BuyGoodsÉèÖùýʧй¶198GBÄÚ²¿Êý¾ÝºÍÓû§ÐÅÏ¢
Ðû²¼Ê±¼ä 2024-01-261ÔÂ24ÈÕ£¬ÍøÂçÇå¾²Ñо¿Ô± Jeremiah Fowler ×î½ü·¢Ã÷ÁËÒ»¸öÉèÖùýʧµÄÔÆÊý¾Ý¿â£¬µ¼Ö´ó×ÚÃô¸ÐÊý¾Ý̻¶¡£ÊÜÓ°ÏìµÄÊý¾Ý¿â°üÀ¨¹éÊôÓÚBuyGoods.com¡£Ì»Â¶µÄÊý¾Ý¿â¾Þϸ×Ü¼Æ 198.3 GB£¬È±·¦ÈκÎÐÎʽµÄÇå¾²ÈÏÖ¤£¬¿É¹©¹«ÖÚ¹ûÕæ»á¼û¡£Õâ¸öδÊܱ£»¤µÄÊý¾Ý¿âÖÐÓÐÁè¼Ý 260,000 Ìõ¼Í¼£¬°üÀ¨ÖÜÈ«µÄÐÅÏ¢¡£Õâ°üÀ¨ÓйØÁªÓª¹«Ë¾¸¶¿î¡¢ÍË¿îÉúÒâ¡¢·¢Æ±¡¢»á¼Æ¼Í¼ºÍÖÖÖÖÆäËûÐÎʽµÄÊý¾ÝµÄÏêϸÐÅÏ¢¡£¸üÔã¸âµÄÊÇ£¬Ì»Â¶µÄ·þÎñÆ÷»¹Ì»Â¶ÁË¿Í»§ºÍÁ¥Êô¹«Ë¾µÄСÎÒ˽¼Ò¼Í¼£¬ÆäÖаüÀ¨¸ß¶ÈÃô¸ÐµÄСÎÒ˽¼ÒÉí·ÝÐÅÏ¢£¨PII£©ºÍÏàʶÄãµÄ¿Í»§£¨KYC£©Êý¾Ý¡£ÕâЩ̻¶µÄÐÅÏ¢°üÀ¨¿Í»§µÄ×ÔÕÕÏàÒÔ¼°ËûÃǵÄСÎÒ˽¼ÒÉí·ÝÖ¤¡¢Ö´ÕÕ¡¢»¤ÕÕ£¬ÉõÖÁδ¾±à¼µÄÐÅÓÿ¨ÏêϸÐÅÏ¢¡£´Ë´ÎÒþ˽й¶ÊÂÎñµÄÈ«ÇòÓ°Ïì¿ÉÄÜÊÇÖØ´óµÄ£¬ÓÉÓÚÕâЩ¼Í¼Éæ¼°À´×ÔÌìϸ÷µØµÄСÎÒ˽¼Ò¡£
2. »ÝÆÕÏòÃÀ¹úî¿Ïµ»ú¹¹Åû¶ÆäÔâµ½Cozy BearµÄÈëÇÖ
1ÔÂ25ÈÕ£¬ÊÖÒÕÖÆÔìÉÌ»ÝÆÕÆóÒµ¹«Ë¾ (HPE) ÖÜÈýÌåÏÖ£¬ÒÉËÆÓë¶íÂÞ˹Õþ¸®ÓÐÁªÏµµÄºÚ¿Í½øÈëÁ˸ù«Ë¾»ùÓÚÔƵĵç×ÓÓʼþÇéÐΡ£ÓëCozy Bear£¨Ò²³ÆΪ Midnight Blizzard£©ÓйصĺڿÍÒѾÇÖÈëÆäÍøÂ磬²¢ÆÆ·ÑÊýÔÂʱ¼äÇÔÈ¡Êý¾Ý¡£¸Ã¹«Ë¾Ã»ÓлØÓ¦ÓйØË֪ͨËûÃÇÕâÒ»ÊÂÎñµÄÖÃÆÀÇëÇó¡£¹¥»÷Ô˶¯´Ó 2023 Äê 5 ÔÂ×îÏÈ£¬¸Ã×éÖ¯Ö÷Òª±»³ÆΪ APT29£¬¾ÝÐÅÊǶíÂÞ˹¶ÔÍâÇ鱨¾Ö (SVR) µÄÒ»²¿·Ö£¬ÈÏÕæÍâ¹úÌع¤Ô˶¯ºÍµç×Ó¼àÊÓ¡£ÕâЩºÚ¿ÍÊǶíÂÞ˹¶ÔÃÀ¹úһЩ×î¾ßÆÆËðÐԵĹ¥»÷µÄÄ»ºóºÚÊÖ£¬°üÀ¨ 2020 Äê SolarWinds ºÚ¿Í¹¥»÷ºÍ 2016 Äê¶ÔÃñÖ÷µ³ÌìÏÂίԱ»áµÄ¹¥»÷¡£
3. Arctic Wolf LabsÆعâÓÃGo¿ª·¢µÄCherryLoader
