Microsoft Windows DWM ÁãÈÕ·ì϶±»´ó¹æÄ£ÀûÓÃ
°ä²¼¹¦·ò 2024-05-165ÔÂ15ÈÕ£¬Î¢Èí°ä²¼ÎåÔ²¹¶¡¸üУ¬×ܹ² 59 ¸ö CVE £¬ÖÁÉÙÓÐÒ»¸ö¶àËùÖÜÖªµÄ·ì϶Òѱ»´ó¹æÄ£ÀûÓ㬲¢ÇÒµÄÈ·ÒѾ±» QakBot ËùʹÓᣱ¾ÔÂÅû¶µÄȱµãÓ°ÏìÁËÍÆËã kahuna µÄÕû¸ö²úÆ·×éºÏ£¬Ô̺¬ Windows¡¢Office¡¢.NET Framework ºÍ Visual Studio£»Î¢Èí365£»µçÁ¦Ã³Ò×ÖÇÄÜ£»DHCP ·þÎñÆ÷£»Microsoft Edge£¨»ùÓÚ Chromium£©£»ºÍ Windows ÒÆ¶¯¿í´ø¡£»ùÓÚ Chromium µÄ Edge ä¯ÀÀÆ÷Êܵ½ CVE-2024-4761 µÄÓ°Ï죬ÕâÊÇ Google ½ñÌ콨²¹µÄÒ»¸ö×Ô¶¯ÀûÓÃµÄ Chrome ÁãÈÕ·ì϶£¬ÕâÊÇÒ»¸öÑϳÁµÄɳÏäÌÓÒÝÃýÎ󣬸õ±¼´½¨²¹¡£
https://www.darkreading.com/vulnerabilities-threats/microsoft-windows-dwm-zero-day-mass-exploit
2. Î÷ÃÅ×Ó Ruggedcom Crossbow Öжà¸öËÁÒâ´úÂëÖ´Ðзì϶
5ÔÂ14ÈÕ£¬Î÷ÃÅ×Ó Ruggedcom Crossbow Öз¢ÏÖÁ˶à¸ö·ì϶£¬ÆäÖÐ×îÑϳÁµÄ·ì϶¿ÉÄÜÔÊÐíËÁÒâ´úÂëÖ´ÐС£Î÷ÃÅ×Ó Ruggedcom Crossbow ½Ó¼ûÖÎÀí½â¾ö¹æ»®Ö¼ÔÚΪ¹¤Òµ½ÚÔìϵͳÌá¹©ÍøÂ簲ȫºÏ¹æÐÔ¡£³É¹¦ÀûÓÃÆäÖÐ×îÑϳÁµÄ·ì϶¿ÉÄÜ»áÔÊÐíÔڵǼÓû§µÄ¸ßµÍÎÄÖÐÖ´ÐÐËÁÒâ´úÂ롣ƾ¾ÝÓëÓû§¹ØÁªµÄȨÏÞ£¬¹¥»÷ÕßÄܹ»×°Ö÷¨Ê½£»²é¿´¡¢¸ü¸Ä»òɾ³ýÊý¾Ý£»»ò´´½¨ÓµÓÐÆëÈ«Óû§È¨ÏÞµÄÐÂÕÊ»§¡£ÓëÓµÓÐÖÎÀíÓû§È¨ÏÞµÄÓû§Ïà±È£¬ÆäÕÊ»§ÅäÖÃΪÔÚϵͳÉÏÕ¼ÓнϺ±Óû§È¨ÏÞµÄÓû§Êܵ½µÄÓ°Ïì¿ÉÄܸüÓס£ÊÜÓ°ÏìµÄϵͳÔ̺¬Ruggedcom Crossbow 5.5 ֮ǰµÄ°æ±¾¡£
