MOVEit TransferÐÞ¸´ÆäwebÓ¦ÓÃÖеĶà¸öSQL×¢ÈëÎó²î
Ðû²¼Ê±¼ä 2023-06-121¡¢MOVEit TransferÐÞ¸´ÆäwebÓ¦ÓÃÖеĶà¸öSQL×¢ÈëÎó²î
¾Ý6ÔÂ10ÈÕ±¨µÀ£¬£¬£¬£¬£¬Progress SoftwareÔÚÆäMOVEit TransferÍйÜÎļþ´«Êä(MFT)½â¾ö¼Æ»®ÖÐз¢Ã÷Á˶à¸öÑÏÖØµÄSQL×¢ÈëÎó²î¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ýÏòMOVEit TransferÓ¦ÓóÌÐòÌá½»ÌØÖÆµÄpayload£¬£¬£¬£¬£¬À´Ð޸ĺÍй¶MOVEitÊý¾Ý¿âµÄÄÚÈÝ¡£¡£¡£¡£ÕâЩÎó²îÊÇͨ¹ý´úÂëÇå¾²É󼯷¢Ã÷µÄ£¬£¬£¬£¬£¬Ó°ÏìÁËËùÓÐMOVEit Transfer°æ±¾£¬£¬£¬£¬£¬ÏÖÔÚÉÐδ·¢Ã÷±»Ê¹Óõļ£Ï󡣡£¡£¡£¸Ã¹«Ë¾ÓÚ6ÔÂ9ÈÕÐû²¼ÁËÇå¾²²¹¶¡£¡£¡£¡£¬£¬£¬£¬£¬²¢ÌåÏÖËùÓÐMOVEit Transfer¿Í»§¶¼±ØÐèÓ¦Óô˲¹¶¡¡£¡£¡£¡£
https://thehackernews.com/2023/06/new-critical-moveit-transfer-sql.html
2¡¢¶íÂÞË¹ÒøÐÐÏà¹ØµÄµçÐŹ«Ë¾Infotel JSCÔâµ½´ó¹æÄ£¹¥»÷
¾ÝýÌå6ÔÂ9ÈÕ±¨µÀ£¬£¬£¬£¬£¬ÎÚ¿ËÀ¼ºÚ¿ÍÍÅ»ïCyber.Anarchy.SquadÉù³Æ¹¥»÷Á˶íÂÞ˹µçÐÅÌṩÉÌInfotel JSC²¢µ¼ÖÂÆäå´»ú¡£¡£¡£¡£InfotelÖ÷ÒªÈÏÕæ¶íÂÞ˹ÑëÐÐÓëÆäËü¶íÂÞË¹ÒøÐС¢ÍøÉÏÊÐËÁºÍÐÅ´û»ú¹¹Ö®¼äµÄÅþÁ¬Ð§ÀÍ¡£¡£¡£¡£Infotel JSC͸¶´Ë´Î´ó¹æÄ£ºÚ¿Í¹¥»÷Ó°ÏìÁËÆä²¿·ÖÍøÂç×°±¸£¬£¬£¬£¬£¬ÏÖÔÚÕýÔÚÆð¾¢»Ö¸´ÊÜÓ°ÏìµÄϵͳ£¬£¬£¬£¬£¬Íê³ÉÈÕÆÚ½«ÁíÐÐ֪ͨ¡£¡£¡£¡£IODA³ÆÐ§ÀÍÓÚUTC 6ÔÂ8ÈÕÉÏÎç11:00×óÓÒÖÐÖ¹¡£¡£¡£¡£ºÚ¿Í»¹Ðû²¼ÁËInfotelϵͳµÄ½ØÍ¼×÷Ϊ¹¥»÷Ö¤¾Ý£¬£¬£¬£¬£¬°üÀ¨ÍøÂç»ù´¡ÉèʩͼºÍ±»ÈëÇÖµç×ÓÓʼþÕÊ»§¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/ukrainian-hackers-take-down-service-provider-for-russian-banks/
