ÐÂÍøÂç´¹µö¹¤¾ß°ü¡°Xi¨± g¨¯u¡±Òý·¢È«Çò°²È«¾¯±¨

°ä²¼¹¦·ò 2024-11-04

1. ÐÂÍøÂç´¹µö¹¤¾ß°ü¡°Xi¨± g¨¯u¡±Òý·¢È«Çò°²È«¾¯±¨


11ÔÂ1ÈÕ £¬ÍøÂ簲ȫÁìÓò½üÆÚ³öÏÖÁËÒ»ÖÖÃûΪXi¨± g¨¯uµÄÐÂÐÍÍøÂç´¹µö¹¤¾ß°ü £¬×Ô2024Äê9ÔÂÆðÒÑÕë¶Ô°Ä´óÀûÑÇ¡¢ÈÕ±¾¡¢Î÷°àÑÀ¡¢Ó¢¹úºÍÃÀ¹úµÈ¶à¸ö¹ú¶ÈÌáÒé¹¥»÷¡£¸Ã¹¤¾ß°üÒÑϰȾ³¬¹ý2000¸ö´¹µöÍøÕ¾ £¬ÖØÒª¹¥»÷¹«¹²²¿ÃÅ¡¢ÓÊÕþ¡¢Êý×Ö·þÎñºÍÒøÐзþÎñµÈ´¹Ö±ÐÐÒµ¡£NetcraftÖ¸³ö £¬ÕâЩ¹¥»÷Õß³£ÀûÓÃCloudflareµÄ·´»úеÈ˺ÍÍйܻìºÏÖ°ÄÜÀ´¶ã±Ü¼ì²â¡£Xi¨± g¨¯uÌṩÖÎÀíÃæ°å £¬Ê¹ÓÃGolangºÍVue.jsµÈ¼¼Êõ £¬Í¨¹ýTelegram´ÓÐéα´¹µöÒ³ÃæÇÔÊØÐÅÏ¢¡£ÕâÐ©ÍøÂç´¹µö¹¥»÷ÖØÒªÍ¨¹ý¸»Í¨ÕÛ·þÎñ£¨RCS£©ÐÂÎÅ´«²¼ £¬ÓÕµ¼Êܺ¦Õßµã»÷Ëõ¶ÌµÄÁ´½ÓÒÔÌṩÓ×ÎÒÐÅÏ¢»ò¸¶¿î¡£¹È¸èµÈ¿Æ¼¼¾ÞÍ·ÒѲÉÈ¡´ëÊ©½ø¹¥´ËÀàÚ¿Æ­ £¬Ô̺¬ÍƳö¼ÓÇ¿ÐÍÚ¿Æ­¼ì²âÖ°ÄܺͰ²È«ÖÒ¸æ £¬²¢´òËãÔÚÈ«ÇòÁìÓòÄÚÍÆ¹ãб£»¤´ëÊ©¡£´Ë±í £¬Ë¼¿ÆTalosÍŶӷ¢ÏÖ £¬Ì¨ÍåµÄFacebookóÒ׺͸æ°×ÕÊ»§Óû§Õý³ÉÎªÍøÂç´¹µö»î¶¯µÄÖ¸±ê £¬Ö¼ÔÚ´«²¼ÇÔÈ¡¶ñÒâÈí¼þ¡£ÕâЩ»î¶¯»¹¼ÙÒâOpenAIµÈ³ÛÃûÆóÒµ £¬ÓÕµ¼È«ÇòÆóÒµ¸üи¶¿îÐÅÏ¢¡£


