLʱ½«¼ì²âMoTW±êÖ¾£¬Èç¹ûûÓУ¬Ôò»áÌáÐÑÄ¿±êÆôÓøüÓÔØÏî¡£Õâ»áÔÚеÄexplorer.exe½ø³ÌÖÐ×¢ÈëKnight Lite¼ÓÃÜ·¨Ê½£¬²¢¿ªÊ¼¼ÓÃܼÆËã»úÉϵÄÎļþ¡£
https://www.bleepingcomputer.com/news/security/knight-ransomware-distributed-in-fake-tripadvisor-complaint-emails/
4¡¢Ö¥¼Ó¸ç±´¶ûÌØÌú·¹«Ë¾Ôâµ½AkiraµÄ¹¥»÷85GBÊý¾Ýй¶
ýÌå8ÔÂ12Èճƣ¬Ö¥¼Ó¸ç±´¶ûÌØÌú·¹«Ë¾³ÆÆäÕýÔÚÊÓ²ìÀÕË÷¹¥»÷µ¼ÖµÄÊý¾Ýй¶Ê¼þ¡£¸Ã¹«Ë¾ÓÉÃÀ¹úºÍ¼ÓÄôóµÄÁù¼ÒÌú·¹«Ë¾ÅäºÏÓµÓУ¬Ã¿¼ÒÌú·¹«Ë¾¶¼Ê¹Óøù«Ë¾µÄתÔ˺ͻ»³ËÉèÊ©£¬ÊÇÃÀ¹ú×î´óµÄÖм任³ËÖÕµãÕ¾Ìú·¡£8ÔÂ10ÈÕ£¬Akira½«¸Ã¹«Ë¾Ìí¼Óµ½ÆäÍøÕ¾£¬²¢ÌåÏÖÒÑ»ñÈ¡85 GBÊý¾Ý¡£·¢ÑÔÈ˳ƣ¬´Ë´Îʼþ²¢Î´Ó°Ï칫˾µÄÔËÓª¡£È¥Ä꣬¶à¼ÒÌú·¹«Ë¾Ôâµ½ÁËÍøÂç¹¥»÷£¬ÃÀ¹úTSAÊÔͼ¶ÔÌú·µÈÖØÒª»ù´¡ÉèÊ©½ÓÄɸüǿӲµÄ´ëÊ©¡£
https://therecord.media/belt-railway-chicago-ransomware-data-theft-akira
5¡¢Ñо¿ÈËÔ±¹ûÈ»Õë¶ÔBarracuda ESGµÄкóÃÅWhirlpool
8ÔÂ10ÈÕ±¨µÀ³Æ£¬CISAÔÚÕë¶ÔBarracuda ESGÉ豸µÄ¹¥»÷»î¶¯Öз¢ÏÖÁËÒ»¸öÃûΪWhirlpoolµÄкóÃÅ¡£ÕâÊÇÒ»¸ö32λELFÎļþ£¬´ÓÄ£¿éÖлñÈ¡Á½¸ö²ÎÊý£¨C2 IPºÍ¶Ë¿ÚºÅ£©À´½¨Á¢´«Êä²ãÄþ¾²(TLS)·´Ïòshell¡£WhirlpoolÊÇÔÚÕë¶ÔBarracuda ESGµÄ¹¥»÷»î¶¯Öз¢ÏֵĵÚ3¸öºóÃÅ£¬ÁíÍâÁ½¸öÊÇSeaSpyºÍSubmarine¡£¹¥»÷»î¶¯ÀûÓÃÁËÃüÁî×¢Èë©¶´(CVE-2023-2868)£¬¸Ã¹«Ë¾Í¨¹ý¸ü»»É豸À´ÐÞ¸´ËüÃÇ¡£
https://securityaffairs.com/149392/hacking/whirlpool-backdoor-barracuda-esg-attacks.html
6¡¢ZscalerÐû²¼Ð¶ñÒâÈí¼þStatc StealerµÄ·ÖÎö³ÂËß
8ÔÂ8ÈÕ£¬ZscalerÐû²¼Á˹ØÓÚ¶ñÒâÈí¼þStatc StealerµÄ·ÖÎö³ÂËß¡£ÕâÊÇÒ»ÖÖÐÂÐÍÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þ£¬¿ÉÒÔ´ÓWindowsÉ豸ÇÔÈ¡ÐÅÏ¢¡£ËüÊÇÓÉC++¿ª·¢µÄ£¬Ö§³ÖÎļþÃû²îÒì¼ì²éÒÔÈÆ¹ýɳÏäºÍÄæÏò¹¤³ÌµÄ·ÖÎö¡£Ñ¬È¾Á´Ê¼ÓÚαÔìµÄ¹È¸è¹ã¸æ£¬»áÇÔÈ¡ä¯ÀÀÆ÷Êý¾Ý¡¢¼ÓÃÜ»õ±ÒÇ®°ü¡¢Æ¾Ö¤ºÍÃÜÂ룬ÉõÖÁ°üÂÞTelegramµÈÏûÏ¢Ó¦Ó÷¨Ê½µÄÊý¾Ý¡£×îºó£¬Ê¹ÓÃHTTPSÐÒ齫ÇÔÈ¡µÄ¼ÓÃÜÊý¾Ý·¢Ë͵½C2·þÎñÆ÷¡£
https://www.zscaler.com/blogs/security-research/statc-stealer-decoding-elusive-malware-threat