NCC³Æ½ü2000̨Citrix NetScalerЧÀÍÆ÷Òѱ»Ö²ÈëºóÃÅ
Ðû²¼Ê±¼ä 2023-08-171¡¢NCC³Æ½ü2000̨Citrix NetScalerЧÀÍÆ÷Òѱ»Ö²ÈëºóÃÅ
¾Ý8ÔÂ16ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬£¬£¬NCC Group·¢Ã÷ÁËCitrix NetScalerÎó²îµÄ´ó¹æÄ£Ê¹Óû¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÒÔ×Ô¶¯»¯·½·¨Ê¹ÓÃÁËÎó²î£¨CVE-2023-3519£©£¬£¬£¬£¬£¬£¬£¬£¬ÔÚNetscalerЧÀÍÆ÷ÖÐÖ²ÈëÁËWebshell¡£¡£¡£¡£¡£¡£¡£¡£×ÝÈ»NetScalerÒÑ´ò²¹¶¡»òÖØÆô£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÒ²¿ÉÒÔʹÓôËWebshellÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±×ܹ²ÔÚ1952¸ö²î±ðµÄNetScalerÖз¢Ã÷ÁË2491¸öWebshell£¬£¬£¬£¬£¬£¬£¬£¬´ó´ó¶¼Î»Óڵ¹ú¡¢·¨¹ú¡¢ÈðÊ¿¡¢ÈÕ±¾ºÍÒâ´óÀûµÈ¹ú¡£¡£¡£¡£¡£¡£¡£¡£×èÖ¹8ÔÂ14ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬ÈÔÓÐ1828¸öNetScaler±£´æºóÃÅ£¬£¬£¬£¬£¬£¬£¬£¬ÆäÖÐÔ¼1248̨ÒѾÕë¶Ô¸ÃÎó²î¾ÙÐÐÁËÐÞ¸´¡£¡£¡£¡£¡£¡£¡£¡£
https://thehackernews.com/2023/08/nearly-2000-citrix-netscaler-instances.html
2¡¢´ó×ÚLinkedInÓû§³ÆÆäÕË»§±»Ð®ÖÆ»òËø¶¨²¿·ÖÒª½»Êê½ð
¾ÝýÌå8ÔÂ15ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬£¬£¬CyberintÔÚ×î½ü¼¸ÖÜ·¢Ã÷ÁËÒ»³¡Ò»Á¬µÄ¹¥»÷»î¶¯Ö÷ÒªÕë¶ÔLinkedInÕÊ»§¡£¡£¡£¡£¡£¡£¡£¡£¸Ã»î¶¯µÄÓ°Ïì¹æÄ£ÁýÕÖÈ«Çò£¬£¬£¬£¬£¬£¬£¬£¬µ¼Ö´ó×ÚÓû§ÎÞ·¨»á¼ûÆäÕÊ»§¡£¡£¡£¡£¡£¡£¡£¡£Ðí¶àLinkedInÓû§Ëß¿àÆäÕË»§±»½ÓÊÜ»òËø¶¨£¬£¬£¬£¬£¬£¬£¬£¬²¢ÇÒÎÞ·¨Í¨¹ýLinkedInµÄÖ§³ÖЧÀͽâ¾ö¡£¡£¡£¡£¡£¡£¡£¡£ÓÐЩÈËÉõÖÁ±»ÆÈ½»Êê½ð²Å»ªÖØÐ»ñµÃ¿ØÖÆÈ¨£¬£¬£¬£¬£¬£¬£¬£¬»òÕßÃæÁÙÕË»§±»ÓÀÊÀɾ³ýµÄÇéÐΡ£¡£¡£¡£¡£¡£¡£¡£ËäÈ»LinkedInÉÐδÐû²¼Õýʽͨ¸æ£¬£¬£¬£¬£¬£¬£¬£¬µ«ËûÃǵÄÖ§³ÖÏìӦʱ¼äËÆºõÒѾÑÓÉ죬£¬£¬£¬£¬£¬£¬£¬Óб¨µÀ³ÆÖ§³ÖÇëÇóµÄÊýÄ¿ºÜ´ó¡£¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/linkedin-accounts-hacked-in-widespread-hijacking-campaign/
