³¯ÏÊLazarus GroupÀûÓÃChromeÁãÈÕ·ì϶ÌáÒé¹¥»÷
°ä²¼¹¦·ò 2024-10-2810ÔÂ24ÈÕ£¬³¯ÏʺڿÍ×éÖ¯Lazarus Group±»Ö¸ÀûÓÃGoogle ChromeµÄÏÖÒѽ¨²¹°²È«·ì϶CVE-2024-4947½øÐÐÁãÈÕ¹¥»÷£¬½ÚÔìÊÜϰȾÉ豸¡£¿¨°Í˹»ù¹«Ë¾ÔÚ2024Äê5Ô·¢ÏÖÁËÒ»ÌõÕë¶Ô¶íÂÞ˹¹«ÃñµÄ¹¥»÷Á´£¬¹¥»÷ͨ¹ýÐéαµÄ¼ÓÃÜÇ®±ÒÁìÓòÓÎÏ·ÍøÕ¾"detankzone[.]com"´¥·¢·ì϶¡£¸ÃÍøÕ¾¼Ù×°³ÉÈ¥ÖÐÐÄ»¯½ðÈÚ£¨DeFi£©NFTµÄ¶àÈËÔÚÏßÕ½¶·¾º¼¼³¡£¨MOBA£©Ì¹¿ËÓÎÏ·£¬ÊµÔòÔ̺¬°µ²Ø¾ç±¾£¬ÔÚÓû§ä¯ÀÀÆ÷ÖÐÔËÐзì϶£¬Ê¹¹¥»÷Õß»ñµÃ¶ÔÊܺ¦ÕßPCµÄÆëÈ«½ÚÔì¡£´Ë±í£¬Lazarus Group»¹±»ÒÉ»óÇÔÈ¡ÁËÒ»¿îºÏ·¨Çø¿éÁ´±ßÍæ±ß׬£¨P2E£©ÓÎÏ·µÄÔ´´úÂëºÍÇ®±Ò£¬ÓÃÓÚʵÏÔìä¹¥»÷Ö¸±ê¡£¿¨°Í˹»ùÖ¸³ö£¬LazarusÊÇ×î»îÔ¾¡¢×ÔÓµÄAPT¹¥»÷ÕßÖ®Ò»£¬¾¼ÃÀûÒæÊÇÆäÖØÒª¶¯»ú£¬ÇÒÆäÕ½ÊõÔÚ²»ÐÝÑݱ䣬ÀûÓÃÌìÉúʽÈËΪÖÇÄܵÈм¼ÊõÌáÒé¸ü¸´ÔӵĹ¥»÷¡£
https://thehackernews.com/2024/10/lazarus-group-exploits-google-chrome.html
2. Fortinet FortiManager RCEÁãÈÕ·ì϶ÔÚÒ°±í±»ÀûÓÃ
10ÔÂ24ÈÕ£¬ÍøÂ簲ȫ¹«Ë¾Fortinet½üÈÕÅû¶ÁËÆäÈí¼þ²úÆ·FortiManager´æÔÚÒ»¸ö¹Ø¼üÁãÈÕ·ì϶£¨CVE-2024-47575£©£¬¸Ã·ì϶ÔÊÐíδ¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õßͨ¹ýÌØÔìÒªÇóÖ´ÐÐËÁÒâ´úÂë»òºÅÁÇÒÒÑÔÚÒ°±í±»»ý¼«ÀûÓ᣸÷ì϶µÄCVSS v3ÆÀ·Ö¸ß´ï9.8£¬Ó°Ïì¶à¸ö°æ±¾µÄFortiManager¼°FortiManager