´ó×ÚQNAP NASÓû§³ÆÆä×°±¸Ôâµ½ech0raixµÄÀÕË÷¹¥»÷
Ðû²¼Ê±¼ä 2022-06-201¡¢´ó×ÚQNAP NASÓû§³ÆÆä×°±¸Ôâµ½ech0raixµÄÀÕË÷¹¥»÷
ýÌå6ÔÂ18ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬£¬Æ¾Ö¤ID Ransomwareƽ̨ÉÏÓû§Ìá½»µÄ±¨¸æºÍÑù±¾£¬£¬£¬£¬£¬£¬£¬ech0raixÀÕË÷Èí¼þÔÚÉÏÖÜ×îÏÈÔÙ´ÎÕë¶ÔQNAP NAS×°±¸¡£¡£¡£¡£¡£Ô½À´Ô½¶àµÄÓû§³ÆÆäÔâµ½¹¥»÷£¬£¬£¬£¬£¬£¬£¬×îÔ籬·¢ÔÚ6ÔÂ8ÈÕ¡£¡£¡£¡£¡£Ö»¹ÜÖ»Óм¸Ê®¸öech0raixÑù±¾£¬£¬£¬£¬£¬£¬£¬µ«Ñо¿Ö°Ô±ÌåÏÖÏÖʵµÄÀֳɹ¥»÷µÄÊýÄ¿ºÜ¿ÉÄܸü¸ß£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚÖ»Óв¿·ÖÓû§»áʹÓÃID RansomwareЧÀÍÀ´Ê¶±ðÀÕË÷Èí¼þ¡£¡£¡£¡£¡£QNAPÉÐδÐû²¼Óйش˴ι¥»÷µÄ¸ü¶àÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬Õâ¸öech0raix»î¶¯Ê¹ÓõĹ¥»÷ǰÑÔÈÔȻδ֪¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/qnap-nas-devices-targeted-by-surge-of-ech0raix-ransomware-attacks/
2¡¢ÃÀ¹úÕþ¸®³ÆÒѵ·»ÙѬȾÊý°ÙÍò×°±¸µÄ½©Ê¬ÍøÂçRSOCKS
¾Ý6ÔÂ18ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬£¬ÃÀ¹úÕþ¸®ÓëµÂ¹ú¡¢ºÉÀ¼ºÍÓ¢¹úµÄÖ´·¨»ú¹¹ÏàÖú£¬£¬£¬£¬£¬£¬£¬Àֳɲð³ýÁËÓë¶íÂÞ˹½©Ê¬ÍøÂçRSOCKSÓйصĻù´¡ÉèÊ©¡£¡£¡£¡£¡£RSOCKSÓÉÈ«ÇòÊý°ÙÍǫ̀±»Ñ¬È¾µÄ×°±¸×é³É£¬£¬£¬£¬£¬£¬£¬×ԳƿÉÒÔ¹©¸¶·Ñ¿Í»§»á¼û±»ÈëÇÖµÄ×°±¸µÄIPµØµã¡£¡£¡£¡£¡£¸ÃÐж¯×îÏÈÓÚ2017Ä꣬£¬£¬£¬£¬£¬£¬Æäʱִ·¨Ö°Ô±´ÓRSOCKSÉñÃØµØ¹ºÖÃÁËÆäЧÀÍÒÔʶ±ðÆä»ù´¡ÉèÊ©ºÍÄ¿µÄ£¬£¬£¬£¬£¬£¬£¬È·¶¨ÁËԼĪ325000̨±»Ñ¬È¾µÄ×°±¸¡£¡£¡£¡£¡£½üÆÚµÄÁíÒ»ÏîÖ´·¨Ðж¯²é»ñÁËÒѳöÊÛ2400ÍòÈËÐÅÏ¢µÄ°µÍøÊг¡SSNDOB¡£¡£¡£¡£¡£
