IvantiÖÒ¸æ³Æ»¹ÓÐÈý¸öCSAÁãÈÕ·ì϶ÔÚ±»¹¥»÷ÕßÀûÓÃ
°ä²¼¹¦·ò 2024-10-101. IvantiÖÒ¸æ³Æ»¹ÓÐÈý¸öCSAÁãÈÕ·ì϶ÔÚ±»¹¥»÷ÕßÀûÓÃ
10ÔÂ8ÈÕ£¬ÃÀ¹úITÈí¼þ¹«Ë¾Ivanti½üÆÚ°ä²¼Á˰²È«¸üУ¬Ö¼ÔÚ½¨¸´Èý¸ö±»»ý¼«ÀûÓõÄÐÂÐÍÔÆ·þÎñÉ豸£¨CSA£©ÁãÈÕ·ì϶£¬ÕâЩ·ì϶±àºÅΪCVE-2024-9379¡¢CVE-2024-9380ºÍCVE-2024-9381¡£¹¥»÷Õß½«ÕâЩ·ì϶Óë9Ô·ÝÒѽ¨²¹µÄÁíÒ»¸öCSAÁãÈÕ·ì϶£¨CVE-2024-8963£©½áºÏʹÓã¬Í¨¹ýSQL×¢Èë¡¢ºÅÁî×¢ÈëºÍõè¾¶±éÀúµÈ¼¿Á©£¬Ô¶³ÌÖ´ÐÐËÁÒâ´úÂë²¢ÈÆ¹ý°²È«ÏÞ¶È¡£IvantiÖÒ¸æ³Æ£¬ÔËÐÐCSA 4.6 patch 518¼°¸üÔç°æ±¾µÄ¿Í»§ÔÚ½áºÏÕâЩ·ì϶ʱ¿ÉÄÜÒÑÔâµ½¹¥»÷£¬²¢½¨ÒéÊÜÓ°Ïì¿Í»§Éý¼¶µ½CSA 5.0.2°æ±¾ÒÔ³Á½¨É豸¡£Í¬Ê±£¬ÖÎÀíÔ±Ó¦ÀûÓÃEDR»òÆäËû°²È«Èí¼þ¾¯±¨£¬ÒÔ¼°²é³ÐµĻòÅú¸ÄºóµÄÖÎÀíÔ±Óû§À´¼ì²âÈëÇÖ¼£Ïó¡£ÓÉÓÚCSA 4.6ÒÑÍ£²ú£¬ÈÔÔÚÔËÐд˰汾µÄ¿Í»§Ó¦¾¡¿ìÉý¼¶¡£´Ë±í£¬CISAÒѽ«Óйطì϶Ôö³¤µ½ÒÑÖª±»ÀûÓ÷ì϶Ŀ¼ÖУ¬²¢ÒªÇóÁª¹ú»ú¹¹ÔÚ10ÔÂ10ÈÕǰ±£»¤Ò×Êܹ¥»÷µÄϵͳ¡£
https://www.bleepingcomputer.com/news/security/ivanti-warns-of-three-more-csa-zero-days-exploited-in-attacks/
2. ¿¨Î÷Å·ÔâÍøÂç¹¥»÷£¬·þÎñÖжϲ¢Òý·¢Êý¾Ýй¶ÓÇÓô
10ÔÂ8ÈÕ£¬ÈÕ±¾¿Æ¼¼¾ÞÍ·¿¨Î÷Å·ÍÆËã»ú¹«Ë¾½üÆÚÔâ·êÁËÒ»Â·ÍøÂ簲ȫÊÂÎñ£¬ÆäÍøÂ类δ¾ÊÚȨµÄÐÐΪÕß½Ó¼û£¬µ¼ÖÂϵͳÖжϣ¬²¢Ó°ÏìÁ˲¿ÃÅ·þÎñ¡£¿¨Î÷Å·ÒÔÍó±í¡¢ÍÆËãÆ÷¡¢ÀÔì÷¡¢Ïà»úµÈµç×Ó²úÆ·ÎÅÃû£¬Õâ´Î¹¥»÷¶ÔÆäÔì³ÉÁ˲»Ó×µÄÓ°Ïì¡£¿¨Î÷Å·ÔÚ²¼¸æÖÐÈ·ÈÏÁËÕâ´ÎÍøÂç¹¥»÷£¬²¢°µÊ¾ÔÚÓë±í²¿×¨¼ÒºÏ×÷£¬ÒÔÈ·¶¨ÊÇ·ñÓÐÓ×ÎÒÊý¾Ý»òÆäËû»úÃÜÐÅÏ¢±»µÁ¡£Ä¿Ç°£¬¸Ã¹«Ë¾Î´Ð¹Â©¸ü¶àϸ½Ú£¬Ò²Î´×¢Ã÷·þÎñÖжϵľßÌåÄÚÈÝ¡£¿¨Î÷Å·ÒÑÏòºÏÓõÄÊý¾Ý±£»¤»ú¹¹»ã±¨ÁË´ËÊÂÎñ£¬²¢²ÉÈ¡ÁËÏÞ¶È±í²¿ÈËÔ±½Ó¼ûµÄ´ëÊ©¡£Ö»¹ÜÉÐδÓÐÀÕË÷Èí¼þ×éÖ¯Ðû³Æ¶ÔÕâ´Î¹¥»÷ÕÆ¹Ü£¬µ«Õâ´ÎÊÂÎñ¶Ô¿¨Î÷Å·À´ËµÎÞÒÉÊÇÒ»´Î½ø¹¥¡£Ô¼ÄªÒ»Äêǰ£¬¿¨Î÷Å·»¹ÔøÅû¶¹ýÁíһ·Êý¾Ýй¶ÊÂÎñ£¬Éæ¼°149¸ö¹ú¶ÈµÄ¿Í»§Êý¾Ý¡£Õâ´Î×îеÄÍøÂ簲ȫÊÂÎñ²úÉúÔÚ¿¨Î÷Å·¼´½«Òò´ó¹æÄ£ÈËʳÁ×é¶øÔâ·ê½ü5000ÍòÃÀÔªÒìʱʱÐÔËðʧµÄ¼è¾Þʱ¿Ì£¬ÎÞÒɸø¸Ã¹«Ë¾´øÀ´Á˸ü´óµÄÌôÕ½¡£
https://www.bleepingcomputer.com/news/security/casio-reports-it-systems-failure-after-weekend-network-breach/
3. Awaken Likho APT×é֯ѡȡÐÂÕ½Êõ¹¥»÷¶íÂÞ˹»ú¹¹
10ÔÂ8ÈÕ£¬¿¨°Í˹»ù×êÑÐÈËÔ±½ÒʾÁËAwaken Likho APT×éÖ¯£¨±ðÃûCore Werewolf£©×Ô2021Äê7ÔÂÒÔÀ´Õë¶Ô¶íÂÞ˹µ±¾Ö»ú¹¹ºÍ¹¤ÒµÆóÒµÌáÒéµÄ×îй¥»÷¡£¸Ã×éÖ¯ÔÚ2024Äê6ÔµÄй¥»÷ÖУ¬ÏÔÖøÅ¤×ªÁËÆäÈí¼þºÍ¼¼Êõ£¬´ÓÀûÓÃUltraVNCÄ£¿éתÏòʹÓúϷ¨µÄMeshCentralƽ̨´úÀíMeshAgent¡£MeshCentral×÷ΪһÖÖ¿ªÔ´Ô¶³ÌÉ豸ÖÎÀí½â¾ö¹æ»®£¬±»¹¥»÷Õß·¸·¨ÀûÓÃÒÔ½ÚÔìÊÜϰȾϵͳ£¬Õâһת±äÔö³¤Á˹¥»÷µÄÒñ±ÎÐÔºÍÄѶȡ£¿¨°Í˹»ùÍŶӷ¢ÏÖ£¬Awaken Likhoͨ¹ýÍøÂç´¹µöµç×ÓÓʼþ´«²¼ÐÂÖ²È뷨ʽ£¬ÕâЩÓʼþÀûÓÃ7-Zip´´½¨µÄSFXÌåʽ·Ö·¢£¬ÄÚº¬¼Ù×°³ÉºÏ·¨ÏµÍ³·þÎñºÍºÅÁîÎļþµÄµö¶ü¡£Ö²È뷨ʽÔËÐк󣬻áÆô¶¯MeshAgentºÍÒ»¸ö¸ß¶È»ìºÏµÄºÅÁîÎļþ£¬Ö¼ÔÚʵÏÖÓÆ¾ÃÐÔ½ÚÔ졣ͨ¹ý´´½¨´òË㹤×÷£¬¹¥»÷ÕßÈ·±£MeshAgentÄܳÁÐÂÏνӵ½ºÅÁîºÍ½ÚÔì·þÎñÆ÷£¬¸ÃÏνÓͨ¹ýWebSocketºÍ̸³ÉÁ¢£¬²¢ÀûÓÃHTTPS¼ÓÃÜ¡£Awaken LikhoµÄÕâ´Î¹¥»÷»î¶¯ÓëÒÔÍùÒ»Ö£¬Ö¸±êÈÔÊǶíÂÞ˹µ±¾Ö»ú¹¹¡¢³Ð°üÉ̺͹¤ÒµÆóÒµ¡£
https://securityonline.info/new-campaign-by-awaken-likho-apt-group-changes-in-software-and-techniques/