https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-siemens-ruggedcom-crossbow-could-allow-for-arbitrary-code-execution_2024-055
3. ·ðÃÉÌØÖÝͨ¹ýÊý¾ÝÒþÖÔ·¨ÔÊÐíÏû·ÑÕ߸æ×´¹«Ë¾
5ÔÂ14ÈÕ£¬·ðÃÉÌØÖÝÁ¢·¨»ú¹¹ÖÜÎåͨ¹ýÁ˸ùú×î׳´óµÄ×ÛºÏÊý¾ÝÒþÖÔ·¨Ö®Ò»£¬ÆäÖÐÔÊÐíÓ×ÎÒ¸æ×´¼Óº¦ÆäÒþÖÔȨµÄ¹«Ë¾¡ª¡ªÕâÊÇÏÖÓÐÀàËÆÖÝ˾·¨ÖÐǰËùδÓеĻ®¶¨¡£¸Ã·¨°¸Ô̺¬Êý¾Ý×îÓ×»¯ÒªÇó£¬Õ⼫´óµØÏÞ¶ÈÁ˹«Ë¾Äܹ»ÍøÂçºÍʹÓõÄÓ×ÎÒÊý¾Ý£¬²¢²»Èݹ«Ë¾ÏúÊÛÏû·ÑÕßµÄÃô¸ÐÊý¾Ý£¬ÔÊÐíÓ×ÎÒÔÚÒÔΪÆóÒµÕâÑù×öʱÌá¸æ×´ËÏ¡£¸öÈËËßËÏȨÔÊÐíÓ×ÎÒÒªÇóËûÃÇÒÔΪ¼Óº¦ÆäÈ¨ÊÆµÄ¹«Ë¾³Ðµ£ÔðÈΣ¬¶øÎÞÐèÒÀÀµ¹ú¶Èµ±¾Ö²ÉÈ¡Ðж¯¡£ÒÁÀûŵÒÁÖÝÉúÎï¼ø±ðÒþÖÔ·¨ÖÐÔ̺¬µÄÀàËÆÌõ¿îÒý·¢ÁËÒ»²¨Ö¸¿ØÆóÒµäÂÖ°µÄ¼¯ÌåËßËÏ¡£·ðÃÉÌØÖÝ·¨°¸µÄ¸öÈËËßËÏȨ±ØÒªÔÚÁ½Äêºó³ÁÐÂÊÚȨ£¬²¢ºÏÓÃÓÚ´¦Öó¬¹ý 100,000 ÌõÏû·ÑÕ߼ͼµÄÈÎºÎÆóÒµ»òÓ×ÎÒ¡£¸ÃÁ¢·¨»¹Ôì¶©ÁËÑϸñµÄ¹«ÃñÈ¨ÊÆ±£ÏÕ´ëÊ©ÒÔÔ¤·ÀÆçÊÓ¡£¼ÓÖÝ׳´óµÄ×ÛºÏÊý¾ÝÒþÖÔ·¨»¹ÔÊÐíÓ×ÎÒ¸æ×´ËûÃÇÒÔΪ¼Óº¦ÆäÈ¨ÊÆµÄÆóÒµ£¬µ«¸ÃÌõ¿î½öºÏÓÃÓÚÊý¾Ýй¶£¬²»ºÏÓÃÓÚÊý×ÖÒþÖÔ¡£
https://therecord.media/vermont-passes-data-privacy-law?&web_view=true
4. Android ¶ñÒâÈí¼þ¼ÙÒâ WhatsApp µÈAPPÇÔÈ¡Êý¾Ý
