¡°Ñ¬È¾ÐԲɷá±Ô˶¯ÖÐOtterCookieÐÂÐͶñÒâÈí¼þÍþвÈí¼þ¿ª·¢Ö°Ô±
Ðû²¼Ê±¼ä 2024-12-271. ¡°Ñ¬È¾ÐԲɷá±Ô˶¯ÖÐOtterCookieÐÂÐͶñÒâÈí¼þÍþвÈí¼þ¿ª·¢Ö°Ô±
12ÔÂ26ÈÕ£¬³¯ÏÊÍþвÐÐΪÕß½üÆÚÔÚÕë¶ÔÈí¼þ¿ª·¢Ö°Ô±µÄ¡°Ñ¬È¾ÐԲɷá±Ô˶¯ÖУ¬ÍƳöÁËÒ»ÖÖÃûΪOtterCookieµÄÐÂÐͶñÒâÈí¼þ¡£¾ÝÍøÂçÇå¾²¹«Ë¾Palo Alto NetworksµÄÑо¿Ö°Ô±³Æ£¬¸ÃÔ˶¯×Ô2022Äê12ÔÂÒÔÀ´Ò»Ö±»îÔ¾£¬Í¨¹ýÌṩÐéαµÄÊÂÇéʱ»úÈö²¥¶ñÒâÈí¼þ£¬ÈçBeaverTailºÍInvisibleFerretµÈ¡£¶øNTT Security JapanµÄ±¨¸æÖ¸³ö£¬OtterCookieºÜ¿ÉÄÜÓÚ9ÔÂÍƳö£¬²¢ÔÚ11Ô·ºÆðÁËеıäÖÖ¡£¸Ã¶ñÒâÈí¼þͨ¹ý¼ÓÔØÆ÷ת´ï£¬»ñÈ¡JSONÊý¾Ý²¢Ö´ÐÐJavaScript´úÂ룬¿ÉÒÔÓëBeaverTailÒ»Æð°²ÅÅ»òµ¥¶À°²ÅÅ¡£ËüʹÓÃGitHub»òBitbucketÏÂÔصÄNode.jsÏîÄ¿»ònpm°üѬȾĿµÄ£¬Ò²Ê¹ÓÃÁËQt»òElectronÓ¦ÓóÌÐò¹¹½¨µÄÎļþ¡£Ò»µ©¼¤»î£¬OtterCookie¾Í»áʹÓÃSocket.IO WebSocket¹¤¾ßÓëÏÂÁîºÍ¿ØÖÆ»ù´¡ÉèÊ©½¨ÉèÇ徲ͨѶ£¬²¢Ö´ÐÐÊý¾Ý͵ÇÔµÄshellÏÂÁ°üÀ¨ÍøÂç¼ÓÃÜÇ®±ÒÇ®°üÃÜÔ¿¡¢Îĵµ¡¢Í¼ÏñµÈÓмÛÖµÐÅÏ¢¡£×îа汾µÄOtterCookie»¹¿ÉÒÔй¶¼ôÌù°åÊý¾Ý£¬²¢¼ì²âµ½ÓÃÓÚÕì̽µÄÏÂÁÅú×¢¹¥»÷ÕßÍýÏë¾ÙÐиüÉîÌõÀíµÄÉø͸»òºáÏòÒƶ¯¡£
https://www.bleepingcomputer.com/news/security/new-ottercookie-malware-used-to-backdoor-devs-in-fake-job-offers/
2. ÈÕº½ÔâDDoS¹¥»÷Öº½°àÑÓÎó£¬ÏµÍ³Òѻָ´
12ÔÂ26ÈÕ£¬ÈÕ±¾Æì½¢º½¿Õ¹«Ë¾ÈÕ±¾º½¿Õ(JAL)ÔâÓöÁËÒ»´ÎÍøÂçÇå¾²ÊÂÎñ£¬µ¼ÖÂÆ䲿·Öº£Äں͹ú¼Êº½°à·ºÆðÑÓÎó¡£ÊÂÎñÒòÓÉÊÇÆäÓÃÓÚÓëÍⲿϵͳ¾ÙÐÐÊý¾ÝͨѶµÄÍøÂç×°±¸ÔâÊÜÁËÂþÑÜʽ¾Ü¾ø·þÎñ(DDoS)¹¥»÷£¬µ¼ÖÂϽµµÍ÷Á¿¼¤Ôö²¢·ºÆð¹ÊÕÏ¡£¹¥»÷»¹Ó°ÏìÁËÂÿÍÐÐÀîÖÎÀíϵͳºÍÒƶ¯Ó¦ÓóÌÐò£¬µ«ÈÕº½ÌåÏÖûÓпͻ§ÐÅϢй¶¡¢ÅÌËã»ú²¡¶¾Ë𺦻òº½ÐÐÇå¾²ÎÊÌâ¡£ÊÜÓ°ÏìµÄϵͳÒÑÔÝʱ¹Ø±Õ£¬²¢ÔÝÍ£Á˵±ÈÕ³ö·¢µÄ»úƱÏúÊۺͲ¿·ÖÔÚÏß·þÎñ¡£Ö»¹ÜÓÐ40¶à¸öº½°àÑÓÎ󣬵«ÈÕº½ÌåÏÖµÚ¶þÌìµÄº½°àÍýÏëÕý³£ÔËÐС£º½¿ÕÒµÈÔÊÇÈ«ÇòºÚ¿ÍµÄÈÈÃÅÄ¿µÄ£¬´ËÇ°Ò²Ôø±¬·¢¶àÆðÕë¶Ôº½¿Õ¹«Ë¾ºÍ»ú³¡µÄÍøÂç¹¥»÷ÊÂÎñ£¬ÕâЩϮ»÷´ó¶à³öÓÚ¾¼ÃÄîÍ·£¬µ«Ò²ÓÐÕþÖÎÄîÍ·µÄ°¸Àý¡£
https://therecord.media/japan-airlines-resumes-operations-after-cyberattack
3. °ÍÎ÷ºÚ¿ÍÒòÉæÏÓÚ²ÆÀÕË÷ÔÚÃÀ¹úÔâÖ¸¿Ø
12ÔÂ26ÈÕ£¬Ò»Ãû°ÍÎ÷¹«ÃñJunior Barros De OliveiraÒòÉæÏÓºÚ¿ÍÈëÇÖ²¢Ú²ÆÀÕË÷Ò»¼ÒλÓÚÐÂÔóÎ÷µÄ¹«Ë¾¶ø±»ÃÀ¹ú˾·¨²¿ÆðËß¡£¾ÝÆðËßÊéÏÔʾ£¬µÂ°ÂÀûάÀÓÚ2020Äê3ÔÂÈëÇÖÁ˸ù«Ë¾µÄ°ÍÎ÷×Ó¹«Ë¾ÍøÂ磬ÇÔÈ¡ÁËÔ¼30ÍòÃû¿Í»§µÄÉñÃØÐÅÏ¢¡£Í¬Äê9Ô£¬ËûʹÓüÙÃûÏò¸Ã¹«Ë¾Ê×ϯִÐйٷ¢Ë͵ç×ÓÓʼþ£¬ÒªÇóÖ§¸¶300±ÈÌرң¨ÆäÊмÛÖµÔ¼320ÍòÃÀÔª£©×÷Ϊ²»³öÊÛÊý¾ÝµÄÌõ¼þ¡£Ò»¸öÔºó£¬ËûÓÖ½«ÏàͬµÄÐÅϢת·¢¸øÁ˸ù«Ë¾ÔÚ°ÍÎ÷µÄÊ×ϯִÐйٺÍÒ»Ãû¸ß¹Ü£¬²¢ÌåÏÖÔ¸ÒâÒÔ75±ÈÌرң¨ÆäʱԼºÏ80ÍòÃÀÔª£©µÄ×Éѯ·Ñ×ÊÖúËûÃǽâ¾öÇå¾²Îó²î¡£µÂ°ÂÀûάÀÒò´Ë±»Ö¸¿ØËÄÏîÉæ¼°´ÓÊܱ£»¤µÄÅÌËã»ú»ñÊØÐÅÏ¢µÄÚ²ÆÀÕË÷×ïºÍËÄÏîÍþвÐÔͨѶ×ï¡£ÈôÊÇ×ïÃû½¨É裬Ëû½«ÃæÁÙ×î¸ß¿É´ï20ÄêµÄî¿ÏµºÍ¸ß´ï100ÍòÃÀÔªµÄ·£¿î£¬»òÊÕÒæÓëËðʧ¼ÛÖµµÄÁ½±¶£¨ÒԽϸßÕßΪ׼£©¡£
https://thehackernews.com/2024/12/brazilian-hacker-charged-for-extorting.html
