Òâ´óÀûÆóÒµÊܵ½±øÆ÷»¯µÄ USB ´«²¼¼ÓÃܽٳֶñÒâÈí¼þµÄ¹¥»÷

°ä²¼¹¦·ò 2024-02-02
1. Òâ´óÀûÆóÒµÊܵ½±øÆ÷»¯µÄ USB ´«²¼¼ÓÃܽٳֶñÒâÈí¼þµÄ¹¥»÷


1ÔÂ31ÈÕ£¬Ò»¸öÃûΪUNC4990µÄ³öÓÚ¾­¼Ã¶¯»úµÄÍþвÐÐΪÕßÔÚÀûÓñøÆ÷»¯ USB É豸×÷Ϊ³õʼϰȾý½é£¬ÒÔÒâ´óÀûµÄ×é֯Ϊָ±ê¡£UNC4990 ²Ù×÷ͨ³£Éæ¼°¿í·ºµÄ USB ϰȾ£¬¶øºó²¿Êð EMPTYSPACE ÏÂÔØ·¨Ê½¡£ÔÚÕâЩ²Ù×÷¹ý³ÌÖУ¬¼¯ÈºÒÀÀµ GitHub¡¢Vimeo ºÍ Ars Technica µÈµÚÈý·½ÍøÕ¾À´ÍйܱàÂëµÄ¸½¼Ó½×¶Î£¬²¢ÔÚÖ´ÐÐÁ´µÄÔçÆÚͨ¹ý PowerShell ÏÂÔØºÍ½âÂë¡£UNC4990 ×Ô 2020 Äêµ×ÆðÍ·»îÔ¾£¬Æ¾¾ÝÒâ´óÀû»ù´¡ÉèÊ©¿í·ºÓÃÓÚÖ¸»ÓÓë½ÚÔì (C2) Ö÷ÕÅ£¬¾ÝÆÀ¹ÀÔÚÒâ´óÀû¾³±íÔËÓª¡£Ä¿Ç°Éв»Ã÷ÏÔ UNC4990 ÊÇ·ñ½ö³äÈÎÆäËû²Î¼ÓÕߵijõʼ½Ó¼ûÍÆ½øÕß¡£ÍþвÐÐΪÕßµÄ×îÖÕÖ¸±êÒ²²»Ã÷ÏÔ£¬Ö»¹ÜÔÚÒ»¸öÀý×ÓÖУ¬Ìý˵ÔÚ¾­¹ýÊýÔµÄÐűê»î¶¯ºó²¿ÊðÁË¿ªÔ´¼ÓÃÜÇ®±ÒÍÚ¿ó·¨Ê½¡£


https://thehackernews.com/2024/01/italian-businesses-hit-by-weaponized.html?&web_view=true


2. CISA ÖÒ¸æ iOS¡¢iPadOS ºÍ macOS ÖеÄÑϳÁ·ì϶±»×Ô¶¯ÀûÓÃ


2ÔÂ1ÈÕ£¬ÃÀ¹úÍøÂ簲ȫºÍ»ù´¡ÉèÊ©°²È«¾Ö (CISA)ƾ¾Ý»îÔ¾ÀûÓõÄÖ¤¾Ý£¬½«Ó°Ïì iOS¡¢iPadOS¡¢macOS¡¢tvOS ºÍ watchOS µÄ¸ßÑϳÁÐÔȱµãÔö³¤µ½ÆäÒÑÖª¿ÉÀûÓ÷ì϶ ( KEV ) Ŀ¼ÖС£¸Ã·ì϶±àºÅΪCVE-2022-48618£¨CVSS ÆÀ·Ö£º7.8£©£¬Éæ¼°ÄÚºË×é¼þÖеÄÃýÎ󡣯»¹ûÔÚÒ»·Ý²¼¸æÖаµÊ¾£¬ ¡°ÓµÓÐËÁÒâ¶ÁдÄÜÁ¦µÄ¹¥»÷Õß¿ÉÄÜ¿ÉÄÜÈÆ¹ýÖ¸ÕëÉí·ÝÑéÖ¤¡±£¬²¢²¹³ä˵¸ÃÎÊÌâ¡°¿ÉÄÜÒѱ»Õë¶Ô iOS 15.7.1 ֮ǰ°ä²¼µÄ iOS °æ±¾ËùÀûÓᱡ£Õâ¼Ò iPhone Ôì×÷Ḛ́µÊ¾£¬¸ÃÎÊÌâÒÑͨ¹ý¸Ä½ø²é³­µÃµ½½â¾ö¡£Ä¿Ç°Éв»Ã÷ÏԸ÷ì϶ÈôºÎÔÚÏÖʵÊÀ½çµÄ¹¥»÷Öб»±øÆ÷»¯¡£ÓÐȤµÄÊÇ£¬¸Ã·ì϶µÄ²¹¶¡ÓÚ 2022 Äê 12 Ô 13 ÈÕËæiOS 16.2¡¢iPadOS 16.2¡¢macOS Ventura 13.1¡¢tvOS 16.2ºÍwatchOS 9.2µÄ°ä²¼¶ø°ä²¼£¬Ö»¹ÜÒ»Äê¶àºóµÄ 2024 Äê 1 Ô 9 ÈղŹ«¿ªÅû¶¡£ÖµÍ×ÌùÐĵÄÊÇ£¬Æ»¹ûÈ·ÇÐʵ 2022 Äê 7 Ô 20 ÈÕ°ä²¼µÄ iOS 15.6 ºÍ iPadOS 15.6 Öнâ¾öÁËÄÚºËÖеÄÀàËÆÈ±µã£¨ CVE-2022-32844 £¬CVSS ÆÀ·Ö£º6.3£©¡£