5ÔÂ15ÈÕ£¬SonicWall Capture Labs Íþв×êÑÐÍŶӻ㱨³Æ£¬ÍþвÐÐΪÕßÔÚʹÓöñÒâ Android ÀûÓ÷¨Ê½À´¼ÙÒâ Google¡¢Instagram¡¢Snapchat¡¢WhatsApp ºÍ X µÈÊ¢ÐеÄÔÚÏß·þÎñ¡£ÕâЩÀûÓ÷¨Ê½Ö¼ÔÚ´ÓÒ×Êܹ¥»÷µÄ Android ÊÖ»úÖÐÇÔÈ¡Ãô¸ÐÊý¾Ý£¬Ô̺¬ÁªÏµÈË¡¢¶ÌÐÅ¡¢Í¨»°¼Í¼ºÍÃÜÂë¡£ÕâЩÀûÓ÷¨Ê½¿´ÆðÀ´ºÏ·¨£¬ÓÉÓÚËüÃÇʹÓÃÊìϤµÄ»Õ±êºÍÃû³ÆÀ´ºýŪºÁÎÞ½äÐĵÄÓû§²¢°µ²ØÔÚÓÐľܲ¼û֮ϡ£´ò¿ªÊ±£¬ÀûÓ÷¨Ê½ÒªÇó½Ó¼ûÁ½¸öȨÏÞ£ºAndroid Accessibility Service ºÍÉ豸ÖÎÀíȨÏÞ¡£ÈôÊÇÊܺ¦ÕßÊÚÓèÕâЩȨÏÞ£¬ÀûÓ÷¨Ê½¾ÍÄܹ»»ñµÃÉ豸µÄÆëÈ«½ÚÔìȨ¡£¶øºó£¬¶ñÒâÀûÓ÷¨Ê½ÓëºÚ¿Í½ÚÔìµÄ C2 ·þÎñÆ÷³ÉÁ¢Ïνӣ¬½Ó¹Ü¸½¼ÓÖ¸Áî¡£ËüÄܹ»¶ÁÈ¡ÐÂÎÅ¡¢Í¨»°¼Í¼¡¢½Ó¼û֪ͨÊý¾Ý¡¢·¢ËÍÐÂÎÅ¡¢×°ÖöñÒâÈí¼þÒÔ¼°´ò¿ª¶ñÒâÍøÕ¾ÒÔ½øÐÐÍøÂç´¹µö¡£
https://www.hackread.com/android-malware-whatsapp-instagram-snapchat-data/
5. Ebury½©Ê¬ÍøÂç¶ñÒâÈí¼þÒÑϰȾ40Íǫ̀Linux·þÎñÆ÷
5ÔÂ14ÈÕ£¬Ò»¸öÃûΪ¡°Ebury¡±µÄ¶ñÒâÈí¼þ½©Ê¬ÍøÂçÒÑϰȾÁ˽ü 400,000 ̨ Linux ·þÎñÆ÷£¬½ØÖÁ 2023 Äêµ×£¬Ô¼ÓÐ 100,000 ̨·þÎñÆ÷ÈÔÊܵ½Íþв¡£ESET ×êÑÐÈËԱʮ¶àÄêÀ´Ò»ÏòÔÚ¸ú×ÙÕâÖÖ³öÓÚ¾¼Ã¶¯»úµÄ¶ñÒâÈí¼þ²Ù×÷£¬²¢ÔÚ 2014 ÄêºÍ 2017 ÄêÔÙ´ÎÖÒ¸æÓÐЧ¸ºÔØÖ°ÄܵijÁ´ó¸üС£ESET ×Ô 2009 ÄêÒÔÀ´Ò»Ïò¹Ø×¢µÄ Ebury ϰȾÇé¿ö£¬ÏÔʾϰȾÁ¿Ëæ×ʦ·òµÄÍÆÒÆ¶øÔö³¤¡£×î½üµÄ Ebury ¹¥»÷Åú×¢£¬¹¥»÷ÍÅ»ïÆ«²îÓÚ·ÛËéÍйÜÌṩÉÌ£¬²¢¶ÔÔÚÊÜϰȾÌṩÉÌÉÏ×âÓÃÐé¹¹·þÎñÆ÷µÄ¿Í»§½øÐй©¸øÁ´¹¥»÷¡£×î³õµÄ·çÏÕÊÇͨ¹ýƾ֤Ìî³ä¹¥»÷½øÐеģ¬Ê¹ÓÃÇÔÈ¡µÄƾ֤µÇ¼·þÎñÆ÷¡£Ò»µ©·þÎñÆ÷Êܵ½Íþв£¬¶ñÒâÈí¼þ¾Í»á´Ówtmp ºÍ known_hosts ÎļþÖÐÇÔÈ¡ÈëÕ¾/´ø±í SSH ÏνÓÁÐ±í£¬²¢ÇÔÈ¡ SSH Éí·ÝÑéÖ¤ÃÜÔ¿£¬¶øºóʹÓÃÕâЩÃÜÔ¿³¢ÊԵǼÆäËûϵͳ¡£
