CLOROX ¹À¼Æ 8 Ô·ÝÍøÂç¹¥»÷Ôì³ÉµÄËðʧ½«³¬¹ý 4900 ÍòÃÀÔª
°ä²¼¹¦·ò 2024-02-051. CLOROX ¹À¼Æ 8 Ô·ÝÍøÂç¹¥»÷Ôì³ÉµÄËðʧ½«³¬¹ý 4900 ÍòÃÀÔª
2ÔÂ3ÈÕ£¬Õâ¼ÒÇå½à²úÆ·¾ÞÍ· ÓÚ 8 ÔÂÖÐÑ®°ä·¢£¬ËüÊÇÒ»´ÎÍøÂ簲ȫÊÂÎñµÄÊܺ¦Õß £¬¸ÃÊÂÎñÆÈʹËü¹Ø¹ØÁËһЩϵͳ¡£Ä¿Ç°£¬¸ßÀÖÊÏÉÐδ·ÖÏíÍøÂç¹¥»÷µÄ¼¼Êõϸ½Ú¡£ËùÃèÊöµÄÓ°ÏìÅú×¢¸Ã¹«Ë¾¿ÉÄÜÔâ·êÀÕË÷Èí¼þ¹¥»÷¡£Æ¾¾ÝÏò SEC Ìá½»µÄÎļþ£¬Clorox ¹À¼Æ 2023 Äê 8 ÔÂÏ®»÷¸Ã¹«Ë¾µÄÍøÂç¹¥»÷Ôì³ÉµÄ¾¼ÃÓ°ÏìΪ 4900 ÍòÃÀÔª¡£ÕâЩ³É±¾Ô̺¬ÖжÏÔì³ÉµÄËðʧ£¬ÒÔ¼°ÐÖú¹«Ë¾µ÷²éºÍ²¹¾È¹¥»÷µÄµÚÈý·½È¡Ö¤ºÍÕÕ·÷µÄÓöȡ£¸Ã¹«Ë¾»¹Ô¤¼Æ 2024 ²ÆÄêÒµ¼¨½«³öÏÖ¸ºÃæÓ°Ïì¡£¸Ã¹«Ë¾²¹³ä˵£¬ÔÚ½ØÖÁ 2023 Äê 12 Ô 31 ÈÕµÄÈý¸öÔºÍÁù¸öÔÂÄÚ£¬ËüûÓмͼÓëÍøÂç¹¥»÷ÓйصÄÈκα£ÏÕÊÕÒæ¡£±£ÏÕÅâ³¥¼òÖ±ÈÏ£¨ÈôÊǺÏÓã©¿ÉÄÜÓëÈ·ÈÏÓйØÓöȵŦ·ò²»Ò»Ö¡£
https://securityaffairs.com/158575/security/clorox-attack-costs-exceed-49m.html
2. AnyDesk Ôâµ½ºÚ¿ÍÈëÇÖ£¬Æä³ö²ú·þÎñÆ÷ÃÜÂë±»³ÁÖÃ
2ÔÂ2ÈÕ£¬AnyDesk ½ñÌì֤ʵ£¬Ëü×î½üÔâ·êÁËÒ»´ÎÍøÂç¹¥»÷£¬ºÚ¿ÍµÃÒÔ½Ó¼û¸Ã¹«Ë¾µÄ³ö²úϵͳ¡£BleepingComputer »ñϤ£¬Ô´´úÂëºÍ˽ÓдúÂëÊðÃûÃÜÔ¿ÔÚ¹¥»÷ÆÚ¼ä±»µÁ¡£AnyDesk ÊÇÒ»ÖÖÔ¶³Ì½Ó¼û½â¾ö¹æ»®£¬ÔÊÐíÓû§Í¨¹ýÍøÂç»ò»¥ÁªÍøÔ¶³Ì½Ó¼ûÍÆËã»ú¡£¸Ã·¨Ê½¼«¶ÈÊÜÆóÒµÓ½Ó£¬ÆóҵʹÓÃËüÀ´ÌṩԶ³ÌÖ§³Ö»ò½Ó¼ûÍйܷþÎñÆ÷¡£¸ÃÈí¼þÔÚÍþвÐÐΪÕßÖÐÒ²ºÜÊÜÓ½Ó£¬ËûÃÇʹÓÃËüÀ´ ³ÖÐø½Ó¼ûÊÜ·ÛËéµÄÉ豸ºÍÍøÂç¡£¸Ã¹«Ë¾»ã±¨³ÆÕ¼ÓÐ 170,000 Ãû¿Í»§£¬Ô̺¬ 7-11¡¢¿µ¿¨Ë¹ÌØ¡¢ÈýÐÇ¡¢ÂéÊ¡Àí¹¤Ñ§Ôº¡¢Ó¢Î°´ï¡¢Î÷ÃÅ×ӺͽáºÏ¹ú¡£
https://www.bleepingcomputer.com/news/security/anydesk-says-hackers-breached-its-production-servers-reset-passwords/#google_vignette
