Ï£À°ÌìÈ»ÆøÔËÓªÉÌDESFAÔâµ½Ragnar LockerµÄÀÕË÷¹¥»÷

°ä²¼¹¦·ò 2022-08-24
1¡¢Ï£À°ÌìÈ»ÆøÔËÓªÉÌDESFAÔâµ½Ragnar LockerµÄÀÕË÷¹¥»÷

      

¾ÝýÌå8ÔÂ22ÈÕ±¨Â·£¬Ï£À°×î´óµÄÌìÈ»ÆøÔËÓªÉÌDESFAÔâµ½ÍøÂç¹¥»÷ºóITϵͳÖжÏ¡£DESFAÚ¹ÊͳÆ£¬¹¥»÷ÕßÊÔͼÈëÇÔìäÍøÂ磬²¿ÃÅÎļþºÍÊý¾Ý¿ÉÄÜÒѱ»½Ó¼û£¬ÆäÍ£ÓÃÁ˺ܶàÔÚÏß·þÎñÒÔ±£»¤¿Í»§Êý¾Ý¡£DESFAÏòÏû·ÑÕß±£ÕÏ£¬´ËÊÂÎñ²»»áÓ°ÏìÌìÈ»ÆøµÄ¹©¸ø£¬ËùÓÐÊäÈëºÍÊä³öµã¾ùÕý³£ÔËÐС£ÉÏÖÜÎ壬Ragnar LockerÐû³Æ¶ÔÕâ´Î¹¥»÷ÕÆ¹Ü£¬ÔÚÆäÊý¾Ý¹«¿ªÍøÕ¾°ä²¼Ò»·Ý±»µÁÊý¾ÝµÄÁбíºó£¬»¹°µÊ¾ËûÃÇÔÚDESFAµÄϵͳÉÏ·¢ÏÖÁ˶à¸ö°²È«·ì϶¡£


https://therecord.media/greek-gas-operator-refuses-to-negotiate-with-ransomware-group-after-attack/


2¡¢VMware Carbon Black¿Éµ¼ÖÂWindows³öÏÖBSODÎÊÌâ

      

¾Ý8ÔÂ23ÈÕ±¨Â·£¬VMware Carbon Black¶Ëµã°²È«½â¾ö¹æ»®µÄ²¿ÃŰ汾¿ÉÄܵ¼ÖÂWindows³öÏÖBSODÎÊÌâ¡£ÎÊÌâÔ´ÓÚµ±ÈÕ²¿Êðµ½Carbon Black Cloud Sensor 3.6.0.1979-3.8.0.398µÄ¹æ¶¨¼¯£¬Ëü»áµ¼ÖÂÉ豸±ÀÀ£ÔÚÆô¶¯Ê±ÏÔʾÀ¶ÆÁ£¬²¢»Ø¾ø½Ó¼û¡£ÔÚÊÜÓ°ÏìµÄϵͳÉÏ£¬ÃýÎó±»¼ø±ðΪ"PFN_LIST_CORRUPT"¡£Carbon BlackºÍAVÊðÃû°ü8.19.22.224Ö®¼äËÆºõ´æÔÚì¶Ü£¬VMwareĿǰÔÚ¶Ô´ËʽøÐе÷²é£¬²¢»Ø¹öÓÐÎÊÌâµÄ¹æ¶¨¼¯¡£


https://www.bleepingcomputer.com/news/security/vmware-carbon-black-causing-bsod-crashes-on-windows/


3¡¢LockBitµÄÊý¾Ý¹«¿ªÍøÕ¾Ôâµ½À´×ÔEntrustµÄDDoS¹¥»÷

      

ýÌå8ÔÂ22Èճƣ¬LockBitµÄÊý¾Ý¹«¿ªÍøÕ¾Ôâµ½Á˰²È«¹«Ë¾EntrustµÄDDoS¹¥»÷¡£LockBitÔÚ6Ô·ݹ¥»÷ÁËEntrust£¬²¢ÓÚÉÏÖÜÎåÍíÉÏÆðÍ·¹«¿ª¸Ã¹«Ë¾µÄÊý¾Ý¡£Õâ´Îй¶Ô̺¬30½ØÍ¼£¬É漰˾·¨Îļþ¡¢ÓªÏúµç×Ó±í¸ñºÍ¹ÜÕÊÊý¾Ý¡£×êÑÐÈËÔ±³Æ£¬ÔÚй¶ºó²»¾Ã£¬¸ÃÍÅ»ïµÄTorÊý¾Ý¹«¿ªÍøÕ¾ÒòDDoS¹¥»÷¶øÎÞ·¨½Ó¼û¡£´Ë±í£¬¹¥»÷Õß»¹ÔÚHTTPSÒªÇóÖÐÔö³¤ÁËÒ»ÌõÐÂÎÅ£¬ÒªÇóËûÃÇɾ³ýEntrustµÄÊý¾Ý¡£Cisco³Æ¹¥»÷ΪÿÃëÀ´×Ô1000¶ą̀·þÎñÆ÷µÄ400¸öÒªÇó£¬EntrustÉÐδ¶Ô´ËÊÂ×ö³ö»Ø¸´¡£


https://www.bleepingcomputer.com/news/security/lockbit-ransomware-blames-entrust-for-ddos-attacks-on-leak-sites/