https://securityaffairs.co/wordpress/132403/cyber-crime/police-dismantled-rsocks-bitnet.html
3¡¢VolexityÅû¶DriftingCloudÍÅ»ï½üÆÚ¹¥»÷»î¶¯µÄϸ½Ú
VolexityÔÚ6ÔÂ15ÈÕÐû²¼±¨¸æ£¬£¬£¬£¬£¬£¬£¬Åû¶ÁËDriftingCloudÍÅ»ï½üÆÚ¹¥»÷»î¶¯µÄϸ½Ú¡£¡£¡£¡£¡£Ñо¿Ö°Ô±·¢Ã÷£¬£¬£¬£¬£¬£¬£¬×Ô3Ô³õ×îÏÈ£¬£¬£¬£¬£¬£¬£¬¸ÃÍÅ»ï¾ÍʹÓÃÁËSophos FirewallÖеÄÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î£¨CVE-2022-1040£¬£¬£¬£¬£¬£¬£¬CVSSÆÀ·Ö9.8£©À´ÈëÇÖÄ¿µÄ£¬£¬£¬£¬£¬£¬£¬È»ºó×°ÖÃÒ»¸öºóÃÅ¡£¡£¡£¡£¡£Volexity³Æ¹¥»÷Õß»áʹÓ÷À»ðǽµÄ»á¼ûȨÏÞÀ´¸Ä¶¯Õë¶ÔÌØ¶¨Ä¿µÄÍøÕ¾µÄDNSÏìÓ¦£¬£¬£¬£¬£¬£¬£¬ÒÔÖ´ÐÐMITM¹¥»÷¡£¡£¡£¡£¡£Ò»µ©»ñµÃ¶ÔÄ¿µÄÍøÂçЧÀÍÆ÷µÄ»á¼ûȨÏÞ£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õ߾ͻá×°Ööà¸ö¿ªÔ´¶ñÒâÈí¼þ£¬£¬£¬£¬£¬£¬£¬°üÀ¨PupyRAT¡¢PanteganaºÍSliver¡£¡£¡£¡£¡£
https://www.volexity.com/blog/2022/06/15/driftingcloud-zero-day-sophos-firewall-exploitation-and-an-insidious-breach/
4¡¢ÉϰÙÍòWordPressÍøÕ¾µÄ²å¼þNinja Forms±»Ç¿ÖƸüÐÂ
¾ÝýÌå6ÔÂ17Èճƣ¬£¬£¬£¬£¬£¬£¬ÉϰÙÍò¸öWordPressÍøÕ¾Òѱ»Ç¿ÖƸüУ¬£¬£¬£¬£¬£¬£¬ÒÔÐÞ¸´Æä²å¼þNinja FormsÖеÄÎó²î¡£¡£¡£¡£¡£ÕâÊÇÒ»¸ö´úÂë×¢ÈëÎó²î£¬£¬£¬£¬£¬£¬£¬CVSSÆÀ·ÖΪ9.8£¬£¬£¬£¬£¬£¬£¬Ó°ÏìÁË´Ó3.0×îÏȵĶà¸öNinja Forms°æ±¾¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÌåÏÖ£¬£¬£¬£¬£¬£¬£¬Î´¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔÔ¶³ÌʹÓôËÎó²îÀ´Å²ÓÃÖÖÖÖNinja±íµ¥À࣬£¬£¬£¬£¬£¬£¬È»ºóͨ¹ý¶à¸öʹÓÃÁ´ÍêÈ«½ÓÊÜWordPressÍøÕ¾¡£¡£¡£¡£¡£Wordfence·¢Ã÷µÄÖ¤¾ÝÅú×¢£¬£¬£¬£¬£¬£¬£¬¸ÃÎó²îÒÑÔÚ¹¥»÷Öб»Ê¹Ó㬣¬£¬£¬£¬£¬£¬WordPressΪ´Ë²å¼þÖ´ÐÐÁËÇ¿ÖÆ×Ô¶¯¸üС£¡£¡£¡£¡£
