AndroxGh0st½©Ê¬ÍøÂçÃé×¼AWS¡¢AzureºÍOffice365ƾ֤

Ðû²¼Ê±¼ä 2024-01-19
1. AndroxGh0st½©Ê¬ÍøÂçÃé×¼AWS¡¢AzureºÍOffice365ƾ֤


1ÔÂ17ÈÕ£¬£¬ £¬£¬£¬£¬£¬AndroxGh0stÊÇÒ»ÖÖ»ùÓÚ Python µÄ¶ñÒâÈí¼þ£¬£¬ £¬£¬£¬£¬£¬ÓÉ Lacework ÓÚ 2022 Äê 12 ÔÂÊ״μͼ£¬£¬ £¬£¬£¬£¬£¬¸Ã¶ñÒâÈí¼þÆô·¢ÁËAlienFox¡¢GreenBot£¨ÓÖÃû Mainance£©¡¢Legion ºÍ Predator µÈ¶à¸öÀàËÆ¹¤¾ß¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÔÆ¹¥»÷¹¤¾ßÄܹ»ÉøÍ¸Ò×ÊÜÒÑÖªÇå¾²Îó²îÓ°ÏìµÄЧÀÍÆ÷£¬£¬ £¬£¬£¬£¬£¬ÒÔ»á¼û Laravel ÇéÐÎÎļþ²¢ÇÔÈ¡ Amazon Web Services (AWS)¡¢Microsoft Office 365¡¢SendGrid ºÍ Twilio µÈ×ÅÃûÓ¦ÓóÌÐòµÄƾ֤¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßʹÓõÄһЩֵµÃ×¢ÖØµÄȱÏݰüÀ¨CVE-2017-9841 (PHPUnit)¡¢CVE-2021-41773 (Apache HTTP Server) ºÍCVE-2018-15133 (Laravel Framework)¡£¡£¡£¡£¡£¡£¡£¡£AndroxGh0st ¾ßÓжàÖÖ¹¦Ð§£¬£¬ £¬£¬£¬£¬£¬¿ÉÒÔʵÏÖ SMTP ÀÄÓᣡ£¡£¡£¡£¡£¡£¡£


2. Ħ¸ù´óÍ¨ÃæÁÙØ¨¹ÅδÓеÄÍøÂçÍþв£¬£¬ £¬£¬£¬£¬£¬ÖðÈÕ450ÒÚ´ÎÈëÇÖʵÑé


1ÔÂ17ÈÕ£¬£¬ £¬£¬£¬£¬£¬»ª¶û½Ö¶¥¼¶½ðÈÚ»ú¹¹Ö®Ò»Ä¦¸ù´óͨÏÖÔÚÕýÔÚÆð¾¢Ó¦¶ÔÍøÂç¹¥»÷ÊýÄ¿µÄ¾ªÈËÔöÌí¡£¡£¡£¡£¡£¡£¡£¡£¾Ý±¨µÀ£¬£¬ £¬£¬£¬£¬£¬¸Ã¹«Ë¾ÌìÌìÃæÁÙ¶à´ï 450 ÒÚ´ÎÍøÂçÈëÇÖʵÑ飬£¬ £¬£¬£¬£¬£¬Õâ˵Ã÷ÎúÈ«Çò½ðÈÚ¹«Ë¾ÏÖÔÚÃæÁÙµÄÍþвµÄÑÏÖØÐÔºÍÆµÂÊ¡£¡£¡£¡£¡£¡£¡£¡£È«Çò¹æÄ£ÄÚÍøÂç·¸·¨µÄ¼¤ÔöʹµÃĦ¸ù´óͨµÈ»ú¹¹´¦ÓÚ×îǰÏߣ¬£¬ £¬£¬£¬£¬£¬Ö´ÐÐÑÏ¿áµÄÇå¾²²½·¥À´±£»£»£»£»¤Ãô¸ÐµÄ½ðÈÚÐÅÏ¢²¢Î¬»¤ÆäϵͳµÄÍêÕûÐÔ¡£¡£¡£¡£¡£¡£¡£¡£Õâ¼ÒÒøÐÐÒµ¾ÞÍ·Åû¶ÁËÆäÌìÌìÔâÊܵĴó×ںڿ͹¥»÷£¬£¬ £¬£¬£¬£¬£¬Í»ÏÔÁËÍøÂç·¸·¨¸ø½ðÈÚ²¿·Ö´øÀ´µÄÒ»Ö±Éý¼¶µÄÌôÕ½¡£¡£¡£¡£¡£¡£¡£¡£ÕâÖÖÇéÐÎҲ͹ÏÔÁËÍøÂçÇå¾²ÔÚµ±½ñÊý×Ö¾­¼ÃÖÐʩչµÄÒªº¦×÷Óᣡ£¡£¡£¡£¡£¡£¡£