3¡¢Ó¢¹úÂü³¹Ë¹ÌØ´óѧÔâµ½¹¥»÷Ô±¹¤ºÍѧÉúÊý¾Ý¿ÉÄÜй¶
ýÌå6ÔÂ9ÈÕ±¨µÀ£¬£¬£¬£¬£¬Ó¢¹úÂü³¹Ë¹ÌØ´óѧÔâµ½¹¥»÷£¬£¬£¬£¬£¬Ô±¹¤ºÍѧÉúµÄÊý¾Ý¿ÉÄÜÒѾй¶¡£¡£¡£¡£¸ÃУ³ÆËüÔÚ6ÔÂ6ÈÕ·¢Ã÷ÁËÕâÒ»ÎÊÌ⣬£¬£¬£¬£¬²¢Á¬Ã¦Õö¿ªÊӲ졣¡£¡£¡£¾È·Èϲ¿·ÖϵͳÒѱ»Î´¾ÊÚȨµÄµÚÈý·½»á¼û£¬£¬£¬£¬£¬Êý¾Ý¿ÉÄÜÒѱ»¸´ÖÆ¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬Âü³¹Ë¹ÌØ´óѧÌåÏÖ´Ë´ÎÇå¾²ÊÂÎñÓë×î½üµÄMOVEit TransferÊý¾Ýй¶¹¥»÷ºÍZellisÏà¹Ø¹¥»÷Î޹ء£¡£¡£¡£¸Ã´óѧûÓÐÌṩ¹ØÓÚ¹¥»÷µÄ½øÒ»²½ÐÅÏ¢£¬£¬£¬£¬£¬µ«Ñо¿Ö°Ô±´ÓÐÂÎÅȪԴ»ñϤÕâÊÇÒ»ÆðÀÕË÷¹¥»÷¡£¡£¡£¡£
https://securityaffairs.com/147290/data-breach/university-of-manchester-cyber-attack.html
4¡¢Elastic·¢Ã÷Ö÷ÒªÕë¶ÔÔ½ÄÏÆóÒµµÄкóÃÅSPECTRALVIPER
ElasticÔÚ6ÔÂ9ÈÕ³ÆÆä·¢Ã÷ÁËÒ»¸öÐÂÐͺóÃÅSPECTRALVIPER£¬£¬£¬£¬£¬Ö÷ÒªÓÃÓÚÕë¶ÔÔ½ÄÏÉÏÊй«Ë¾µÄ¹¥»÷»î¶¯¡£¡£¡£¡£PECTRALVIPERÊÇÒ»¸ö»ìÏýµÄx64ºóÃÅ£¬£¬£¬£¬£¬Ëü¾ßÓÐPE¼ÓÔØºÍ×¢Èë¡¢ÎļþÉÏ´«ºÍÏÂÔØ¡¢ÎļþºÍĿ¼¿ØÖÆÒÔ¼°ÁîÅÆÄ£Ä⹦Ч¡£¡£¡£¡£Ñо¿Ö°Ô±½«¸Ã»î¶¯¹éÒòÓÚÔ½ÄϵĹ¥»÷ÍÅ»ïREF2754¡£¡£¡£¡£×îÐÂѬȾÁ´ÖУ¬£¬£¬£¬£¬Ê¹ÓÃÁËSysInternals ProcDumpÊÊÓóÌÐò¼ÓÔØ°üÀ¨DONUTLOADERµÄδÊðÃûDLLÎļþ£¬£¬£¬£¬£¬´ËºóÕßÓÖ±»ÉèÖÃΪ¼ÓÔØSPECTRALVIPERºÍÆäËü¶ñÒâÈí¼þ£¬£¬£¬£¬£¬ÀýÈçP8LOADER»òPOWERSEAL¡£¡£¡£¡£
https://www.elastic.co/cn/security-labs/elastic-charms-spectralviper
5¡¢Sorgu Paneli¿É¹ûÕæ¼ìË÷Ô¼8500ÍòÍÁ¶úÆäסÃñµÄÐÅÏ¢