1ÔÂ24ÈÕ£¬CherryLoader Åû×ÅÎÞ¹¼µÄÍâÒ¾ÙÐÐÓÕÆ£¬Î±×°³ÉÕýµ±µÄ CherryTree Ìõ¼ÇÓ¦ÓóÌÐò¡£È»¶ø£¬ÔÚÕâ¸öÍâ±íÖ®ÏÂÒþ²Ø×ÅÒ»¸ö½ÆÕ©¶øΣÏյŤ¾ß£¬Ö¼ÔÚÒÔ¾ªÈ˵ÄЧÂÊÉø͸ϵͳ¡£Í¨¹ýʹÓà Go µÄÇ¿Ê¢¹¦Ð§£¬CherryLoader ÒýÈëÁ˶ñÒâÈí¼þÏÂÔØÆ÷ÖÐÒÔǰδÔø¼û¹ýµÄÄ£¿é»¯Ë®Æ½ºÍÎÞаÐÔ£¬Ê¹¹¥»÷ÕßÄܹ»½»Á÷Îó²î¶øÎÞÐèÖØбàÒë¡£CherryLoader µÄ¹¥»÷Á´¼ÈÖØ´óÓÖÓÐÓá£×î³õ£¬Êܺ¦Õß´ÓÌض¨µÄ IP µØµãÎüÊÕ¶ñÒâÈí¼þ£¬µ¼ÖÂÏÂÔØÁ½¸öÎļþ£ºÒ»¸öÊÜÃÜÂë±£»¤µÄ RAR ÎļþºÍÒ»¸öÈÏÕæ½âѹ RAR ÄÚÈݵĿÉÖ´ÐÐÎļþ¡£½âѹºóµÄÄÚÈÝÏÔʾÁËÒ»¸ö Golang ¶þ½øÖÆÎļþÒÔ¼°ÆäËûÎļþ£¬ÕâЩ¶¼ÊǼÓÔسÌÐò¹¤¾ß°üµÄÒ»²¿·Ö£¬Ö¼ÔÚͨ¹ý°þÀë¶þ½øÖÆÎļþºÍÆÆËðµ¼ÈëµØµã±íµÈÊÖÒÕÀ´×è°ÆÊÎöÊÂÇé¡£CherryLoader µÄÖ´ÐÐÉæ¼°Ò»¸ö¶à°ì·¨Àú³Ì£¬´ÓÃÜÂë¼ì²é×îÏÈ£¬È»ºóʹÓüòÆ XOR Ëã·¨½âÃÜǶÈëÎļþ¡£ÖµµÃ×¢ÖصÄÊÇ£¬¸Ã½âÃÜÀú³Ì²»ÒÀÀµÓÚÊäÈëµÄÃÜÂ룬ÕâÌåÏÖÆäÖ÷Òª×÷ÓÃÊÇ×èÖ¹ÆÊÎö¶ø²»ÊÇÇå¾²¡£
4. GKE¼¯ÈºÑÏÖØÎó²îSys:All¿Éµ¼ÖÂ25Íò¸ö¼¯Èº±»¿ØÖÆ
1ÔÂ24ÈÕ£¬ÍøÂçÇå¾²Ñо¿Ö°Ô±·¢Ã÷ÁËÒ»¸öÓ°Ïì Google Kubernetes Engine (GKE) µÄÎó²î£¬ÓµÓÐ Google ÕÊ»§µÄÍþв¼ÓÈëÕß¿ÉÄÜ»áʹÓøÃÎó²îÀ´¿ØÖÆ Kubernetes ¼¯Èº¡£ÔÆÇå¾²¹«Ë¾ Orca½«ÕâÒ»ÑÏÖØȱÏÝ´úºÅΪSys:All ¡£¾ÝÔ¤¼Æ£¬¶à´ï 250,000 ¸ö»îÔ¾µÄ GKE ¼¯ÈºÈÝÒ×Êܵ½¹¥»÷¡£system:authentiated group ÊÇÒ»¸öÌØÊâµÄ×飬°üÀ¨ËùÓоÓÉÉí·ÝÑéÖ¤µÄʵÌ壬°üÀ¨ÈËÀàÓû§ºÍ·þÎñÕÊ»§¡£Òò´Ë£¬µ±ÖÎÀíÔ±ÎÞÒâÖÐÊÚÓèËü¹ýÓÚ¿íËɵĽÇɫʱ£¬¿ÉÄܻᱬ·¢ÑÏÖØЧ¹û¡£Sys:All Òѱ»·¢Ã÷Ó°ÏìÖÚ¶à×éÖ¯£¬µ¼ÖÂÖÖÖÖÃô¸ÐÊý¾Ý̻¶£¬ÀýÈç JWT ÁîÅÆ¡¢GCP API ÃÜÔ¿¡¢AWS ÃÜÔ¿¡¢Google OAuth ƾ֤¡¢Ë½Ô¿ºÍÈÝÆ÷×¢²á±íƾ֤£¬ÆäÖÐ×îºóÒ»¸ö¿ÉÄÜÈ»ºóÓÃÓÚ¶ÔÈÝÆ÷¾µÏñ¾ÙÐÐľÂí»¯¡£ÔÚÏò Google ÈÏÕæÈεØÅû¶ºó£¬¸Ã¹«Ë¾ÒѽÓÄɲ½·¥×èÖ¹½« system:authentiated ×é°ó¶¨µ½ GKE 1.28 ¼°¸ü¸ß°æ±¾ÖÐµÄ cluster-admin ½ÇÉ«¡£
