ÍøÂç·¸×ï·Ö×Ó½« Raspberry Pi Ôì³Éڲƺͼäµý¹¤¾ß
°ä²¼¹¦·ò 2024-03-273ÔÂ25ÈÕ£¬Ò»ÖÖÃûΪ GEOBOX µÄÐÂÈí¼þ°üѡȡ¼Ûֵʵ»ÝÇÒ¿í·ºÊ¹ÓõÄRaspberry PiÍÆËã»ú£¬²¢½«Æäת±äΪ¸´ÔÓµÄÄäÃû¹¤¾ß - רΪڲơ¢¼äµý»î¶¯ºÍÈÆ¹ý°²È«½ÚÔì¶ø¶¨Ôì¡£GEOBOX ÔÚ°µÍøÂÛ̳Éϵĸæ°×¼ÛÖµ½öΪÿÔ 80 ÃÀÔª£¬³ÐÅµÍøÂç·¸×ï·Ö×Ó¿ÉÄÜ£ºÐéα GPS µØÎ»£»ºýÅªÍøÂçÉèÖú͸²¸Ç»¥ÁªÍø»î¶¯¡£GEOBOX ϵͳµÄÉè¼Æ¼«¶Èµ¥Ò»¡£Í¨¹ýÌṩÓû§Êֲᣬ¼´±ã¼¼Êõרҵ֪ʶÓÐÏÞµÄÈËÒ²¿ÉÄܻᲿÊðÕâÖÖΣÏյŤ¾ß¡£GEOBOX ÒÔ¼°ÀàËÆ¹¤¾ß¸ø·¨Âɲ¿ÃźÍÍøÂ簲ȫÉçÇø´øÀ´ÁËÔ½À´Ô½´óµÄÌôÕ½¡£Ëæ×ÅÁªÍøÉ豸±äµÃÔ½·¢×³´óÇÒ¼Ûֵʵ»Ý£¬ÍøÂç·¸×ï·Ö×ÓÔÚѰÕÒеIJ½ÖèÀ´ÀûÓÃËüÃÇ¡£
https://securityonline.info/cybercriminals-turn-cheap-raspberry-pi-into-powerful-fraud-and-espionage-tool/
2. kimsuky ´«²¼¼Ù×°³Éº«¹úij¹«¹²»ú¹¹×°Ö÷¨Ê½µÄ¶ñÒâÈí¼þ
3ÔÂ26ÈÕ£¬AhnLab °²È«µý±¨ÖÐÐÄ (ASEC) ×î½ü·¢ÏÖ Kimsuky ×éÖ¯´«²¼¼Ù×°³Éº«¹ú¹«¹²»ú¹¹×°Ö÷¨Ê½µÄ¶ñÒâÈí¼þ¡£ËùÉæ¼°µÄ¶ñÒâÈí¼þÊÇÒ»¸ö´´½¨EndorºóÃŵÄÖ²È뷨ʽ¡£¹ÌȻûÓÐÔÚÏÖʵ¹¥»÷ÖÐʹÓøÃÖ²È뷨ʽµÄ¼Í¼£¬µ«ÔÚÓë¸ÃÖ²È뷨ʽ±»ÍøÂçµÄԼĪͳһʱÆÚ£¬ÓÐÒ»¸öÉæ¼°¸ÃÖ²È뷨ʽ´´½¨ºóÃŵĹ¥»÷°¸Àý¡£ÍþвÐÐΪÕßʹÓúóÃÅÏÂÔØÆäËû¶ñÒâÈí¼þ»ò×°ÖÃ½ØÆÁ¶ñÒâÈí¼þ¡£Endor ҲʱʱÓÃÓÚÆäËû¹¥»÷£»´Óǰ£¬ËüÓëNikidoorһ·ʹÓã¬Nikidoor ͨ¹ýÓã²æÊ½ÍøÂç´¹µö¹¥»÷½øÐзַ¢¡£Dropper ±»¼Ù×°³Éº«¹úij¹«¹²»ú¹¹µÄ×°Ö÷¨Ê½¡£Æäͼ±êѡȡÁ˸ûú¹¹µÄ±êÖ¾£¬Óйعؼü´Ê¿ÉÔÚ°æ±¾ÐÅÏ¢ºÍÉèÖÃÒ³ÃæÖÐÕÒµ½¡£Áí±í£¬Ã»ÓÐÈκκϷ¨·¨Ê½µÄ°æ±¾Óë´ËÒ»Ñù¡£ÕâÅú×¢¸Ã¶ñÒâÈí¼þÖ»ÊDZ»Éè¼ÆµÃÏñÈÎºÎÆäËûºÏ·¨·¨Ê½Ò»Ñù£¬ÎÞÒ⽫×Ô¼º¼Ù×°³ÉÏÖÓз¨Ê½¡£¼´±ãÔÚ×°Öùý³ÌÖУ¬¶ñÒâÈí¼þÒ²ÊÇΨһÒÔÕý³£·½Ê½×°Öõķ¨Ê½¡£
