S¨¹dwestfalen IT±»ºÚµ¼Öµ¹ú70¶à¸ö³ÇÊеÄϵͳ崻ú

°ä²¼¹¦·ò 2023-11-03

1¡¢S¨¹dwestfalen IT±»ºÚµ¼Öµ¹ú70¶à¸ö³ÇÊеÄϵͳ崻ú


¾ÝýÌå11ÔÂ1ÈÕ±¨Â·£¬·þÎñÌṩÉÌS¨¹dwestfalen ITÔâµ½ÀÕË÷¹¥»÷£¬µ¼Öµ¹ú70¶à¸ö³ÇÊеÄÊÐÕþϵͳ崻ú¡£±¾ÖÜÒ»£¬¸Ã·þÎñÌṩÉ̵Äϵͳ±»¼ÓÃÜ¡£ÎªÁËÔ¤·À¶ñÒâÈí¼þ´«²¼£¬¸Ã¹«Ë¾ÖжÏÁË70¶à¸ö³ÇÊÐ¶ÔÆä»ù´¡ÉèÊ©µÄ½Ó¼û£¬ÖØÒªÓ°ÏìÁ˵¹úÎ÷²¿µÄ±±À³Òð-ÍþË¹ÌØ·¨Â×ÖÝ¡£¹¥»÷µ±Ì죬µÂ¹úÎý¸ùÊе±¾ÖÈ¡µÞÁ˹«ÃñµÄÔ¤Ô¼£¬½ØÖÁ±¾Öܶþ£¬¸ÃÊе±¾ÖµÄ´ó²¿ÃÅÔÚÏß·þÎñÈÔÎÞ·¨Ê¹Óá£Î¤Ã·¶û˹»ùÐ˺Ͳ¼¶ûɳÒÁµÂÊе±¾ÖµÄÍøÕ¾Ò²ÔÚÖÜÈý¹Ø¹Ø¡£µÂ¹ú¾¯·½ºÍ°²È«»ú¹¹ÔÚµ÷²éÕâÆðÊÂÎñ£¬²¢ÖÂÁ¦¸´Ô­³ÇÊÐÖÎÀí²¿ÃŵķþÎñ¡£


https://therecord.media/massive-cyberattack-hinders-services-in-germany


2¡¢Êý¾ÝÖÐÐÄÍ£µçµ¼ÖÂCloudflare¶à¸ö²úÆ·ÁÙʱÎÞ·¨Ê¹ÓÃ


¾Ý11ÔÂ2ÈÕ±¨Â·£¬CloudflareÖжϵ¼ÖÂÆäºÜ¶à²úÆ·ÎÞ·¨Ê¹Óá£Cloudflare°µÊ¾£¬Õâ¸öÎÊÌâÓ°ÏìÁËËùÓÐÒÀÀµÆäAPI»ù´¡ÉèÊ©µÄ·þÎñ£¬Ô̺¬½ÚÔìÃæ°å¡¢Cloudflare API¡¢LogpushºÍAlert Notification SystemµÈ¡£¿Í»§ÔÚ³¢ÊԵǼÕÊ»§²¢½Ó¼ûCloudflare½ÚÔìÃæ°åʱ£¬»á¿´µ½¡°Code:10000¡±Éí·ÝÑéÖ¤ÃýÎóºÍÄÚ²¿·þÎñÆ÷ÃýÎó¡£ÖжÏÁ½Ó×ʱºó£¬¸Ã¹«Ë¾Ð¹Â©£¬ÕâÊǶà¸öÊý¾ÝÖÐÐÄÍ£µçµ¼ÖµÄ¡£µ××ÓÔ­ÒòÊÇ·¢µç»ú¹ÊÕϵ¼ÖµÄÇøÓòÐÔµçÁ¦ÎÊÌ⣬Ôì³ÉÉ豸ÍÑ»ú¡£Ä¿Ç°£¬´ó²¿ÃÅ·þÎñ¶¼ÒѸ´Ô­¡£


https://www.bleepingcomputer.com/news/security/cloudflare-dashboard-and-apis-down-after-data-center-power-outage/


3¡¢Advarra¹«Ë¾Ôâµ½AlphVÀÕË÷¹¥»÷³¬¹ý120 GBÊý¾Ýй¶


ýÌå11ÔÂ1Èճƣ¬Ò½ÁÆ×ۺϽâ¾ö¹æ»®¹«Ë¾AdvarraÔâµ½ÁËÀÕË÷¹¥»÷¡£¾ÝϤ£¬¹¥»÷²úÉúÓÚ10ÔÂ25ÈÕ×óÓÒ£¬¹«Ë¾ÖÎÀíÈËÔ±°µÊ¾»Ø¾ø½»Êê½ð£¬Ò²²»Óë¹¥»÷Õß½»Éæ¡£10ÔÂ31ÈÕ£¬¹¥»÷ÕßÔÚAlphVÍøÕ¾ÉÏÁгöÁ˸ù«Ë¾£¬Ðû³ÆÒÑÇÔÈ¡Á˳¬¹ý120GBÊý¾Ý£¬Éæ¼°¿Í»§¡¢»¼ÕßÒÔ¼°Ô±¹¤¡£Advarra°µÊ¾£¬¹¥»÷Ô´ÓÚÒ»ÃûÔ±¹¤µÄµç»°ºÅÂë±»µÁ£¬¹¥»÷Õß½è´Ë½Ó¼ûÁ˸ÃÔ±¹¤µÄһЩÕË»§£¬Ô̺¬LinkedInºÍ¹¤×÷ÕË»§¡£


https://www.databreaches.net/exclusive-advarra-hacked-threat-actors-threatening-to-leak-data/