3. Uber ±»ºÉÀ¼Êý¾Ý¼à¹Ü»ú¹¹·£¿î 1000 ÍòÅ·Ôª
2ÔÂ1ÈÕ£¬ºÉÀ¼Êý¾Ý±£»¤»ú¹¹·¢ÏÖ Uber δÄܹ«¿ªÆä±£Áô˾»úÊý¾ÝµÄ¹¦·òÒÔ¼°ÄÄЩŷÖÞÒÔ±íµÄÔ±¹¤Äܹ»½Ó¼ûÕâЩÊý¾Ý£¬Òò¶ø¸Ã»ú¹¹±ØÐëÏò Uber Ö§¸¶ 1000 ÍòÅ·ÔªµÄ·£¿î¡£Õâ´Î·£¿îÊÇÆ¾¾Ý 172 Ãû·¨¹ú Uber ˾»úºÍ×ܲ¿Î»ÓÚ°ÍÀèµÄÃñ¼äÉç»á×éÖ¯ Ligue des Droits de l'Homme et du Citoyen (LDH) Ìá³öµÄͶËß¶ø²úÉúµÄ¡£×î³õµÄͶËßÊÇÏò·¨¹úÊý¾Ý¼à¹Ü»ú¹¹Ìá³öµÄ£¬µ«ÓÉÓڸù«Ë¾µÄÅ·ÖÞ×ܲ¿Î»ÓÚ°¢Ä·Ë¹Ìص¤£¬Òò¶øºÉÀ¼¼à¹Ü»ú¹¹³Ðµ£Á˹ÜϽȨ¡£ºÉÀ¼ÃÀÁªÉçÖ÷ϯ°¢À³µÂ¡¤ÎÖ¶û·òÉ (Aleid Wolfsen) °µÊ¾£º¡°Uber Óû§ÓÐȨ֪· Uber ÈôºÎ´¦ÖÃËûÃǵÄÊý¾Ý¡£µ«ÊÇ£¬Uber ²¢Ã»ÓжԴ˽øÐÐ×ã¹»Ç峺µÄÚ¹ÊÍ¡£¡± ¡°ÕâÅú×¢ Uber ÉèÖÃÁ˸÷Àà×è°£¬×èÖ¹Óû§ÐÐʹÆäÒþÖÔȨ£¬¶øÕâÊDZ»²»Èݵġ£¡±
https://www.bankinfosecurity.com/uber-fined-10-million-euros-by-dutch-data-regulator-a-24250?&web_view=true
4. ¹ú¼ÊÐ̾¯×éÖ¯ Synergia Ðж¯·ÛËé 1300 ̨ÓÃÓÚ·¸×ïµÄ·þÎñÆ÷
2ÔÂ2ÈÕ£¬´úºÅΪ¡°Synergia¡±µÄ¹ú¼Ê·¨ÂÉÐж¯ÒѹعØÁË 1,300 ¶à¸öÓÃÓÚÀÕË÷Èí¼þ¡¢ÍøÂç´¹µöºÍ¶ñÒâÈí¼þ»î¶¯µÄºÅÁîºÍ½ÚÔì·þÎñÆ÷¡£ºÅÁîºÍ½ÚÔì·þÎñÆ÷ (C2) ÊÇÓÉÍþвÐÐΪÕß²Ù×÷µÄÉ豸£¬ÓÃÓÚ½ÚÔì¹¥»÷ÖÐʹÓõĶñÒâÈí¼þ²¢ÍøÂç´ÓÊÜϰȾÉ豸·¢Ë͵ÄÐÅÏ¢¡£ÕâЩ·þÎñÆ÷ÔÊÐíÍþвÐÐΪÕßÍÆËͶî±íµÄÓÐЧ¸ºÔØ»òºÅÁîÒÔÔÚÊÜϰȾµÄÉ豸ÉÏÖ´ÐУ¬Ê¹ËüÃdzÉΪºÜ¶à¹¥»÷Öв»³É»òȱµÄ¼Ü¹¹¡£¶ÔÓÚijЩ¶ñÒâÈí¼þ£¬Ê¹ºÅÁîºÍ½ÚÔì·þÎñÆ÷ÍÑ»úÄܹ»Ô¤·À½øÒ»²½µÄ¶ñÒâ»î¶¯£¬ÓÉÓÚÍþвÐÐΪÕßÎÞ·¨´ÓÊÜϰȾµÄÉ豸·¢ËÍ»ò½Ó¹ÜÊý¾Ý¡£Synergia Ðж¯ÔÚ 2023 Äê 9 ÔÂÖÁ 11 ÔÂÆÚ¼ä¼ø±ð²¢¹Ø¹ØÁËÖ¸»ÓºÍ½ÚÔì·þÎñÆ÷£¬À´×Ô 55 ¸ö¹ú¶ÈµÄ 60 ¸ö·¨ÂÉ»ú¹¹²Î¼ÓÁ˸ÃÐж¯¡£
https://www.bleepingcomputer.com/news/legal/interpol-operation-synergia-takes-down-1-300-servers-used-for-cybercrime/
