ResecurityÅû¶ͨ¹ýÎäÆ÷»¯OfficeÎĵµ·Ö·¢µÄEscanor
Ðû²¼Ê±¼ä 2022-08-231¡¢ResecurityÅû¶ͨ¹ýÎäÆ÷»¯OfficeÎĵµ·Ö·¢µÄEscanor
8ÔÂ21ÈÕ£¬£¬£¬£¬£¬£¬Resecurity³ÆÔÚ°µÍøºÍTelegramÖз¢Ã÷ÁËÒ»ÖÖÃûΪEscanorµÄÐÂRAT¡£¡£¡£¡£¸Ã¹¤¾ßÓÚ½ñÄê1ÔÂ26ÈÕÐû²¼£¬£¬£¬£¬£¬£¬×î³õÊÇ×÷Ϊ½ô´ÕÐÍHVNCÖ²Èë³ÌÐò£¬£¬£¬£¬£¬£¬¿ÉÓÃÀ´½¨ÉèÓëÄ¿µÄÅÌËã»úµÄÔ¶³Ì¾²Ä¬ÅþÁ¬£¬£¬£¬£¬£¬£¬ØÊºóת±äΪ¾ßÓжàÖÖ¹¦Ð§¼¯µÄÉÌÒµRAT¡£¡£¡£¡£×î½ü¼ì²âµ½µÄ´ó´ó¶¼Ñù±¾¶¼ÊÇʹÓÃEscanor Exploit Builder·Ö·¢µÄ£¬£¬£¬£¬£¬£¬¹¥»÷ÕßʹÓÃÁËÓÕ¶üÎÄ£¬£¬£¬£¬£¬£¬Ä£ÄâÊ¢ÐÐÔÚÏßЧÀ͵ķ¢Æ±ºÍ֪ͨ¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬ÓòÃûescanor[.]live´ËǰÒѱ»È·ÈÏÓëAridViperµÄ»ù´¡ÉèÊ©Óйء£¡£¡£¡£
https://resecurity.com/blog/article/escanor-malware-delivered-in-weaponized-microsoft-office-documents
2¡¢ÃÀ¹úNovant HealthµÄ130Íò»¼ÕßµÄСÎÒ˽¼ÒÐÅϢй¶
¾Ý8ÔÂ22ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬ÃÀ¹úÒ½ÁƱ£½¡ÌṩÉÌNovant HealthÅû¶ÁËÒ»ÆðÊý¾Ýй¶ÊÂÎñ£¬£¬£¬£¬£¬£¬Ó°ÏìÁË1362296¸ö»¼Õß¡£¡£¡£¡£¸ÃÊÂÎñʼÓÚ2020Äê5Ô£¬£¬£¬£¬£¬£¬ÆäʱNovant¿ªÕ¹ÁËÉæ¼°Facebook¹ã¸æµÄCOVID-19ÒßÃç½ÓÖÖÐû´«»î¶¯¡£¡£¡£¡£ÎªÁ˸ú×ÙÕâЩ¹ã¸æ£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾ÔÚÍøÕ¾ÉÏÌí¼ÓÁËMeta Pixel´úÂ룬£¬£¬£¬£¬£¬À´ÅÐ¶Ï¹ã¸æµÄЧ¹û¡£¡£¡£¡£¿ÉÊÇ£¬£¬£¬£¬£¬£¬Novant HealthµÄÍøÕ¾ºÍMyChartÃÅ»§ÉϵÄMeta PixelÉèÖùýʧ£¬£¬£¬£¬£¬£¬µ¼Ö»¼ÕßµÄÐÅÏ¢»á±»·¢Ë͸øMeta¼°Æä¹ã¸æÏàÖúͬ°é¡£¡£¡£¡£NovantÔÚ2022Äê5ÔÂ´ÓÆäÍøÕ¾ºÍÃÅ»§ÖÐɾ³ýÁËMeta Pixel¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/misconfigured-meta-pixel-exposed-healthcare-data-of-13m-patients/
