ÐÂÍøÂç´¹ÂÚ¹¤¾ß°ü¡°Xi¨± g¨¯u¡±Òý·¢È«ÇòÇå¾²¾¯±¨
Ðû²¼Ê±¼ä 2024-11-041. ÐÂÍøÂç´¹ÂÚ¹¤¾ß°ü¡°Xi¨± g¨¯u¡±Òý·¢È«ÇòÇå¾²¾¯±¨
11ÔÂ1ÈÕ£¬ÍøÂçÇå¾²ÁìÓò½üÆÚ·ºÆðÁËÒ»ÖÖÃûΪXi¨± g¨¯uµÄÐÂÐÍÍøÂç´¹ÂÚ¹¤¾ß°ü£¬×Ô2024Äê9ÔÂÆðÒÑÕë¶Ô°Ä´óÀûÑÇ¡¢ÈÕ±¾¡¢Î÷°àÑÀ¡¢Ó¢¹úºÍÃÀ¹úµÈ¶à¸ö¹ú¼ÒÌᳫ¹¥»÷¡£¸Ã¹¤¾ß°üÒÑѬȾÁè¼Ý2000¸ö´¹ÂÚÍøÕ¾£¬Ö÷Òª¹¥»÷¹«¹²²¿·Ö¡¢ÓÊÕþ¡¢Êý×Ö·þÎñºÍÒøÐзþÎñµÈ±ÊÖ±ÐÐÒµ¡£NetcraftÖ¸³ö£¬ÕâЩ¹¥»÷Õß³£Ê¹ÓÃCloudflareµÄ·´»úеÈ˺ÍÍйܻìÏý¹¦Ð§À´¹æ±Ü¼ì²â¡£Xi¨± g¨¯uÌṩÖÎÀíÃæ°å£¬Ê¹ÓÃGolangºÍVue.jsµÈÊÖÒÕ£¬Í¨¹ýTelegram´ÓÐéα´¹ÂÚÒ³ÃæÇÔÊØÐÅÏ¢¡£ÕâЩÍøÂç´¹ÂÚ¹¥»÷Ö÷Ҫͨ¹ý¸»Í¨Ñ¶·þÎñ£¨RCS£©ÐÂÎÅÈö²¥£¬ÓÕµ¼Êܺ¦Õßµã»÷Ëõ¶ÌµÄÁ´½ÓÒÔÌṩСÎÒ˽¼ÒÐÅÏ¢»ò¸¶¿î¡£¹È¸èµÈ¿Æ¼¼¾ÞÍ·ÒѽÓÄɲ½·¥¹¥»÷´ËÀàÕ©Æ£¬°üÀ¨ÍƳöÔöÇ¿ÐÍթƼì²â¹¦Ð§ºÍÇå¾²ÖÒÑÔ£¬²¢ÍýÏëÔÚÈ«Çò¹æÄ£ÄÚÍƹãб£»¤²½·¥¡£±ðµÄ£¬Ë¼¿ÆTalosÍŶӷ¢Ã÷£¬Ì¨ÍåµÄFacebookÉÌÒµºÍ¹ã¸æÕÊ»§Óû§Õý³ÉΪÍøÂç´¹ÂÚÔ˶¯µÄÄ¿µÄ£¬Ö¼ÔÚÈö²¥ÇÔÈ¡¶ñÒâÈí¼þ¡£ÕâЩÔ˶¯»¹Ã°³äOpenAIµÈ×ÅÃûÆóÒµ£¬ÓÕµ¼È«ÇòÆóÒµ¸üи¶¿îÐÅÏ¢¡£
https://thehackernews.com/2024/11/new-phishing-kit-xiu-gou-targets-users.html
2. InterlockÀÕË÷Èí¼þ£ºÕë¶ÔFreeBSD·þÎñÆ÷µÄÐÂÐ͹¥»÷Ðж¯
11ÔÂ3ÈÕ£¬InterlockÊÇÒ»¸öÐÂÐ˵ÄÀÕË÷Èí¼þ²Ù×÷£¬×Ô2024Äê9ÔÂβÆô¶¯ÒÔÀ´£¬ÒѶÔÈ«Çò¶à¸ö×éÖ¯Ìᳫ¹¥»÷¡£Ëü½ÓÄÉÒ»ÖÖ²»³£¼ûµÄÒªÁ죬¼´½¨ÉèרÃÅÕë¶ÔFreeBSD·þÎñÆ÷µÄ¼ÓÃÜÆ÷¡£ÕâÖÖ¼ÓÃÜÆ÷ÔÚFreeBSD 