¶íÀÕ¸ÔÖݶ¯ÎïÔ°ÊÛÆ±·þÎñÔâºÚ¿Í¹¥»÷£¬11.8ÍòÓû§ÐÅÏ¢±»µÁ

°ä²¼¹¦·ò 2024-08-21
1. ¶íÀÕ¸ÔÖݶ¯ÎïÔ°ÊÛÆ±·þÎñÔâºÚ¿Í¹¥»÷£¬11.8ÍòÓû§ÐÅÏ¢±»µÁ


8ÔÂ19ÈÕ£¬¶íÀÕ¸ÔÖݶ¯ÎïÔ°½üÆÚ²úÉúÁËһ·ÑϳÁµÄÊý¾Ýй¶ÊÂÎñ£¬Ô¼118,000ÃûÓû§µÄÓ×ÎÒÐÅÏ¢ºÍÖ§¸¶¿¨Êý¾ÝÔÚ2023Äê12ÔÂ20ÈÕÖÁ2024Äê6ÔÂ26ÈÕÆÚ¼äµÄÔÚÏßÊÛÆ±·þÎñÖб»µÁ¡£ÕâЩÐÅÏ¢Ô̺¬ÐÕÃû¡¢Ö§¸¶¿¨ºÅ¡¢CVV°²È«Âë¼°µ½ÆÚÈÕÆÚ£¬¶ÔÊܺ¦Õß×é³ÉDZÔÚ·çÏÕ¡£ÊÂÎñÓÚ6ÔÂ26ÈÕ±»·¢Ïֺ󣬶¯ÎïÔ°µ±¼´Í£ÓÃÁËÊÜÓ°ÏìµÄÍøÕ¾£¬²¢³ÉÁ¢ÁËÐµİ²È«¹ºÆ±Æ½Ì¨¡£¶¯ÎïÔ°ÒÑÏòÃåÒòÖÝ×ܼì²ì³¤°ì¹«Êһ㱨£¬²¢Ïò¿ÉÄÜÊÜÓ°ÏìµÄ117,815ÃûÓû§·¢ËÍÁË֪ͨÐÅ£¬Í¬Ê±ÎªËûÃÇÌṩÁËÒ»ÄêµÄÃâ·ÑÐÅÓþ¼à¿ØºÍÉí·Ý±£»¤·þÎñ¡£¶¯ÎïÔ°°µÊ¾£¬Õâ´Îй¶ÊÇÓÉÓÚµÚÈý·½¹©¸øÉÌÂòÂô±»ÍþвÕß³Á¶¨ÏòËùÖ£¬²¢ÒÑÏòÁª¹ú·¨Âɲ¿ÃÅ´«µÝ¡£ÎªÔ¤·À½«À´ÀàËÆÊÂÎñ£¬¶¯ÎïÔ°Õý»ý¼«Éó²éÆä°²È«Õþ²ßºÍ·¨Ê½¡£Ö»¹Üδ¹«¿ª¾ßÌå¹¥»÷ÀàÐÍ£¬µ«·ÖÎöÒÔΪ¿ÉÄÜÊÇÍøÂçä¯ÀÀÆ÷ϰȾÁËÊý×ÖÇÔÈ¡Æ÷£¬ÕâÀà¶ñÒâÈí¼þ³£±»ÓÃÓÚÔÚ½áÕËÒ³ÃæµÈ¹Ø¼üµØÎ»ÇÔÈ¡Óû§Ãô¸ÐÐÅÏ¢¡£