https://asec.ahnlab.com/en/63396/
3. ·ðÂÞÀï´ïÖݵÄÊ¥¿ËÀ͵ÂÊÐÔâµ½ÀÕË÷¹¥»÷
3ÔÂ26ÈÕ£¬Ê¥¿ËÀ͵ÂÊаµÊ¾£¬ÀÕË÷¹¥»÷µ¼ÖºܶಿÃÅÊܵ½Ó°Ï죬µ«ËûÃÇÔÚ¾¡¿ÉÄÜ×î¼ÑµØÔË×÷£¬Ö±µ½ÎÊÌâµÃµ½½â¾ö¡£Ê¥¿ËÀ͵ÂλÓÚ°ÂÀ¼¶àÒÔÄÏÔ¼Ò»Ó×ʱ³µ³Ì´¦£¬Õ¼ÓÐ 60000 Ãû¾ÓÃñ¡£²¢ÇÒ¹«Ô°ºÍÐÝÏл¼°·þÎñµÄÏÖ³¡¸¶¿îÒ²ÁÙʱֻÄÜʹÓÃÏÖ½ð¡£ÔÚÏßÉèʩԤԼ¸¶¿îºÍÔÚÏ߻ע²áÒÀÈ»½ÓÊÜÐÅÓþ¿¨¸¶¿î¡£¾¯Ô±ºÍÏû·À½Ó¼ÃÔÚÏìÓ¦·þÎñÒªÇó¡£×ªÔËÕ¾µÄ·þÎñÓöÈÁÙʱֻÄÜÓÃÏÖ½ðÖ§¸¶£¬ËùÓÐÀ¬»øºÍ»ØÊÕÍøÂç·Ïß½«°´´òËãÔËÐС£°ÂÎ÷°ÂÀÏØË°Îñ¾ÖºÍ OUC µÈ±í²¿¹«ÓÃÊÂÒµµÄÌṩÉ̲¢Î´Êܵ½Õâ´Î¹¥»÷µÄÓ°Ïì¡£
https://therecord.media/st-cloud-hit-with-ransomware-florida-string
4. Top.gg Discord »úеÈËÉçÇøÔâµ½¹©¸øÁ´¹¥»÷
3ÔÂ25ÈÕ£¬¶àÄêÀ´£¬ÍþвÐÐΪÕßÒ»ÏòÔÚʹÓöàÖÖÕ½Êõ¡¢¼¼ÊõºÍ·¨Ê½ (TTP)£¬Ô̺¬½Ù³Ö GitHub ÕÊ»§¡¢·Ö·¢¶ñÒâ Python °ü¡¢Ê¹ÓÃÐéαµÄ Python »ù´¡ÉèÊ©ºÍÉç»á¹¤³Ì¡£ÉÏ´«µ½ PyPI µÄ¶ñÒâ°ü³äÈÎÁË·ÛËéϵͳµÄ³õÊ¼ÔØÌå¡£Ò»µ©ÏµÍ³Ôâµ½·ÛË飬»òÕß¹¥»÷Õß½Ù³ÖÁËÌØÈ¨ GitHub ÕÊ»§£¬ËûÃǾͻá¸ü¸ÄÏîÄ¿ÎļþÒÔÖ¸Ïò¼Ù¾µÏñÉÏÍйܵÄÒÀÀµÏî¡£Top.gg Êǹ¥»÷Õß×î½üµÄÊܺ¦ÕßÖ®Ò»£¬ÕâÊÇÒ»¸öÊ¢ÐеÄËÑË÷ºÍ·¢ÏÔì½Ì¨£¬ºÏÓÃÓÚ Discord ·þÎñÆ÷¡¢»úеÈËºÍÆäËûÉç½»¹¤¾ß£¬Ö¼ÔÚÓÎÏ·¡¢Ìá¸ß²Î¼Ó¶ÈºÍ¸Ä½øÖ°ÄÜ¡£¹¥»÷ÕßÈëÇÖÁË top.gg ÊØ»¤Õß¡°editor-syntax¡±µÄÕÊ»§£¬¸ÃÊØ»¤Õß¶Ô¸ÃÆ½Ì¨µÄ GitHub ´æ´¢¿âÕ¼ÓгÁÒªµÄдÈë½Ó¼ûȨÏÞ¡£
https://www.bleepingcomputer.com/news/security/hackers-poison-source-code-from-largest-discord-bot-platform/
5. ÓëÒÁÀÊÓÐ¹ØµÄ APT TA450 ÔÚ PDF ¸½¼þÖÐǶÈë¶ñÒâÁ´½Ó