https://www.bleepingcomputer.com/news/security/ebury-botnet-malware-infected-400-000-linux-servers-since-2009/
6. ºÚ¿ÍÀÄÓà GoTo »áÒ鹤¾ß²¿Êð Remcos RAT
5ÔÂ14ÈÕ£¬ÔÚÒ»´Î¸´ÔÓµÄÍøÂç¹¥»÷»î¶¯Öз¢ÏÖºÚ¿ÍÀûÓÃÔÚÏß»áÒéÆ½Ì¨ GoToMeeting ´«²¼ÃûΪ Remcos µÄÔ¶³Ì½Ó¼ûľÂí¡£ÕâÒ»ÁîÈËÕ𾪵ķ¢Õ¹Í»ÏÔÁËÍøÂç·¸×ï·Ö×ÓÀûÓÿÉÐÅÈí¼þÍ»ÆÆ°²È«·ÀÓù²¢Î´¾ÊÚȨ½Ó¼ûÊܺ¦ÕßϵͳµÄ²»ÐÝÑݱäµÄÕ½Êõ¡£¹¥»÷»úÔìÉæ¼°°Ñ³Ö GoToMeeting£¨Ò»ÖÖ±»ÆóÒµ¿í·ºÓÃÓÚÐé¹¹»áÒéµÄ¹¤¾ß£©×÷Ϊ Remcos RAT µÄÇþ·¡£Remcos ÊÇÒ»ÖÖ׳´óµÄ¶ñÒâÈí¼þ£¬¹¥»÷ÕßÄܹ»ÀûÓÃËüÔ¶³Ì½ÚÔìÊÜϰȾµÄÍÆËã»ú¡¢ÇÔÈ¡Ãô¸ÐÐÅÏ¢£¬ÉõÖÁ²¿ÊðÆäËû¶ñÒâ¸ºÔØ¡£¹¥»÷Õ߯æÃîµØÔÚ¿´ËƺϷ¨µÄ GoToMeeting ֪ͨÖмÙ×°ÁË Remcos ÓÐЧ¸ºÔØ¡£ºÁÎÞ½äÐĵÄÓû§ÏàÐÅÕâЩ֪ͨÊÇÕæÊµµÄ£¬Òò¶ø±»ÓÕÆÔÚËûÃǵÄϵͳÉÏÖ´ÐжñÒâÈí¼þ¡£Ò»µ©×°Öã¬Remcos ¾Í»áÊÚÓè¹¥»÷Õß¶ÔÊÜÏ°È¾ÍÆËã»úµÄÆëÈ«½ÚÔìȨ£¬Ê¹ËûÃÇ¿ÉÄÜÔÚ²»±»·¢ÏÖµÄÇé¿öϽøÐмäµý»î¶¯¡¢Êý¾Ý͵ÇԺͽøÒ»²½µÄ¶ñÒâ»î¶¯¡£Remcos µÄÒþÃØÐԺ͸´ÔÓÐÔ£¬¼ÓÉÏ¶Ô GoToMeeting µÄ¿í·ºÐÅÀµ£¬Ê¹µÃÕâÖÖ¹¥»÷³ö¸ñÒõÏÕÇÒÄÑÒÔÓ¦¶Ô¡£
https://gbhackers.com/hackers-abuse-goto-meeting-tool/


¾©¹«Íø°²±¸11010802024551ºÅ