4. ͨÓö¯Á¦¹«Ë¾ÔâÍøÂç´¹ÂÚ¹¥»÷£¬ÊýʮԱ¹¤¸£ÀûÕË»§±»ÈëÇÖ
12ÔÂ26ÈÕ£¬º½¿Õº½ÌìºÍ¹ú·À¾ÞͷͨÓö¯Á¦¹«Ë¾ÔâÓöÁËÒ»´ÎÀֳɵÄÍøÂç´¹ÂÚ¹¥»÷£¬µ¼ÖÂÊýÊ®¸öÔ±¹¤¸£ÀûÕË»§±»ÈëÇÖ¡£¹¥»÷Õßͨ¹ýµÚÈý·½ÍйܵĵǼÃÅ»§»á¼û²¢¸ü¸ÄÁËÔ±¹¤¸£ÀûÕË»§£¬ÕâЩÕË»§°üÀ¨ÁËÔ±¹¤µÄÐÕÃû¡¢³öÉúÈÕÆÚ¡¢Õþ¸®½ÒÏþµÄÉí·ÝÖ¤ºÅÂë¡¢Éç»áÇå¾²ºÅÂë¡¢ÒøÐÐÕË»§ÐÅÏ¢ºÍ²Ð¼²×´Ì¬µÈÃô¸ÐÐÅÏ¢¡£¾ÝͨÓö¯Á¦¹«Ë¾Í¸Â¶£¬¹²ÓÐ37ÈËÊܵ½Ó°Ï죬¹¥»÷ÕßÔÚijЩÇéÐÎÏ»¹¸ü¸ÄÁ˱»µÁÕË»§µÄÒøÐÐÕË»§ÐÅÏ¢¡£Í¨Óö¯Á¦¹«Ë¾ÔÚ·¢Ã÷Õâһδ¾ÊÚȨµÄÔ˶¯ºóÁ¬Ã¦ÔÝÍ£Á˶Ը÷þÎñµÄ»á¼û£¬²¢ÏòÊÜÓ°ÏìµÄÖ°Ô±ÌṩÁËÁ½ÄêµÄÃâ·ÑÐÅÓüà¿Ø¡£±ðµÄ£¬Í¨Óö¯Á¦¹«Ë¾»¹ÌáÐÑÊÜÓ°ÏìµÄСÎÒ˽¼ÒÖØÖÃËûÃǵĸ»´ïÕË»§µÇ¼ƾ֤£¬²¢×èÖ¹ÔÚ¶à¸öÕË»§ÖÐʹÓÃÏàͬµÄƾ֤¡£½ñÄêÔçЩʱ¼ä£¬¸»´ï¹«Ë¾Ò²ÔøÔâÓö¹ýÁ½´ÎÊý¾Ýй¶ÊÂÎñ£¬Ó°ÏìÁËÊýÍòСÎÒ˽¼Ò¡£
https://www.securityweek.com/defense-giant-general-dynamics-says-employees-targeted-in-phishing-attack/
5. WDACÔâʹÓ㬹¥»÷Õ߿ɽûÓÃEDR´«¸ÐÆ÷·¢¶¯¹¥»÷
12ÔÂ25ÈÕ£¬Ç徲ר¼Ò·¢Ã÷ÁËÒ»ÖÖʹÓÃWindows DefenderÓ¦ÓóÌÐò¿ØÖÆ£¨WDAC£©µÄ¹¥»÷ÊÖÒÕ£¬¿ÉÒÔ½ûÓÃWindowsÉè±¹ØÁ¬Ä¶Ëµã¼ì²âºÍÏìÓ¦£¨EDR£©´«¸ÐÆ÷£¬Ê¹¹¥»÷ÕßÄܹ»ÈƹýÇå¾²¼ì²â²¢¶Ôϵͳ·¢¶¯¹¥»÷¡£WDACÊÇWindows 10ºÍWindows Server 