Ï£À°ÌìÈ»ÆøÔËÓªÉÌDESFAÔâµ½Ragnar LockerµÄÀÕË÷¹¥»÷
°ä²¼¹¦·ò 2022-08-24
¾ÝýÌå8ÔÂ22ÈÕ±¨Â·£¬Ï£À°×î´óµÄÌìÈ»ÆøÔËÓªÉÌDESFAÔâµ½ÍøÂç¹¥»÷ºóITϵͳÖжϡ£DESFAÚ¹Êͳƣ¬¹¥»÷ÕßÊÔͼÈëÇÔìäÍøÂ磬²¿ÃÅÎļþºÍÊý¾Ý¿ÉÄÜÒѱ»½Ó¼û£¬ÆäÍ£ÓÃÁ˺ܶàÔÚÏß·þÎñÒÔ±£»¤¿Í»§Êý¾Ý¡£DESFAÏòÏû·ÑÕß±£ÕÏ£¬´ËÊÂÎñ²»»áÓ°ÏìÌìÈ»ÆøµÄ¹©¸ø£¬ËùÓÐÊäÈëºÍÊä³öµã¾ùÕý³£ÔËÐС£ÉÏÖÜÎ壬Ragnar LockerÐû³Æ¶ÔÕâ´Î¹¥»÷ÕÆ¹Ü£¬ÔÚÆäÊý¾Ý¹«¿ªÍøÕ¾°ä²¼Ò»·Ý±»µÁÊý¾ÝµÄÁбíºó£¬»¹°µÊ¾ËûÃÇÔÚDESFAµÄϵͳÉÏ·¢ÏÖÁ˶à¸ö°²È«·ì϶¡£
https://therecord.media/greek-gas-operator-refuses-to-negotiate-with-ransomware-group-after-attack/
2¡¢VMware Carbon Black¿Éµ¼ÖÂWindows³öÏÖBSODÎÊÌâ
¾Ý8ÔÂ23ÈÕ±¨Â·£¬VMware Carbon Black¶Ëµã°²È«½â¾ö¹æ»®µÄ²¿ÃŰ汾¿ÉÄܵ¼ÖÂWindows³öÏÖBSODÎÊÌâ¡£ÎÊÌâÔ´ÓÚµ±ÈÕ²¿Êðµ½Carbon Black Cloud Sensor 3.6.0.1979-3.8.0.398µÄ¹æ¶¨¼¯£¬Ëü»áµ¼ÖÂÉ豸±ÀÀ£ÔÚÆô¶¯Ê±ÏÔʾÀ¶ÆÁ£¬²¢»Ø¾ø½Ó¼û¡£ÔÚÊÜÓ°ÏìµÄϵͳÉÏ£¬ÃýÎó±»¼ø±ðΪ"PFN_LIST_CORRUPT"¡£Carbon BlackºÍAVÊðÃû°ü8.19.22.224Ö®¼äËÆºõ´æÔÚì¶Ü£¬VMwareĿǰÔÚ¶Ô´ËʽøÐе÷²é£¬²¢»Ø¹öÓÐÎÊÌâµÄ¹æ¶¨¼¯¡£
https://www.bleepingcomputer.com/news/security/vmware-carbon-black-causing-bsod-crashes-on-windows/
3¡¢LockBitµÄÊý¾Ý¹«¿ªÍøÕ¾Ôâµ½À´×ÔEntrustµÄDDoS¹¥»÷
ýÌå8ÔÂ22Èճƣ¬LockBitµÄÊý¾Ý¹«¿ªÍøÕ¾Ôâµ½Á˰²È«¹«Ë¾EntrustµÄDDoS¹¥»÷¡£LockBitÔÚ6Ô·ݹ¥»÷ÁËEntrust£¬²¢ÓÚÉÏÖÜÎåÍíÉÏÆðÍ·¹«¿ª¸Ã¹«Ë¾µÄÊý¾Ý¡£Õâ´Îй¶Ô̺¬30½ØÍ¼£¬É漰˾·¨Îļþ¡¢ÓªÏúµç×Ó±í¸ñºÍ¹ÜÕÊÊý¾Ý¡£×êÑÐÈËÔ±³Æ£¬ÔÚй¶ºó²»¾Ã£¬¸ÃÍÅ»ïµÄTorÊý¾Ý¹«¿ªÍøÕ¾ÒòDDoS¹¥»÷¶øÎÞ·¨½Ó¼û¡£´Ë±í£¬¹¥»÷Õß»¹ÔÚHTTPSÒªÇóÖÐÔö³¤ÁËÒ»ÌõÐÂÎÅ£¬ÒªÇóËûÃÇɾ³ýEntrustµÄÊý¾Ý¡£Cisco³Æ¹¥»÷ΪÿÃëÀ´×Ô1000¶ą̀·þÎñÆ÷µÄ400¸öÒªÇó£¬EntrustÉÐδ¶Ô´ËÊÂ×ö³ö»Ø¸´¡£