3. ÒÁÀʺڿÍʹÓÃÐ嵀 MediaPl ¶ñÒâÈí¼þÃé×¼´óѧºÍÑо¿»ú¹¹


1ÔÂ17ÈÕ£¬£¬ £¬£¬£¬£¬£¬Î¢ÈíÌåÏÖ£¬£¬ £¬£¬£¬£¬£¬Ò»ÈººÚ¿ÍÕýÔÚÕë¶ÔÅ·ÖÞºÍÃÀ¹úÑо¿»ú¹¹ºÍ´óѧµÄ×ÅÃûÔ±¹¤¾ÙÐÐÓã²æÊ½ÍøÂç¹¥»÷£¬£¬ £¬£¬£¬£¬£¬ÍÆËÍеĺóÃŶñÒâÈí¼þ¡£¡£¡£¡£¡£¡£¡£¡£ÕâЩ¹¥»÷ÕßÊÇÎÛÃûÕÑÖøµÄ APT35£¨Ò²³ÆÎª Charming Kitten ºÍ Phosphorus£©µÄÒ»¸ö×Ó×éÖ¯£¬£¬ £¬£¬£¬£¬£¬ËûÃÇͨ¹ý֮ǰ±»ÈëÇÖµÄÕÊ»§·¢ËͶ¨ÖÆÇÒÄÑÒÔ¼ì²âµÄÍøÂç´¹ÂÚµç×ÓÓʼþ¡£¡£¡£¡£¡£¡£¡£¡£ÔÚÕâ´Î»î¶¯ÖУ¬£¬ £¬£¬£¬£¬£¬Mint Sandstorm ʹÓö¨ÖƵÄÍøÂç´¹ÂÚÓÕ¶ü£¬£¬ £¬£¬£¬£¬£¬ÊÔͼͨ¹ýÉç»á¹¤³ÌÊÖ¶ÎÈÃÄ¿µÄÏÂÔØ¶ñÒâÎļþ¡£¡£¡£¡£¡£¡£¡£¡£MediaPl ¶ñÒâÈí¼þʹÓüÓÃܵÄͨѶͨµÀÓëÆäÏÂÁîºÍ¿ØÖÆ (C2) ЧÀÍÆ÷½»Á÷ÐÅÏ¢£¬£¬ £¬£¬£¬£¬£¬Ö¼ÔÚαװ³É Windows Media Player ÒÔÈÆ¹ý¼ì²â¡£¡£¡£¡£¡£¡£¡£¡£