3¡¢ÃÀ¹ú¸ßÀÖÊÏ(Clorox)Ôâµ½¹¥»÷µ¼ÖÂÔËÓªÔÝʱÖÐÖ¹
8ÔÂ16ÈÕ±¨µÀ³Æ£¬£¬£¬£¬£¬£¬£¬£¬ÃÀ¹úÈÕÓÃÆ·Éú²úÉ̸ßÀÖÊÏ(Clorox)Ôâµ½¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬µ¼ÖÂÔËÓªÔÝʱÖÐÖ¹¡£¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÔÚ2022ÄêµÄÊÕÈëÁè¼Ý70ÒÚÃÀÔª¡£¡£¡£¡£¡£¡£¡£¡£´Ë´Î¹¥»÷ÓÚ8ÔÂ14ÈÕ±»¼ì²âµ½£¬£¬£¬£¬£¬£¬£¬£¬CloroxÁ¬Ã¦½ÓÄÉÐж¯£¬£¬£¬£¬£¬£¬£¬£¬¹Ø±ÕÁËÊÜÓ°ÏìµÄϵͳ¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÊÂÎñµÄÊÓ²ìÈÔÔÚÔçÆÚ½×¶Î£¬£¬£¬£¬£¬£¬£¬£¬Éв»ÇåÎúÊÇÄÄÖÖÀàÐ͵Ĺ¥»÷¡£¡£¡£¡£¡£¡£¡£¡£È»¶øÏÖÓÐÐÅÏ¢Åú×¢£¬£¬£¬£¬£¬£¬£¬£¬Õâ¿ÉÄÜÊÇÀÕË÷¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£´Ë´Î¹¥»÷Ó°ÏìÁËCloroxµÄÖÆÔìºÍÏúÊÛÁ÷³Ì£¬£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°ÆäÍÆÐж©µ¥ºÍά³ÖÕý³£ÔËÓªµÄÄÜÁ¦¡£¡£¡£¡£¡£¡£¡£¡£
https://www.infosecurity-magazine.com/news/clorox-disrupted-cyber-attack/
4¡¢ÒÑÍù°ëÄêCloudflare R2ÍйܵĴ¹ÂÚÍøÒ³Á÷Á¿ÔöÌí61±¶
NetskopeÔÚ8ÔÂ14Èճƣ¬£¬£¬£¬£¬£¬£¬£¬´Ó½ñÄê2Ôµ½7Ô£¬£¬£¬£¬£¬£¬£¬£¬Cloudflare R2ÖÐÍйܵĴ¹ÂÚÒ³ÃæÁ÷Á¿ÔöÌíÁË61±¶¡£¡£¡£¡£¡£¡£¡£¡£´ó´ó¶¼´¹Âڻ¶¼Õë¶ÔMicrosoftµÇ¼ƾ֤£¬£¬£¬£¬£¬£¬£¬£¬µ«Ò²ÓÐһЩÕë¶ÔAdobe¡¢DropboxºÍÆäËüÔÆÓ¦ÓóÌÐò¡£¡£¡£¡£¡£¡£¡£¡£ÕâЩ¹¥»÷Ö÷ÒªÕë¶Ô±±ÃÀºÍÑÇÖÞ£¬£¬£¬£¬£¬£¬£¬£¬Éæ¼°ÖÖÖÖÁìÓò£¬£¬£¬£¬£¬£¬£¬£¬ÒÔÊÖÒÕ¡¢½ðÈÚЧÀͺÍÒøÐÐҵΪÊס£¡£¡£¡£¡£¡£¡£¡£ÕâЩ´¹Âڻ²»µ«Ê¹ÓÃCloudflare R2·Ö·¢¾²Ì¬´¹ÂÚÒ³Ãæ£¬£¬£¬£¬£¬£¬£¬£¬»¹Ê¹Óøù«Ë¾µÄTurnstile²úÆ·À´Èƹý¼ì²â¡£¡£¡£¡£¡£¡£¡£¡£
https://www.netskope.com/blog/evasive-phishing-campaign-steals-cloud-credentials-using-cloudflare-r2-and-turnstile
5¡¢AhnLab·¢Ã÷Hakuna MatataÕë¶Ôº«¹úÆóÒµµÄ¹¥»÷»î¶¯