https://thehackernews.com/2024/02/cisa-warns-of-active-exploitation-of.html


3. ¿¨°Í˹»ù2024ÄêÔ¤²â£ºÀÕË÷Èí¼þºáÐÐ


2ÔÂ1ÈÕ£¬¿¨°Í˹»ù°ä²¼Á˹¤Òµ½ÚÔìÏµÍ³ÍøÂçÓ¦¼±ÏìÓ¦Ó××é (ICS CERT) 2024 ÄêµÄÔ¤²â£¬¸ÅÊöÁ˹¤ÒµÆóÒµÔÚ½«À´Ò»ÄêÃæ¶ÔµÄÖØÒªÍøÂ簲ȫÌôÕ½¡£ÕâЩԤ²âÇ¿µ÷ÁËÀÕË÷Èí¼þÍþвµÄ³ÖÐø´æÔÚ¡¢ÊÀ½çÕþÖκڿÍÐж¯Ö÷ÒåµÄ¹ÄÆð¡¢¶Ô¡°½ø¹¥ÐÔÍøÂ簲ȫ¡±Çé¿öµÄÕ°Íû£¬ÒÔ¼°ÎïÁ÷ºÍÔËÊäÍþвµÄË¢ÐÂÐÔת±ä¡£»ØÊ× 2023 Ä꣬¿¨°Í˹»ùÔ¤²â¹¤ÒµÍøÂ簲ȫ¸ñ¾Ö½«³ÖÐø·¢Õ¹£¬²¢³öÏÖ¼¸¸ö¹Ø¼üÇ÷Ïò¡£IIoT ºÍ SmartXXX ϵͳ¶ÔЧÄܵÄ×êÓªÍÆ¶¯Á˹¥»÷ÃæµÄÀ©´ó£¬¶øÄÜÔ´ÔËÓªÉ̼ÛÖµµÄì­Éýµ¼ÖÂÓ²¼þ³É±¾ÉÏÉý£¬´ÙʹսÊõתÏòÔÆ·þÎñ¡£µ±¾Ö¶Ô¹¤ÒµÁ÷³ÌµÄÔ½À´Ô½¶àµÄ²Î¼ÓÒ²´øÀ´ÁËеķçÏÕ£¬Ô̺¬ÓÉÓÚÔ±¹¤×ʸñ²»¼°ºÍÕÆ¹ÜÈεÄÅû¶ʵ¼Ê²»¼°¶øµ¼ÖÂÊý¾Ýй¶µÄÓÇÓô¡£2024 Ä깤ҵÆóÒµÃæ¶ÔµÄÍøÂ簲ȫ¾ÖÊÆÔ̺¬£ºÕë¶Ô¸ß¼ÛֵʵÌåµÄÀÕË÷Èí¼þ¡¢ÊÀ½çÕþÖο¹ÒéºÚ¿ÍÐж¯Ö÷ÒåºÍ¸ü°ÂÃîµÄÍþвºÍ¼ì²âÌôÕ½µÈ¡£


https://www.darkreading.com/vulnerabilities-threats/kasperskys-ics-cert-predictions-for-2024-ransomware-rampage-cosmopolitical-hacktivism-and-beyond


