MiraiбäÖÖÀûÓÃCVE-2024-3721·ì϶½Ù³ÖTBK DVRÉ豸
°ä²¼¹¦·ò 2025-06-091. MiraiбäÖÖÀûÓÃCVE-2024-3721·ì϶½Ù³ÖTBK DVRÉ豸
6ÔÂ8ÈÕ£¬£¬Mirai¶ñÒâÈí¼þ½©Ê¬ÍøÂç³öÏÖбäÖÖ£¬£¬ÕýÀûÓÃTBK DVR-4104ºÍDVR-4216Êý×ÖÊÓÆµÂ¼ÖÆÉ豸ÖеĺÅÁî×¢Èë·ì϶½øÐнٳ֡£¸Ã·ì϶±àºÅΪCVE-2024-3721£¬£¬Óɰ²È«×êÑÐÔ±¡°netsecfish¡±ÓÚ2024Äê4ÔÂÅû¶£¬£¬Æä¸ÅÄîÑéÖ¤£¨PoC£©ÒÔÏòÒ×Êܹ¥»÷¶Ëµã·¢ËÍÌØÖÆPOSTÒªÇóµÄ´ó¾Ö³öÏÖ£¬£¬Í¨¹ý°Ñ³ÖmdbºÍmdc²ÎÊýʵÏÖshellºÅÁîÖ´ÐС£¿¨°Í˹»ù»ã±¨³Æ£¬£¬ÔÚÆäLinuxÃÛ¹ÞÖз¢ÏÖÁËÀ´×ÔÐÂMirai½©Ê¬ÍøÂç±äÖֶԸ÷ì϶µÄ×Ô¶¯ÀûÓ᣹¥»÷ÕßÀûÓô˷ì϶ֲÈëARM32¶ñÒâÈí¼þ¶þ½øÖÆÎļþ£¬£¬¸ÃÎļþÓëºÅÁîºÍ½ÚÖÆ£¨C2£©·þÎñÆ÷³ÉÁ¢Í¨Ñ¶£¬£¬½«É豸²ÎÓë½©Ê¬ÍøÂçȺ£¬£¬Ö®ºóÉ豸¿ÉÄܱ»ÓÃÓÚÉ¢²¼Ê½»Ø¾ø·þÎñ£¨DDoS£©¹¥»÷¡¢¡¢¡¢´úÀí¶ñÒâÁ÷Á¿µÈÐÐΪ¡£Ö»¹ÜnetsecfishÈ¥Äê»ã±¨Ô¼114,000̨¶³öÔÚ»¥ÁªÍøÉϵÄDVRÒ×Êܸ÷ì϶¹¥»÷£¬£¬µ«¿¨°Í˹»ùɨÃèÏÔʾ¶³öÉ豸Լ50,000̨£¬£¬ÊýÁ¿ÈÔÏ൱¿É¹Û¡£¿¨°Í˹»ùÒÔΪ£¬£¬Óë×îÐÂMirai±äÖÖÓйصĴóÎÞÊýϰȾӰÏìÁËÖйú¡¢¡¢¡¢Ó¡¶ÈµÈ¶à¸ö¹ú¶È£¬£¬²»ÍâÕâÒ»Êý¾Ý»ùÓÚÆäÒ£²âÊý¾Ý£¬£¬¿ÉÄÜÎÞ·¨ÕýÈ··´Ó³½©Ê¬ÍøÂçÖ¸±ê¶¨Î»¡£Ä¿Ç°Éв»Ã÷ÏÔ¹©¸øÉÌTBK VisionÊÇ·ñÒѰ䲼°²È«¸üÐÂÐÞ¸´¸Ã·ì϶¡£´ËÍ⣬£¬DVR-4104ºÍDVR-4216ÒÑ¿í·º¸ÄÃûΪ¶à¸öÆ·ÅÆ£¬£¬ÊÜÓ°ÏìÉ豸²¹¶¡¿ÉÓÃÐÔ¸´ÔÓ¡£
