ÍøÂç¹¥»÷µ¼ÖÂÅíÈø¿ÆÀÊе±¾Öµç»°Ïß·̱»¾
°ä²¼¹¦·ò 2024-03-213ÔÂ20ÈÕ£¬·ðÂÞÀï´ïÖÝÅíÈø¿ÆÀÊе±¾ÖÔÚ´¦ÖÃÒòÉÏÖÜÄ©°ä·¢µÄÍøÂç¹¥»÷¶øÔì³ÉµÄ´óÁìÓòµç»°ÖжÏÎÊÌâ¡£Êе±¾Ö½²»°È˼ÖÉ¡¤»ÝÀÕ (Jason Wheeler) ֪ͨ Recorded Future News£¬Êе±¾Ö¸÷¸ö²¿ÃŵĹÙÔ±¶¼Óöµ½Á˵绰ÎÊÌ⣬µ¼Ö 311 ¹«ÃñÖ§³Öϵͳ½Ó¹Ü·þÎñ³öÏÖÑÓÎó¡£911 µÈ´¹Î£µç»°ºÅÂëÈÔÔÚʹÓ㬻ÝÀÕ°µÊ¾£¬Äܹ»Ê¹Ó÷Ǵ¹Î£µç»°ºÅÂëÁªÏµÅíÈø¿ÆÀ¾¯Ô±¾ÖºÍÏû·À¾Ö¡£¸ÃÊл¹ÎªÄÜÔ´²¿ÃÅ¡¢ÎÀÉú²¿ÃÅ¡¢¹«¹²¹¤³Ì¡¢¹¤³Ì¡¢×¡·¿ºÍÆäËû²¿ÃÅ´´½¨Á˱¸Óõ绰ºÅÂë¡£¡¶ÅíÈø¿ÆÀÐÂÎÅÈÕ±¨¡·³Æ»ÝÀÕÏòËûÃÇ´«µÝÁËÍøÂç¹¥»÷£¬²¢³ÁÉ꾯ԱºÍÏû·ÀµÈ´¹Î£·þÎñ²¢Î´Êܵ½Í£µçÓ°Ïì¡£ÅíÈø¿ÆÀλÓÚ·ðÂÞÀï´ïÖݺͰ¢À°ÍÂíÖݽÓÈÀ´¦£¬¾àĪ±È¶ûÔ¼Ò»Ó×ʱ³µ³Ì£¬Õ¼Óг¬¹ý 53,000 Ãû¾ÓÃñ¡£¸ÃÊдËÇ°ÔøÔâ·ê¹ýÀÕË÷Èí¼þ¹¥»÷£¬ÔÚ 2019 ÄêµÄÒ»´ÎÊÂÎñÖÐÔøÓëÀ´×Ô Maze ÀÕË÷Èí¼þÍÅ»ïµÄºÚ¿Í´ò½»Â·¡£¾Ý¡¶ÅíÈø¿ÆÀÐÂÎÅÔÓÖ¾¡·±¨Â·£¬¸ÃÍÅ»ïÇÔÈ¡ÁË 2GB Êý¾Ý£¬µ«Êе±¾Ö»Ø¾øÖ§¸¶Êê½ð£¬¶øÊÇÆÆ·ÑÁËÔ¼ 30 ÍòÃÀÔª´ÓÊÂÎñÖи´Ô¹ýÀ´¡£¸ÃÊб»ÆÈ֪ͨ³¬¹ý 57000 ÈË£¬ËûÃǵÄÐÅÏ¢ÔÚÏ®»÷ÆÚ¼ä±»µÁÈ¡¡£
https://therecord.media/cyberattack-pensacola-florida-knocks-out-phones?&web_view=true
2. °×¹¬ºÍ»·±£¾ÖÖÒ¸æºÚ¿Í¿ÉÄܹ¥»÷¹©Ë®ÏµÍ³
3ÔÂ19ÈÕ£¬ÃÀ¹ú¹ú¶È°²È«ÕÕ·÷½Ü¿Ë¡¤É³ÀûÎĺͻ·¾³±£»¤¾Ö (EPA) ¾Ö³¤Âõ¿Ë¶û¡¤Àï¸ù½ñÌìÖÒ¸æÖݳ¤ÃÇ£¬ºÚ¿ÍÔÚ¹¥»÷È«¹úË®Îñ²¿ÃŵĹؼü»ù´¡ÉèÊ©¡£ÔÚÖܶþ·¢Ë͵ÄÒ»·â½áºÏÐÅÖУ¬ËûÃÇÒªÇóÖݳ¤ÃÇÌṩ֧³Ö£¬ÒÔÈ·±£¸÷ÖݵĹ©Ë®ÏµÍ³µÃµ½³ä·Ö·ÀÓù£¬ÃâÊÜÍøÂç¹¥»÷£¬²¢ÇÒÔÚÔâµ½·ÛËéʱ¿ÉÄܸ´Ô¡£¹ú¶È°²È«Î¯Ô±»á (NSC) ºÍ»·¾³±£»¤¾Ö (EPA) Ô¼ÇëÖݳ¤ÃDzÎÓë 3 Ô 21 ÈÕµÄÐé¹¹»áÒ飬ÒÔ¼Ó¾¢µÐÔÖʵÌåºÍˮϵͳ֮¼äµÄºÏ×÷£¬²¢³ÉÁ¢Ë®²¿ÃÅÍøÂ簲ȫ¹¤×÷×é¡£¸Ã¹¤×÷×齫կ¹ÜÈ·¶¨¿ÉÔÚÈ«¹úÁìÓòÄÚÖ´ÐеÄÐж¯ºÍÕ½Êõ£¬ÒÔ¾¡Á¿Ï÷¼õ¹©Ë®ÏµÍ³Ôâ·êÍøÂç¹¥»÷µÄ·çÏÕ¡£½ü¼¸¸öÔÂÀ´£¬¶à¸öÍþв×éÖ¯¶¼¶Ô×¼²¢·ÛËéÁËÃÀ¹úµÄ¹©Ë®ÏµÍ³¡£IRGC ´ÓÊôÍþвÐÐΪÕßÉøÈëÁ˱öϦ·¨ÄáÑÇÖݵũˮÉèÊ©£¬¶ø Volt Typhoon ºÚ¿ÍÔòÈëÇÖÁ˹ؼü»ù´¡ÉèÊ©×éÖ¯µÄÍøÂ磬Ô̺¬ÒûÓÃˮϵͳ¡£
https://www.bleepingcomputer.com/news/security/white-house-and-epa-warn-of-hackers-breaching-water-systems/
3. еĴ¹µö¹¥»÷ÀûÓà Office ²¿Êð NetSupport RAT
3ÔÂ19ÈÕ£¬Ò»ÏîеÄÍøÂç´¹µö»î¶¯Õë¶ÔÃÀ¹ú£¬Ö¼ÔÚ²¿ÊðÃûΪ NetSupport RAT µÄÔ¶³Ì½Ó¼ûľÂí¡£ÒÔÉ«ÁÐÍøÂ簲ȫ¹«Ë¾ Perception Point ÔÚ×·×ÙÃûΪ¡°Operation PhantomBlu¡±µÄ»î¶¯¡£PhantomBlu ²Ù×÷ÒýÈëÁËÒ»ÖÖ°ÂÃîµÄÀûÓò½Ö裬Óë NetSupport RAT µÄµäÐͽ»¸¶»úÔì·ÖÆç£¬ËüÀûÓà OLE£¨¶ÔÏóÁ´½ÓºÍǶÈ룩ģ°å²Ù×÷£¬ÀûÓà Microsoft Office ÎĵµÄ£°åÖ´ÐжñÒâ´úÂ룬ͬʱÌӱܼì²â¡£NetSupport RAT ÊǺϷ¨Ô¶³Ì×ÀÃæ¹¤¾ß£¨³ÆÎª NetSupport Manager£©µÄ¶ñÒâ·ÖÖ§£¬ÔÊÐíÍþв²Î¼ÓÕßÔÚÊÜϰȾµÄ¶ËµãÉÏÖ´ÐÐһϵÁÐÊý¾ÝÍøÂç²Ù×÷¡£ÆðµãÊÇÒ»·âÒÔн×ÊΪÖ÷ÌâµÄÍøÂç´¹µöµç×ÓÓʼþ£¬¸Ãµç×ÓÓʼþÐû³ÆÀ´×Ô¹ÜÕʲ¿ÃÅ£¬²¢¶½´ÙÊÕ¼þÈË´ò¿ªË渽µÄ Microsoft Word ÎĵµÒԲ鿴¡°Ô¶Èн×ʻ㱨¡±¡£¶Ôµç×ÓÓʼþ±êÍ·£¨ÓÈÆäÊÇ Return-Path ºÍ Message-ID ×ֶΣ©µÄ×Ðϸ·ÖÎöÅú×¢£¬¹¥»÷ÕßʹÓÃÃûΪ Brevo£¨ÒÔǰ³ÆÎª Sendinblue£©µÄºÏ·¨µç×ÓÓʼþÓªÏúƽ̨À´·¢Ë͵ç×ÓÓʼþ¡£Word Îĵµ´ò¿ªºó£¬»áÅúʾÊܺ¦ÕßÊäÈëµç×ÓÓʼþÕýÎÄÖÐÌṩµÄÃÜÂë²¢ÆôÓñà×룬¶øºóË«»÷ÎĵµÖÐǶÈëµÄ´òÓ¡»úͼ±êÒԲ鿴¹¤×Êͼ±í¡£