4. Europcar·ñ¶¨5000ÍòÓû§Êý¾Ýй¶£¬³ÆÊý¾ÝÊǼٵÄ


1ÔÂ31ÈÕ£¬Æû³µ×âÁÞ¹«Ë¾ Europcar °µÊ¾£¬ÔÚÍþвÐÐΪÕßÐû³ÆÏúÊÛ 5000 Íò¿Í»§µÄÓ×ÎÒÐÅÏ¢ºó£¬¸Ã¹«Ë¾²¢Î´Ôâ·êÊý¾Ýй¶£¬²¢ÇÒ¹²ÏíµÄ¿Í»§Êý¾ÝÊÇαÔìµÄ¡£ÓÐÈËÐû³ÆÔÚÒ»¸öÊ¢ÐеĺڿÍÂÛ̳ÉÏÏúÊÛ 48,606,700 Europcar.com ¿Í»§µÄÊý¾Ý¡£¸ÃÌû×ÓÔ̺¬ 31 Ãû Europcar ¿Í»§µÄ±»µÁÊý¾ÝÑù±¾£¬Ô̺¬ÐÕÃû¡¢µØÖ·¡¢µ®ÉúÈÕÆÚ¡¢¼ÝÊ»ÅÆÕÕºÅÂëºÍÆäËûÐÅÏ¢¡£Europcar ֪ͨ BleepingComputer ËûÃÇÏàÐÅÕâЩÊý¾ÝÊÇʹÓÃÈËΪÖÇÄÜ´´½¨µÄ£¬µ« Hunt Ö¸³ö£¬Ò»Ð©µç×ÓÓʼþµØÖ·ÊÇÕæÊµµÄ£¬³Ê´Ë¿Ì Have I Been Pwned ¼à¿ØµÄ֮ǰµÄÊý¾Ýй¶ÊÂÎñÖС£ÕýÈ簲ȫ×êÑÐÈËÔ±NexusFuzzyÖ¸³öµÄÄÇÑù £¬ ÏÖÓеÄÏîÄ¿ ÔÊÐíÈκÎÈË´´½¨¿´ÆðÀ´ÏÕЩÓëÐéαÊý¾Ýй¶Ñù±¾Öй²ÏíµÄÊý¾ÝÈç³öÒ»ÕÞµÄÊý¾Ý¡£¹ÌÈ» ÍþвÐÐΪÕßÒѾ­Ê¹ÓÃÈËΪÖÇÄÜ ×÷ΪÆäÚ¿Æ­ºÍ¹¥»÷µÄÒ»²¿ÃÅ£¬²¢ÇÒ ½«À´¿ÉÄÜ»áÀ©´óÆäʹÓÃÁìÓò£¬µ«ÕâÒ»ÊÂÎñËÆºõ²¢²»ÊÇÆäÖÐÖ®Ò»¡£


https://www.bleepingcomputer.com/news/security/europcar-denies-data-breach-of-50-million-users-says-data-is-fake/


5. Êý°Ù¸ö±»µÁµÄ RIPE ƾ֤ÔÚ°µÍøÉÏÏúÊÛ


2ÔÂ1ÈÕ£¬RIPE ÊÇÖж«ÁйúÒÔ¼°Å·Ö޺ͷÇÖÞÁйúµÄ IP µØÖ·¼°ÆäËùÓÐÕßÊý¾Ý¿â£¬×î½üÒѳÉΪÈȵãÖ¸±ê£¬ÓÉÓÚ¹¥»÷ÕßΪÁËÍøÂçÐÅÏ¢¶ø·ÛËéÁËÕÊ»§µÇ¼¡£²»Á¼ÐÐΪÕßÀûÓûñµÃµÄ RIPE ºÍÆäËûÃÅ»§µÄй¶ʹ´¦À´Ì½²âÊܺ¦Õß¿ÉÄÜÓÐÌØÈ¨½Ó¼ûµÄÆäËûÀûÓ÷¨Ê½ºÍ·þÎñ¡£Æ¾¾ÝGA»Æ½ð¼×ÆÀ¹À£¬´ËÀàÕ½ÊõÔö³¤ÁËËûÃdzɹ¦ÈëÇÖÖ¸±êÆóÒµºÍµçÐÅÔËÓªÉÌÍøÂçµÄ»úÓö¡£±¾ÔÂÔçЩʱ³½£¬  Orange Spain Ôâ·êÁË»¥ÁªÍøÖжÏ£¬Ô­ÒòÊǺڿÍÇÖÈëÁ˸ù«Ë¾µÄ RIPE ÕÊ»§£¬ÃýÎóÅäÖÃÁË BGP ·ÓÉºÍ RPKI ÅäÖá£Resecurity ×ܹ²ÔÚ RIPE ºÍÆäËûÇøÓòÍøÂ磨Ô̺¬ APNIC¡¢AFRINIC ºÍ LACNIC£©Öз¢ÏÖÁË 1,572 ¸ö¿Í»§ÕÊ»§£¬ÕâЩÕÊ»§ÒòÉæ¼°Redline¡¢Vidar¡¢Lumma¡¢Azorult ºÍ Taurus µÈ ³ÛÃûÃÜÂëÇÔÈ¡·¨Ê½µÄ¶ñÒâÈí¼þ»î¶¯¶øÊܵ½ÇÖº¦¡£


