VMware vCenter Server¼°Cloud FoundationÆØÒªº¦Äþ¾²Â©¶´
Ðû²¼Ê±¼ä 2024-09-199ÔÂ18ÈÕ£¬VMware¹«Ë¾½üÆÚ½Ò¶ÁËÁ½¸öÕë¶ÔÆävCenter ServerºÍCloud Foundation²úÎïµÄÖØ´óÄþ¾²Â©¶´£¬CVE-2024-38812ºÍCVE-2024-38813£¬·Ö±ðÉæ¼°¶ÑÒç³öºÍȨÏÞÌáÉýÎÊÌ⣬¶ÔvCenter Server 7.0ºÍ8.0¼°Cloud Foundation 4.xºÍ5.x°æ±¾×é³ÉÍþв¡£CVE-2024-38812ÓÈΪÑÏÖØ£¬CVSSÆÀ·Ö¸ß´ï9.8£¬ÔÊÐíÓµÓÐÍøÂç·ÃÎÊȨÏ޵Ĺ¥»÷Õßͨ¹ý·¢ËͶ¨ÖÆÊý¾Ý°üÖ´ÐÐÔ¶³Ì´úÂë¡£¶øCVE-2024-38813ÔòÄÜÈù¥»÷Õß½«È¨ÏÞÌáÉýÖÁroot¼¶±ð£¬CVSSÆÀ·ÖΪ7.5¡£VMwareÒÑѸËÙÏìÓ¦£¬Ðû²¼ÁËÐÞ²¹·¨Ê½£¬²¢Ç¿ÁҶشÙÓû§Á¢¼´Éý¼¶ÖÁ×îа汾£¨vCenter Server 8.0 U3b»ò7.0 U3s£¬Cloud FoundationÔòÓ¦ÓÃKB88287ÖеÄÒì²½²¹¶¡£©¡£¾¡¹ÜĿǰδ·¢ÏÖÕâЩ©¶´µÄÒ°ÍâÀûÓð¸Àý£¬µ«¼øÓÚvCenter ServerÔÚÐéÄ⻯»·¾³¹ÜÀíÖеĺËÐÄְ룬ÆäDZÔÚ·çÏÕ²»ÈݺöÊÓ¡£
https://cybersecuritynews.com/vmware-vcenter-server-remote-code/#google_vignette
2. CISA ¾¯¸æ Adobe Flash Player ©¶´Õý±»»ý¼«ÀûÓÃ
9ÔÂ17ÈÕ£¬ÃÀ¹úÍøÂçÄþ¾²ºÍ»ù´¡ÉèÊ©Äþ¾²¾Ö£¨CISA£©½üÆÚ½«ËĸöÑÏÖصÄAdobe Flash Player©¶´ÁÐÈëÆäÒÑÖª¿ÉÀûÓ鶴£¨KEV£©Ä¿Â¼ÖУ¬ÕâЩ©¶´µÄÆعâÔÙ´Î͹ÏÔÁ˼´±ãÔÚFlash PlayerÒÑÐû²¼ÓÚ2020ÄêÖÕֹʹÓúó£¬ÒÅÁôÈí¼þ©¶´µÄÁ¬ÐøÄþ¾²Íþв¡£ÕâЩ©¶´£¬°üÂÞ¿É×·ËÝÖÁ2013ÄêµÄCVE-2013-0643ºÍCVE-2013-0648´úÂëÖ´ÐЩ¶´£¬ÒÔ¼°2014ÄêµÄCVE-2014-0497ÕûÊýÏÂÒçºÍCVE-2014-0502Ë«ÖØÊÍ·Å©¶´£¬¶¼ÔøÊÇÁãÈÕ¹¥»÷µÄÄ¿±ê£¬¶ÔFirefoxÓû§µÈ×é³ÉÍþв¡£¾¡¹ÜFlash