Cloud¡£FortinetÒѰ䲼²¹¶¡²¢ÌṩÁ˶àÖÖ½â¾ö²½Öè¡£¾Ý»ã±¨£¬¸Ã·ì϶Òѱ»ÓÃÓÚй¼ûô¸ÐÎļþ£¬Ô̺¬IPµØÖ·¡¢Æ¾Ö¤ºÍÉ豸ÅäÖ㬵«ÉÐδ·¢ÏÖ¶ñÒâÈí¼þ»òºóÃÅ×°Öá£Íþв×éÖ¯UNC5820×Ô2024Äê6ÔÂ27ÈÕÆð¾ÍÀûÓô˷ì϶£¬»ñÈ¡ÁËFortiGateÉ豸ÅäÖÃÊý¾Ý£¬Ô̺¬Óû§¼ÓÃÜÃÜÂ룬¿ÉÄÜÓÃÓÚ½øÒ»²½·ÛËéºÍºáÏòÒÆ¶¯¡£MandiantÎÞ·¨È·¶¨¹¥»÷ÕßÉí·ÝºÍÖ÷ÕÅ£¬½¨ÒéËùÓж³öÔÚ»¥ÁªÍøÉϵÄFortiManager×éÖ¯µ±¼´½øÐÐȡ֤µ÷²é¡£Fortinet¶½´ÙÓû§µ±¼´Éý¼¶ÖÁ°²È«°æ±¾£¬²¢²ÉÈ¡×èֹδ֪É豸ע²á¡¢Ê¹ÓÃ×Ô½ç˵֤ÊéÉí·ÝÑéÖ¤µÈ½â¾ö²½Öè¡£
https://cybersecuritynews.com/fortimanager-zero-day-vulnerability/#google_vignette
3. FogÓëAkiraÀÕË÷Èí¼þÀûÓÃSonicWall VPN·ì϶ƵÈÔÈëÇÔìóÒµÍøÂç
10ÔÂ27ÈÕ£¬FogºÍAkiraÀÕË÷Èí¼þÔËÓªÉÌÕýÔ½À´Ô½¶àµØÀûÓÃSonicWall VPNÕÊ»§ÈëÇÔìóÒµÍøÂ磬¹Ø¼ü·ì϶CVE-2024-40766±»ÒÔΪÊÇÆäÈëÇÖµÄÖØÒªÍ¨Â·¡£SonicWallÓÚ2024Äê8ÔÂÏÂÑ®½¨¸´Á˸÷ì϶£¬µ«Ò»Öܺó±ãÖÒ¸æ³Æ·ì϶Òѱ»»ý¼«ÀûÓᣱ±¼«Àǰ²È«×êÑÐÈËÔ±·¢ÏÖ£¬AkiraÀÕË÷Èí¼þ´ÓÊô»ú¹¹ÒÑÀûÓø÷ì϶»ñÈ¡³õʼ½Ó¼ûȨÏÞ¡£¾ÝArctic Wolf»ã±¨£¬AkiraºÍFogÖÁÉÙ½øÐÐÁË30´ÎÈëÇÖ£¬¾ùʼÓÚͨ¹ýSonicWall VPNÕÊ»§Ô¶³Ì½Ó¼û¡£ÆäÖУ¬75%µÄ°¸¼þÓëAkiraÓйأ¬ÆäÓàΪFogËùΪ¡£ÕâÁ½¸ö×éÖ¯ËÆºõ¹²Ïí»ù´¡ÉèÊ©£¬Åú×¢ÈÔ´æÔÚ·ÇÕýʽºÏ×÷¡£ËùÓб»¹¥ÆÆµÄ¶Ëµã¶¼ÔËÐÐÒ×Êܹ¥»÷µÄ佨²¹°æ±¾£¬ÇÒ´ÓÈëÇÖµ½Êý¾Ý¼ÓÃܵŦ·òͨ³£½Ï¶Ì£¬×î¿ì½öÐè1.5-2Ó×ʱ¡£ÍþвÐÐΪÕßͨ¹ýVPN/VPS½Ó¼û¶Ëµã²¢»ìºÏÕæÊµIPµØÖ·¡£ÊÜϰȾ×é֯δÆôÓöà³É·ÖÉí·ÝÑéÖ¤£¬Ò²Î´ÔÚĬÈ϶˿ÚÉÏÔËÐзþÎñ¡£ÈëÇÖ¹ý³ÌÖУ¬¹Û²ìµ½Ìض¨ÐÂÎÅÊÂÎñIDÅú×¢Ô¶³ÌÓû§µÇ¼ºÍIP·ÖÅä³É¹¦¡£ÍþвÐÐΪÕßÖØÒªÕë¶ÔÐé¹¹»ú¼°Æä±¸·ÝÌáÒé¼±¾ç¼ÓÃܹ¥»÷£¬²¢ÇÔÈ¡ÎĵµºÍרÓÐÈí¼þ£¬µ«²»¹Ø×¢³¬¹ýÁù¸öÔ»ò30¸öÔµÄÎļþ¡£
https://www.bleepingcomputer.com/news/security/fog-ransomware-targets-sonicwall-vpns-to-breach-corporate-networks/