https://www.bleepingcomputer.com/news/security/new-mirai-botnet-infect-tbk-dvr-devices-via-command-injection-flaw/
2. ÷è÷ëÀÕË÷Èí¼þÀûÓöà¸öFortiGate·ì϶ÌáÒé¹¥»÷
6ÔÂ6ÈÕ£¬£¬Íþвµý±¨¹«Ë¾PRODAFTÖҸ棬£¬2025Äê5ÔÂÖÁ6ÔÂÆÚ¼ä£¬£¬÷è÷ëÀÕË÷Èí¼þ£¨±ðÃûPhantom Mantis£©×éÖ¯ÀûÓöà¸öFortiGate·ì϶£¨Ô̺¬CVE-2024-21762ºÍCVE-2024-55591£©¶Ô¶à¸ö×éÖ¯ÌáÒé¹¥»÷¡£¸Ã×éÖ¯ÖÁÉÙ×Ô2022Äê8ÔÂÆð»îÔ¾£¬£¬2024Äê6ÔÂÒò¹¥»÷Ó¢¹úµ±¾ÖÒ½ÁÆ·þÎñÌṩÉÌSynnovis¶øÊܹØ×¢£¬£¬Í¨³£Ñ¡È¡¡°Ë«ÖØÀÕË÷¡±¼¿Á©¡£Ä¿Ç°£¬£¬ÆäÕýÀûÓÃFortiGate·ì϶¹¥»÷Î÷°àÑÀÓï¹ú¶È×éÖ¯£¬£¬ÇÒ¿ÉÄܽ«¹¥»÷ÁìÓòÀ©´óµ½È«Çò£¬£¬ÇÒ¸üÆ«²îÓÚËæ»úÑ¡ÔñÊܺ¦Õß¡£2024Äê2Ô£¬£¬FortinetÖÒ¸æFortiOS SSL VPNÖеÄCVE-2024-21762·ì϶ÔÚÒ°ÍâÒѱ»»ý¼«ÀûÓ㬣¬CISAÒѽ«ÆäÔö³¤µ½KEVĿ¼ÖС£2025Äê3Ô£¬£¬Forescout Research - Vedere Labs»ã±¨³Æ£¬£¬1ÔÂÖÁ3ÔÂÆÚ¼ä£¬£¬ÍþвÐÐΪÕßÀûÓÃFortinetµÄÁ½¸ö·ì϶²¿ÊðÁËSuperBlackÀÕË÷Èí¼þ£¬£¬¹é×ïÓÚÃûΪ¡°Mora_001¡±µÄÍþвÐÐΪÕߣ¬£¬Æä¿ÉÄÜÓëLockBitÉú̬ϵͳÓйء£´ËÍ⣬£¬CISAÈ·ÈÏ·ì϶CVE-2025-24472Òѱ»ÓÃÓÚÀÕË÷Èí¼þ»î¶¯¡£·ì϶CVE-2024-55591ÊÇÒ»¸öÀûÓñ¸ÓÃõè¾¶»òͨµÀÈÆ¹ýÉí·ÝÑéÖ¤µÄ·ì϶£¬£¬Ó°ÏìFortiOSºÍFortiProxy¶à¸ö°æ±¾£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õßͨ¹ý¾«ÐÄÉè¼ÆµÄÒªÇó»ñÈ¡³¬µÈÖÎÀíԱȨÏÞ£¬£¬ÇÒÒÑÓл㱨ÏÔʾ¸Ã·ì϶ÕýÔÚ±»¿í·ºÀûÓá£