https://www.bleepingcomputer.com/news/security/lockbit-ransomware-blames-entrust-for-ddos-attacks-on-leak-sites/
4¡¢ÐµÄGAIROSCOPE¹¥»÷Ä£ÐÍ¿É´ÓÆøÏ¶ÏµÍ³ÖÐÇÔÊØÐÅÏ¢
ýÌå8ÔÂ22ÈÕ±¨Â·£¬×êÑÐÈËÔ±·¢ÏÖʹÓÃMEMSÍÓÂÝÒdz¬Éù²¨Òñ±Îͨ·ÇÔÈ¡Êý¾ÝµÄGAIROSCOPE¹¥»÷Ä£ÐÍ¡£ÓëÆäËüÕë¶ÔÆøÏ¶ÏµÍ³µÄ¹¥»÷Ò»Ñù£¬GAIROSCOPE±ØÒªÒÀ¸½¹¥»÷Õßͨ¹ý±»Ï°È¾µÄUSB¡¢Ë®¿Ó¹¥»÷»ò¹©¸øÁ´¹¥»÷µÈÕ½ÊõÀ´ÈëÇÖÖ¸±êÍøÂç²¢´«²¼¶ñÒâÈí¼þ£¬»¹±ØÒªÊ¹ÓöñÒâÀûÓÃϰȾԱ¹¤µÄÊÖ»ú¡£±»Ï°È¾µÄÊÖ»úÓöÔÚÎïÀí¾àÀëºÜ½üµÄ´¦Ëù¼ì²âµ½´«Ê䣬²¢Í¨¹ýÉ豸ÄÚÖõÄÍÓÂÝÒÇ´«¸ÐÆ÷½øÐмàÌý£¬Ëæºó½«Êý¾Ý±»½âºÍг½âÂ룬ͨ¹ýWi-Fi´«Ê䏸¹¥»÷Õß¡£
https://thehackernews.com/2022/08/new-air-gap-attack-uses-mems-gyroscope.html
5¡¢×êÑÐÍŶӷ¢ÏÖLinuxÄÚºËÖдæÔÚ8ÄêµÄ·ì϶DirtyCred
8ÔÂ22ÈÕ±¨Â·³Æ£¬×êÑÐÍŶӷ¢ÏÖLinuxÄÚºËÖдæÔÚ8ÄêµÄDirtyCred£¬ÏñDirtyPipeÒ»ÑùÁîÈËÌÖÑá¡£DirtyCredÊÇÒ»¸öÄÚºËÀûÓøÅÏ룬Ëü½«·ÇÌØÈ¨ÄÚºËÆ¾Ö¤ÓëÌØÈ¨Æ¾Ö¤»¥»»À´ÌáÉýÌØÈ¨¡£DirtyCredûÓи²¸ÇÄں˶ÑÉϵÄÈκιؼüÊý¾Ý×ֶΣ¬¶øÊÇÀÄÓöÑÄÚ´æ³ÁÓûúÔìÀ´»ñµÃÌØÈ¨¡£DirtyCredÀûÓÃÁË¿ªÊͺóʹÓ÷ì϶£¨CVE-2022-2588£©£¬¸Ã·ì϶´æÔÚÓÚLinuxÄÚºËÖÐnet/sched/ls_route.c¹ýÂËÆ÷ʵÏÖµÄroute4_change¡£
https://thehackernews.com/2022/08/as-nasty-as-dirty-pipe-8-year-old-linux.html
6¡¢Ó¢¹úijÆû³µ¾ÏúÉÌÔâµ½ÀÕË÷¹¥»÷ºóÖ÷ÌâϵͳÎÞ·¨¸´Ô
¾ÝýÌå8ÔÂ22Èճƣ¬Ó¢¹úÆû³µ¾ÏúÉÌHoldcroft Motor GroupÔâµ½ÁËÀÕË÷¹¥»÷¡£¹¥»÷²úÉúÔÚ7ÔÂ28ÈÕ£¬¸Ã¹«Ë¾µÄIT»ù´¡ÉèÊ©Êܵ½ÁËÑϳÁµÄÓ°Ï죬ÄÚ²¿´æ´¢ÇøÓòµÄÊý¾ÝÃÔʧ¡£¾¹ýµ÷²é£¬È·Èϲ¿ÃÅÔ±¹¤µÄÓ×ÎÒÐÅÏ¢ÒѾй¶¡£¸Ã¹«Ë¾µÄÉêÃ÷°µÊ¾£¬ËûÃÇÒѾÉè·¨½â¾öÁË´ó²¿ÃŵĽӼûÎÊÌ⣬µ«Ò»Ð©Ö÷ÌâϵͳÒѱ»°Ü»µÎÞ·¨¸´Ô»ò±»ÓÀԶɾ³ý¡£¼øÓÚÆû³µ¾ÏúÉÌ´¦ÖÃÁË´óÁ¿¿Í»§µÄÓ×ÎҺͲÆÕþÐÅÏ¢£¬¸ÃÐÐÒµÔâµ½ÀÕË÷¹¥»÷µÄÇ÷ÏòÉÏÉý¡£
https://www.infosecurity-magazine.com/news/car-dealership-hit-by-major/


¾©¹«Íø°²±¸11010802024551ºÅ