Nitrogen¼Ù×°³É PuTTY »ò FileZilla ²¿ÊðBlackCat

°ä²¼¹¦·ò 2024-04-11
1. Nitrogen¼Ù×°³É PuTTY »ò FileZilla ²¿ÊðBlackCat


4ÔÂ9ÈÕ£¬×î³õµÄÈëÇÖÊÇ´Óͨ¹ý Google ËÑË÷ÏÔʾµÄ¶ñÒâ¸æ°×ÆðÍ·µÄ¡£ÎÒÃǹ۲쵽Á˼¸¸ö·ÖÆçµÄ¸æ°×¿Í»§ÕÊ»§£¬ÕâЩÕÊ»§¶¼»ã±¨¸øÁ˹ȸè¡£ÕâЩµö¶üÊÇ IT ÖÎÀíÔ±³£ÓõÄʵÓ÷¨Ê½£¬ÀýÈç PuTTY ºÍ FileZilla¡£Nitrogen ÍþвÐÐΪÕß²¿ÊðµÄ¶ñÒâ¸æ°×»ù´¡ÉèʩʹÓüÙ×°Ò³Ãæ£¬¸ÃÒ³ÃæÄܹ»³Á¶¨Ïòµ½µö¶üÍøÕ¾»ò³ôÃûÔ¶ÑïµÄ Rick Astley ÊÓÆµ¡£ÈôÊǻÉÐδ±øÆ÷»¯»ò¶ñÒâ·þÎñÆ÷¼ì²âµ½ÎÞЧÁ÷Á¿£¨»úеÈË¡¢ÅÀ³æµÈ£©£¬ÔòÄܹ»¼¤»îµ½µö¶üÒ³ÃæµÄ³Á¶¨Ïò¡£¸Ã¶ñÒâ¸æ°×Á´µÄ×îºóÒ»²½Ô̺¬ÏÂÔØ²¢ÔËÐжñÒâÈí¼þÓÐЧ¸ºÔØ¡£Nitrogen ʹÓÃÒ»ÖÖ³ÆÎª DLL ÅÔ¼ÓÔØµÄ¼¼Êõ£¬Í¨¹ý¸Ã¼¼Êõ£¬ºÏ·¨ÇÒ¾­¹ýÊðÃûµÄ¿ÉÖ´ÐÐÎļþ»áÆô¶¯ DLL¡£ÔÚ±¾ÀýÖУ¬setup.exe£¨À´×Ô Python Software Foundation£©²àÔØpython311.dll (Nitrogen)¡£


https://www.malwarebytes.com/blog/threat-intelligence/2024/04/active-nitrogen-campaign-delivered-via-malicious-ads-for-putty-filezilla


2. ΢Èí½¨¸´ÁË Windows Á½¸öÒѾ­±»ÀûÓõÄÁãÈÕ·ì϶


4ÔÂ9ÈÕ£¬Î¢ÈíÔÚ 2024 Äê 4 ÔµIJ¹¶¡ÐÇÆÚ¶þÆÚ¼ä½¨¸´ÁËÁ½¸ö±»»ý¼«ÀûÓõÄÁãÈÕ·ì϶£¬Ö»¹Ü¸Ã¹«Ë¾×î³õδÄܶÔËüÃǽøÐÐÏóÕ÷¡£µÚÒ»¸ö·ì϶±»¸ú×ÙΪCVE-2024-26234£¬±»ÃèÊöΪ´úÀíÇý¶¯·¨Ê½ºýŪ·ì϶£¬Ö¼ÔÚ¸ú×٠ʹÓÃÓÐЧµÄ Microsoft Ó²¼þ¿¯ÐÐÉÌÖ¤ÊéÊðÃûµÄ¶ñÒâÇý¶¯·¨Ê½£¬¸Ã¶ñÒâÎļþ±»¡°Catalog Thales¡±ÏóÕ÷Ϊ¡°Catalog Authentication Client Service¡±£¬¿ÉÄÜÊÇÊÔͼ¼ÙÒâ Thales Group¡£µÚ¶þ¸öÁãÈÕ·ì϶±»×·×ÙΪCVE-2024-29988£¬±»ÃèÊöΪÓɱ£»¤»úÔì¹ÊÕÏÈõµãµ¼ÖµÄSmartScreenÌáÐѰ²È«Ö°ÄÜÈÆ¹ý·ì϶¡£CVE-2024-29988 ÊÇ CVE-2024-21412 ȱµãµÄÈÆ¹ý²½Ö裬ÓÉÇ÷Ïò¿Æ¼¼ÁãÈÕ´òËãµÄ Peter Girnus ÒÔ¼° Google Íþв·ÖÎöÓ××é Dmitrij Lenz ºÍ Vlad Stolyarov »ã±¨¡£


https://www.bleepingcomputer.com/news/microsoft/microsoft-fixes-two-windows-zero-days-exploited-in-malware-attacks/