https://www.securityweek.com/oregon-zoo-ticketing-service-hack-impacts-118000/


2. Jewish Home LifecareÔâBlackCatÀÕË÷Èí¼þ¹¥»÷£¬10ÍòÈËÊý¾Ýй¶


8ÔÂ19ÈÕ£¬Å¦Ô¼ÊеķÇͶ»úÐÔÒ½ÁƱ£½¡×éÖ¯Jewish Home Lifecare£¨ÏÖ³ÆÐÂÓÌÌ«¼ÒÍ¥ÖÐÐÄ£©Åû¶Á˽üÆÚ²úÉúµÄһ·³Á´óÊý¾Ýй¶ÊÂÎñ£¬¸ÃÊÂÎñ²¨¼°³¬¹ý104,000Ãû»¼Õß¼°ÉçÇø³ÉÔ±¡£½ñÄê2Ô£¬¸ÃÖÐÐÄÏòÊÜÓ°Ïì¿Í»§´«µÝ³Æ£¬ÆäÍøÂçÔÚ1ÔÂ7ÈÕÔâ·êÒì³£»î¶¯£¬ºÚ¿Í¿ÉÄÜÒÑ»ñÈ¡Ô̺¬Ó×ÎÒÉí·ÝÐÅÏ¢¡¢½ðÈÚÕË»§ÏêÇé¡¢Ò½ÁƼͼÔÚÄÚµÄÃô¸ÐÐÅÏ¢¡£ÎªÈ·±£Êܺ¦Õß°²È«£¬ÖÐÐÄÌṩÁËÃâ·ÑµÄÐÅÓþ¼à¿Ø·þÎñ£¬²¢Ç¿µ÷ËäÎÞÖ±½ÓÖ¤¾ÝÅú×¢ÐÅÏ¢Òѱ»ÀÄÓ㬵«ÈÔÉóÉ÷°ä²¼Í¨Öª¡£Õâ´Îй¶ÓëÀÕË÷Èí¼þ×éÖ¯BlackCat(Alphv)ÓйØ£¬ËüÃÇÐû³Æ¹¥»÷ÁËJewish Home Lifecare²¢»ñÈ¡ÁËÁÙ´²×êÑÓ×¢²ÆÕþ¼°Ô±¹¤¿Í»§Êý¾Ý£¬ÉõÖÁÉæ¼°¾èÔù×ʽðÀÄÓõÄÖ¤¾Ý¡£È»¶ø£¬±»µÁÎļþÊÇ·ñ¹«¿ªÉдýÈ·ÈÏ£¬ÇÒBlackCat×éÖ¯ÔÚ3Ô³õºöÈ»Òþû£¬ÆäÍøÕ¾ÒÑÎÞ·¨½Ó¼û¡£


https://www.securityweek.com/100000-impacted-by-jewish-home-lifecare-data-breach/


