Fortinet¹Ì¼þ¸üÐÂÐÞ¸´Fortigate SSL-VPNÖеÄRCE
Ðû²¼Ê±¼ä 2023-06-131¡¢Fortinet¹Ì¼þ¸üÐÂÐÞ¸´Fortigate SSL-VPNÖеÄRCE
¾ÝýÌå6ÔÂ12ÈÕ±¨µÀ£¬FortinetÐû²¼ÁËFortigate¹Ì¼þ¸üУ¬ÐÞ¸´ÁËSSL VPN×°±¸ÖеÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2023-27997£©¡£Ñо¿Ö°Ô±³Æ£¬×ÝÈ»ÆôÓÃÁËMFA£¬¸ÃÎó²îÒ²»á±»¶ñÒâÊðÀíÓÃÀ´Í¨¹ýVPN¾ÙÐÐ×ÌÈÅ¡£Æù½ñΪֹ£¬ËùÓа汾¶¼»áÊܵ½¸ÃÎó²îµÄÓ°Ïì¡£ÏÖÔÚÉÐδÅû¶¹ØÓÚÕâÒ»Îó²îµÄÏêϸÐÅÏ¢¡£¾Ý×îÐÂ×ÊѶ£¬¸ÃÎó²î¿ÉÄÜÒѱ»ÓÃÓÚÕë¶ÔÕþ¸®»ú¹¹¡¢ÖÆÔìÐÐÒµºÍÒªº¦»ù´¡ÉèÊ©µÄ¹¥»÷¡£
https://securityaffairs.com/147353/hacking/fortinet-fortigate-rce.html
2¡¢Microsoft AzureÃÅ»§ÍøÕ¾ÔÝʱÖÐÖ¹²¢Î´Í¸Â¶»ù´¡Ôµ¹ÊÔÓÉ
¾Ý6ÔÂ9ÈÕ±¨µÀ£¬Microsoft AzureÃÅ»§ÍøÕ¾ÔÝʱÖÐÖ¹¡£Óû§»á¼ûʱ»áÏÔʾ¡°ÎÒÃǵķþÎñÏÖÔÚ²»¿ÉÓá£ÎÒÃÇÕýÔÚÆð¾¢¾¡¿ì»Ö¸´ËùÓзþÎñ¡£ÇëÉÔºóÔÙ»ØÀ´Éó²é¡£¡±¿ÉÊÇÒÆ¶¯Ó¦ÓÃËÆºõ²»ÊÜÓ°Ïì¡£Óë´Ëͬʱ£¬ºÚ¿ÍÍÅ»ïAnonymous SudanÉù³Æ¶Ô¸ÃÍøÕ¾¾ÙÐÐÁËDDoS¹¥»÷£¬²¢¹ûÕæÁËÒ»ÕÅÎÞ·¨Õý³£ÊÂÇéµÄÒ³Ãæ½ØÍ¼¡£Î¢ÈíÉÐδȷÈÏÕâЩÖÐÖ¹ÊÇ·ñÊÇÓÉDDoS¹¥»÷µ¼Öµġ£×èÖ¹6ÔÂ9ÈÕÏÂÖç1:32 ET£¬AzureÍøÕ¾ÔÙ´ÎÉÏÏß²¢ÎȹÌÔËÐС£¾Ý6ÔÂ12ÈÕ×îб¨µÀ£¬Î¢Èí͸¶µ¼ÖÂÖÐÖ¹µÄÆðÔ´Ôµ¹ÊÔÓÉÊÇÍøÂçÁ÷Á¿¼¤Ôö¡£
https://www.bleepingcomputer.com/news/microsoft/microsofts-azure-portal-down-following-new-claims-of-ddos-attacks/
3¡¢°Ä´óÀûÑÇÂÉËùHWL EbsworthÔâµ½ALPHV¹¥»÷¾Ü¸¶Êê½ð
6ÔÂ9ÈÕ±¨µÀ³Æ£¬°Ä´óÀûÑÇ×î´óµÄ״ʦÊÂÎñËùÖ®Ò»HWL EbsworthÈ·ÈÏÆäÔâµ½ºÚ¿Í¹¥»÷¡£ÀÕË÷ÍÅ»ïALPHV£¨Ò²³ÆBlackCat£©ÔÚÆäÍøÕ¾Ðû²¼ÁË1.45 TBµÄÊý¾Ý£¬Éù³Æ°üÀ¨ÓÚ½ñÄê4Ô´ӸÃÂÉËùµÄϵͳÖÐÇÔÈ¡µÄÁè¼ÝÒ»°ÙÍò·ÝÎļþ¡£²¢ÍþвÈôÊDz»½»Êê½ð£¬½«Ð¹Â¶¸ü¶àÎļþ¡£ÂÉËù½²»°ÈËÌåÏÖ£¬ËûÃDz»»áÖª×ã¸ÃÍÅ»ïµÄÒªÇó£¬×ÝÈ»ÕâÒâζ×ÅËûºÍËûµÄ¿Í»§½«²»µÃ²»ÔâÊÜÊý¾Ýй¶µÄЧ¹û¡£ÓÉÓÚ¸ÃÂÉËùÒ²Ó빫¹²²¿·ÖÓÐÓªÒµÍùÀ´£¬Òò´ËÈËÃǵ£ÐÄй¶µÄÎļþ°üÀ¨Óë¹ú¼ÒÊÂÎñÏà¹ØµÄÃô¸Ð»òÉñÃØÐÅÏ¢¡£