3¡¢Donot TeamΪÆä¶ñÒâÈí¼þ¿ò¼ÜJacaÌí¼ÓÐµĹ¦Ð§
ýÌå8ÔÂ22ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬Donot Team£¨ÓÖÃûAPT-C-35£©ÒÑΪÆäWindows¶ñÒâÈí¼þ¿ò¼ÜJacaÌí¼ÓÁËÐµĹ¦Ð§¡£¡£¡£¡£¸ÃÍÅ»ï×Ô2016Äê×îÏÈ»îÔ¾£¬£¬£¬£¬£¬£¬Ö÷ÒªÕë¶ÔÓ¡¶È¡¢°Í»ù˹̹¡¢Ë¹ÀïÀ¼¿¨¡¢ÃϼÓÀ¹úµÈÄÏÑǹú¼ÒµÄÕþ¸®»ú¹¹¡¢¾üÊÂ×éÖ¯¡¢Íâ½»²¿ºÍ´óʹ¹Ý¡£¡£¡£¡£Ð°汾ÔöÇ¿ÁËä¯ÀÀÆ÷ÇÔȡģ¿£¿£¿£¿£¿£¿£¿£¿é£¬£¬£¬£¬£¬£¬Ê¹ÓÃǰһ½×¶ÎÏÂÔØµÄ4¸ö¸½¼Ó¿ÉÖ´ÐÐÎļþ(WavemsMp.dll)ʵÏÖÇÔÈ¡¹¦Ð§£¬£¬£¬£¬£¬£¬¶ø²»ÊÇÔÚDLLÖУ¬£¬£¬£¬£¬£¬Ã¿¸ö¸½¼ÓµÄ¿ÉÖ´ÐÐÎļþ¶¼¿ÉÒÔ´ÓChrome»òFirefoxÖÐÇÔÊØÐÅÏ¢¡£¡£¡£¡£
https://securityaffairs.co/wordpress/134674/apt/donot-team-improves-jaca-framework.html
4¡¢APT29ÔÚÕë¶Ô±±Ô¼µÄ¹¥»÷»î¶¯ÖÐʹÓÃеÄTTPÈÆ¹ý¼ì²â
8ÔÂ18ÈÕ£¬£¬£¬£¬£¬£¬MandiantÅû¶Á˶íÂÞ˹APT29£¨Cozy Bear£©Õë¶Ô±±Ô¼¹ú¼ÒµÄÐÂÒ»ÂÖ¹¥»÷»î¶¯¡£¡£¡£¡£ÔÚ¹¥»÷ÖУ¬£¬£¬£¬£¬£¬APT29ʹÓÃÁËеÄÕ½Êõ¡¢ÊÖÒպͳÌÐò£¨TTP£©À´Èƹý¼ì²â£¬£¬£¬£¬£¬£¬°üÀ¨ÔÚÔÚѬȾµÄÄ¿µÄÕÊ»§ÉϽûÓÃPurview Audit¹¦Ð§£¬£¬£¬£¬£¬£¬È»ºóÍøÂçÊÕ¼þÏäÖеĵç×ÓÓʼþ£»£»£»£»£»£»£»£»Ê¹ÓÃAzure Active DirectoryºÍÆäËüƽ̨ÖеÄMFA×ÔÎÒ×¢²áÀú³Ì£¬£¬£¬£¬£¬£¬¸ÃÍÅ»ï¿É±©Á¦ÆÆ½â´ÓδµÇ¼¹ýµÄÓòµÄÕÊ»§²¢½«Æä×°±¸×¢²áµ½MFA£»£»£»£»£»£»£»£»Ñо¿Ö°Ô±Ç¿µ÷APT29½ÓÄÉÁ˵ÄÌØÊâµÄÔËÓªÇå¾²ºÍÈÆ¹ýÕ½ÂÔ£¬£¬£¬£¬£¬£¬ËüʹÓÃÁËAzureÐéÄâ»ú¡£¡£¡£¡£