https://securityaffairs.com/178736/hacking/attackers-exploit-fortinet-flaws-to-deploy-qilin-ransomware.html
3. Optima Tax ReliefÔâChaosÀÕË÷Èí¼þ¹¥»÷
6ÔÂ6ÈÕ£¬£¬ÃÀ¹ú³ÛÃû˰Îñ½â¾öºÍ½áË㹫˾Optima Tax Relief½üÈÕÔâ·êÁËChaosÀÕË÷Èí¼þ¹¥»÷£¬£¬ÍþвÐÐΪÕßÒѽ«ÇÔÈ¡µÄÊý¾Ýй¶¡£Optima Tax Relief×Ô³ÆÊÇÃÀ¹úµ±ÏȵÄ˰Îñ½â¾ö¹«Ë¾£¬£¬ÒÑΪ¿Í»§½â¾ö³¬30ÒÚÃÀԪ˰ÎñÔðÈΡ£Õâ´ÎChaosÀÕË÷Èí¼þÍŻォOptima Tax ReliefÔö³¤µ½ÆäÊý¾ÝÐ¹Â¶ÍøÕ¾£¬£¬Ðû³ÆÇÔÈ¡ÁË69GBÊý¾Ý£¬£¬ÕâЩÊý¾ÝËÆºõÔ̺¬¹«Ë¾Êý¾ÝºÍ¿Í»§°¸ÀýÎļþ¡£¼øÓÚ˰ÎñÎļþͨ³£Ô̺¬Éç±£º£ºÅÂë¡¢¡¢¡¢µç»°ºÅÂëºÍ¼ÒͥסַµÈÃô¸ÐСÎÒÐÅÏ¢£¬£¬ÕâЩÐÅÏ¢Ò»µ©Ð¹Â¶£¬£¬¿ÉÄܱ»ÆäËûÍþвÐÐΪÕßÓÃÓÚ¶ñÒâ»î¶¯»òÉí·Ý͵ÇÔ£¬£¬¶ÔСÎÒºÍÆóÒµ×é³ÉÑÏÖØÍþв¡£ÓÐÐÂÎÅÈËʿй©£¬£¬ÕâÊÇÒ»´ÎË«ÖØÀÕË÷¹¥»÷£¬£¬ÍþвÐÐΪÕß²»½öÇÔÈ¡Á˹«Ë¾Êý¾Ý£¬£¬»¹¶Ô·þÎñÆ÷½øÐÐÁ˼ÓÃÜ¡£ChaosÀÕË÷Èí¼þÊÇÒ»ÖÖÏà¶Ô½ÏеÄÀÕË÷Èí¼þ²Ù×÷£¬£¬ÓÚ2025Äê3ÔÂÆô¶¯£¬£¬ÆäʱÆäÊý¾ÝÐ¹Â¶ÍøÕ¾ÉÏÓÐÎåÃûÊܺ¦Õß¡£Ðè°ÑÎȵÄÊÇ£¬£¬²»Òª½«¸ÃÀÕË÷Èí¼þÍÅ»ïÓë×Ô2021ÄêÆð¾ÍÒÑ´æÔÚµÄChaosÀÕË÷Èí¼þ¹¹½¨Æ÷»ìºÏ£¬£¬ºóÕßÓÃÓÚ´´½¨´óÁ¿Æ·ÅƼÓÃÜÆ÷ÒÔ½øÐÐÍøÂç´¹µöºÍ¶ñÒâÈí¼þ»î¶¯¡£
https://www.bleepingcomputer.com/news/security/tax-resolution-firm-optima-tax-relief-hit-by-ransomware-data-leaked/