https://thehackernews.com/2024/03/new-phishing-attack-uses-clever.html
4. ·¨¹ú×îTravail³Á´ó°²È«·ì϶й¶³¬¹ý 4300 ÍòÓ×ÎÒÐÅÏ¢
3ÔÂ13ÈÕ£¬¾Ý±¨Â·£¬¸Ã¹«Ë¾³ÉΪÊý¾Ýй¶µÄÊܺ¦Õߣ¬¸ÃÊÂÎñ¶³öÁË×¢²áÓû§µÄÓ×ÎÒ¾ßÌåÐÅÏ¢£¬Ô̺¬ÐÕÃû¡¢Éç»á°²È«ºÅÂë¡¢µ®ÉúÈÕÆÚ¡¢µç×ÓÓʼþµØÖ·¡¢ÓÊÕþµØÖ·¡¢µç»°ºÅÂëºÍÓû§±êʶ·û¡£ÕâÒ»ÊÂÎñÓ°ÏìÁ˸ùúÔ¼Èý·ÖÖ®¶þµÄÈ˶¡£¬Òý·¢ÁËÈËÃǶÔڲƺÍÉí·Ý͵ÇÔ·çÏÕµÄÓÇÓô¡£·¢ÏÖÕâÒ»ÊÂÎñºó£¬¸Ã»ú¹¹µ±¼´Í¨Öª·¨¹ú¹ú¶ÈÐÅÏ¢Óë×ÔÓÉίԱ»á£¨CNIL£©²¢Ïò¾¯·½±¨°¸£¬Æô¶¯Õýʽµ÷²é¡£³õ´ëÊ©²éÁ˾ÖÏÔʾ£¬·¸×ïÕßÓÚ 2 Ô 6 ÈÕ¼ÙÒâÒ»ÃûÔ±¹¤£¬Î´¾ÊÚȨ½Ó¼ûÁ˸ûú¹¹µÄϵͳ¡£Ö»¹Ü¸Ã»ú¹¹Ç¿µ÷ÒøÐÐÐÅÏ¢ºÍÕË»§ÃÜÂ벢δ±»µÁ£¬µ« CNIL ÖÒ¸æ³Æ£¬·¸×ï·Ö×Ó¿ÉÄÜ»áÀûÓÃÅû¶µÄÊý¾Ý´ÓÆäËûÆðÔ´ÍøÂç¸ü¶àÐÅÏ¢¡£Òò¶ø£¬½¨Ò鹫Ãñ¶ÔDZÔÚµÄÍøÂç´¹µö¡¢Ú²ÆºÍÉí·Ý͵ÇÔά³Ö¾¯Ìè¡£¸ÃίԱ»á»¹Ð¹Â©£¬Õâ´ÎÊý¾Ýй¶¿ÉÄÜ»áÓ°Ïì´Óǰ 20 ÄêÀ´µÄÏÖÈκÍǰÈÎÇóÖ°Õß¡£¾Ý CNIL ³Æ£¬ËùÓÐÊÜÓ°ÏìµÄÓû§¶¼½«ÊÕµ½µ¥¶À֪ͨ¡£´Ë±í£¬¼¤ÀøËùÓÐÊܺ¦ÕßÏò°ÍÀè¼ì²ì¹Ù°ì¹«ÊÒÌá³öÉêÊö£¬ÒÔÐÖúµ÷²é¡£
https://meterpreter.org/france-travail-breach-compromises-data-of-millions/
5. Êý°Ù¸öÍøÕ¾ÃýÎóÅäÖà Firebase й¶³¬¹ý 1.25 ÒÚÌõÓû§¼Í¼