10.4ÉϱàÒ룬ֻ¹ÜBleepingComputerµÈÇå¾²»ú¹¹ÔÚÐéÄâ»úÉϲâÊÔʱδÄÜʹÆä׼ȷִÐС£InterlockÔÚ¹¥»÷Àֳɺ󣬻áÔÚδ֧¸¶Êê½ðµÄÇéÐÎÏ£¬ÔÚÆäÊý¾Ýй¶ÍøÕ¾ÉÏÐû²¼±»µÁÊý¾Ý¡£¾ÝÍøÂçÇå¾²¹«Ë¾Ç÷ÊƿƼ¼³Æ£¬InterlockµÄÄ¿µÄÊÇFreeBSD£¬ÓÉÓÚËüÆÕ±éÓ¦ÓÃÓÚ·þÎñÆ÷ºÍÒªº¦»ù´¡ÉèÊ©£¬¹¥»÷Õß¿ÉÒÔÆÆËðÖ÷Òª·þÎñ£¬Ë÷Òª¾Þ¶îÊê½ð¡£±ðµÄ£¬Ç÷ÊƿƼ¼»¹·¢Ã÷Á˸òÙ×÷µÄWindows¼ÓÃÜÆ÷Ñù±¾¡£ÔÚ¼ÓÃÜÎļþʱ£¬Interlock»á½«.interlockÀ©Õ¹Ãû¸½¼Óµ½ËùÓмÓÃÜÎļþÃûºó£¬²¢ÔÚÿ¸öÎļþ¼ÐÖн¨ÉèÀÕË÷¼Í¼¡£±»µÁÊý¾Ý±»ÓÃÓÚË«ÖØÀÕË÷¹¥»÷£¬ÍþвÐÐΪÕßÍþв³Æ£¬ÈôÊDz»Ö§¸¶Êê½ð£¬ËûÃǾͻá¹ûÕæй¶Êý¾Ý¡£¾Ý³Æ£¬InterlockÀÕË÷Èí¼þ²Ù×÷ÒªÇóµÄÊê½ð´ÓÊýÊ®ÍòÃÀÔªµ½Êý°ÙÍòÃÀÔª²»µÈ£¬Ïêϸȡ¾öÓÚ×éÖ¯µÄ¹æÄ£¡£
https://www.bleepingcomputer.com/news/security/meet-interlock-the-new-ransomware-targeting-freebsd-servers/
3. SharePoint RCEÎó²îCVE-2024-38094Õý±»ºÚ¿ÍʹÓþÙÐÐÍøÂç¹¥»÷
11ÔÂ2ÈÕ£¬Microsoft SharePointµÄÒ»¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2024-38094£©±»Åû¶²¢ÕýÔÚ±»ºÚ¿ÍʹÓã¬ÒÔ»ñÈ¡¶Ô¹«Ë¾ÍøÂçµÄ³õʼ»á¼ûȨÏÞ¡£¸ÃÎó²îÊÇÒ»¸ö¸ßÑÏÖØÐÔ£¨CVSS v3.1 ÆÀ·Ö£º7.2£©µÄRCEÎó²î£¬Ó°ÏìÆÕ±éʹÓõĻùÓÚWebµÄSharePointƽ̨¡£Î¢ÈíÒÑÓÚ2024Äê7ÔÂ9ÈÕÐû²¼Á˲¹¶¡ÐÞ¸´¸ÃÎó²î£¬²¢½«Æä±ê¼ÇΪ¡°Ö÷Òª¡±¡£È»¶ø£¬CISAÉÏÖܽ«¸ÃÎó²îÌí¼Óµ½ÒÑ֪ʹÓÃÎó²îĿ¼ʱ£¬²¢Î´Í¸Â¶ÏêϸµÄʹÓ÷½·¨¡£Rapid7Ðû²¼µÄб¨¸æÕ¹ÏÖÁ˹¥»÷ÕßÔõÑùʹÓøÃÎó²î£¬Ö¸³ö¹¥»÷Õßͨ¹ýδ¾ÊÚȨ»á¼ûÒ×Êܹ¥»÷µÄSharePoint·þÎñÆ÷²¢Ö²ÈëWebshell£¬½ø¶øÔÚÍøÂçÖкáÏòÒƶ¯£¬Î£¼°Õû¸öÓò¡£¹¥»÷Õß»¹ÆÆËðÁ˾ßÓÐÓòÖÎÀíԱȨÏÞµÄMicrosoft Exchange·þÎñÕÊ»§£¬»ñµÃÌáÉýµÄ»á¼ûȨÏÞ£¬²¢×°ÖÃÁËHoroung AntivirusÈí¼þ£¬Ôì³ÉÇå¾²·ÀÓù³åÍ»£¬½ûÓÃÇå¾²·þÎñ£¬Ï÷Èõ¼ì²âÄÜÁ¦¡£ËûÃÇʹÓöàÖÖ¹¤¾ß¾ÙÐÐƾ֤ÍøÂç¡¢Ô¶³Ì»á¼û¡¢³¤ÆÚÐÔÉèÖõȲÙ×÷£¬²¢½ûÓÃÁËWindows Defender¡¢¸ü¸ÄÁËÊÂÎñÈÕÖ¾£¬ÒÔ×èÖ¹±»·¢Ã÷¡£Ö»¹Ü¹¥»÷ÕßÊÔͼɾ³ý±¸·Ý£¬µ«²¢Î´ÀֳɼÓÃÜÊý¾Ý£¬Òò´Ë¹¥»÷ÀàÐÍÉв»ÇåÎú¡£