4. ÐÂÐÍPathWiperÊý¾Ý²Á³ýÈí¼þÏ®»÷ÎÚ¿ËÀ¼¹Ø¼ü»ù´¡ÉèÊ©
6ÔÂ6ÈÕ£¬£¬Ò»ÖÖÃûΪ¡°PathWiper¡±µÄÐÂÐÍÊý¾Ý²Á³ý¶ñÒâÈí¼þÕý±»ÓÃÓÚÕë¶ÔÎÚ¿ËÀ¼¹Ø¼ü»ù´¡ÉèÊ©µÄ¹¥»÷£¬£¬ÆäÖ÷ÕÅÔÚÓÚ·ÛËé¸Ã¹úÔËÓª¡£¸Ã¶ñÒâÈí¼þµÄÓÐÐ§ÔØºÉͨ¹ýºÏ·¨¶ËµãÖÎÀí¹¤¾ß²¿Ê𣬣¬Åú×¢¹¥»÷ÕßÒÑͨ¹ýÏÈǰ¹¥»÷»ñȡϵͳÖÎÀí½Ó¼ûȨÏÞ¡£Ë¼¿ÆTalos×êÑÐÈËÔ±¸ß¶È×¢¶¨µØ½«Õâ´Î¹¥»÷¹é×ïÓÚÓë¶íÂÞ˹Óйصĸ߼¶³ÖÐøÐÔÍþв£¨APT£©£¬£¬²¢Ö¸³öPathWiper¿ÉÄÜÊÇ´ËǰÔÚÎÚ¿ËÀ¼²¿ÊðµÄHermeticWiperµÄÑݱ䣬£¬ÓÃÓÚÒ»Ñù»òÖØµþÍþв¼¯ÈºµÄ¹¥»÷¡£PathWiperͨ¹ýWindowsÅú´¦ÖÃÎļþÖ´ÐУ¬£¬Æô¶¯¶ñÒâVBScript£¬£¬½ø¶øÉ¾³ý²¢Ö´ÐÐÖØÒªÓÐÐ§ÔØºÉ£¬£¬ÆäÖ´Ðз½Ê½·ÂÕպϷ¨ÖÎÀí¹¤¾ßÐÐΪÒÔÌӱܼì²â¡£ÓëHermeticWiper·ÖÆç£¬£¬PathWiperÒÔ±à³Ì·½Ê½¼ø±ðϵͳÉÏËùÓÐÏνӵÄÇý¶¯Æ÷£¬£¬ÀÄÓÃWindows APIÐ¶ÔØ¾í£¬£¬²¢ÎªÃ¿¸ö¾í´´½¨Ï̸߳²¸Ç¹Ø¼üNTFS½á¹¹£¬£¬Ô̺¬MBR¡¢¡¢¡¢MFT¡¢¡¢¡¢LogFile¡¢¡¢¡¢$BootµÈÎļþ£¬£¬µ¼ÖÂϵͳÆëÈ«ÎÞ·¨ÔËÐС£Õâ´Î¹¥»÷²»Éæ¼°ÀÕË÷»ò²ÆÕþÒªÇ󣬣¬Î¨Ò»Ö÷ÕÅÊÇ·ÛËéºÍÖжÏÔËÓª¡£Cisco TalosÒѰ䲼Îļþ¹þÏ£º£ºÍSnort¹æ¶¨£¬£¬ÒÔÔ®ÊÖ¼ì²âÍþв²¢ÔÚÆä·ÛËéÇý¶¯Æ÷֮ǰ×èÖ¹¡£×ÔÕ½ÕùÆðÍ·ÒÔÀ´£¬£¬Êý¾Ý²Á³ýÆ÷ÒѳÉΪ¹¥»÷ÎÚ¿ËÀ¼µÄÓÐÁ¦¹¤¾ß£¬£¬¶íÂÞ˹ÍþвÐÐΪÕ߯µÈÔʹÓÃËüÃÇ·ÛËé¸Ã¹ú¹Ø¼üÐж¯£¬£¬´ËǰÒÑÓжàÖÖ²Á³ýÆ÷±»ÓÃÓÚ´ËÀ๥»÷¡£