4¡¢VMware·¢ÏÖÊýÊ®¸öÄÚºËÇý¶¯·¨Ê½ÈÝÒ×Ôâµ½ÍøÂç¹¥»÷


VMware Carbon Black TAUÔÚ10ÔÂ31ÈÕ³ÆÆä·¢ÏÖÁË34¸öÒ×±»¹¥»÷µÄÄÚºËÇý¶¯·¨Ê½£¨30¸öWDMºÍ4¸öWDF£©¡£ÆäÖÐ6¸öÄܹ»ÓÃÀ´½Ó¼ûÄÚºËÄڴ棬ËùÓÐÇý¶¯·¨Ê½¶¼¿É±»ÓµÓзÇϵͳȨÏ޵Ĺ¥»÷ÕßÓÃÓÚÆëÈ«½ÚÔìÉ豸¡£Í¨¹ýÀûÓÃÕâЩÇý¶¯·¨Ê½£¬¹¥»÷ÕßÄܹ»²Á³ý»ò¸ü¸Ä¹Ì¼þ£¬ÒÔ¼°ÌáÉýȨÏÞ¡£ÕâЩÇý¶¯µÄ¿ª·¢ÈËÔ±ÒÑÓÚ2023Äê´º¼¾ÊÕµ½Í¨Öª£¬µ«Ö»ÓÐÁ½¼Ò¹«Ë¾½¨¸´ÁË·ì϶¡£VMwareÕë¶Ô¶à¸öÇý¶¯·¨Ê½¿ª·¢ÁËPoC·ì϶£¬ÒÔÑÝʾÈôºÎÀûÓÃËüÃÇÀ´²Á³ý¹Ì¼þ»òÌáÉýȨÏÞ¡£


https://blogs.vmware.com/security/2023/10/hunting-vulnerable-kernel-drivers.html


5¡¢Unit 42°ä²¼¹ØÓÚTurlaµÄºóÃÅKazuarбäÌåµÄ»ã±¨


10ÔÂ31ÈÕ£¬Unit 42°ä²¼Á˹ØÓÚTurlaºóÃÅKazuarµÄбäÌåµÄ·ÖÎö»ã±¨¡£KazuarÊÇÒ»¸ö.NETºóÃÅ£¬×÷ΪTurlaµÄµÚ¶þ½×¶ÎpayloadÓëÆäËü³£Óù¤¾ßһ·ʹÓá£ÔÚа汾ÖУ¬¹¥»÷ÕßʹÓÃÁ˸÷ÀิÔӵķ´·ÖÎö¼¼Êõ£¬²¢Í¨¹ýÓÐЧµÄ¼ÓÃܺͻìºÏÀ´±£»¤¶ñÒâÈí¼þ´úÂë¡£KazuarµÄÐÂÖ°ÄÜÔ̺¬£º¸üÈ«ÃæµÄϵͳ·ÖÎö£¬ÇÔÈ¡ÔÆÀûÓ÷¨Ê½ºÍÐźÅÐÂÎÅÀûÓ÷¨Ê½£¬Ö§³Ö45¸öºÅÁ¹¥»÷Õ߿ɿªÆô/¹Ø¹ØÒ»ÏµÁÐ×Ô¶¯»¯¹¤×÷£¬ÊµÏÖ·ÖÆçµÄ¼ÓÃÜËã·¨ºÍ¹æ»®£¬ÒÔ¼°ÓµÓжàÖÖ×¢Èëģʽ¡£


https://unit42.paloaltonetworks.com/pensive-ursa-uses-upgraded-kazuar-backdoor/


6¡¢HP°ä²¼2023ÄêµÚÈý¼¾¶ÈÍøÂç°²È«Ì¬ÊÆµÄ·ÖÎö»ã±¨


10ÔÂ31ÈÕ£¬HP°ä²¼ÁË2023ÄêµÚÈý¼¾¶ÈÍøÂç°²È«Ì¬ÊÆµÄ·ÖÎö»ã±¨¡£¹¥»÷ÕßÔÚQ3³ÖÐøÀûÓÃliving-off-the-land¹¥»÷Õ½Êõ£¬Í¨¹ýWindowsÄÚÖõŤ¾ßÖ´Ðй¥»÷¡£ÀûÓÃExcel²å¼þ(XLL)ÎļþµÄ»î¶¯¼¤Ôö£¬ÔÚ¹¥»÷Õß×î³£ÓõÄÎļþÀ©´óÃûÖУ¬ÆôÓúêµÄExcel²å¼þ¶ñÒâÈí¼þ´ÓQ2µÄµÚ46λÉÏÉýµ½µÚ7λ¡£HP»¹·¢ÏÖÁËÒ»¸öÕë¶ÔÀ­¶¡ÃÀÖ޾ƵêµÄ¹¥»÷»î¶¯£¬Ê¹ÓÃÁËÆôÓúêµÄPowerPoint²å¼þ¡£¹¥»÷Õß»¹ÔÚGitHubÉÏÍйÜαÔìµÄRAT£¬ÊÔͼÓÕÆ­²»×ã¾­ÑéµÄºÚ¿ÍϰȾËûÃÇ×Ô¼ºµÄPC¡£


https://threatresearch.ext.hp.com/hp-wolf-security-threat-insights-report-q3-2023/