https://www.bleepingcomputer.com/news/security/microsoft-sharepoint-rce-bug-exploited-to-breach-corporate-network/
4. Âåɼí¶ÊÐס·¿ÖÎÀí¾ÖÔâCactusÀÕË÷Èí¼þÍŻ﹥»÷
11ÔÂ1ÈÕ£¬Âåɼí¶ÊÐס·¿ÖÎÀí¾Ö£¨HACLA£©ÊÇÃÀ¹ú×î´óµÄ¹«¹²×¡·¿ÖÎÀí¾ÖÖ®Ò»£¬ÈÏÕæÖÎÀíÁè¼Ý32,000Ì×¹«¹²×¡·¿£¬Äê¶ÈÔ¤ËãÁè¼Ý10ÒÚÃÀÔª£¬ÎªµÍÊÕÈë¼ÒÍ¥¡¢¶ùͯºÍÍíÄêÈËÌṩ¾¼ÃÊÊÓ÷¿ºÍÔ®ÖúÍýÏë¡£×î½ü£¬CactusÀÕË÷Èí¼þÍÅ»ïÉù³Æ¶ÔHACLAµÄITÍøÂç¾ÙÐÐÁËÈëÇÖ¹¥»÷¡£HACLA֤ʵÁËÕâÒ»ÍøÂç¹¥»÷£¬²¢ÌåÏÖÒÑÔ¼ÇëÍⲿȡ֤ITר¼Ò¾ÙÐÐÊÓ²ìºÍÓ¦¶Ô¡£Ö»¹ÜHACLAδ͸¶¹¥»÷µÄÏêϸʱ¼äºÍÐÔ×Ó£¬µ«CactusÀÕË÷Èí¼þÍÅ»ïÉù³ÆÒÑ´ÓÊÜѬȾµÄÍøÂçÖÐÇÔÈ¡ÁË891 GBµÄÎļþ£¬°üÀ¨Ð¡ÎÒ˽¼ÒÉí·ÝÐÅÏ¢¡¢²ÆÎñÎļþ¡¢¸ß¹ÜºÍÔ±¹¤Ð¡ÎÒ˽¼ÒÊý¾Ý¡¢¿Í»§Ð¡ÎÒ˽¼ÒÐÅÏ¢¡¢¹«Ë¾ÉñÃØÊý¾ÝºÍͨѶµÈ£¬²¢ÔÚÆäйÃÜÍøÕ¾ÉÏÐû²¼ÁËһЩÃô¸ÐÎļþµÄ½Øͼ×÷Ϊ֤¾Ý¡£±ðµÄ£¬HACLAÔÚ2022ÄêÒ²ÔøÔâµ½LockBitÀÕË÷Èí¼þÍÅ»ïµÄ¹¥»÷£¬¹¥»÷ÕßÔÚ³¤´ïÒ»ÄêµÄʱ¼äÀï»á¼ûÁËHACLAµÄϵͳ£¬²¢¿ÉÒÔ»á¼û»áÔ±µÄÃô¸ÐСÎÒ˽¼ÒÐÅÏ¢¡£Õþ¸®»ú¹¹ÔھܾøÖ§¸¶ÍøÂç·¸·¨·Ö×ÓÒªÇóµÄÊê½ðºó£¬LockBitÀÕË÷Èí¼þ×é֯й¶ÁËËùÓб»µÁÎļþ¡£
https://www.bleepingcomputer.com/news/security/la-housing-authority-confirms-breach-claimed-by-cactus-ransomware/
5. LastPassÓû§Ð¡ÐÄÐéα֧³Öµç»°ÊµÑéÔ¶³Ì»á¼ûÕ©Æ
