¼ÓÄôóÍøÂçÔËÓªÉÌRogers´ó¹æÄ£Öжϲ¨¼°¶à¸öÁìÓò

°ä²¼¹¦·ò 2022-07-11

1¡¢¼ÓÄôóÍøÂçÔËÓªÉÌRogers´ó¹æÄ£Öжϲ¨¼°¶à¸öÁìÓò

 ¾ÝýÌå7ÔÂ8ÈÕ±¨Â·  £¬¼ÓÄôóÍøÂçÔËÓªÉÌÂÞ½Ü˹£¨Rogers£©²úÉúÁË´ó¹æÄ£·þÎñÖжÏ ¡£DownDetector³Æ  £¬ÖÐ¶ÏÆðÍ·×ÔÃÀ¹ú¶«²¿¹¦·òÔçÉÏ5µã×óÓÒ  £¬¿Í»§·´Ó³ºöÈ»ÎÞ·¨²¦´òµç»°»òÏνӵ½»¥ÁªÍø ¡£ÁªÍø¼à¿Ø×éÖ¯NetBlocks°µÊ¾  £¬¸ÃÊÂÎñµ¼Ö¼ÓÄôóµÄÍøÂçÏνÓÏ÷¼õÁË25% ¡£ÖжÏÓ°ÏìÁ˼ÓÄôóµÄÒøÐкͽðÈÚÂòÂô  £¬×Ô¶¯¹ñÔ±»úºÍÐÅÓþ¿¨ÂòÂôÎÞ·¨Õý³£¹¤×÷  £¬¶ø²¿ÃŵØÓòµÄ911·þÎñÒ²Êܵ½Ó°Ïì ¡£½ØÖÁ7ÔÂ9ÈÕÉÏÎç8:00  £¬Roger°ä²¼ÉêÃ÷³Æ  £¬ÒÑΪ¾ø´óÎÞÊý¿Í»§¸´Ô­ÁË·þÎñ  £¬µ«ÒÀȻûÓÐÚ¹Ê͵¼ÖÂÖжϵÄÔ­Òò ¡£

https://www.bleepingcomputer.com/news/technology/massive-rogers-outage-disrupts-mobile-service-payments-in-canada/


2¡¢MangatoonÊý¾Ý¿âÅäÖÃÃýÎóй¶2300ÍòÓû§µÄÐÅÏ¢

¾Ý7ÔÂ9ÈÕ±¨Â·  £¬Êý¾Ýй¶֪ͨ·þÎñHave I Been Pwned(HIBP)ÔÚÆäÆ½Ì¨ÉÏй©2300Íò¸öMangatoonÕÊ»§Ð¹Â¶ ¡£MangatoonÊÇÒ»¿îÊÜÓ­½ÓµÄÔÚÏßÂþ»­ÀûÓà  £¬Õâ´Îй¶ÁËÓû§µÄÐÕÃû¡¢ÓʼþµØÖ·¡¢É罻ýÌåÕË»§¡¢Éí·ÝÑéÖ¤ÁîÅÆºÍÃÜÂë ¡£¾ÝºÚ¿Ípompompurin³Æ  £¬ËûÃÇ´ÓʹÓÃÁËÈõÃÜÂë"password"µÄElasticsearch·þÎñÆ÷ÉÏÇÔÈ¡ÁËÊý¾Ý ¡£¸ÃºÚ¿Í»¹°µÊ¾  £¬¹«Ë¾ÔÚÊÕµ½Ð¹Â¶Í¨Öªºó¸ü¸ÄÁËÃÜÂë  £¬µ«²¢Î´Í¨Öª¿Í»§  £¬Ò²Î´¶Ô´ËÊÂ×÷³ö»ØÓ¦ ¡£

https://www.bleepingcomputer.com/news/security/mangatoon-data-breach-exposes-data-from-23-million-accounts/


3¡¢Fortinet·¢ÏÖÀûÓÃDiscord·Ö·¢ºóÃÅRozenaµÄ»î¶¯

7ÔÂ6ÈÕ  £¬FortinetÅû¶ÁË·Ö·¢¶ñÒâÈí¼þRozenaµÄ¹¥»÷»î¶¯µÄ¼¼Êõϸ½Ú ¡£RozenaÊÇÒ»¸öеĺóÃÅ  £¬Äܹ»½«Ô¶³ÌshellÏνÓ×¢Èë¹¥»÷ÕßµÄÍÆËã»ú ¡£Õâ´Î»î¶¯ÀûÓÃÁËMSDTÔ¶³Ì´úÂëÖ´Ðзì϶Follina£¨CVE-2022-30190£©  £¬Ê¼ÓÚÒ»¸ö±øÆ÷»¯µÄOfficeÎĵµ  £¬¸ÃÎĵµÔÚ´ò¿ªÊ±»áÏνӵ½Discord CDN URLÒÔ¼ìË÷HTMLÎļþ£¨¡°index.htm¡±£© ¡£¸ÃÎļþʹÓÃPowerShellºÅÁîŲÓÃÕï¶Ï¹¤¾ß  £¬´Óͳһ¸öCDN¸½¼þ¿Õ¼äÏÂÔØÏÂÒ»½×¶ÎµÄpayload  £¬ÕâÔ̺¬RozenaÖ²È뷨ʽ£¨¡°Word.exe¡±£©ºÍÒ»¸öÅú´¦ÖÃÎļþ£¨¡°cd.bat¡±£© ¡£

https://www.fortinet.com/blog/threat-research/follina-rozena-leveraging-discord-to-distribute-a-backdoor