https://www.bleepingcomputer.com/news/security/new-pathwiper-data-wiper-malware-hits-critical-infrastructure-in-ukraine/
5. Ӣ˰Îñº£¹Ø×ÜÊðÔâ´¹µö¹¥»÷£¬£¬Ëðʧ4700ÍòÓ¢°÷
6ÔÂ5ÈÕ£¬£¬Ó¢¹ú˰Îñº£¹Ø×ÜÊð£¨HMRC£©½üÈÕÅû¶£¬£¬·¸×ïÍÅ»ïͨ¹ý´¹µö¼¿Á©µÁÓó¬¹ý10Íò¸öÄÉ˰ÈËÕË»§£¬£¬²¢ÀûÓÃÕâЩÕË»§Ìá½»ÐéαÍË˰ÉêÇ룬£¬·¸·¨ÌáÈ¡ÁË4700ÍòÓ¢°÷£¨Ô¼ºÏ6400ÍòÃÀÔª£©×ʽð¡£HMRCÊ×ϯִÐйÙÔ¼º²-±£ÂÞ¡¤Âí¿Ë˹ÏòÒé»á²ÆÕþίԱ»á°µÊ¾£¬£¬´ËÊÂÎñÔ´ÓÚ¹¥»÷Õßͨ¹ý´¹µö»î¶¯»òÍⲿÊý¾Ýй¶»ñȡСÎÒÐÅÏ¢£¬£¬¶ø·ÇHMRCϵͳÔâµ½ÈëÇÖ¡£ÊÜÓ°ÏìµÄÄÉ˰È˽«ÔÚÈýÖÜÄÚÊÕµ½Í¨ÖªÐꝣ¬£¬ÆäÕË»§Òѱ»Ò»Ê±Ëø¶¨²¢¶Ï¸ùÒì³£µÇ¼ÐÅÏ¢¡£Âí¿Ë˹ǿµ÷£¬£¬ÊÜÓ°ÏìµÄÄÉ˰È˲»»á³Ðµ£¾¼ÃËðʧ£¬£¬HMRCÒÑ´Ó˰Îñ¼Í¼ÖÐɾ³ýÃýÎóÉ걨ÐÅÏ¢¡£Êý¾ÝÏÔʾ£¬£¬HMRCÈ¥Äê³É¹¦À¹½ØÁË·¸×ï·Ö×ÓÊÔͼÇÔÈ¡µÄ19ÒÚÓ¢°÷×ʽ𣬣¬ÏÖʵËðʧ½ð¶î½öÕ¼¹¥»÷×ܶîµÄ2.5%¡£HMRC¸±Ê×ϯִÐйٰ²¼ªÀ¡¤Âó¿ËÌÆÄÉÖ¸³ö£¬£¬Ú¿ÆÕßÀûÓñ»µÁÉí·ÝÐÅÏ¢´´½¨»ò½Ù³ÖÔÚÏßÕË»§£¬£¬Í¨¹ý¸ß¶È×éÖ¯»¯µÄ·¸×ïÍøÂçÖ´ÐÐڲơ£Ö»¹Üµ±¾Öδй©¾ßÌå¹¥»÷ÊÖ·¨£¬£¬µ«ÍøÂ簲ȫר¼Ò´§Ä¦¿ÉÄÜÉæ¼°ÐÅÏ¢ÇÔÈ¡Èí¼þϰȾ»òÉ繤¹¥»÷¡£Ä¿Ç°ÓйØÐÌʵ÷²éÈÔÔÚ½øÐУ¬£¬²¿ÃÅÏÓÒÉÈËÒÑÓÚÈ¥Äê±»¿ÛÁô¡£HMRCÕýÓë·¨Âɲ¿ÃźÏ×÷×·»Ø±»µÁ×ʽ𣬣¬²¢½¨ÒéÄÉ˰È˾¯Ìè¿ÉÒÉÓʼþ¡¢¡¢¡¢¶ÌÐż°µç»°£¬£¬Ô¤·ÀÔڷǹٷ½ÇþµÀÌá½»Ãô¸ÐÐÅÏ¢£¬£¬ÒÔÔ¤·ÀСÎÒÐÅϢй¶ºÍÔâ·êÚ¿Æ¡£
https://therecord.media/uk-hmrc-tax-authority-scammers-stole-47million-pounds