4. »¥ÁªÍøµµ°¸¹ÝÔâÊý¾Ýй¶£¬3100ÍòÓû§ÐÅÏ¢±»µÁ
10ÔÂ9ÈÕ£¬»¥ÁªÍøµµ°¸¹ÝµÄ¡°Wayback Machine¡±½üÆÚÔâ·êÁËÑϳÁµÄÊý¾Ýй¶ÊÂÎñ¡£Ò»ÃûÍþвÐÐΪÕ߳ɹ¦ÈëÇÖ¸ÃÍøÕ¾£¬ÇÔÈ¡ÁËÔ̺¬3100ÍòÌõΨһ¼Í¼µÄÓû§Éí·ÝÑéÖ¤Êý¾Ý¿â£¬²¢Í¨¹ýJavaScript¾¯±¨Ïòarchive.orgµÄ½Ó¼ûÕßÐû¸æÁËÕâÒ»ÈëÇÖ¡£¸Ã¾¯±¨»¹Ìá¼°ÁËTroy Hunt´´½¨µÄHave I Been Pwned£¨HIBP£©Êý¾Ýй¶֪ͨ·þÎñ£¬ÍþвÐÐΪÕßÒÑÓë¸Ã·þÎñ¹²ÏíÁ˱»µÁÊý¾Ý¡£±»µÁµÄÊý¾Ý¿âÃûΪ¡°ia_users.sql¡±£¬ÊÇÒ»¸ö6.4GBµÄSQLÎļþ£¬Ô̺¬×¢²á³ÉÔ±µÄÉí·ÝÑéÖ¤ÐÅÏ¢£¬Èçµç×ÓÓʼþµØÖ·¡¢ÆÁÄ»Ãû³Æ¡¢ÃÜÂë¸ü¸Ä¹¦·ò´Á¡¢Bcrypt¹þÏ£ÃÜÂëµÈ¡£¾ÝHIBPµÄÊ×´´È˺àÌØÐ¹Â©£¬Êý¾Ý¿âÖÐÓÐ3100Íò¸öΨһµç×ÓÓʼþµØÖ·£¬ÆäÖкܶàÒѶ©ÔÄHIBPµÄÊý¾Ýй¶֪ͨ·þÎñ¡£ÕâЩÊý¾Ý½«ºÜ¿ì±»Ôö³¤µ½HIBPÖУ¬ÒÔ±ãÓû§Äܹ»²éÎÊËûÃǵÄÊý¾ÝÊÇ·ñÔÚÕâ´Îй¶Öб»Ð¹Â¶¡£Ä¿Ç°Éв»Ã÷ÏÔÍþвÐÐΪÕßÊÇÈôºÎÇÖÈ뻥ÁªÍøµµ°¸¹ÝµÄ£¬ÒÔ¼°ÊÇ·ñÓÐÆäËûÊý¾Ý±»µÁ¡£¶ø¾ÍÔÚ½ñÌìÔçЩʱ³½£¬»¥ÁªÍøµµ°¸¹Ý»¹Ôâ·êÁËDDoS¹¥»÷£¬BlackMetaºÚ¿Í×éÖ¯ÒÑÐû³Æ¶Ô´ËÕÆ¹Ü£¬²¢°µÊ¾½«½øÐиü¶à¹¥»÷¡£
https://www.bleepingcomputer.com/news/security/internet-archive-hacked-data-breach-impacts-31-million-users/
5. Å·ÑǶà¹ú³¬2.8ÍòÈËÔâ¼ÓÃÜÇ®±ÒÇÔÈ¡¶ñÒâÈí¼þ¹¥»÷
10ÔÂ9ÈÕ£¬½üÆÚһ·´ó¹æÄ£¼ÓÃÜÇ®±ÒÇÔÈ¡¶ñÒâÈí¼þ»î¶¯Ó°ÏìÁ˶íÂÞ˹¡¢ÍÁ¶úÆä¡¢ÎÚ¿ËÀ¼¼°Å·ÑǵØÓòÆäËû¹ú¶ÈµÄ³¬¹ý28,000ÈË¡£¸Ã»î¶¯Í¨¹ý¼Ù×°³ÉºÏ·¨Èí¼þ£¬ÔÚYouTubeÊÓÆµºÍÚ²ÆÐÔGitHub´æ´¢¿âÉϽøÐÐÍÆ¹ã£¬ÓÕµ¼Êܺ¦ÕßÏÂÔØÊÜÃÜÂë±£»¤µÄµµ°¸²¢Æô¶¯Ï°È¾¡£¾ÝÍøÂ簲ȫ¹«Ë¾Dr. Web³Æ£¬¾ø´óÎÞÊýÊܺ¦ÕßÊǶíÂÞ˹¾ÓÃñ£¬Í¬Ê±°×¶íÂÞ˹¡¢ÎÚ×ȱð¿Ë˹̹¡¢¹þÈø¿Ë˹̹¡¢ÎÚ¿ËÀ¼¡¢¼ª¶û¼ªË¹Ë¹Ì¹ºÍÍÁ¶úÆäÒ²