2016ÒýÈëµÄÊÖÒÕ£¬Ö¼ÔÚ¿ØÖÆWindowsÉè±¹ØÁ¬Ä¿ÉÖ´ÐдúÂë¡£¹¥»÷Õß¿ÉÒÔÖƶ©ºÍ°²ÅÅרÃÅÉè¼ÆµÄWDACÕ½ÂÔ£¬×èÖ¹EDR´«¸ÐÆ÷ÔÚϵͳÆô¶¯Ê±¼ÓÔØ£¬Ê¹ÆäÎÞ·¨ÊÂÇé¡£¹¥»÷·½·¨°üÀ¨Õë¶Ôµ¥¸ö×°±¸ºÍÕû¸öÓò£¬ÓµÓÐÓòÖÎÀíԱȨÏ޵Ĺ¥»÷Õß¿ÉÒÔÔÚÕû¸ö×éÖ¯ÄÚ·Ö·¢¶ñÒâWDACÕ½ÂÔ£¬ÏµÍ³ÐԵؽûÓÃËùÓж˵ãÉϵÄEDR´«¸ÐÆ÷¡£¹¥»÷Éæ¼°Õ½ÂÔ°²ÅÅ¡¢ÖØÆôÖն˺ͽûÓÃEDRÈý¸öÖ÷Òª½×¶Î¡£Çå¾²Ö°Ô±½¨ÉèÁË¡°Krueger¡±¿´·¨ÑéÖ¤¹¤¾ßÀ´¼ì²âÕâÖÖ¹¥»÷¡£»º½âÕ½ÂÔ°üÀ¨Í¨¹ýGPOÖ´ÐÐWDACÕ½ÂÔ¡¢Ó¦ÓÃ×îСȨÏÞÔÔòºÍʵÑéÇå¾²µÄÖÎÀíʵ¼ù¡£ÃæÁÙзºÆðµÄ¹¥»÷ÊÖÒÕ£¬ÐèÒª½ÓÄɶàÌõÀíµÄÍøÂçÇå¾²ÒªÁ죬²¢Ê±¿Ì¼á³ÖСÐÄ¡£
https://cybersecuritynews.com/attack-weaponizes-windows-defender/#google_vignette
6. ΢ÈíÖÒÑÔ£ºÊ¹ÓÃýÌå×°ÖÃWindows 11 24H2¿ÉÖÂÎÞ·¨ÎüÊÕÇå¾²¸üÐÂ
12ÔÂ26ÈÕ£¬Î¢Èí·¢³öÖÒÑÔ£¬Ö¸³öʹÓÃýÌåÖ§³Ö×°ÖÃWindows 11°æ±¾24H2ʱ±£´æÒ»¸öÎÊÌ⣬¿ÉÄܵ¼Ö²Ù×÷ϵͳÎÞ·¨½ÓÊܽøÒ»²½µÄÇå¾²¸üС£Ïêϸ¶øÑÔ£¬ÔÚ2024Äê10ÔÂ8ÈÕÖÁ11ÔÂ12ÈÕʱ´ú£¬Ê¹ÓÃCDºÍUSBÉÁ´æÇý¶¯Æ÷×°ÖðüÀ¨´Ëʱ´úÇå¾²¸üеÄWindows 11°æ±¾24H2ʱ£¬×°±¸¿ÉÄÜ»áÏÝÈëÎÞ·¨½ÓÊܺóÐøWindowsÇå¾²¸üеÄ״̬¡£²»¹ý£¬Õâ¸öÎó²î²»»áÓ°Ïìͨ¹ýWindows¸üлòMicrosoft¸üÐÂĿ¼ÍøÕ¾Ó¦ÓõÄÇå¾²¸üУ¬Ò²²»»áÔÚʹÓÃ×îеÄ2024Äê12ÔÂÇå¾²¸üÐÂʱ·ºÆð¡£Î¢ÈíÕýÔÚÖÂÁ¦ÓÚÓÀÊÀÐÞ¸´´ËÎÊÌ⣬²¢½¨ÒéʹÓûùÓÚýÌåµÄWindows 11 24H2×°ÖõÄÓû§Ó¦ÓÃ2024Äê12ÔÂ10ÈÕÐû²¼µÄÇå¾²¸üУ¬ÒÔ×èÖ¹ºóÐø¸üÐÂÎÊÌâ¡£±ðµÄ£¬Windows 11 24H2»¹ÃæÁÙ×ÅһϵÁÐÆäËûÎÊÌ⣬°üÀ¨ÒôƵÎÊÌâ¡¢ÓÎÏ·ÐÔÄÜÎÊÌâ¡¢Íß½âºÍËÀ»úµÈ£¬ÉõÖÁÔÚÌض¨µÄÓ²¼þºÍÈí¼þÉèÖÃÉϱ»ÔÝʱ×èÖ¹¡£
https://www.bleepingcomputer.com/news/security/windows-11-installation-media-bug-causes-security-update-failures/