4¡¢ÐµÄGAIROSCOPE¹¥»÷Ä£ÐÍ¿É´ÓÆøÏ¶ÏµÍ³ÖÐÇÔÊØÐÅÏ¢

      

ýÌå8ÔÂ22ÈÕ±¨Â·£¬×êÑÐÈËÔ±·¢ÏÖʹÓÃMEMSÍÓÂÝÒdz¬Éù²¨Òñ±Îͨ·ÇÔÈ¡Êý¾ÝµÄGAIROSCOPE¹¥»÷Ä£ÐÍ¡£ÓëÆäËüÕë¶ÔÆøÏ¶ÏµÍ³µÄ¹¥»÷Ò»Ñù£¬GAIROSCOPE±ØÒªÒÀ¸½¹¥»÷Õßͨ¹ý±»Ï°È¾µÄUSB¡¢Ë®¿Ó¹¥»÷»ò¹©¸øÁ´¹¥»÷µÈÕ½ÊõÀ´ÈëÇÖÖ¸±êÍøÂç²¢´«²¼¶ñÒâÈí¼þ£¬»¹±ØÒªÊ¹ÓöñÒâÀûÓÃϰȾԱ¹¤µÄÊÖ»ú¡£±»Ï°È¾µÄÊÖ»úÓöÔÚÎïÀí¾àÀëºÜ½üµÄ´¦Ëù¼ì²âµ½´«Ê䣬²¢Í¨¹ýÉ豸ÄÚÖõÄÍÓÂÝÒÇ´«¸ÐÆ÷½øÐмàÌý£¬Ëæºó½«Êý¾Ý±»½âºÍг½âÂ룬ͨ¹ýWi-Fi´«Ê䏸¹¥»÷Õß¡£


https://thehackernews.com/2022/08/new-air-gap-attack-uses-mems-gyroscope.html


5¡¢×êÑÐÍŶӷ¢ÏÖLinuxÄÚºËÖдæÔÚ8ÄêµÄ·ì϶DirtyCred 

      

8ÔÂ22ÈÕ±¨Â·³Æ£¬×êÑÐÍŶӷ¢ÏÖLinuxÄÚºËÖдæÔÚ8ÄêµÄDirtyCred£¬ÏñDirtyPipeÒ»ÑùÁîÈËÌÖÑá¡£DirtyCredÊÇÒ»¸öÄÚºËÀûÓøÅÏ룬Ëü½«·ÇÌØÈ¨ÄÚºËÆ¾Ö¤ÓëÌØÈ¨Æ¾Ö¤»¥»»À´ÌáÉýÌØÈ¨¡£DirtyCredûÓи²¸ÇÄں˶ÑÉϵÄÈκιؼüÊý¾Ý×ֶΣ¬¶øÊÇÀÄÓöÑÄÚ´æ³ÁÓûúÔìÀ´»ñµÃÌØÈ¨¡£DirtyCredÀûÓÃÁË¿ªÊͺóʹÓ÷ì϶£¨CVE-2022-2588£©£¬¸Ã·ì϶´æÔÚÓÚLinuxÄÚºËÖÐnet/sched/ls_route.c¹ýÂËÆ÷ʵÏÖµÄroute4_change¡£


https://thehackernews.com/2022/08/as-nasty-as-dirty-pipe-8-year-old-linux.html


6¡¢Ó¢¹úijÆû³µ¾­ÏúÉÌÔâµ½ÀÕË÷¹¥»÷ºóÖ÷ÌâϵͳÎÞ·¨¸´Ô­

      

¾ÝýÌå8ÔÂ22Èճƣ¬Ó¢¹úÆû³µ¾­ÏúÉÌHoldcroft Motor GroupÔâµ½ÁËÀÕË÷¹¥»÷¡£¹¥»÷²úÉúÔÚ7ÔÂ28ÈÕ£¬¸Ã¹«Ë¾µÄIT»ù´¡ÉèÊ©Êܵ½ÁËÑϳÁµÄÓ°Ï죬ÄÚ²¿´æ´¢ÇøÓòµÄÊý¾ÝÃÔʧ¡£¾­¹ýµ÷²é£¬È·Èϲ¿ÃÅÔ±¹¤µÄÓ×ÎÒÐÅÏ¢ÒѾ­Ð¹Â¶¡£¸Ã¹«Ë¾µÄÉêÃ÷°µÊ¾£¬ËûÃÇÒѾ­Éè·¨½â¾öÁË´ó²¿ÃŵĽӼûÎÊÌ⣬µ«Ò»Ð©Ö÷ÌâϵͳÒѱ»°Ü»µÎÞ·¨¸´Ô­»ò±»ÓÀԶɾ³ý¡£¼øÓÚÆû³µ¾­ÏúÉÌ´¦ÖÃÁË´óÁ¿¿Í»§µÄÓ×ÎҺͲÆÕþÐÅÏ¢£¬¸ÃÐÐÒµÔâµ½ÀÕË÷¹¥»÷µÄÇ÷ÏòÉÏÉý¡£


https://www.infosecurity-magazine.com/news/car-dealership-hit-by-major/