4. BlackBastaÀÕË÷Èí¼þÐж¯ÀûÓÃMicrosoft Teams½øÐÐÉç»á¹¤³Ì¹¥»÷
10ÔÂ25ÈÕ£¬BlackBastaÀÕË÷Èí¼þÐж¯×Ô2022Äê4ÔÂÒÔÀ´Ò»Ïò»îÔ¾£¬¶ÔÈ«ÇòÊý°ÙÆðÆóÒµ¹¥»÷ÕÆ¹Ü¡£¸Ã×é֯ͨ¹ý·ì϶¡¢ºÏ×÷¡¢¶ñÒâÈí¼þ½©Ê¬ÍøÂçºÍÉç»á¹¤³ÌѧµÈ¶àÖÖ²½Öè·ÛËéÍøÂç¡£×î½ü£¬BlackBastaµÄ´ÓÊô»ú¹¹½«Éç»á¹¤³Ì¹¥»÷×ªÒÆµ½ÁËMicrosoft TeamsÉÏ£¬ËûÃǼÙÒ⹫˾ITÔ®ÊǪ̈ÁªÏµÔ±¹¤£¬ÐÖú½â¾öÀ¬»øÓʼþÎÊÌâ¡£¹¥»÷ÕßÊ×ÏÅ×õç×ÓÓʼþ¸²Ã»Ô±¹¤µÄÊÕ¼þÏ䣬¶øºóÒÔ±í²¿Óû§µÄÉí·Ýͨ¹ýMicrosoft TeamsÁªÏµÔ±¹¤£¬ÕâЩÕÊ»§ÊÇÔÚEntra ID×â»§Ï´´½¨µÄ£¬Ãû³Æ¿´ÆðÀ´ÏñÊÇÔ®ÊǪ̈¡£ÔÚ̸ÌìÖУ¬¹¥»÷Õß·¢ËͶþάÂë»òÓÕÆÓû§×°ÖÃAnyDeskÔ¶³ÌÖ§³Ö¹¤¾ß»òÆô¶¯Windows Quick AssistÔ¶³Ì½ÚÔìºÍÆÁÄ»¹²Ïí¹¤¾ß£¬ÒÔ±ãÔ¶³Ì½Ó¼ûÓû§µÄ¹«Ë¾É豸¡£Ò»µ©Ïνӣ¬¹¥»÷Õß»á×°Öø÷ÀàÓÐÐ§ÔØºÉ£¬ÈçScreenConnect¡¢NetSupport ManagerºÍCobalt Strike£¬ÒÔ³ÖÐøÔ¶³Ì½Ó¼ûÓû§µÄ¹«Ë¾É豸£¬²¢ºáÏòÀ©É¢µ½ÆäËûÉ豸£¬Í¬Ê±ÌáÉýȨÏÞ¡¢ÇÔÈ¡Êý¾Ý£¬²¢×îÖÕ²¿ÊðÀÕË÷Èí¼þ¼ÓÃÜÆ÷¡£ReliaQuest½¨Òé×éÖ¯ÏÞ¶ÈMicrosoft TeamsÖÐÀ´×Ô±í²¿Óû§µÄͨѶ£¬²¢ÆôÓÃÈÕÖ¾¼Í¼ÒÔ²éÕÒ¿ÉÒÉ̸Ìì¡£
https://www.bleepingcomputer.com/news/security/black-basta-ransomware-poses-as-it-support-on-microsoft-teams-to-breach-networks/
5. ÑÇÂíÑ·²é·âAPT29ºÚ¿Í×éÖ¯¹¥»÷ÓòÃû
10ÔÂ25ÈÕ£¬ÑÇÂíÑ·ÒѲé·â¶íÂÞ˹APT29ºÚ¿Í×éÖ¯ÓÃÓÚµ±¾ÖºÍ¾üÊÂ×éÖ¯Õë¶ÔÐÔ¹¥»÷µÄÓòÃû¡£APT29£¬Óֳơ°Cozy Bear¡±ºÍ¡°Midnight