PlayerÔøÊÇÍøÂ绥¶¯ÄÚÈݵĻùʯ£¬µ«Ëæ×Åʱ¼äµÄÍÆÒÆ£¬ËüÒѳÉΪÖ÷ÒªµÄÄþ¾²Òþ»¼£¬Æµ·±Êܵ½¹¥»÷ÕßÀûÓá£CISAÒò´Ë½ô¼±ºôÓõËùÓÐÁª°î»ú¹¹ÔÚ2024Äê10ÔÂ8ÈÕÇ°³¹µ×ÒƳýFlash Player£¬ÒÔ½µµÍDZÔÚµÄÄþ¾²·çÏÕ£¬±£»¤Ãô¸ÐÕþ¸®Êý¾ÝºÍÒªº¦»ù´¡ÉèÊ©ÃâÊÜÇÖº¦¡£Adobe×Ô2020ÄêÆðÒÑÍ£Ö¹Flash PlayerµÄ¿ª·¢£¬Ö÷Á÷ä¯ÀÀÆ÷Ò²²»ÔÙ¼æÈÝ£¬ËäÈ» Flash Ôø¾ÔÚ»¥ÁªÍøµÄÉú³¤Öз¢»Ó¹ýÖØÒª×÷Ó㬵«ÆäÄþ¾²·çÏÕÒÑʹÆä¹ýʱ¡£
https://securityonline.info/cisa-warns-of-actively-exploited-adobe-flash-player-vulnerabilities/
3. UNC2970×éÖ¯ÀûÓÃľÂí»¯PDFÔĶÁÆ÷¹¥»÷Òªº¦»ù´¡ÉèÊ©
9ÔÂ17ÈÕ£¬Mandiant½ÒʾÁËÓ볯ÏʹØÁªµÄUNC2970×éÖ¯ÌᳫµÄÅÓ´óÍøÂç¼äµý»î¶¯£¬¸Ã×éÖ¯ÀûÓø߶ȶ¨ÖƵÄÍøÂçµöÓãÊֶΣ¬Õë¶ÔÄÜÔ´ºÍº½¿Õº½ÌìµÈÒªº¦ÐÐÒµµÄ¸ß¼¶Ô±¹¤¡£UNC2970ͨ¹ýαװ³ÉÖªÃûÆóÒµµÄÊÂÇé»ú»áÓÕ¶ü£¬ÏòÄ¿±ê·¢ËÍ°üÂÞľÂí»¯SumatraPDFÔĶÁÆ÷µÄZIPÎļþ£¬¸ÃÔĶÁÆ÷ÄÚǶMISTPENºóÃÅ£¬Ò»µ©Êܺ¦ÕßʹÓÃÆä´ò¿ªÎ±×°³ÉְλÃèÊöµÄPDFÎļþ£¬¼´´¥·¢Ñ¬È¾Á´¡£MISTPEN×÷ΪһÖÖÒþÃع¤¾ß£¬Ö§³Ö¶àÖÖ¶ñÒâ²Ù×÷£¬ÀûÓúϷ¨·þÎñÈÚÈëÍøÂçÁ÷Á¿£¬ÒÔʵÏÖºã¾Ã¿ØÖƺÍÊý¾ÝÇÔÈ¡¡£UNC2970ͨ¹ýÐ޸ĿªÔ´Èí¼þ´úÂëºÍ¾«ÐÄÉè¼ÆµÄְλÃèÊö£¬Ìá¸ßÁ˹¥»÷µÄÒþ±ÎÐÔºÍÀÖ³ÉÂÊ£¬¶Ô¶à¸ö¹ú¼ÒµÄ»ù´¡ÉèÊ©Äþ¾²×é³ÉÖØ´óÍþв¡£¼øÓÚÆäÕë¶ÔÒªº¦ÁìÓòµÄ»î¶¯£¬Ïà¹Ø×éÖ¯Ðè½ô¼±¼ÓÇ¿·ÀÓù´ëÊ©£¬ÒÔµÖÓù´ËÀà¸ß¼¶ÍøÂçµöÓã¹¥»÷¡£
https://securityonline.info/unc2970s-backdoor-deployed-via-trojanized-pdf-reader-targets-critical-infrastructure/
4. ¶íÂÞ˹Äþ¾²¹«Ë¾Dr.WebÔâºÚ¿Í¹¥»÷