4¡¢QNAPÌáÐѳÆÐÂÀÕË÷Èí¼þCheckmatÖØÒªÕë¶ÔÆäNASÉ豸

QNAPÔÚ7ÔÂ7ÈÕ°ä²¼²¼¸æ³Æ  £¬ÐÂÀÕË÷Èí¼þCheckmatÖØÒªÕë¶ÔÆäNASÉ豸 ¡£³õ´ëÊ©²éÅú×¢  £¬Checkmate»áͨ¹ý¶³öÔÚ»¥ÁªÍøÉϵÄSMB·þÎñ½øÐй¥»÷  £¬²¢Ê¹ÓÃ×ֵ乥»÷À´ÆÆ½âÈõÃÜÂëµÄÕÊ»§ ¡£¹¥»÷ÕßÒ»µ©³É¹¦µÇ¼É豸  £¬¾Í»á¶Ô¹²ÏíÎļþ¼ÐÖеÄÊý¾Ý½øÐмÓÃÜ  £¬²¢ÔÚÿ¸öÎļþ¼ÐÖÐÁôÏÂÒ»¸öÎļþ¡°£¡CHECKMATE_DECRYPTION_README¡±×÷ΪÀÕË÷¼Í¼ ¡£CheckmateÓÚ5ÔÂ28ÈÕ×óÓÒ³õ´ÎÔÚ¹¥»÷Öб»Ê¹Óà  £¬QNAP½¨Ò鏿Óû§²»Òª½«SMB·þÎñ¶³öÔÚ»¥ÁªÍøÉÏ  £¬²¢Ê¹ÓÃVPN½Ó¼ûNASÀ´Ï÷¼õ¹¥»÷Ãæ ¡£

https://securityaffairs.co/wordpress/132989/malware/checkmate-ransomware-targets-qnap-nas.html


5¡¢IBM X-Force°ä²¼¹ØÓÚTrickbotÕë¶ÔÎÚ¿ËÀ¼µÄ·ÖÎö»ã±¨

7ÔÂ7ÈÕ  £¬IBM Security X-Force°ä²¼Á˹ØÓÚTrickbotÍÅ»ïÆðÍ·Õë¶ÔÎÚ¿ËÀ¼µÄ·ÖÎö»ã±¨ ¡£ÔÚ2022Äê4ÔÂÖÁ6Ô  £¬Trickbot²ß¶¯ÁËÖÁÉÙ6´ÎÕë¶ÔÎÚ¿ËÀ¼µÄ¹¥»÷»î¶¯  £¬²¢ÔÚÕâЩ»î¶¯ÖÐ×°ÖÃÁ˶ñÒâÈí¼þIcedID¡¢CobaltStrike¡¢AnchorMailºÍMeterpreter ¡£ÔÚµ÷²éÕâЩ»î¶¯Ê±  £¬X-Force»¹·¢ÏÖÁ˸ÃÍÅ»ïÔÚʹÓõÄеĶñÒâÈí¼þºÍ¹¤¾ß£ºÓÃÓÚ´«µÝpayloadµÄ¶ñÒâExcelÏÂÔØ·¨Ê½¡¢ÓÃÓÚͶ·ÅºÍ¹¹½¨payload£¨ÈçAnchorMail£©µÄ×Ô½âѹ´æµµ£¨SFX£©  £¬ÒÔ¼°Ò»¸ö±»³ÆÎªForestµÄ¶ñÒâÈí¼þ¼ÓÃÜ·¨Ê½ ¡£

https://securityintelligence.com/posts/trickbot-group-systematically-attacking-ukraine/


6¡¢×êÑÐÈËÔ±ÑÝʾÈôºÎͨ¹ýRolling-PWN¹¥»÷½âËø±¾ÌïÆû³µ

ýÌå7ÔÂ10ÈÕ³Æ  £¬Star-V³¢ÊÔÊÒµÄÒ»×é×êÑÐÈËÔ±³ÆÆäÄܹ»Í¨¹ýRolling-PWN¹¥»÷½âËø¶à¸ö±¾Ìï³µÐÍ ¡£×êÑÐÈËÔ±ÔÚ±¾ÌïÖз¢ÏÖÁËÒ»¸ö·ì϶(CVE-2021-46145)  £¬¿ÉÓÃÀ´½âËø³µÁ¾  £¬ÉõÖÁÆô¶¯³µÁ¾·¢Æð»ú ¡£¾ÝϤ  £¬¸ÃÎÊÌâÓ°ÏìÊг¡ÉÏ´Ó2012Äêµ½2022ÄêµÄËùÓб¾ÌïÆû³µ ¡£¸Ã·ì϶´æÔÚÓÚÓÃÀ´Ô¤·À³Á·Å¹¥»÷µÄ¹ö¶¯´úÂë»úÔìÖÐ  £¬×êÑÐÈËÔ±»¹°ä²¼ÁËÒ»×éPoCÊÓÆµ  £¬À´ÑÝʾÀûÓø÷ì϶¶Ô±¾ÌïCRVµÄ¹¥»÷ ¡£

https://securityaffairs.co/wordpress/133090/hacking/honda-rolling-pwn-attack.html