https://thehackernews.com/2024/11/new-phishing-kit-xiu-gou-targets-users.html


2. InterlockÀÕË÷Èí¼þ£ºÕë¶ÔFreeBSD·þÎñÆ÷µÄÐÂÐ͹¥»÷Ðж¯


11ÔÂ3ÈÕ £¬InterlockÊÇÒ»¸öÐÂÐ˵ÄÀÕË÷Èí¼þ²Ù×÷ £¬×Ô2024Äê9ÔÂµ×Æô¶¯ÒÔÀ´ £¬ÒѶÔÈ«Çò¶à¸ö×éÖ¯ÌáÒé¹¥»÷¡£ËüѡȡһÖÖ²»³£¼ûµÄ²½Öè £¬¼´´´½¨×¨ÃÅÕë¶ÔFreeBSD·þÎñÆ÷µÄ¼ÓÃÜÆ÷¡£ÕâÖÖ¼ÓÃÜÆ÷ÔÚFreeBSD 10.4ÉϱàÒë £¬Ö»¹ÜBleepingComputerµÈ°²È«»ú¹¹ÔÚÐé¹¹»úÉϲâÊÔʱδÄÜʹÆäÕýÈ·Ö´ÐС£InterlockÔÚ¹¥»÷³É¹¦ºó £¬»áÔÚδ֧¸¶Êê½ðµÄÇé¿öÏ £¬ÔÚÆäÊý¾ÝÐ¹Â¶ÍøÕ¾Éϰ䲼±»µÁÊý¾Ý¡£¾ÝÍøÂ簲ȫ¹«Ë¾Ç÷Ïò¿Æ¼¼³Æ £¬InterlockµÄÖ¸±êÊÇFreeBSD £¬ÓÉÓÚËü¿í·ºÀûÓÃÓÚ·þÎñÆ÷ºÍ¹Ø¼ü»ù´¡ÉèÊ© £¬¹¥»÷ÕßÄܹ»·ÛËé³ÁÒª·þÎñ £¬Ë÷Òª¾Þ¶îÊê½ð¡£´Ë±í £¬Ç÷Ïò¿Æ¼¼»¹·¢ÏÖÁ˸òÙ×÷µÄWindows¼ÓÃÜÆ÷Ñù±¾¡£ÔÚ¼ÓÃÜÎļþʱ £¬Interlock»á½«.interlockÀ©´óÃû¸½¼Óµ½ËùÓмÓÃÜÎļþÃûºó £¬²¢ÔÚÿ¸öÎļþ¼ÐÖд´½¨ÀÕË÷¼Í¼¡£±»µÁÊý¾Ý±»ÓÃÓÚË«³ÁÀÕË÷¹¥»÷ £¬ÍþвÐÐΪÕßÍþв³Æ £¬ÈôÊDz»Ö§¸¶Êê½ð £¬ËûÃǾͻṫ¿ªÐ¹Â¶Êý¾Ý¡£¾Ý³Æ £¬InterlockÀÕË÷Èí¼þ²Ù×÷ÒªÇóµÄÊê½ð´ÓÊýÊ®ÍòÃÀÔªµ½Êý°ÙÍòÃÀÔª²»µÈ £¬¾ßÌåÈ¡¾öÓÚ×éÖ¯µÄ¹æÄ£¡£


https://www.bleepingcomputer.com/news/security/meet-interlock-the-new-ransomware-targeting-freebsd-servers/


3. SharePoint RCE·ì϶CVE-2024-38094Õý±»ºÚ¿ÍÀûÓýøÐÐÍøÂç¹¥»÷


11ÔÂ2ÈÕ £¬Microsoft SharePointµÄÒ»¸öÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2024-38094£©±»Åû¶²¢ÔÚ±»ºÚ¿ÍÀûÓà £¬ÒÔ»ñÈ¡¶Ô¹«Ë¾ÍøÂçµÄ³õʼ½Ó¼ûȨÏÞ¡£¸Ã·ì϶ÊÇÒ»¸ö¸ßÑϳÁÐÔ£¨CVSS v3.1 ÆÀ·Ö£º7.2£©µÄRCE·ì϶ £¬Ó°Ïì¿í·ºÊ¹ÓõĻùÓÚWebµÄSharePointƽ̨¡£Î¢ÈíÒÑÓÚ2024Äê7ÔÂ9ÈÕ°ä²¼Á˲¹¶¡½¨¸´¸Ã·ì϶ £¬²¢½«ÆäÏóÕ÷Ϊ¡°³ÁÒª¡±¡£È»¶ø £¬CISAÉÏÖܽ«¸Ã·ì϶Ôö³¤µ½ÒÑÖªÀûÓ÷ì϶Ŀ¼ʱ £¬²¢Î´Ð¹Â©¾ßÌåµÄÀûÓ÷½Ê½¡£Rapid7°ä²¼µÄл㱨½ÒʾÁ˹¥»÷ÕßÈôºÎÀûÓø÷ì϶ £¬Ö¸³ö¹¥»÷Õßͨ¹ýδ¾­ÊÚȨ½Ó¼ûÒ×Êܹ¥»÷µÄSharePoint·þÎñÆ÷²¢Ö²ÈëWebshell £¬½ø¶øÔÚÍøÂçÖкáÏòÒÆ¶¯ £¬Î£¼°Õû¸öÓò¡£¹¥»÷Õß»¹·ÛËéÁËÓµÓÐÓòÖÎÀíԱȨÏÞµÄMicrosoft Exchange·þÎñÕÊ»§ £¬»ñµÃÌáÉýµÄ½Ó¼ûȨÏÞ £¬²¢×°ÖÃÁËHoroung AntivirusÈí¼þ £¬Ôì³É°²È«·ÀÓùì¶Ü £¬½ûÓð²È«·þÎñ £¬¼õÈõ¼ì²âÄÜÁ¦¡£ËûÃÇʹÓöàÖÖ¹¤¾ß½øÐÐÆ¾Ö¤ÍøÂç¡¢Ô¶³Ì½Ó¼û¡¢ÓƾÃÐÔÉèÖõȲÙ×÷ £¬²¢½ûÓÃÁËWindows Defender¡¢¸ü¸ÄÁËÊÂÎñÈÕÖ¾ £¬ÒÔÔ¤·À±»·¢ÏÖ¡£Ö»¹Ü¹¥»÷ÕßÊÔͼɾ³ý±¸·Ý £¬µ«²¢Î´³É¹¦¼ÓÃÜÊý¾Ý £¬Òò¶ø¹¥»÷ÀàÐÍÉв»Ã÷ÏÔ¡£