https://www.mandiant.com/resources/blog/apt29-continues-targeting-microsoft
5¡¢AppleÐÞ¸´SafariÖÐÒѱ»Ê¹ÓõÄÎó²îCVE-2022-32893
8ÔÂ18ÈÕ£¬£¬£¬£¬£¬£¬AppleΪmacOS Big SurºÍCatalinaÐû²¼ÁËSafari 15.6.1£¬£¬£¬£¬£¬£¬ÒÔÐÞ¸´Ò»¸ö±»ÓÃÀ´ÈëÇÖMacµÄÎó²î¡£¡£¡£¡£ÕâÊÇWebKitÖеÄÒ»¸öÔ½½çдÈëÎó²î(CVE-2022-32893)£¬£¬£¬£¬£¬£¬¿ÉÓÃÀ´ÔÚÄ¿µÄ×°±¸ÉÏÔ¶³ÌÖ´ÐдúÂë¡£¡£¡£¡£¸ÃÎó²îÓëApple֮ǰÐÞ¸´µÄmacOS MontereyºÍiPhone/iPadÖеÄÎó²îÏàͬ£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾²¢Î´ÌṩÓйØÔõÑù±»Ê¹ÓõÄÏêϸÐÅÏ¢£¬£¬£¬£¬£¬£¬Ö»ÊÇ˵Ëü¿ÉÄÜÒѱ»Æð¾¢Ê¹Óᣡ£¡£¡£ÕâÊÇAppleÔÚ2022ÄêÐÞ¸´µÄµÚ7¸ö0 day¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/apple-releases-safari-1561-to-fix-zero-day-bug-used-in-attacks/
6¡¢Unit42Ðû²¼2022Äê2ÔÂÖÁ4ÔÂÍøÂçÇå¾²Ì¬ÊÆµÄÆÊÎö±¨¸æ
Unit42ÔÚ8ÔÂ19ÈÕÐû²¼ÁË2022Äê2ÔÂÖÁ4ÔÂÍøÂçÇå¾²Ì¬ÊÆµÄÆÊÎö±¨¸æ¡£¡£¡£¡£´Ó½ñÄê2ÔÂÖÁ4Ô£¬£¬£¬£¬£¬£¬Unit42¹²¼Í¼ÁË5962¸öеÄCVE£¬£¬£¬£¬£¬£¬ÆäÖÐ26.4%±»¹éÀàΪÍâµØÎó²î£¬£¬£¬£¬£¬£¬Ê£ÓàµÄ73.6%ÊÇ¿Éͨ¹ýÍøÂçʹÓõÄÔ¶³ÌÎó²î¡£¡£¡£¡£XSSÎó²îÈÔÊDZ¨¸æ×î¶àµÄÎó²î£¬£¬£¬£¬£¬£¬Æä´ÎÊÇÔ½½çдÈë¡¢ÐÅϢй¶ºÍSQL×¢ÈëÎó²î¡£¡£¡£¡£¶ÔÍøÂç¹¥»÷¾ÙÐзÖÀ࣬£¬£¬£¬£¬£¬×î¶àµÄÊÇÔ¶³Ì´úÂëÖ´Ðй¥»÷£¬£¬£¬£¬£¬£¬Æä´ÎÊDZéÀú¹¥»÷¡¢ÐÅϢй¶¹¥»÷¡¢¿çÕ¾¾ç±¾¹¥»÷ºÍSQL×¢Èë¹¥»÷¡£¡£¡£¡£´ó´ó¶¼¹¥»÷ËÆºõÀ´×ÔÃÀ¹ú£¬£¬£¬£¬£¬£¬Æä´ÎÊǵ¹úºÍ¶íÂÞ˹¡£¡£¡£¡£
https://unit42.paloaltonetworks.com/recent-exploits-network-security-trends/


¾©¹«Íø°²±¸11010802024551ºÅ