5. ˼¿ÆÐÞ¸´Éæ¼°¶à¸ö²úÆ·µÄRCEÎó²îCVE-2024-20253
1ÔÂ24ÈÕ£¬Ë¼¿ÆÒѾÐÞ¸´ÁËͳһͨѶºÍÁªÂçÖÐÐĽâ¾ö¼Æ»®µÄÒ»¸öÒªº¦Çå¾²Îó²î£¬¸ÃÎó²î¿ÉÄÜÈÃδ¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÔÚÊÜÓ°ÏìµÄ×°±¸ÉÏÖ´ÐÐí§Òâ´úÂë¡£¸ÃÇå¾²Îó²î¹Ù·½±àºÅΪ CVE-2024-20253£¬ÔÚ CVSS ÉϵÄÑÏÖØÆ·¼¶¸ß´ï 9.9¡£CVE-2024-20253 µÄ½¹µãÔÚÓÚÒ»¸öΣÏÕµÄÇå¾²Îó²î£ºÔÚ½«Óû§ÌṩµÄÊý¾ÝÉãÈëÄÚ´æʱ¶ÔÆä¾ÙÐв»µ±´¦Öóͷ£¡£´ËȱÏÝΪδ¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß·¿ªÁË´óÃÅ£¬¿ÉÒÔÖÆ×÷¶ñÒâÐÂÎŲ¢½«Æä·¢Ë͵½Ò×Êܹ¥»÷µÄÉè±¹ØÁ¬ÄÕìÌý¶Ë¿Ú¡£¸ÃÎó²îÓ°ÏìÒÔÏÂĬÈÏÉèÖõÄ˼¿Æ²úÆ·PCCE¡¢Unified CM¡¢UCCEºÍUCCXµÈ¡£
6. Ñо¿ÍŶÓÐû²¼APT10µÄ¶ñÒ⹤¾ßLODEINFOµÄÆÊÎö±¨¸æ
1ÔÂ24ÈÕ£¬ÔÚÊý×ÖÌìϵÄÒõ»Þ½ÇÂ䣬ÍøÂçÇå¾²·ÀÓùÕߺ͹¥»÷ÕßÖ®¼äµÄÕ½¶·Ò»Ö±Ç¿ÁÒµØÕö¿ª£¬Ò»¸öеĵÐÊÖÒѾ·ºÆð£¬ËûÃÇʹÓÃÖØ´óµÄÓÕƺÍÌӱܹ¤¾ß£ºLODEINFO¶ñÒâÈí¼þ¡£ÕâÖÖÎÞÎļþÍþв×Ô 2019 Äê 12 ÔÂÒÔÀ´Ò»Ö±À§ÈÅ×ÅÍøÂç¿Õ¼ä£¬´ú±í×ÅÍøÂç·¸·¨·Ö×ÓÕ½ÂÔµÄÖØ´óת±ä£¬ÌØÊâÊÇÕë¶ÔÈÕ±¾²¿·Ö£¬°üÀ¨Ã½Ìå¡¢Íâ½»¡¢¹«¹²»ú¹¹¡¢¹ú·À¹¤ÒµºÍÖÇ¿âµÄÍøÂç·¸·¨·Ö×ÓÕ½ÂÔµÄÖØ´óת±ä¡£×î½ü£¬ ITOCHU Cyber & Intelligence Inc.µÄÇå¾²Ñо¿Ö°Ô±¡£ÆÊÎöÁË LODEINFO ¶ñÒâÈí¼þµÄÿ¸ö°æ±¾²¢·¢Ã÷ÁËת±ä¡£
LODEINFO ÊÇÎÛÃûÕÑÖøµÄ APT ×éÖ¯ APT10 µÄÏȷ棬չʾÁËÍøÂçÍþвµÄ¾ªÈËÑݱ䡣Ëüͨ¹ý¿´ËÆÎÞº¦µÄÓã²æʽÍøÂç´¹ÂÚµç×ÓÓʼþÉø͸ϵͳ£¬Ê¹ÓöñÒâ Word ÎĵµÀ´Ö´ÐÐÆäа¶ñµÄÒé³Ì¡£×î³õҲʹÓà Excel Îļþ£¬µ«¹¥»÷ÕßË¢ÐÂÁËÒªÁìÒÔÌá¸ßÀÖ³ÉÂÊ¡£