https://www.bleepingcomputer.com/news/security/microsoft-sharepoint-rce-bug-exploited-to-breach-corporate-network/


4. Âåɼí¶ÊÐס·¿ÖÎÀí¾ÖÔâCactusÀÕË÷Èí¼þÍŻ﹥»÷


11ÔÂ1ÈÕ £¬Âåɼí¶ÊÐס·¿ÖÎÀí¾Ö£¨HACLA£©ÊÇÃÀ¹ú×î´óµÄ¹«¹²×¡·¿ÖÎÀí¾ÖÖ®Ò» £¬ÕƹÜÖÎÀí³¬¹ý32,000Ì×¹«¹²×¡·¿ £¬Äê¶ÈÔ¤Ë㳬¹ý10ÒÚÃÀÔª £¬ÎªµÍÊÕÈë¼ÒÍ¥¡¢¶ùͯºÍÀÏÄêÈËÌṩ¾­¼ÃºÏÓ÷¿ºÍÔöÔ®´òËã¡£×î½ü £¬CactusÀÕË÷Èí¼þÍÅ»ïÐû³Æ¶ÔHACLAµÄITÍøÂç½øÐÐÁËÈëÇÖ¹¥»÷¡£HACLA֤ʵÁËÕâÒ»ÍøÂç¹¥»÷ £¬²¢°µÊ¾ÒÑÀñƸ±í²¿È¡Ö¤ITר¼Ò½øÐе÷²éºÍÓ¦¶Ô¡£Ö»¹ÜHACLAδй©¹¥»÷µÄ¾ßÌ幦·òºÍÐÔÖÊ £¬µ«CactusÀÕË÷Èí¼þÍÅ»ïÐû³ÆÒÑ´ÓÊÜϰȾµÄÍøÂçÖÐÇÔÈ¡ÁË891 GBµÄÎļþ £¬Ô̺¬Ó×ÎÒÉí·ÝÐÅÏ¢¡¢²ÆÕþÎļþ¡¢¸ß¹ÜºÍÔ±¹¤Ó×ÎÒÊý¾Ý¡¢¿Í»§Ó×ÎÒÐÅÏ¢¡¢¹«Ë¾»úÃÜÊý¾ÝºÍͨѶµÈ £¬²¢ÔÚÆäйÃÜÍøÕ¾Éϰ䲼ÁËһЩÃô¸ÐÎļþµÄ½ØÍ¼×÷Ϊ֤¾Ý¡£´Ë±í £¬HACLAÔÚ2022ÄêÒ²ÔøÔâµ½LockBitÀÕË÷Èí¼þÍÅ»ïµÄ¹¥»÷ £¬¹¥»÷ÕßÔÚ³¤´ïÒ»ÄêµÄ¹¦·òÀï½Ó¼ûÁËHACLAµÄϵͳ £¬²¢Äܹ»½Ó¼û»áÔ±µÄÃô¸ÐÓ×ÎÒÐÅÏ¢¡£µ±¾Ö»ú¹¹ÔڻؾøÖ§¸¶ÍøÂç·¸×ï·Ö×ÓÒªÇóµÄÊê½ðºó £¬LockBitÀÕË÷Èí¼þ×é֯й¶ÁËËùÓб»µÁÎļþ¡£


https://www.bleepingcomputer.com/news/security/la-housing-authority-confirms-breach-claimed-by-cactus-ransomware/