3. ³¬¹ý9.1Íǫ̀ LG ÖÇÄܵçÊÓÈÝÒ×Êܵ½ºÚ¿Í¹¥»÷


4ÔÂ9ÈÕ£¬Bitdefender ×êÑÐÈËÔ±ÔÚÖÇÄܵçÊÓÉÏÔËÐÐµÄ LG webOS Öз¢ÏÖÁ˶à¸ö·ì϶£¬ÕâЩ·ì϶¿É±»ÓÃÀ´ÈƹýÊÚȨ²¢»ñµÃÉ豸µÄ root ½Ó¼ûȨÏÞ¡£×êÑÐÈËÔ±·¢Ïֵķì϶ӰÏì LG µçÊÓÉÏÔËÐÐµÄ WebOS °æ±¾ 4 ÖÁ 7¡£WebOS ÔÚ¶Ë¿Ú 3000/3001 (HTTP/HTTPS/WSS) ÉÏÔËÐÐÒ»Ïî·þÎñ£¬LG ThinkQ ÖÇÄÜÊÖ»úÀûÓ÷¨Ê½Ê¹Óø÷þÎñÀ´½ÚÔìµçÊÓ¡£ÒªÉèÖøÃÀûÓ÷¨Ê½£¬Óû§±ØÐëÔÚµçÊÓÆÁÄ»ÉÏÊäÈë PIN Âë¡£ÕÊ»§´¦Ö÷¨Ê½ÖеÄÃýÎóʹ¹¥»÷ÕßÄܹ»ÆëÈ«Ìø¹ý PIN ÑéÖ¤²¢´´½¨ÌØÈ¨Óû§ÅäÖÃÎļþ¡£Ö»¹Ü¸ÃÒ×Êܹ¥»÷µÄ·þÎñ½öÓÃÓÚ LAN ½Ó¼û£¬µ«Í¨¹ý²éÎÊ Shodan£¬ËûÃÇ·¢ÏÖÁ˳¬¹ý 91000 ¸ö½«¸Ã ·þÎñ¶³öµ½»¥ÁªÍøµÄÉ豸¡£´Ëʱ£¬Â¶³öµÄÉ豸ÊýÁ¿Ï÷¼õÖÁ88000¸ö¡£´óÎÞÊýÃæÏò»¥ÁªÍøµÄÉ豸λÓÚº«¹ú¡¢ÃÀ¹ú¡¢ÈðµäºÍ·ÒÀ¼µÈ¡£


https://securityaffairs.com/161651/hacking/lg-smart-tvs-vulnerable.html


4. GHC-SCW³ÆÀÕË÷Èí¼þÍÅ»ïÇÔÈ¡ÁËÆä53ÍòÈ˵Ľ¡È«Êý¾Ý


4ÔÂ9ÈÕ£¬Íþ˹¿µÐÇÖÝÖÐÄϲ¿·ÇͶ»úÐÔÒ½ÁÆ·þÎñÌṩÉÌ Group Health Cooperative (GHC-SCW) Åû¶£¬ÀÕË÷Èí¼þÍÅ»ïÓÚ 1 Ô·ÝÇÖÈëÆäÍøÂ磬ÇÔÈ¡ÁËÔ̺¬³¬¹ý 50 ÍòÈ˵ÄÓ×ÎÒºÍÒ½ÁÆÐÅÏ¢µÄÎļþ¡£È»¶ø£¬¹¥»÷ÕßÎÞ·¨¼ÓÃÜÊÜϰȾµÄÉ豸£¬ÕâʹµÃ GHC-SCW ÔÚ±í²¿ÍøÂçÊÂÎñÏìӦר¼ÒµÄÔ®ÊÖϱ£»¤Æäϵͳ£¬²¢ÔÚ¸ôÀëÕâЩÉ豸ÒÔ¶ôÔì·ì϶ºó½«Æä¸´Ô­ÔÚÏß¡£Ò»Ô·ÝÀÕË÷Èí¼þ¹¥»÷ÆÚ¼ä±»µÁµÄ½¡È«Êý¾ÝÔ̺¬ÊÜÓ°ÏìÓ×ÎÒµÄÐÕÃû¡¢µØÖ·¡¢µç»°ºÅÂë¡¢µç×ÓÓʼþµØÖ·¡¢µ®ÉúºÍ/»òéæÃüÈÕÆÚ¡¢Éç»á°²È«ºÅÂë¡¢»áÔ±ºÅÂëÒÔ¼°Ò½ÁƱ£ÏÕºÍ/»òÒ½ÁƲ¹ÖúºÅÂë¡£Ö»¹ÜûÓÐÌṩÊÜÓ°ÏìÈËÊýµÄ¾ßÌåÊý×Ö£¬µ«ÓëÃÀ¹úÎÀÉúÓ빫¼Ò·þÎñ²¿¹²ÏíµÄÆäËûÐÅÏ¢ÏÔʾ£¬Êý¾Ýй¶ӰÏìÁË 533809 ÈË¡£


https://www.bleepingcomputer.com/news/security/ghc-scw-ransomware-gang-stole-health-data-of-533-000-people/