³öÏÖ´óÁ¿Ï°È¾¡£¶ñÒâÈí¼þÀûÓöàÖÖ¼¿Á©ºýŪÓû§ÏÂÔØ£¬Ò»µ©Ï°È¾£¬»á²é³µ÷ÊÔ¹¤¾ß¡¢ÌáÈ¡ËùÐèÎļþ¡¢Åú¸ÄWindows×¢²á±íÒÔʵÏÖÓÆ¾ÃÐÔ£¬²¢½Ù³ÖºÏ·¨µÄWindowsϵͳ·þÎñºÍä¯ÀÀÆ÷¸üйý³Ì¡£´Ë±í£¬¶ñÒâÈí¼þ»¹»áÍøÂçϵͳÐÅÏ¢²¢Í¨¹ýTelegram»úеÈËÇÔÈ¡£¬Í¶·ÅSilentCryptoMinerÍÚ¾ò¼ÓÃÜÇ®±Ò£¬ÒÔ¼°³äÈμô¼Æ÷¼à¶½²¢´úÌæWindows¼ôÌù°åÖеÄÇ®°üµØÖ·¡£Dr. Web·¢ÏÖ£¬½öClipper¾Í½Ù³ÖÁ˼ÛÖµ6,000ÃÀÔªµÄÂòÂô¡£ÎªÔ¤·À²ÆÕþËðʧ£¬½¨Òé´Ó¹Ù·½ÍøÕ¾ÏÂÔØÈí¼þ£¬²¢ÉóÉ÷¶Ô´ýYouTube»òGitHubÉϵÄÁ´½Ó¡£
https://www.bleepingcomputer.com/news/cryptocurrency/crypto-stealing-malware-campaign-infects-28-000-people/
6. ÃÀ˾·¨²¿Óë΢ÈíÁªÊÖ²é»ñ°ÙÓà¶íÂÞ˹ºÚ¿ÍÍøÂç´¹µöÍøÕ¾
10ÔÂ4ÈÕ£¬ÃÀ¹ú˾·¨²¿ºÍ΢Èí½áºÏÐж¯£¬³É¹¦²é»ñÁË100¶à¸öÓɶíÂÞ˹ºÚ¿ÍÓÃÓÚÕë¶ÔÃÀ¹ú½øÐÐÍøÂç´¹µö»î¶¯µÄÍøÕ¾¡£Õâ´ÎÐж¯Ö¼ÔÚ×èÖ¹¹ú¶ÈÖ§³ÖµÄÍøÂç¹¥»÷£¬±£»¤ÃÀ¹úµÄÃô¸ÐÊý¾Ý¡£±»²é·âµÄÓòÃûÓÉÃûΪCallisto GroupµÄ×é֯ʹÓ㬸Ã×éÖ¯ÊǶíÂÞ˹Áª¹ú°²È«²¿ÃÅÊôµÄÐж¯µ¥Ôª£¬±»Ö¸¿Ø²ß¶¯Óã²æÊ½ÍøÂç´¹µö»î¶¯£¬Ö¼ÔÚºýŪÊÕ¼þÈËй¶µÇ¼ʹ´¦£¬Î´¾ÊÚȨ½Ó¼ûµÐÔÖʵÌåºÍÆäËû¸ß¼ÛÖµÖ¸±êµÄ»úÃÜÐÅÏ¢¡£Î¢ÈíÔÚÐж¯ÖвûÑïÁ˹ؼü×÷Óã¬ÌáÆðÁËÃñÊÂËßËÏ£¬ÒªÇó²é·âÓëCallisto GroupÓйØÁªµÄ66¸öÓòÃû¡£Õâ´ÎÐж¯²»½ö·ÛËéÁËÏÖÓÐÔËÓªºÍ»ù´¡ÉèÊ©£¬»¹Ïò±í¹úµÐÊÖºÍÃÀ¹ú¹úÄÚÃñ¶à·¢³öÁËÃ÷È·µÄÐÅÏ¢£¬Åú×¢¶íÂÞ˹ÊÇÒ»¸öÕæÕýµÄÍøÂçÐж¯µÐÊÖ¡£´Ë±í£¬Õâ´ÎÐж¯Ò²Õ¹Ê¾Á˵±¾ÖºÍ˽Ӫ²¿ÃÅÖ®¼ä³ÖÐøºÏ×÷µÄ³ÁÒªÐÔ£¬Äܹ»¹²Í¬¸ü¿ìµØ¶ôÔìÍøÂç·¸×ï¡£
https://hackread.com/doj-microsoft-seize-russian-phishing-sites-target-us/


¾©¹«Íø°²±¸11010802024551ºÅ