9ÔÂ18ÈÕ£¬¶íÂÞ˹֪ÃûµÄ·´¶ñÒâÈí¼þ¹«Ë¾Doctor Web£¨Dr.Web£©¹ûÈ»Ðû²¼£¬ÆäIT»ù´¡ÉèÊ©ÔâÓöÁËÍøÂç¹¥»÷£¬²¢Òò´Ë·¢ÏÖÁËÄþ¾²Â©¶´¡£Ãæ¶ÔÕâÒ»½ô¼±Çé¿ö£¬Dr.WebѸËÙ½ÓÄÉÐж¯£¬ÇжÏÁËËùÓзþÎñÆ÷ÓëÄÚ²¿ÍøÂçµÄÁ¬½Ó£¬ÒÔ·ÀÖ¹¹¥»÷½øÒ»²½À©É¢¡£´Ë´Î¹¥»÷ʼÓÚ9ÔÂ14ÈÕ£¬Dr.WebËæ¼´Õ¹¿ªÁËÏ꾡µÄÊӲ첢ÑÏÃܼà¿ØÊÂ̬Éú³¤¡£ÔÚÊÓ²ìÆڼ䣬ΪÁ˱£ÕÏ¿Í»§Äþ¾²£¬Dr.Web²»µÃ²»ÔÚÖÜÒ»ÔÝÍ£Á˲¡¶¾Êý¾Ý¿âµÄ¸üзþÎñ¡£È»¶ø£¬¹«Ë¾Ç¿µ÷£¬¶Ô»ù´¡ÉèÊ©µÄÆÆ»µÆóͼÒѱ»¼°Ê±Í£Ö¹£¬ËùÓÐÊÜDr.Web±£»¤µÄÓû§ÏµÍ³¾ùδÊܵ½Ó°Ïì¡£ÖÜÈý£¬Dr.WebÐû²¼Òѻָ´²¡¶¾Êý¾Ý¿âµÄ¸üзþÎñ£¬²¢È·ÈÏ´Ë´ÎÄþ¾²Ê¼þ²¢Î´¸øÆä¿Í»§´øÀ´ÈκθºÃæÓ°Ï졣Ϊ³¹µ×Ïû³ýÄþ¾²Íþв£¬Dr.Web½ÓÄÉÁË°üÂÞʹÓÃÊÊÓÃÓÚLinuxµÄDr.Web FixIt!ÔÚÄÚµÄһϵÁÐÓ¦¼±´ëÊ©£¬²¢ÀֳɸôÀëÁËDZÔÚ·çÏÕ¡£¹«Ë¾ÊÕ¼¯µÄÊý¾ÝΪÄþ¾²×¨¼ÒÌṩÁËÒªº¦ÐÅÏ¢£¬×ÊÖúËûÃÇÈ·±£ÏµÍ³Äþ¾²ÎÞÓÝ¡£
https://www.bleepingcomputer.com/news/security/russian-security-firm-drweb-disconnects-all-servers-after-breach/
5. FleetPanda·þÎñÆ÷ÅäÖôíÎó̻¶°ÙÍò·ÝÃô¸ÐÎļþ
9ÔÂ18ÈÕ£¬Ê¯ÓÍÓëȼÁÏÐÐÒµµÄÁìÏÈÈí¼þ¹©Ó¦ÉÌFleetPandaÒò·þÎñÆ÷ÅäÖôíÎó¶øÔâÓöÁËÑÏÖصÄÊý¾Ýй¶Ê¼þ£¬½ü°ÙÍò·ÝÃô¸ÐÎļþ±»·Ç·¨Ì»Â¶¡£ÕâЩÎļþº¸ÇÁË´Ó2019ÄêÖÁ2024Äê8Ôµķ¢Æ±¡¢ÔËÊä¼Ç¼¡¢¼ÝÕÕÐÅÏ¢¼°Åä¾°ÊÓ²ìµÈ£¬Éæ¼°¼ÓÖÝ¡¢¶íÀÕ¸Ô¡¢µÂ¿ËÈø˹µÈ¶à¸öÖÝ£¬×ÜÁ¿¸ß´ï193GB¡£ÍøÂçÄþ¾²×¨¼ÒJeremiah