https://www.darkreading.com/cyberattacks-data-breaches/looted-ripe-credentials-for-sale-on-dark-web


6. ½­É­×ԿسÆÀÕË÷Èí¼þ¹¥»÷Ôì³É 2700 ÍòÃÀÔªËðʧ

1ÔÂ31ÈÕ£¬½­É­×Կعú¼Ê¹«Ë¾ (Johnson Controls International) È·ÈÏ£¬2023 Äê 9 ÔµÄÒ»´ÎÀÕË÷Èí¼þ¹¥»÷¸ø¸Ã¹«Ë¾Ôì³ÉÁË 2700 ÍòÃÀÔªµÄÓöÈ£¬²¢µ¼ÖºڿÍÇÔÈ¡¹«Ë¾Êý¾Ýºó²úÉúÊý¾Ýй¶¡£½­É­×Ô¿ØÊÇÒ»¼Ò¿ª·¢ºÍÔì×÷¹¤Òµ½ÚÔìϵͳ¡¢°²È«É豸¡¢¿ÕºÍгÏû·À°²È«É豸µÄ¿ç¹úÆóÒµ¼¯ÍÅ¡£ÕýÈç BleepingComputer ³õ´Î±¨Â·µÄÄÇÑù£¬ ½­É­×Ô¿Ø ÔÚÆäÑÇÖÞ´¦Ê´¦×î³õÔâµ½ÈëÇÖºó£¬ÓÚ 9 Ô·ÝÔâ·êÁËÀÕË÷Èí¼þ¹¥»÷£¬¹¥»÷Õ߱鲼Õû¸öÍøÂç¡£Õâ´Î¹¥»÷ÆÈʹ¸Ã¹«Ë¾¹Ø¹ØÁË´ó²¿ÃÅ IT »ù´¡ÉèÊ©£¬´Ó¶øÓ°ÏìÁËÃæÏò¿Í»§µÄϵͳ¡£Dark Angels ÀÕË÷Èí¼þÍÅ»ïÊÇÕâ´Î¹¥»÷µÄÄ»ºóºÚÊÖ£¬²¢Ðû³Æ´Ó Johnson Controls ÇÔÈ¡Á˳¬¹ý 27 TB µÄ»úÃÜÊý¾Ý¡£Ëæºó£¬ÍþвÐÐΪÕßË÷Òª 5100 ÍòÃÀÔªµÄÊê½ð£¬ÒÔɾ³ýÊý¾Ý²¢ÌṩÎļþ½âÃÜÆ÷¡£Dark Angels ÊÇÒ»¸öÀÕË÷Èí¼þÍŻÓÚ 2022 Äê 5 ÔÂÌáÒ飬ʹÓûùÓÚÏÖÒÑDzɢµÄ Babuk ºÍ Ragnar Locker ²Ù×÷µÄй¶Դ´úÂëµÄ¼ÓÃÜÆ÷¡£¸Ã¹«Ë¾ÈϿɷþÎñÖжÏ£¬ºóÀ´½«Ô­Òò¹éÒòÓÚ¡°ÍøÂ簲ȫÊÂÎñ¡±£¬µ«Ã»ÓÐÌṩÓйع¥»÷ÀàÐÍ»òµ¼ÖÂÊý¾Ýй¶µÄ¿ÉÄÜÐԵľßÌåÐÅÏ¢¡£


https://www.bleepingcomputer.com/news/security/johnson-controls-says-ransomware-attack-cost-27-million-data-stolen/