6. GlueStack×é¼þÔ⹩¸øÁ´¹¥»÷£¬£¬¶à¶ñÒâÈí¼þ°üÏÖÉí
6ÔÂ8ÈÕ£¬£¬½üÆÚ£¬£¬ÍøÂ簲ȫÁìÓò²úÉú¶àÆðÕë¶ÔÈí¼þ¹©¸øÁ´µÄ¶ñÒâ¹¥»÷ÊÂÎñ¡£ÍøÂ簲ȫ×êÑÐÈËÔ±·¢ÏÖÕë¶ÔGlueStackÓйØ×é¼þµÄ¹©¸øÁ´¹¥»÷£¬£¬³¬¹ý12¸öÈí¼þ°ü±»Ö²Èë¶ñÒâ´úÂ룬£¬¹¥»÷Õßͨ¹ý´Û¸ÄÎļþ×¢Èë¶ñÒⷨʽ£¬£¬¿ÉÖ´ÐÐshellºÅÁî¡¢¡¢¡¢½ØÈ¡ÆÁÄ»½ØÍ¼²¢ÉÏ´«ÊÜϰȾÉ豸Îļþ£¬£¬ÕâЩÈí¼þ°üÖÜÏÂÔØÁ¿¼ÆËã½ü100Íò´Î¡£Î´ÊÚȨ½Ó¼ûȨÏ޿ɱ»ÓÃÓÚ¼ÓÃÜÇ®±ÒÍڿ󡢡¢¡¢ÇÔÈ¡Ãô¸ÐÐÅÏ¢µÈºóÐø¹¥»÷¡£Í¬Ê±£¬£¬°²È«»ú¹¹Socket·¢ÏÖÁ½¸ö¼Ù×°³ÉºÏ·¨¹¤¾ßµÄ¶ñÒânpm°ü¡ª¡ªexpress-api-syncºÍsystem-health-sync-api£¬£¬Ç°Õ߿ɵݹéɾ³ýµ±Ç°Ä¿Â¼ËùÓÐÎļþ£¬£¬ºóÕß¼æ¾ßÐÅÏ¢ÇÔÈ¡Óë·ÛËéÖ°ÄÜ£¬£¬ÇÒͨ¹ýÓʼþΪÒñ±ÎͨѶÐŵÀ£¬£¬¹¥»÷Õß¿Éͨ¹ýÌØ¶¨¶Ëµã´¥·¢·ÛËéºÅÁî¡£´ËÍ⣬£¬Èí¼þ¹©¸øÁ´°²È«¹«Ë¾»¹ÔÚPython°üË÷Òý£¨PyPI£©·¢ÏÖÃûΪimad213µÄƾ֤ÇÔÈ¡·¨Ê½£¬£¬¸Ã·¨Ê½¼ÙÒâInstagramÕÇ·Û¹¤¾ß£¬£¬ÓÕµ¼Óû§ÊäÈëInstagramƾ֤£¬£¬Ëæºó½«Æ¾Ö¤·¢ËÍÖÁ10¸öµÚÈý·½»úеÈË·þÎñ¡£¹¥»÷ÕßͬÆÚ»¹ÉÏ´«ÁËtaya¡¢¡¢¡¢a-b27¡¢¡¢¡¢poppo213µÈÆäËû¶ñÒâÈí¼þ°ü£¬£¬±ðÀëÓÃÓÚÇÔÈ¡¶àÖÖÉ罻ýÌ対֤ºÍ·¢ÆðDDoS¹¥»÷¡£¹¥»÷ÕßÔÚGitHubÎĵµÖÐÐû³ÆÆä¿â¡°½öÓÃÓÚ½ÌÓý×êÑС±£¬£¬ÊµÎªÖÆ×÷Ðéα°²È«¸Ð¡£
https://thehackernews.com/2025/06/new-supply-chain-malware-operation-hits.html


¾©¹«Íø°²±¸11010802024551ºÅ