3. BlindEagle£¨APT-C-36£©£ºÀ­¶¡ÃÀÖ޵ijÖÐøÍþв


8ÔÂ20ÈÕ£¬¿¨°Í˹»ù³¢ÊÔÊÒ¶ÔÃûΪBlindEagle£¨ÓÖ½ÐAPT-C-36£©µÄ³ÖÐøÐÔÍþв×éÖ¯·¢³öÖҸ棬¸Ã×é֯ר³¤ÓÚÕë¶ÔÀ­¶¡ÃÀÖÞµÄÍøÂç¹¥»÷£¬BlindEagleÖØÒªÍ¨¹ý¾«ÐÄÉè¼ÆµÄÍøÂç´¹µö»î×÷Ϊ°¸£¬¼Ùð¹Ù·½»ú¹¹Èç˰Îñ²¿ÃÅ»ò±í½»²¿£¬ÓÕÆ­Óû§µã»÷¶ñÒâÁ´½Ó£¬ÏÂÔØ¼Ù×°³É¹Ù·½ÎļþµÄѹËõ°ü£¬ÄÚº¬Ö¸ÏòÊܿضñÒâÈí¼þÕ¾µãµÄÁ´½Ó¡£ÕâЩÓʼþÕæÇзÂÕÕ¹Ù·½Í¨Ñ¶£¬ÀûÓÃURLËõ¶ÌÆ÷ºÍ¶¯Ì¬DNS·þÎñÔö³¤Òñ±ÎÐÔ£¬Æ¾¾ÝÓû§µØÎ»³Á¶¨Ïò£¬ÒÔÌӱܼì²â¡£Ò»µ©Óû§ÖÐÕУ¬BlindEagle±ãÆô¶¯¶à½×¶ÎϰȾ£¬²¿ÊðÔ̺¬njRAT¡¢LimeRATµÈ¹«¿ªÔ¶³Ì½Ó¼ûľÂí£¨RAT£©£¬ÕâЩ¹¤¾ß±»¶¨ÔìÒÔÂú×ã·ÖÆç¹¥»÷ÐèÒª£¬ÔÊÐí¸Ã×éÖ¯¼à¿ØÊܺ¦Õß¡¢ÇÔÈ¡Ãô¸ÐÐÅÏ¢¼°²ÆÕþƾ֤¡£BlindEagle»¹ÀûÓùý³Ì×¢Èë¼¼Êõ£¬Èç¹ý³ÌÍÚ¿Õ£¬½«¶ñÒâ´úÂë°µ²ØÓںϷ¨¹ý³ÌÖУ¬ÒԴ˶ã±Ü°²È«¼ì²â£¬ÊµÏÖ³Ö¾ÃÂñ·üÓëÊý¾ÝÇÔÈ¡¡£BlindEagleµÄ¹¥»÷Ö¸±êÔ̺¬¸çÂ×±ÈÑÇ¡¢¶ò¹Ï¶à¶û¡¢ÖÇÀûºÍ°ÍÄÃÂíµÄÓ×ÎÒºÍ×éÖ¯£¬Éæ¼°µ±¾Ö¡¢½ÌÓý¡¢ÎÀÉúºÍ½»Í¨µÈ¸÷¸öÁìÓò¡£


https://securityonline.info/blindeagle-apt-group-a-persistent-threat-in-latin-america/


4. ΢о¿Æ¼¼Ôâ·êÍøÂç¹¥»÷£¬²¿ÃÅÒµÎñÊÜÓ°Ïì


8ÔÂ21ÈÕ£¬ÃÀ¹ú°ëµ¼ÌåÔì×÷ÉÌ΢о¿Æ¼¼Microchip½üÆÚÔâ·êÁËÒ»Â·ÍøÂ簲ȫÊÂÎñ£¬¶Ô¹«Ë¾ÔËÓªÔì³ÉÁËÏÔÖøÓ°Ïì¡£¾Ý¸Ã¹«Ë¾Ð¹Â©£¬8ÔÂ17ÈÕ£¬Î¢Ð¾¿Æ¼¼µÄÐÅÏ¢¼¼Êõϵͳ±»¼ì²âµ½´æÔÚDZÔڵĿÉÒɻ£¬ËæºóÓÚ8ÔÂ19ÈÕÈ·ÈÏϵͳÒÑÔ⵽δ¾­ÊÚȨµÄ½Ó¼û¡£Ãæ¶ÔÕâÒ»´¹Î£Çé¿ö£¬¹«Ë¾Ñ¸¿ì²ÉÈ¡Ðж¯£¬¸ôÀëÁËÊÜÓ°ÏìµÄ·þÎñÆ÷ϵͳ£¬²¢¹Ø¹ØÁË¿ÉÄÜÊܲ¨¼°µÄÆäËûϵͳ£¬Í¬Ê±ÀñƸÁËרҵµÄ±í²¿ÍøÂ簲ȫÕÕ·÷ÍŶÓÀ´È«ÃæÆÀ¹ÀÊÂÎñµÄÑϳÁˮƽ¼°Ó°ÏìÁìÓò¡£Õâ´Î°²È«ÊÂÎñµ¼ÖÂ΢о¿Æ¼¼²¿ÃÅÔì×÷ÉèÊ©µÄÔËӪЧÄܽµÖÁÕý³£Ë®Æ½ÒÔÏ£¬Ö±½ÓÓ°ÏìÁ˹«Ë¾°´Ê±Íƹã¿Í»§¶©µ¥µÄÄÜÁ¦¡£Ö»¹Ü¹«Ë¾ÕýÈ«Á¦ÒÔ¸°½â¾öÕâÒ»ÎÊÌ⣬²¢³Ðŵ½«¾¡¿ì¸´Ô­Õý³£ÔËÓª£¬µ«Ä¿Ç°¹ØÓÚÊÂÎñµÄ¾ßÌåÔ­Òò¡¢Ð¾Æ¬Ôì×÷ÒµÎñÊÜ×ÌÈŵľßÌåˮƽ£¬ÒÔ¼°ÊÇ·ñÉæ¼°ÀÕË÷Èí¼þµÈÃô¸ÐÐÅÏ¢£¬ÈÔ´ý½øÒ»´ëÊ©²éÈ·ÈÏ¡£ÖµÍ×ÌùÐĵÄÊÇ£¬Î¢Ð¾¿Æ¼¼²ÉÈ¡¸ôÀë´ëÊ©µÄ×ö·¨Åú×¢£¬Î´¾­ÊÚȨ·½µÄ»î¶¯¿ÉÄÜÒѳõ²½ÏÔʾ³öÏò¹«Ë¾¸ü¿í·ºIT×ʲúÀ©É¢µÄ¼£Ïó¡£