3ÔÂ25ÈÕ£¬ÓëÒÁÀÊÓÐ¹ØµÄ APT ×éÖ¯MuddyWater £¨±ðÃû SeedWorm¡¢ TEMP.Zagros¡¢TA450 ºÍ Static Kitten£©ÊÇ 2024 Äê 3 ÔÂÌáÒéµÄÒ»´ÎеÄÍøÂç´¹µö»î¶¯µÄÄ»ºóºÚÊÖ£¬¸Ã»î¶¯ÊÔͼÔÚ 2024 Äê 3 ÔÂͶ·ÅÃûΪ Atera µÄºÏ·¨Ô¶³Ì¼à¿ØºÍÖÎÀí (RMM) ½â¾ö¹æ»®¡£¸Ã»î¶¯Õë¶Ô´óÐÍ¿ç¹ú×éÖ¯µÄÒÔÉ«ÁÐÔ±¹¤£¬ÀûÓÃÓëн³êÓйصÄÉç»á¹¤³Ì¡£¸ÃÍøÂç´¹µö»î¶¯ÓÚ 3 Ô 7 ÈÕÆðÍ·£¬Ò»Ïò³ÖÐøµ½ 2024 Äê 3 Ô 11 ÈÕÕâÒ»ÖÜ¡£TA450 ×éÖ¯·¢ËÍÓã²æÊ½ÍøÂç´¹µöÓʼþ£¬ÆäÖÐÔ̺¬Ô̺¬¶ñÒâÁ´½ÓµÄ PDF ¸½¼þ¡£ÍþвÐÐΪÕßÏòͳһÊÕ¼þÈË·¢ËÍÁ˶à·â´øÓÐ PDF ¸½¼þµÄÍøÂç´¹µöµç×ÓÓʼþ£¬ÆäÖÐǶÈëµÄÁ´½ÓÂÔÓÐ·ÖÆç¡£Proofpoint ƾ¾Ý¶ÔÓëÍøÂç¼äµý×éÖ¯¡¢»î¶¯Ö¸±êÒÔ¼°¹¥»÷ÖÐʹÓõĶñÒâÈí¼þÓйصÄÕ½Êõ¡¢¼¼ÊõºÍ·¨Ê½µÄ¹Û²ì£¬½«Õâ´Î»î¶¯¹éÒòÓÚ TA450¡£
https://securityaffairs.com/161042/apt/iran-ta450-rmm-atera.html
6. ºÚ¿Í¿É½âËø Dormakaba ÏúÊÛµÄ 300 ¶àÍò¸ö·¿ÃÅ
3ÔÂ25ÈÕ£¬ÊýǧÃû°²È«×êÑÐÈËÔ±Æë¾ÛÀ˹ά¼Ó˹²ÎÓëËùνµÄ¡°ºÚ¿ÍÏÄÁîÓª¡±£¨Â½Ðø½øÐÐ Black Hat ºÍ Defcon ºÚ¿Í»áÒ飩ʱ£¬ËûÃÇÖеÄһЩÈË×¢¶¨»á³¢ÊÔÈëÇÖ»ù´¡Éèʩά¼Ó˹×ÔÉí£¬Õâ×ù³ÇÊÐÕ¼ÓÐһϵÁо«ÐÄÉè¼ÆµÄ¶Ä³¡ºÍ¾Æµê¼¼Êõ¡£Ian Carroll¡¢Lennert Wouters ºÍÆäËû°²È«×êÑÐÈËÔ±ÍŶӽÒʾÁËÒ»ÖÖËûÃdzÆÖ®Îª Unsaflok µÄ¾ÆµêÔ¿³×¿¨ºÚ¿Í¼¼Êõ¡£¸Ã¼¼ÊõÊÇһϵÁа²È«·ì϶µÄ¼¯ÖУ¬ºÚ¿ÍÏÕЩÄܹ»µ±¼´´ò¿ªÈðÊ¿Ëø¾ßÔì×÷ÉÌ Dormakaba ÏúÊÛµÄ Saflok Æ·ÅÆ»ùÓÚ RFID µÄÔ¿³×¿¨ËøµÄ¶àÖÖÐͺš£Saflok ϵͳװÖÃÔÚÈ«Çò 131 ¸ö¹ú¶È 13000 ´¦·¿²úµÄ 300 ÍòÉÈÃÅÉÏ¡£
https://news.hitb.org/content/hackers-can-unlock-over-3-million-hotel-doors-seconds


¾©¹«Íø°²±¸11010802024551ºÅ