5. BatBadBut Rust ·ì϶ʹ Windows ÏµÍ³Ãæ¶Ô¹¥»÷


4ÔÂ10ÈÕ£¬Rust ³ß¶È¿âÖеÄÒ»¸ö¹Ø¼ü°²È«·ì϶¿ÉÄܻᱻÀûÓÃÀ´Õë¶Ô Windows Óû§²¢ÌáÒéºÅÁî×¢Èë¹¥»÷¡£¸Ã·ì϶µÄ±àºÅΪCVE-2024-24576£¬CVSS ÆÀ·ÖΪ 10.0£¬Åú×¢ÑϳÁˮƽ×î¸ß¡£Ò²¾ÍÊÇ˵£¬Ëü½öÓ°ÏìÔÚ Windows ÉÏʹÓò»ÊÜÐÅÀµµÄ²ÎÊýŲÓÃÅú´¦ÖÃÎļþµÄ³¡¾°¡£Rust °²È«ÏìÓ¦¹¤×÷×éÔÚ 2024 Äê 4 Ô 9 ÈÕ°ä²¼µÄ²¼¸æÖаµÊ¾£ºÔÚ Windows ÉÏʹÓà Command API ŲÓÃÅú´¦ÖÃÎļþ£¨´øÓÐ bat ºÍ cmd À©´óÃû£©Ê±£¬Rust ³ß¶È¿âûÓÐÕýȷתÒå²ÎÊý¡£¿ÉÄܽÚÔì´«µÝ¸øÌìÉú¹ý³ÌµÄ²ÎÊýµÄ¹¥»÷ÕßÄܹ»Í¨¹ýÈÆ¹ýתÒåÀ´Ö´ÐÐËÁÒâ shell ºÅÁî¡£¸ÃȱµãÓ°Ïì 1.77.2 ֮ǰµÄËùÓÐ Rust °æ±¾¡£


https://thehackernews.com/2024/04/critical-batbadbut-rust-vulnerability.html


6. Medusa ÍÅ»ï³Æ¶ÔµÂ¿ËÈøË¹ÖÝijµ±¾Ö»ú¹¹µÄ¹¥»÷ÕÆ¹Ü


4ÔÂ9ÈÕ£¬ËþÀ¼ÌØÏØÆÀ¹ÀÇø£¨Tarrant County Appraisal District£©ÕƹÜÈ·¶¨ÎÖ˹±¤µØÓòÓÃÓÚ˰ÊÕÖ÷Õŵķ¿µØ²ú£¬Á½ÖÜǰÏò Recorded Future News  Ö¤Êµ£¬¸ÃÏØÊÇÀÕË÷Èí¼þ¹¥»÷µÄÊܺ¦Õß¡£ÖÜÒ»£¬Medusa ÍøÂç·¸×ïÍÅ»ïÐû³Æ¶ÔÕâÆðÊÂÎñÕÆ¹Ü£¬²¢Íþв³Æ£¬ÈôÊDz»Ö§¸¶ 10 ÍòÃÀÔªµÄÊê½ð£¬ËûÃǽ«ÔÚÁùÌìÄÚ¹«¿ª½ü 218 GB µÄÊý¾Ý¡£ÏعÙԱûÓлØÓ¦ÓйØÊÇ·ñÖ§¸¶Êê½ðµÄÖÃÆÀÒªÇ󣬵«ËûÃÇÓÚ 4 Ô 3 ÈÕ°ä²¼ÖÒ¸æ³Æ£¬ºÚ¿Í¹«¿ªÁËÔ¼ 300 È˵ÄÊý¾Ý¡£¸Ã×éÖ¯ÓÚ 2023 Äê³õ´Î³öÏÖ£¬ÆäÊܺ¦ÕßÃûµ¥Ñ¸¿ìÀ©´ó¡£ÃÀ¶ÅɯÒò¶Ô·áÌïºÍ¼ÓÄôóÁ½¼Ò×î´óÒøÐеĹ¥»÷¶ø³ÉΪͷÌõÐÂÎÅ¡£


https://therecord.media/tarrant-county-texas-ransomware-attack-medusa