https://thehackernews.com/2022/06/over-million-wordpress-sites-forcibly.html
5¡¢Ñо¿Ö°Ô±·¢Ã÷ʹÓÃÀ¬»øÓʼþ·Ö·¢MatanbuchusµÄ»î¶¯
¾Ý6ÔÂ18ÈÕµÄýÌ屨µÀ£¬£¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±·¢Ã÷ÁË·Ö·¢¶ñÒâÈí¼þMatanbuchusµÄÀ¬»øÓʼþ»î¶¯¡£¡£¡£¡£¡£¹¥»÷ÕßÊ×ÏÈʹÓÃð³äÊǶÔÏÈǰµç×ÓÓʼþµÄ»Ø¸´×÷ΪÓÕ¶ü£¬£¬£¬£¬£¬£¬£¬ÆäÖаüÀ¨Ò»¸öZIP¸½¼þ£¬£¬£¬£¬£¬£¬£¬¿ÉÏÂÔØÒ»¸öMSI°ü£¬£¬£¬£¬£¬£¬£¬¸Ã°üʹÓÃÓÉDigiCertΪ¡°Westeast Tech Consulting, Corp.¡±½ÒÏþµÄÓÐÓÃÖ¤Êé¾ÙÐÐÊðÃû¡£¡£¡£¡£¡£Ö®ºó£¬£¬£¬£¬£¬£¬£¬»áÏÂÔØÁ½¸öMatanbuchus DLL payload£¬£¬£¬£¬£¬£¬£¬¸Ã¶ñÒâÈí¼þ×îÖÕ»á´ÓC2ЧÀÍÆ÷ÏÂÔØCobalt Strike£¬£¬£¬£¬£¬£¬£¬ÎªºóÐø¹¥»÷×ö×¼±¸¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/new-phishing-attack-infects-devices-with-cobalt-strike/
6¡¢¿ý±±¿Ë·¨ÔºÑ¶¶ÏDesjardins¾ÍÊý¾Ýй¶ÊÂÎñÖ§¸¶2ÒÚ¼ÓÔª
6ÔÂ18ÈÕ±¨µÀ³Æ£¬£¬£¬£¬£¬£¬£¬¿ý±±¿Ë·¨ÔºÒÑѶ¶ÏDesjardinsÖ§¸¶2.009ÒÚ¼ÓÔªÒÔ½â¾ö¶ÔÊý¾Ýй¶ÊÂÎñµÄÕûÌåËßËÏ¡£¡£¡£¡£¡£î¿Ïµ»ú¹¹ÌåÏÖ£¬£¬£¬£¬£¬£¬£¬DesjardinsµÄÎ¥¹æÊÂÎñÊÇÓÉһϵÁÐÎó²îÔì³ÉµÄ£¬£¬£¬£¬£¬£¬£¬Ð¹Â¶ÁË420Íò¸öÓµÓлîÔ¾ÕË»§µÄÓû§µÄÊý¾Ý¡£¡£¡£¡£¡£¾ÝϤ£¬£¬£¬£¬£¬£¬£¬Ã¿¸öÊÜÓ°ÏìµÄÓû§¶¼ÓÐ×ʸñÌá³öË÷Åâ¡£¡£¡£¡£¡£Ôڴ˽׶Σ¬£¬£¬£¬£¬£¬£¬Óû§²»±Ø½ÓÄÉÈκβ½·¥£¬£¬£¬£¬£¬£¬£¬°üÀ¨Ë÷Åâ˵Ã÷ÔÚÄÚµÄ֪ͨ½«ÔÚ×Ô7ÔÂ21ÈÕ×îÏȵöÔÂÄÚ·Ö·¢¡£¡£¡£¡£¡£
https://www.databreaches.net/quebec-court-approves-200-9m-settlement-against-desjardins-over-data-breach/