Blizzard¡±£¬Óë¶íÂÞ˹¶Ô±íµý±¨¾ÖÓÐÁªÏµ£¬ÉÆÓÚʹÓÃÍøÂç´¹µöºÍ¶ñÒâÈí¼þÇÔÈ¡Ãô¸ÐÐÅÏ¢¡£Õâ´Î¹¥»÷ÖУ¬APT29ͨ¹ý¼Ù×°³ÉAWSÓòÃûµÄÍøÂç´¹µöÒ³Ãæ£¬ÓÕÆÖ¸±êÏàÐŲ¢Ê¹ÓöñÒâÔ¶³Ì×ÀÃæºÍ̸ÏνÓÎļþ£¬ÒÔÇÔÈ¡Windowsƾ֤ºÍÊý¾Ý¡£Ö»¹ÜÑÇÂíÑ·³ÎÇåÆäÔÆÆ½Ì¨²¢·ÇÖ±½ÓÖ¸±ê£¬µ«ÈÔµ±¼´Æô¶¯Á˲é·â¼ÙÒâAWSÓòÃûµÄ·¨Ê½¡£APT29ÒԸ߶ȸ´ÔӵĹ¥»÷ÎÅÃû£¬Õë¶ÔÈ«Çòµ±¾Ö¡¢ÖÇ¿âºÍ×êÑлú¹¹£¬ÇÒ×î½ü»î¶¯ÁìÓò¿í·º£¬Ô̺¬Ïò¸ü¶àÖ¸±ê·¢ËÍÍøÂç´¹µöµç×ÓÓʼþ¡£ÎÚ¿ËÀ¼ÍÆËã»úÓ¦¼±·´Ó³Ó××éÒ²°ä²¼ÁËÓйØÖҸ棬²¢½¨Òé²ÉÈ¡¶àÏî´ëÊ©Ï÷¼õ¹¥»÷Ãæ£¬Èç×èÖ¹¡°.rdp¡±Îļþ¡¢ÏÞ¶ÈRDPÏνӵȡ£APT29ÈÔÊǶíÂÞ˹×î׳´óµÄÍøÂçÍþв֮һ£¬´ÓǰһÄêÖÐÔøÈëÇÖ¶à¸ö³ÁÒªÈí¼þ¹©¸øÉÌ£¬²¢ÀûÓ÷þÎñÆ÷·ì϶ÈëÇÖÈ«Çò³ÁÒª×éÖ¯¡£
https://www.bleepingcomputer.com/news/security/amazon-seizes-domains-used-in-rogue-remote-desktop-campaign-to-steal-data/
6. RansomHubºÚ¿Í×éÖ¯Ðû³Æ¶ÔÄ«Î÷¸ç13¸ö»ú³¡ÔËÓªÉÌÌáÒé¹¥»÷
10ÔÂ26ÈÕ£¬ºÚ¿Í×éÖ¯RansomHub×î½üÐû³Æ¶ÔÄ«Î÷¸ç13¸ö»ú³¡ÔËÓªÉÌGrupo Aeroportuario del Centro Norte£¨OMA£©µÄÍøÂç¹¥»÷ÕÆ¹Ü£¬²¢ÍþвÈôÊDz»Ö§¸¶Êê½ð£¬½«Ð¹Â¶3TB±»µÁÊý¾Ý¡£OMAÔËÓª×ÅÄ«Î÷¸çÖв¿ºÍ±±²¿µØÓòµÄ»ú³¡£¬½ñÄêÒÑ»¶Ó³¬1900ÍòÃû³Ë¿Í¡£Õâ´ÎÍøÂçÊÂÎñÆÈʹOMAתÏò±¸ÓÃϵͳÒÔά³ÖÔËÓª£¬µ«ÏÔʾº½°àº½Õ¾Â¥µØÎ»µÄÆÁÄ»ÈÔÎÞ·¨Ê¹Óá£OMA°µÊ¾ÔÚÓë±í²¿ÍøÂ簲ȫר¼ÒºÏ×÷µ÷²éÊÂÎñÁìÓò£¬²¢ÒÑÖ𲽸´ÔijЩ·þÎñ£¬µ«¶Ô¹«Ë¾ÔËÓªºÍ²ÆÕþÇé¿öδÔì³É³Á´ó²»ÀûÓ°Ï졣΢Èí±¾ÖÜÖ¸³ö£¬RansomHubÈÔÊÇÀÕË÷Èí¼þÁìÓò×î»îÔ¾µÄÍþв֮һ£¬¶à¸öÆäËûÍþвÐÐΪÕßÒ²³ÖÐøÊ¹ÓÃÆä¶ñÒâÈí¼þ½øÐй¥»÷¡£
https://therecord.media/ransomhub-gang-behind-attack-mexican-airport-operator


¾©¹«Íø°²±¸11010802024551ºÅ