4. Have I Been Pwned ÔöÌí7100Íò¸öÒѾ­Ð¹Â¶µÄÓʼþÕ˺Å


1ÔÂ17ÈÕ£¬£¬ £¬£¬£¬£¬£¬Have I Been Pwned Òѽ« Naz.API Êý¾Ý¼¯ÖÐÓë±»µÁÕÊ»§Ïà¹ØµÄ½ü 7100 Íò¸öµç×ÓÓʼþµØµãÌí¼Óµ½ÆäÊý¾Ýй¶֪ͨЧÀÍÖС£¡£¡£¡£¡£¡£¡£¡£Naz.API Êý¾Ý¼¯ÊÇʹÓÃײ¿âÁбíºÍÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þÇÔÈ¡µÄÊý¾Ý±àÒë¶ø³ÉµÄ 10 ÒÚ¸öƾ֤µÄÖØ´óÜöÝÍ¡£¡£¡£¡£¡£¡£¡£¡£×²¿âÁбíÊÇ´Ó֮ǰµÄÊý¾Ýй¶ÊÂÎñÖÐÇÔÈ¡µÄµÇ¼ÃûºÍÃÜÂë¶ÔµÄÜöÝÍ£¬£¬ £¬£¬£¬£¬£¬ÕâЩÊý¾Ýй¶ÊÂÎñÓÃÓÚÆÆËðÆäËüÍøÕ¾ÉϵÄÕÊ»§¡£¡£¡£¡£¡£¡£¡£¡£±»µÁÊý¾Ý±»ÍøÂçÔÚÎı¾ÎļþºÍͼÏñÖУ¬£¬ £¬£¬£¬£¬£¬ÕâЩÎļþ´æ´¢ÔÚ³ÆÎª¡°ÈÕÖ¾¡±µÄµµ°¸ÖС£¡£¡£¡£¡£¡£¡£¡£È»ºó£¬£¬ £¬£¬£¬£¬£¬ÕâЩÈÕÖ¾»áÉÏ´«µ½Ô¶³ÌЧÀÍÆ÷£¬£¬ £¬£¬£¬£¬£¬ÒԱ㹥»÷ÕßÉÔºóÍøÂç¡£¡£¡£¡£¡£¡£¡£¡£ÎÞÂÛÆ¾Ö¤ÔõÑù±»µÁ£¬£¬ £¬£¬£¬£¬£¬ËüÃǶ¼»á±»ÓÃÀ´ÆÆËðÊܺ¦ÕßÓµÓеÄÕÊ»§£¬£¬ £¬£¬£¬£¬£¬³öÊÛ¸øÍøÂç·¸·¨Êг¡ÉÏµÄÆäËûÍþвÐÐΪÕߣ¬£¬ £¬£¬£¬£¬£¬»òÔÚºÚ¿ÍÂÛ̳ÉÏÃâ·ÑÐû²¼ÒÔÔÚºÚ¿ÍÉçÇøÖлñµÃÉùÓþ¡£¡£¡£¡£¡£¡£¡£¡£