5.FritzFrog ½©Ê¬ÍøÂç¹¥»÷ Linux ·þÎñÆ÷ÇÔÈ¡ SSH ƾ֤
2ÔÂ2ÈÕ£¬FritzFrog ½©Ê¬ÍøÂç×î³õÓÚ 2020 Äê±»·¢ÏÖ£¬ÊÇÒ»ÖÖÓà Golang ¹¹½¨µÄ¸ß¼¶µã¶Ôµã½©Ê¬ÍøÂ磬Äܹ»ÔÚ»ùÓÚ AMD ºÍ ARM µÄÉ豸ÉÏÔËÐС£Ëæ×Ų»ÐݵĸüУ¬¶ñÒâÈí¼þËæ×Ź¦·òµÄÍÆÒÆ²»ÐÝ·¢Õ¹£¬Ôö³¤ºÍ¼ÓÇ¿ÁËÖ°ÄÜ¡£ÈËÃÇ·¢ÏÖÁË FritzFrog ½©Ê¬ÍøÂçµÄбäÖÖ£¬ËüÀûÓÃLog4Shell ·ì϶À´Õë¶ÔÄÚ²¿ÍøÂçÖеÄËùÓÐÖ÷»ú¡£´Ë±í£¬Í¨¹ýʹÓÃÈõ SSH Í´´¦£¬¶ñÒâÈí¼þ»á¹¥»÷¿Éͨ¹ý»¥ÁªÍø½Ó¼ûµÄ·þÎñÆ÷¡£Akamai Óë¡¶ÍøÂ簲ȫÐÂÎÅ¡··ÖÏí·£º¡°½ÏеıäÌå´Ë¿Ì»á¶ÁÈ¡ÊÜϰȾÖ÷»úÉϵĶà¸öϵͳÎļþ£¬ÒÔ¼ì²âºÜ¿ÉÄÜÈÝÒ×Êܵ½¹¥»÷µÄDZÔÚÖ¸±ê¡£¡±FritzFrog ʹÓõÄΨһϰȾý½éÊÇ SSH±©Á¦ÆÆ½â£»È»¶ø£¬¸Ã¶ñÒâÈí¼þµÄ×îа汾Ôö³¤ÁËÃûΪ¡°Frog4Shell¡±µÄ Log4Shell ·ì϶ÀûÓá£
https://gbhackers.com/fritzfrog-botnet-linux-servers/
6. PurpleFox ¶ñÒâÈí¼þϰȾÎÚ¿ËÀ¼ÊýÇ§Ì¨ÍÆËã»ú
2ÔÂ1ÈÕ£¬ÎÚ¿ËÀ¼ÍÆËã»ú´¹Î£ÏìÓ¦Ó××é (CERT-UA) ÖÒ¸æ³Æ£¬PurpleFox ¶ñÒâÈí¼þ»î¶¯ÒÑϰȾ¸Ã¹úÖÁÉÙ 2,000 Ì¨ÍÆËã»ú¡£ÕâÖÖ¿í·ºÏ°È¾¼òÖ±ÇÐÓ°ÏìÒÔ¼°ËüÊÇ·ñÓ°ÏìÁ˹ú¶È×éÖ¯»òͨ³£È˵ÄÍÆËã»úÉÐδȷ¶¨£¬µ«¸Ã»ú¹¹ÒѾ·ÖÏíÁËÓйØÈôºÎ¶¨Î»Ï°È¾ºÍɾ³ý¶ñÒâÈí¼þµÄ¾ßÌåÐÅÏ¢¡£PurpleFox£¨»ò¡°DirtyMoe¡±£©ÊÇÒ»ÖÖ Ä£¿é»¯ Windows ½©Ê¬ÍøÂç¶ñÒâÈí¼þ £¬ÓÚ 2018 Äê³õ´Î·¢ÏÖ£¬´øÓÐ rootkit Ä£¿é£¬ÔÊÐíÆäÔÚÉ豸³ÁÐÂÆô¶¯ÆÚ¼ä°µ²Ø²¢³ÖÐø´æÔÚ¡£ËüÄܹ»ÓÃ×÷ÏÂÔØ·¨Ê½£¬ÔÚÊÜϰȾµÄϵͳÉÏÒýÈë¸ü׳´óµÄµÚ¶þ½×¶ÎÓÐЧ¸ºÔØ£¬ÎªÆäÔËÓªÉÌÌṩºóÃÅÖ°ÄÜ£¬»¹Äܹ»³äÈÎÉ¢²¼Ê½»Ø¾ø·þÎñ£¨DDoS£©»úеÈË¡£
https://www.bleepingcomputer.com/news/security/purplefox-malware-infects-thousands-of-computers-in-ukraine/?&web_view=true


¾©¹«Íø°²±¸11010802024551ºÅ