https://www.bleepingcomputer.com/news/security/blackcat-ransomware-fails-to-extort-australian-commercial-law-giant/
4¡¢Intellihartx±»ClopÀÕË÷¹¥»÷Ô¼49ÍòÓû§µÄÐÅϢй¶
ýÌå6ÔÂ12Èճƣ¬ÊÖÒÕ¹«Ë¾IntellihartxÔâµ½ClopµÄÀÕË÷¹¥»÷£¬Ð¹Â¶ÁË489830Óû§µÄСÎÒ˽¼ÒºÍ¿µ½¡ÐÅÏ¢¡£IntellihartxÊÇÒ»¼ÒΪҽԺÌṩ»¼ÕßÓà¶î½â¾ö·þÎñµÄ¹«Ë¾¡£¹¥»÷±¬·¢ÔÚ½ñÄêÔçЩʱ¼ä£¬¹¥»÷ÕßʹÓÃÁËGoAnywhereÎó²î£¨CVE-2023-0669£©¡£Ð¹Â¶µÄÐÅÏ¢Éæ¼°ÐÕÃû¡¢µØµã¡¢Ò½ÁÆÕ˵¥ºÍ°ü¹ÜÐÅÏ¢ÒÔ¼°Éç»áÇå¾²ºÅÂëµÈ¡£¸Ã¹«Ë¾½«ÎªÊÜÓ°ÏìÓû§ÌṩExperianµÄΪÆÚÒ»ÄêµÄÃâ·ÑÐÅÓÃ¼à¿Ø·þÎñ¡£
https://securityaffairs.com/147380/data-breach/intellihartx-data-breach.html
5¡¢·¨¹ú¹æÄ£×î´óµÄ°¬¿Ë˹ÂíÈü´óѧ±»¹¥»÷ϵͳÔÝʱÎÞ·¨»á¼û
ýÌå6ÔÂ8ÈÕ±¨µÀ³Æ£¬·¨¹ú°¬¿Ë˹-ÂíÈü´óѧ£¨Aix-Marseille University£©Ôâµ½ÍøÂç¹¥»÷£¬ÏµÍ³ÔÝʱÎÞ·¨»á¼û¡£ËüÊÇÏÖÔÚ·¨¹úºÍ·¨ÓïµØÇø¹æÄ£×î´óµÄ´óѧ£¬ÆäÀúÊ·¿É×·ËÝÖÁ1409Äê¡£ÕâËù´óѧ³Æ¹¥»÷À´×ÔÍâ¹ú£¬ÆäÇ徲ϵͳ´¥·¢Á˾¯±¨£¬Òò´ËËûÃÇÄܹ»ÔÚÔì³É¸ü´óµÄÓ°Ïì֮ǰ½«ÏµÍ³¹Ø±Õ¡£ÏÖÔÚ£¬¹¥»÷µÄÐÔ×ÓÉÐδ֤ʵ£¬Ò²²»ÖªµÀÊÇ·ñ±£´æÊý¾Ýй¶¡£¸ÃУÍýÏë´ÓÉÏÖÜËÄ×îÏÈÖð²½»Ö¸´·þÎñ£¬µ«Ã»ÓÐ˵Ã÷ÐèÒª¶à¾Ã£¬Ñ§ÉúºÍÔ±¹¤ÈÔÎÞ·¨¼ÓÈëÒÀÀµÓÚ»á¼ûÑ§Ð£ÍøÂçÉϵŤ¾ßµÄ½ÌÓýÔ˶¯¡£
https://therecord.media/aix-marseille-university-cyberattack-france
6¡¢ESET¹ûÕæ¹ØÓÚAsylum Ambuscade¹¥»÷Ô˶¯µÄ¸ü¶àϸ½Ú
6ÔÂ8ÈÕ£¬ESET¹ûÕæÁ˹ØÓÚAsylum Ambuscade¹¥»÷Ô˶¯µÄ¸ü¶àϸ½Ú¡£Asylum AmbuscadeÖÁÉÙ´Ó2020Äê×îÏÈ»îÔ¾£¬Ö÷ÒªÕë¶Ô²î±ðµØÇøÒøÐпͻ§ºÍ¼ÓÃÜÇ®±ÒÉúÒâËù¡£¸ÃÍÅ»ïµÄ´ó²¿·ÖÖ²Èë³ÌÐò¶¼ÊÇÓþ籾ÓïÑÔ¿ª·¢µÄ£¬ÀýÈçAutoHotkey¡¢JavaScript¡¢Lua¡¢PythonºÍVBS¡£ESETÌåÏÖ£¬ÔÚ2023ÄêµÄÔ˶¯Öз¢Ã÷ÁËÐµĹ¥»÷ÔØÌ壬°üÀ¨¿ÉÒÔ½«Óû§Öض¨Ïòµ½ÔËÐжñÒâJavaScript´úÂëµÄÍøÕ¾µÄGoogle Ads¡£±ðµÄ£¬¹¥»÷ÕßÓÚ3Ô·Ý×îÏÈ·Ö·¢Ð¹¤¾ßNodebot£¬ÕâËÆºõÊÇAhkbotµÄNode.js¶Ë¿Ú¡£
https://www.welivesecurity.com/2023/06/08/asylum-ambuscade-crimeware-or-cyberespionage/


¾©¹«Íø°²±¸11010802024551ºÅ