https://www.theregister.com/2024/08/21/microchip_technology_security_incident/


5. ½Ý¿ËÒÆ¶¯Óû§ÔâPWAÍøÂç´¹µö¹¥»÷


8ÔÂ20ÈÕ£¬½Ý¿Ë¹²ºÍ¹úµÄÒÆ¶¯Óû§ÕýÃæ¶ÔÒ»ÖÖÐÂÐÍÇÒ¸´ÔÓµÄÍøÂç´¹µöÍþв£¬¸ÃÍþвÀûÓý¥½øÊ½WebÀûÓ÷¨Ê½£¨PWA£©¼¼Êõ£¬Õë¶Ô¶à¼ÒÒøÐÐÓû§ÇÔÈ¡ÒøÐÐÕË»§Æ¾Ö¤¡£¾Ý˹Âå·¥¿ËÍøÂ簲ȫ¹«Ë¾ESET»ã±¨£¬¹¥»÷Ö¸±êÔ̺¬½Ý¿ËµÄCSOBÒøÐÓ×¢ÐÙÑÀÀûµÄOTPÒøÐкϸñ³¼ªÑǵÄTBCÒøÐС£¹¥»÷Õßͨ¹ý×Ô¶¯ÓïÒôµç»°¡¢¶ÌÐż°É罻ýÌå¶ñÒâ¸æ°×É¢²¼´¹µöÁ´½Ó£¬ÓÕµ¼Óû§µã»÷²¢×°Öÿ´ËƺϷ¨µÄÒøÐÐÀûÓ÷¨Ê½PWA»òAndroidÉϵÄWebAPK£¬ÕâЩÀûÓÃÏÕЩÃÀÂú¸´ÔìÁËÕæÊµÒøÐÐÀûÓõĽçÃæ£¬´Ó¶øÈƹýÁË´«Í³ä¯ÀÀÆ÷µÄ°²È«ÖҸ档ֵÍ×ÌùÐĵÄÊÇ£¬¹¥»÷±³ºóÉæ¼°Á½¸ö·ÖÆçµÄÍþвÐÐΪÕߣ¬ËûÃÇÀûÓÃChrome WebAPK¼¼ÊõµÄĬÈÏÐÐΪ£¬ÀÄÓøÃÖ°ÄÜÒÔ°µ²Ø¡°À´×Ô²»ÊÜÐÅÀµÆðÔ´µÄ×°Öá±ÖҸ棬ʹµÃÓû§ÄÑÒÔ¾õ²ì·çÏÕ¡£¶ÔÓÚiOSÓû§£¬Ôòͨ¹ýÁìµ¼½«Î±ÔìµÄPWAÔö³¤µ½Ö÷ÆÁÄ»À´Ö´Ðй¥»÷¡£Ò»µ©Óû§ÔÚÕâЩÀûÓÃÖÐÊäÈëÒøÐÐÆ¾Ö¤£¬ÐÅÏ¢±ã»á±»Ð¹Â¶ÖÁ¹¥»÷Õß½ÚÔìµÄºÅÁîÓë½ÚÔ죨C2£©·þÎñÆ÷»òTelegramȺÁÄÖС£ESETÒѼà²âµ½¶à²¨ÀàËÆ»î¶¯¡£