8ÔÂ16ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬AhnLab͸¶ÀÕË÷Èí¼þHakuna MatataÕý±»ÓÃÀ´¹¥»÷º«¹úµÄÆóÒµ¡£¡£¡£¡£¡£¡£¡£¡£Hakuna MatataÊǽüÆÚ¿ª·¢µÄÀÕË÷Èí¼þ£¬£¬£¬£¬£¬£¬£¬£¬ÓÚ7ÔÂ6ÈÕÊ״α»Åû¶¡£¡£¡£¡£¡£¡£¡£¡£Hakuna MatataÓëÆäËü¹Å°åÀÕË÷Èí¼þµÄ²î±ðÖ®´¦ÔÚÓÚ£¬£¬£¬£¬£¬£¬£¬£¬Ëü¾ßÓÐClipBanker¹¦Ð§¡£¡£¡£¡£¡£¡£¡£¡£×ÝÈ»ÔÚ¼ÓÃÜÖ®ºó£¬£¬£¬£¬£¬£¬£¬£¬ËüÈÔÈ»±£±£´æÏµÍ³ÖУ¬£¬£¬£¬£¬£¬£¬£¬½«±ÈÌØ±ÒÇ®°üµØµã¸ü¸ÄΪ¹¥»÷Õߵĵص㡣¡£¡£¡£¡£¡£¡£¡£¼ÓÃÜϵͳºó£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß»áɾ³ý¹¥»÷ÖÐʹÓõÄÊÂÎñÈÕÖ¾ºÍ¶ñÒâÈí¼þ£¬£¬£¬£¬£¬£¬£¬£¬Òò´ËºÜÄÑ»ñµÃÈ·ÇеÄÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£¿ÉÊÇ£¬£¬£¬£¬£¬£¬£¬£¬Æ¾Ö¤ÖÖÖÖÇéÐΣ¬£¬£¬£¬£¬£¬£¬£¬ÍƲâÔ¶³Ì×ÀÃæÐÒ飨RDP£©±»×÷Ϊ³õʼ¹¥»÷ÔØÌå¡£¡£¡£¡£¡£¡£¡£¡£
https://asec.ahnlab.com/en/56010/
6¡¢Group-IBÐû²¼¹ØÓÚ¶ñÒâÈí¼þGigabudµÄÆÊÎö±¨¸æ
8ÔÂ14ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬Group-IBÐû²¼Á˹ØÓÚ¶ñÒâÈí¼þGigabudµÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¡£¡£¡£ËüÖ÷ÒªÕë¶ÔÌ©¹ú¡¢Ó¡¶ÈÄáÎ÷ÑÇ¡¢Ô½ÄÏ¡¢·ÆÂɱöºÍÃØÂ³µÄ½ðÈÚ»ú¹¹¡£¡£¡£¡£¡£¡£¡£¡£Gigabud RATÔÚÓû§±»ÊÚȨ½øÈë¶ñÒâÓ¦ÓÃ֮ǰ²»»áÖ´ÐÐÈκζñÒâ»î¶¯£¬£¬£¬£¬£¬£¬£¬£¬Õâ¼Ó´óÁ˼ì²âµÄÄѶȡ£¡£¡£¡£¡£¡£¡£¡£ËüÖ÷Ҫͨ¹ýÆÁÄ»Â¼ÖÆÀ´ÍøÂçÃô¸ÐÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬£¬¶ø²»ÊÇHTMLÁýÕÖ¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£¼ÌÐøÊӲ췢Ã÷ÁËÁíÒ»¸ö²»¾ß±¸RAT¹¦Ð§µÄÑù±¾£¬£¬£¬£¬£¬£¬£¬£¬´úºÅΪGigabud.Loan£¬£¬£¬£¬£¬£¬£¬£¬ÕâÊÇÒ»¸öαÔìµÄ´û¿îÓ¦Ó㬣¬£¬£¬£¬£¬£¬£¬»áÇÔÈ¡Óû§ÊäÈëµÄÊý¾Ý¡£¡£¡£¡£¡£¡£¡£¡£
https://www.group-ib.com/blog/gigabud-banking-malware/


¾©¹«Íø°²±¸11010802024551ºÅ