5. ¿¨°Í˹»ùÐû²¼iOS¼ì²âÌØ¹¤Èí¼þµÄ¿ªÔ´¹¤¾ßiShutdown


1ÔÂ17ÈÕ£¬£¬ £¬£¬£¬£¬£¬´ÓÀúÊ·ÉÏ¿´£¬£¬ £¬£¬£¬£¬£¬¼ì²â¶ñÒâÈí¼þÐèÒª¶Ô iPhone ¾ÙÐÐÍêÕû±¸·Ý£¬£¬ £¬£¬£¬£¬£¬È»ºó³¹µ×¼ì²é±¸·ÝÊý¾ÝÊÇ·ñ±£´æÒì³£¡£¡£¡£¡£¡£¡£¡£¡£È»¶ø£¬£¬ £¬£¬£¬£¬£¬¿¨°Í˹»ùÏÖÔÚÉè¼ÆÁËÒ»ÖÖ¸ü¼ò»¯µÄÒªÁ죬£¬ £¬£¬£¬£¬£¬ÃûΪ¡°iShutdown¡±¡£¡£¡£¡£¡£¡£¡£¡£¿£¿£¿£¿¨°Í˹»ùÒѾ­Ðû²¼ÁËiShutdown ÊÇÒ»¸ö¿ªÔ´¾ç±¾£¬£¬ £¬£¬£¬£¬£¬Ö¼ÔÚ¿ìËÙ¼ì²â iOS ×°±¸ÖеÄÊÇ·ñÑ¬È¾ÌØ¹¤Èí¼þ¡£¡£¡£¡£¡£¡£¡£¡£Õâ¸öÃûΪ shutdown.log µÄÈÕÖ¾Îļþ³ÉΪ¿¨°Í˹»ù¶ÔÒÔÉ«ÁÐÌØ¹¤Èí¼þ¿ª·¢ÉÌ£¨°üÀ¨ NSO Group µÄ Pegasus¡¢QuaDream µÄ Reign ºÍ Intellexa µÄ Predator£©Ñо¿µÄ½¹µã¡£¡£¡£¡£¡£¡£¡£¡£·¢Ã÷ÕâÐ©ÌØ¹¤Èí¼þ³ÌÐòµÄ¹²ÐÔ¡£¡£¡£¡£¡£¡£¡£¡£¾­³£ÖØÐÂÆô¶¯ iPhone µÄÓû§¸üÓпÉÄÜÊÓ²ìÈÕÖ¾ÖеÄÏà¹ØÌõÄ¿¡£¡£¡£¡£¡£¡£¡£¡£Òò´Ë£¬£¬ £¬£¬£¬£¬£¬ÌáÈ¡ shutdown.log Îļþ×ãÒÔÆÊÎö iPhone ÊÇ·ñÊܵ½Ìع¤Èí¼þµÄΣº¦¡£¡£¡£¡£¡£¡£¡£¡£


6. ColdRiver APTÐû²¼¶¨ÖưæºóÃŶñÒâÈí¼þSpica


1ÔÂ19ÈÕ£¬£¬ £¬£¬£¬£¬£¬ ColdRiver µÄ¸ß¼¶Ò»Á¬Íþв (APT) ÒÑÉîÈë¶¨ÖÆ¶ñÒâÈí¼þÁìÓò£¬£¬ £¬£¬£¬£¬£¬ÍƳöÁËÃûΪSpicaµÄרÓкóÃÅ¡£¡£¡£¡£¡£¡£¡£¡£ColdRiver£¨ÓÖÃû Blue Charlie¡¢Callisto¡¢Star Blizzard »ò UNC4057£©Í¨³£ÒÔ·ÇÕþ¸®×éÖ¯¡¢Ç°Ç鱨ºÍ¾üʹÙÔ±ÒÔ¼°±±Ô¼Õþ¸®ÎªÄ¿µÄ¾ÙÐÐÍøÂçÌØ¹¤»î¶¯¡£¡£¡£¡£¡£¡£¡£¡£µ±Ä¿µÄ²»¿É×èÖ¹µØ»ØÓ¦ËµËûÃÇÎÞ·¨¶ÁÈ¡¼ÓÃÜÎĵµÊ±£¬£¬ £¬£¬£¬£¬£¬ColdRiver »á·¢ËÍÒ»¸öÁ´½Ó£¬£¬ £¬£¬£¬£¬£¬ÇÉÃîµØÉù³Æ¿ÉÒÔͨÍù¡°½âÃÜ¡±ÊÊÓóÌÐò¡ª¡ªËäÈ»£¬£¬ £¬£¬£¬£¬£¬ÕâÏÖʵÉÏÊÇ Spica ¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¡£¡£¡£Ò»µ©Ö´ÐУ¬£¬ £¬£¬£¬£¬£¬Spica ¾Í»á·­¿ªÒ»¸öËùν¡°ÒѽâÂ롱µÄ PDF ×÷ΪÓÕ¶ü£¬£¬ £¬£¬£¬£¬£¬Í¬Ê±ÇÄÇĵؽ¨É賤ÆÚÐÔ²¢ÓëÆäÏÂÁîºÍ¿ØÖÆÐ§ÀÍÆ÷ (C2) ÅþÁ¬¡£¡£¡£¡£¡£¡£¡£¡£