https://thehackernews.com/2024/08/czech-mobile-users-targeted-in-new.html


6. ÐÂÐÍDNSºóÃÅBackdoor.MsupedgeÕë¶Ǫ̂Íå´óѧ


8ÔÂ20ÈÕ£¬Íþв·ÖÎöÈËÔ±½üÆÚÔŲ́Íå´óѧÔâ·êµÄ¹¥»÷Öи淢ÁËÒ»ÖÖÐÂÐͰ²È«ÍþвBackdoor.Msupedge£¬ÓÉÈüÃÅÌú¿Ë¹«Ë¾·¢ÏÖ²¢¶¨Ãû¡£¶ûºóÃÅѡȡÁËÒ»ÖÖº±¼ûµÄDNSͨѶ»úÔ죬ËäΪÒÑÖª¼¼Êõµ«ÏʼûÓÚÍøÂç·¸×ï»î¶¯ÖС£MsupedgeÒÔDLL´ó¾ÖDZ²ØÓÚÊÜϰȾϵͳµÄÌØ¶¨õè¾¶£¬Í¨¹ýDNS²éÎʽӹܲ¢Ö´ÐÐÖ¸ÁÕâÒ»Õ½Êõ²»½ö¶ã±ÜÁËͨÀý¼ì²â£¬»¹ÊµÏÖÁ˶ÔÖ¸±ê»úеµÄÒþÃØ²Ù¿Ø¡£ÓÈΪֵÍ×ÌùÐĵÄÊÇ£¬MsupedgeÄÜÆ¾¾ÝDNS²éÎʽâÎö³öµÄIPµØÖ·ÖеÄÌØ¶¨×Ö½ÚÀ´½Ã½Ýµ÷ÕûÆäÐÐΪ£¬ÈçÆô¶¯¹ý³Ì¡¢ÏÂÔØ¶ñÒâÎļþ¡¢É趨ϵͳÐÝÃßʱ³¤µÈ£¬¼«´ó¼ÓÇ¿ÁËÆä½Ã½ÝÐÔºÍÒñ±ÎÐÔ¡£´Ë±í£¬¸ÃºóÃÅÖ§³Ö¶àÖÖ²Ù×÷Ö¸ÁÔ̺¬»ùÓÚDNS TXT¼Í¼´´½¨¹ý³Ì¡¢´ÓÖ¸¶¨URLÏÂÔØÎļþ¡¢Ê¹ÏµÍ³ÐÝÃß³¤´ï24Ó×ʱ¼°ËãÕʺۼ£µÈ¡£¾ÝÈüÃÅÌú¿Ë·ÖÎö£¬Õâ´ÎÈëÇֵijõʼÈë¿Úµã¼«ÓпÉÄÜÊǽüÆÚÆØ¹âµÄPHP·ì϶£¨CVE-2024-4577£©£¬¸Ã·ì϶Äܵ¼ÖÂWindowsƽ̨ÉϵÄPHP°æ±¾Ô¶³Ì´úÂëÖ´ÐС£ÈüÃÅÌú¿Ë°ä²¼ÁËÏ꾡µÄÈëÇÖÖ¸±ê£¨IOC£©£¬ÒÔЭÖúÓû§¼ø±ðºÍ·ÀÓùBackdoor.MsupedgeµÄ¹¥»÷¡£


https://www.infosecurity-magazine.com/news/dns-based-backdoor-taiwanese/