6ÔÂ10ÈÕ±¨µÀ£¬£¬£¬£¬£¬8500ÍòÍÁ¶úÆäסÃñµÄÃô¸ÐÐÅϢй¶¡£¡£¡£¡£ÍÁ¶úÆäµÄƽ̨Free Web TurkeyÆØ¹âÁËÒ»¸öÃûΪSorgu PaneliµÄÍøÕ¾£¬£¬£¬£¬£¬¿É²»ÊÜÏÞÖÆµØ»á¼ûСÎÒ˽¼ÒÐÅÏ¢£¬£¬£¬£¬£¬ÀýÈçÉí·ÝÖ¤ºÅÂë¡¢ÐÕÃû¡¢µØµã¡¢µç»°ºÅÂëÉõÖÁÒøÐÐÕË»§ÏêϸÐÅÏ¢£¬£¬£¬£¬£¬ÒÔ»»È¡Ãâ·Ñ»áÔ±×ʸñ¡£¡£¡£¡£¸¶·Ñ»áÔ±¿ÉÒÔ»ñµÃ¸ü¶àÐÅÏ¢£¬£¬£¬£¬£¬ÀýÈçլȯ¡£¡£¡£¡£¸ÃÍøÕ¾ÔÚÓòÃûSorgu.liveÏÂÔËÓª£¬£¬£¬£¬£¬ÏÖÔÚ¹²ÓÐ5195ÃûÓû§£¬£¬£¬£¬£¬²¢ÔÚTelegramºÍDiscordÉÏÌṩÀàËÆµÄЧÀÍ¡£¡£¡£¡£¾ÝÔ¤¼Æ£¬£¬£¬£¬£¬Ô¼ÓÐ8500ÍòÍÁ¶úÆä¹«ÃñµÄÐÅÏ¢Êܵ½Ó°Ïì¡£¡£¡£¡£
https://medyanews.net/website-leak-exposes-sensitive-data-of-85-million-turkish-residents-report/
6¡¢Check Point¹ûÕæÊ¹ÓÃStealth Soldier¹¥»÷±±·ÇµÄ»î¶¯
6ÔÂ8ÈÕ£¬£¬£¬£¬£¬Check Point¹ûÕæÁËÒ»ÆðÕë¶ÔÐÔºÜÇ¿µÄÌØ¹¤¹¥»÷£¬£¬£¬£¬£¬Ê¹ÓÃÁËÐµĶ¨ÖÆÄ£¿£¿£¿£¿£¿£¿é»¯ºóÃÅStealth Soldier¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þÖ÷ÒªÔËÐмàÊÓ¹¦Ð§£¬£¬£¬£¬£¬ÀýÈçÎļþй¶¡¢ÆÁÄ»ºÍÂó¿Ë·çÂ¼ÖÆ¡¢¼üÅ̼ͼºÍÇÔÈ¡ä¯ÀÀÆ÷ÐÅÏ¢¡£¡£¡£¡£Stealth SoldierÓëThe Eye on the NileµÄ»ù´¡ÉèÊ©Óв¿·ÖÖØµþ£¬£¬£¬£¬£¬¹¥»÷ÕßʹÓÃÁËαװ³ÉÀû±ÈÑÇÍâ½»²¿ÍøÕ¾µÄC2Óò¡£¡£¡£¡£Ñо¿Ö°Ô±³Æ£¬£¬£¬£¬£¬Ñ¬È¾Á´´ÓºÜÖØ´ó£¬£¬£¬£¬£¬Éæ¼°´ÓC&CЧÀÍÆ÷ÏÂÔØµÄÁù¸öÎļþ£¬£¬£¬£¬£¬°üÀ¨Loader( MSDataV5.16945.exe)¡¢Watchdog(MSCheck.exe)ºÍPayload(MShc.txt)µÈ¡£¡£¡£¡£
https://research.checkpoint.com/2023/stealth-soldier-backdoor-used-in-targeted-espionage-attacks-in-north-africa/


¾©¹«Íø°²±¸11010802024551ºÅ