5. LastPassÓû§¾¯ÌèÐéα֧³Öµç»°Ö´ÐÐÔ¶³Ì½Ó¼ûÚ¿Æ­


11ÔÂ1ÈÕ £¬LastPass ÊÇÒ»¿îÊ¢ÐеÄÃÜÂëÖÎÀíÆ÷ £¬ËüÀûÓà LastPass Chrome À©´ó·¨Ê½À´ÌìÉú¡¢±£Áô¡¢ÖÎÀíºÍ×Ô¶¯Ìî³äÍøÕ¾ÃÜÂë¡£LastPass·¢³öÖÒ¸æ £¬Ú¿Æ­ÕßÔÚͨ¹ýÔÚÆäChromeÀ©´ó·¨Ê½Éϰ䲼Ðéα5ÐÇÆÀÂÛ £¬ÍƹãÒ»¸ö¼ÙðµÄ¿Í»§Ö§³Öµç»°ºÅÂë805-206-2892 £¬ÒÔÓÕÆ­LastPassÓû§¡£Ò»µ©Óû§²¦´ò¸Ãµç»° £¬Æ­×Ó»á¼ÙÒâLastPass £¬Êèµ¼ËûÃǽӼû¡°dghelp[.]top¡±ÍøÕ¾ £¬²¢ÒªÇóÊäÈë´úÂëÏÂÔØÔ¶³ÌÖ§³Ö·¨Ê½ £¬¸Ã·¨Ê½ÏÖʵÉÏÊÇConnectWise ScreenConnect´úÀí £¬ÔÊÐíÚ¿Æ­Õ߯ëÈ«½Ó¼ûÓû§µÄÍÆËã»ú¡£BleepingComputer·¢ÏÖ £¬¸Ãµç»°ºÅÂëÓëÒ»³¡¸ü´ó¹æÄ£µÄÚ¿Æ­»î¶¯ÓйØ £¬¸ÃºÅÂ뻹±»ÓÃ×÷ºÜ¶àÆäËû¹«Ë¾£¨ÈçÑÇÂíÑ·¡¢Adobe¡¢FacebookµÈ£©µÄ¼Ùð֧³Öµç»°ºÅÂë £¬²¢ÔÚ¸÷ÀàÍøÕ¾Éϰ䲼¡£LastPassÓû§±»ÌáÐѲ»ÒªÓëÈκÎÈË·ÖÏíËûÃǵÄÖ÷ÃÜÂë £¬ÒÔÔ¤·À°µÀï½Ó¼ûÆäÃÜÂë¿âÖд洢µÄËùÓÐÃÜÂëºÍÊý¾Ý¡£


https://www.bleepingcomputer.com/news/security/lastpass-warns-of-fake-support-centers-trying-to-steal-customer-data/


6. ·¨¹úÀ͹¤²¿ÔâÍøÂç¹¥»÷ £¬¾ÍÒµÖú·öÄêÇáÈËÊý¾ÝÒÉÔâй¶


11ÔÂ1ÈÕ £¬·¨¹úÀ͹¤²¿°ä·¢ £¬Æä¡°´¦ËùʹÍÅ¡±ÍøÂçʹÓõÄÒ»¼Ò·þÎñÌṩÉÌÒÉËÆ½üÆÚÔâ·êÍøÂç¹¥»÷ £¬¸ÃÍøÂçÖØÒªÎª16ÖÁ25ËêµÄÄêÇáÈËÌṩ¾ÍÒµºÍÅàѵ½¨ÒéÓëÖ§³Ö¡£Õâ´Î¹¥»÷¿ÉÄÜй¶ÁËÒÑÔÚ¸ÃϵͳÖеǼǵÄÄêÇáÈ˵ÄÓ×ÎÒÊý¾Ý £¬Ô̺¬È«Ãû¡¢µ®ÉúÈÕÆÚ¡¢¹ú¼®¡¢µç×ÓÓʼþºÍÓÊÕþµØÖ·ÒÔ¼°µç»°ºÅÂë £¬µ«ÒøÐоßÌåÐÅÏ¢¡¢Éç»á±£ÏպźÍÉí·ÝÖ¤¼þδÊÜÓ°Ïì¡£Ö»¹Ü¼¼Êõµ÷²éÉÐδʵÏÖ £¬¸Ã²¿ÒѲÉÈ¡¶àÏî´ëÊ©½â¾ö·ì϶ÎÊÌâ £¬²¢ÒÑÏò·¨¹úÒþÖÔ¼à¹Ü»ú¹¹CNILºÍÍøÂ簲ȫ»ú¹¹ANSSI»ã±¨´ËÊ £¬Í¬Ê±Ïò˾·¨µ±¾ÖÌáÆðͶËß¡£ÊÜÓ°ÏìµÄÄêÇáÈËÔÚ±»´«µÝÇé¿ö £¬²¢ÌáÐÑËûÃǾ¯ÌèÍøÂç´¹µöºÍÉí·Ý͵ÇԵķçÏÕ £¬ÇÐÎðͨ¹ýµç»°¡¢¶ÌÐÅ»òµç×ÓÓʼþй©ÃÜÂë»òÒøÐоßÌåÐÅÏ¢¡£


https://therecord.media/france-data-breach-government-contractor-local-missions