Fowler·¢ÏÖÁËÕâһδÊܱ£»¤µÄÊý¾Ý¿â£¬ÆäÄÚÈÝÏ꾡µØÕ¹ÏÖÁËÐÐÒµÄÚµÄȼÁÏÔËÊäÓëÒµÎñÍùÀ´£¬ÉõÖÁ°üÂÞÁËÉç»áÄþ¾²ºÅÂëµÈ¸ß¶ÈÃô¸ÐµÄ¸öÈËÐÅÏ¢¡£´Ë´Îй¶²»½öÍþвµ½¸öÈËÒþ˽Äþ¾²£¬»¹¿ÉÄÜÒý·¢Éí·Ý͵ÇԺ;¼ÃËðʧ£¬Í¬Ê±£¬·¸×ï·Ö×Ó¿ÉÄÜÀûÓ÷¢Æ±ÐÅϢʵʩÆÛÕ©ÐÐΪ¡£¶ÔʯÓͺÍȼÁÏÐÐÒµ¶øÑÔ£¬¹©Ó¦Á´µÄÎȶ¨ÐÔºÍÐÅÏ¢Äþ¾²ÒàÊܵ½¹¥»÷£¬¿ÉÄÜÒý·¢Êг¡µßô¤ºÍ¼Û¸ñÉÏÕÇ¡£Fowler½¨ÒéÆóÒµÓ¦½«Ãô¸ÐÊý¾ÝÓëÈÕ³£ÒµÎñÎļþÊèÉ¢´æ´¢£¬Ç¿»¯·ÃÎÊ¿ØÖÆ£¬¶¨ÆÚ¸üÐÂϵͳ²¢¼ÓÇ¿Ô±¹¤Åàѵ£¬ÒÔ¹¹½¨Ô½·¢Îȹ̵ÄÍøÂçÄþ¾²·ÀÏß¡£
https://hackread.com/server-misconfiguration-fuel-software-exposed-pii-data/
6. Delta Primeƽ̨ÔâÊÜÍøÂç¹¥»÷£¬¼ÓÃÜ»õ±ÒʧÇÔ½üÁù°ÙÍòÃÀÔª
9ÔÂ18ÈÕ£¬Delta Primeƽ̨½üÆÚÔâÓöÑÏÖØÍøÂç¹¥»÷£¬µ¼Ö¼ÛÖµ¸ß´ïÔ¼600ÍòÃÀÔªµÄ¼ÓÃÜ»õ±Ò±»µÁ£¬Ô¶³¬×î³õ³ÂËßµÄ450ÍòÃÀÔªËðʧ¡£Çø¿éÁ´Äþ¾²¹«Ë¾CyversÓÚ9ÔÂ16ÈÕÂÊÏȽÒ¶´ËÊ£¬Ö¸³öºÚ¿ÍÒÑ¿ªÊ¼½«ÍµÈ¡µÄUSDCת»»ÎªETH£¬²¢¾¯¸æÔÚ¼ì²â³õÆÚ£¬ºÚ¿ÍÇ®°üÈÔÁ¬Ðø´Óƽ̨³é×Ê£¬Íþв½øÒ»²½Ëðʧ¡£Ëæºó£¬Fuzzland´ú±íÈ·ÈÏÁËËðʧ×ܶîÒÑÅÊÉýÖÁ½ü600ÍòÃÀÔª£¬²¢½Òʾ´æÔÚ¸ü¶à¶ñÒâ½»Ò׻¡£´Ë´ÎÈëÇÖ±»¹éÒòÓÚDelta Primeƽ̨Ǯ±£Ö¤ÀíÔ±ÃÜԿʧÇÔ£¬ºÚ¿ÍµÃÊÖºó¿ØÖÆÁËÍйÜÊðÀíºÏÔ¼µÄÇ®°ü£¬½ø¶øÐ޸ĺÏÔ¼ÉèÖ㬽«ÆäÖض¨ÏòÖÁ¶ñÒâºÏÔ¼£¬´Ó¶øÔÚArbitrumÍøÂçÉÏ·ÅËÁÇÔÈ¡×ʽð£¬×ÜËðʧ¹ÀËãµ½´ï590ÍòÃÀÔª¡£ÕâһʼþÒýÆðÁËÍøÂçÄþ¾²ÁìÓòµÄ¸ß¶È¹Ø×¢£¬×¨¼Ò¾¯¸æºÚ¿ÍδÀ´¿ÉÄÜÃé×¼¸ü´ó¹æÄ£µÄÄ¿±ê£¬ÌرðÊÇÃÀ¹ú¼ÓÃÜ»õ±ÒETF»ù½ð£¬ÆäÅÓ´óµÄ±ÈÌرҴ¢Ðî¶ÔºÚ¿Í¼«¾ßÓÕ»óÁ¦£¬°üÂÞ³¯ÏÊLazarus¼¯ÍŵÈDZÔÚÍþв¡£¾ÝDune·ÖÎöƽ̨Êý¾ÝÏÔʾ£¬±ÈÌرÒÖ§³ÖµÄETF×Ü×ʲúÒѸߴï534ÒÚÃÀÔª£¬½øÒ»²½Í¹ÏÔÁË´ËÀà×ʲúµÄÄþ¾²·çÏÕ¡£
https://securityonline.info/cyberattack-on-delta-prime-losses-soar-to-6m/