3ÔÂ19ÈÕ£¬ÕâËùÓж¼Ê¼ÓÚChattr µÄºÚ¿Í¹¥»÷£¬ÕâÊÇÒ»¸öΪÃÀ¹ú¶à¸ö×éÖ¯Ìṩ·þÎñµÄÈËΪÖÇÄÜÕÐÆ¸ÏµÍ³£¬ÆäÖÐÔ̺¬ Applebee's¡¢Chick-fil-A¡¢KFC¡¢Subway¡¢Taco Bell ºÍ Wendy's µÈ¿ì²ÍÁ¬Ëøµê¡£Chattr µÄFirebaseÖ´ÐÐÖеÄÒ»¸öÈõµãʹµÃ×êÑÐÈËÔ±¿ÉÄÜͨ¹ý×¢²áÐÂÓû§À´»ñµÃÊý¾Ý¿âµÄÆëȫȨÏÞ¡£ËûÃÇ»ñµÃÁËÐÕÃû¡¢µç»°ºÅÂë¡¢µç×ÓÓʼþµØÖ·¡¢Ä³Ð©ÕÊ»§µÄÃ÷ÎÄÃÜÂë¡¢»úÃÜÐÂÎŵȵĽӼûȨÏÞ¡£×êÑÐÈËÔ±°µÊ¾£¬ÊÜÓ°ÏìµÄÓ×ÎÒÔ̺¬Ô±¹¤¡¢ÌØÐí¾Óª¾ÀíºÍÇóÖ°Õß¡£Í¨¹ý´´½¨ÐµÄÖÎÀíÕÊ»§£¬×êÑÐÈËÔ±Äܹ»½Ó¼ûÖÎÀíÒDZí°å£¬ÕâÌṩÁ˶ÔϵͳµÄ¸ü¶à½Ó¼ûȨÏÞ£¬Ô̺¬ÍË¿îÑ¡Ïî¡£»¹·¢ÏÖÁËÒ»ÖÖ¶î±íµÄ¡°¹í»ê¡±Ä£Ê½£¬Ìṩ¶ÔÕ˵¥ÐÅÏ¢µÄ½Ó¼û¡¢¶ÔÓû§ÕÊ»§µÄÆëÈ«½ÚÔìÒÔ¼°¹ÍÓÃÈËÔ±µÄÑ¡Ïî¡£
https://www.securityweek.com/misconfigured-firebase-instances-expose-125-million-user-records/
6. ³¬¹ý 13Íǫ̀ Fortinet É豸Ò×Êܵ½ CVE-2024-21762 µÄÓ°Ïì
3ÔÂ19ÈÕ£¬Ö»¹Ü·ì϶²¹¶¡ÒѾ¸üУ¬µ«Â¶³öÔÚ¹«¹²»¥ÁªÍøÉÏÇÒÒ×ÊÜ FortiOS Ò»¸öÔÂǰÑϳÁ°²È«·ì϶ӰÏìµÄ Fortinet ºÐ×ÓÊýÁ¿ÒÀÈ»¼«¶È¸ß¡£Æ¾¾Ý°²È«·ÇͶ»ú×éÖ¯ Shadowserver µÄ×îÐÂÊý¾Ý£¬Ò×ÊÜ CVE-2024-21762 Ó°ÏìµÄ Fortinet É豸ÊýÁ¿³¬¹ý 133000 ̨£¬½ö±ÈÊ®ÌìǰµÄ 150000 ¶ą̀ÂÔÓнµÂä¡£ÊýÁ¿×î¶àµÄÊÇÑÇÖÞ£¬ÓÐ 54310 ̨É豸ÒÀÈ»ÈÝÒ×Êܵ½ÑϳÁ RCE ·ì϶µÄÓ°Ïì¡£±±ÃÀºÍÅ·ÖÞ±ðÀëÒÔ 34945 ºÍ 28058 Õ¼¾ÝµÚ¶þºÍµÚÈý룬ÆäÓàΪÄÏÃÀÖÞ¡¢·ÇÖ޺ʹóÑóÖÞ¡£Â¶³öµÄ SSL VPN µÄÊýÁ¿ËµÁËÈ»¸Ã¹Ø¼ü·ì϶µÄ¿í·º¹¥»÷Ãæ£¬²¢ÇÒÒÑÖª¸Ã·ì϶Òѱ»»ý¼«ÀûÓá£
https://www.theregister.com/2024/03/18/more_than_133000_fortinet_appliances/?&web_view=true


¾©¹«Íø°²±¸11010802024551ºÅ