11ÔÂ1ÈÕ£¬LastPass ÊÇÒ»¿îÊ¢ÐеÄÃÜÂëÖÎÀíÆ÷£¬ËüʹÓà LastPass Chrome À©Õ¹³ÌÐòÀ´ÌìÉú¡¢ÉúÑÄ¡¢ÖÎÀíºÍ×Ô¶¯Ìî³äÍøÕ¾ÃÜÂë¡£LastPass·¢³öÖÒÑÔ£¬Õ©ÆÕßÕýÔÚͨ¹ýÔÚÆäChromeÀ©Õ¹³ÌÐòÉÏÐû²¼Ðéα5ÐÇ̸ÂÛ£¬ÍƹãÒ»¸öð³äµÄ¿Í»§Ö§³Öµç»°ºÅÂë805-206-2892£¬ÒÔÓÕÆLastPassÓû§¡£Ò»µ©Óû§²¦´ò¸Ãµç»°£¬Æ×Ó»áð³äLastPass£¬Ö¸µ¼ËûÃÇ»á¼û¡°dghelp[.]top¡±ÍøÕ¾£¬²¢ÒªÇóÊäÈë´úÂëÏÂÔØÔ¶³ÌÖ§³Ö³ÌÐò£¬¸Ã³ÌÐòÏÖʵÉÏÊÇConnectWise ScreenConnectÊðÀí£¬ÔÊÐíÕ©ÆÕßÍêÈ«»á¼ûÓû§µÄÅÌËã»ú¡£BleepingComputer·¢Ã÷£¬¸Ãµç»°ºÅÂëÓëÒ»³¡¸ü´ó¹æÄ£µÄÕ©ÆÔ˶¯Óйأ¬¸ÃºÅÂ뻹±»ÓÃ×÷Ðí¶àÆäËû¹«Ë¾£¨ÈçÑÇÂíÑ·¡¢Adobe¡¢FacebookµÈ£©µÄð³äÖ§³Öµç»°ºÅÂ룬²¢ÔÚÖÖÖÖÍøÕ¾ÉÏÐû²¼¡£LastPassÓû§±»ÌáÐѲ»ÒªÓëÈκÎÈË·ÖÏíËûÃǵÄÖ÷ÃÜÂ룬ÒÔ×èֹ˽Ï»á¼ûÆäÃÜÂë¿âÖд洢µÄËùÓÐÃÜÂëºÍÊý¾Ý¡£
https://www.bleepingcomputer.com/news/security/lastpass-warns-of-fake-support-centers-trying-to-steal-customer-data/
6. ·¨¹úÀ͹¤²¿ÔâÍøÂç¹¥»÷£¬¾ÍÒµ°ï·öÄêÇáÈËÊý¾ÝÒÉÔâй¶
11ÔÂ1ÈÕ£¬·¨¹úÀ͹¤²¿Ðû²¼£¬Æä¡°µØ·½Ê¹ÍÅ¡±ÍøÂçʹÓõÄÒ»¼Ò·þÎñÌṩÉÌÒÉËƽüÆÚÔâÊÜÍøÂç¹¥»÷£¬¸ÃÍøÂçÖ÷ҪΪ16ÖÁ25ËêµÄÄêÇáÈËÌṩ¾ÍÒµºÍÅàѵ½¨ÒéÓëÖ§³Ö¡£´Ë´Î¹¥»÷¿ÉÄÜй¶ÁËÒÑÔÚ¸ÃϵͳÖйҺŵÄÄêÇáÈ˵ÄСÎÒ˽¼ÒÊý¾Ý£¬°üÀ¨È«Ãû¡¢³öÉúÈÕÆÚ¡¢¹ú¼®¡¢µç×ÓÓʼþºÍÓÊÕþµØµãÒÔ¼°µç»°ºÅÂ룬µ«ÒøÐÐÏêϸÐÅÏ¢¡¢Éç»á°ü¹ÜºÅºÍÉí·ÝÖ¤¼þδÊÜÓ°Ïì¡£Ö»¹ÜÊÖÒÕÊÓ²ìÉÐδÍê³É£¬¸Ã²¿ÒѽÓÄɶàÏî²½·¥½â¾öÎó²îÎÊÌ⣬²¢ÒÑÏò·¨¹úÒþ˽î¿Ïµ»ú¹¹CNILºÍÍøÂçÇå¾²»ú¹¹ANSSI±¨¸æ´ËÊ£¬Í¬Ê±Ïò˾·¨Õþ¸®ÌáÆðͶËß¡£ÊÜÓ°ÏìµÄÄêÇáÈËÕýÔÚ±»×ª´ïÇéÐΣ¬²¢ÌáÐÑËûÃÇСÐÄÍøÂç´¹ÂÚºÍÉí·Ý͵ÇÔµÄΣº¦£¬ÇÐÎðͨ¹ýµç»°¡¢¶ÌÐÅ»òµç×ÓÓʼþ͸¶ÃÜÂë»òÒøÐÐÏêϸÐÅÏ¢¡£
https://therecord.media/france-data-breach-government-contractor-local-missions