ÐÂÍøÂç´¹µö¹¤¾ß°ü¡°Xi¨± g¨¯u¡±Òý·¢È«Çò°²È«¾¯±¨
°ä²¼¹¦·ò 2024-11-041. ÐÂÍøÂç´¹µö¹¤¾ß°ü¡°Xi¨± g¨¯u¡±Òý·¢È«Çò°²È«¾¯±¨
11ÔÂ1ÈÕ£¬ÍøÂ簲ȫÁìÓò½üÆÚ³öÏÖÁËÒ»ÖÖÃûΪXi¨± g¨¯uµÄÐÂÐÍÍøÂç´¹µö¹¤¾ß°ü£¬×Ô2024Äê9ÔÂÆðÒÑÕë¶Ô°Ä´óÀûÑÇ¡¢ÈÕ±¾¡¢Î÷°àÑÀ¡¢Ó¢¹úºÍÃÀ¹úµÈ¶à¸ö¹ú¶ÈÌáÒé¹¥»÷¡£¸Ã¹¤¾ß°üÒÑϰȾ³¬¹ý2000¸ö´¹µöÍøÕ¾£¬ÖØÒª¹¥»÷¹«¹²²¿ÃÅ¡¢ÓÊÕþ¡¢Êý×Ö·þÎñºÍÒøÐзþÎñµÈ´¹Ö±ÐÐÒµ¡£NetcraftÖ¸³ö£¬ÕâЩ¹¥»÷Õß³£ÀûÓÃCloudflareµÄ·´»úеÈ˺ÍÍйܻìºÏÖ°ÄÜÀ´¶ã±Ü¼ì²â¡£Xi¨± g¨¯uÌṩÖÎÀíÃæ°å£¬Ê¹ÓÃGolangºÍVue.jsµÈ¼¼Êõ£¬Í¨¹ýTelegram´ÓÐéα´¹µöÒ³ÃæÇÔÊØÐÅÏ¢¡£ÕâÐ©ÍøÂç´¹µö¹¥»÷ÖØÒªÍ¨¹ý¸»Í¨ÕÛ·þÎñ£¨RCS£©ÐÂÎÅ´«²¼£¬ÓÕµ¼Êܺ¦Õßµã»÷Ëõ¶ÌµÄÁ´½ÓÒÔÌṩÓ×ÎÒÐÅÏ¢»ò¸¶¿î¡£¹È¸èµÈ¿Æ¼¼¾ÞÍ·ÒѲÉÈ¡´ëÊ©½ø¹¥´ËÀàÚ¿Æ£¬Ô̺¬ÍƳö¼ÓÇ¿ÐÍڿƼì²âÖ°ÄܺͰ²È«ÖҸ棬²¢´òËãÔÚÈ«ÇòÁìÓòÄÚÍÆ¹ãб£»¤´ëÊ©¡£´Ë±í£¬Ë¼¿ÆTalosÍŶӷ¢ÏÖ£¬Ì¨ÍåµÄFacebookóÒ׺͸æ°×ÕÊ»§Óû§Õý³ÉÎªÍøÂç´¹µö»î¶¯µÄÖ¸±ê£¬Ö¼ÔÚ´«²¼ÇÔÈ¡¶ñÒâÈí¼þ¡£ÕâЩ»î¶¯»¹¼ÙÒâOpenAIµÈ³ÛÃûÆóÒµ£¬ÓÕµ¼È«ÇòÆóÒµ¸üи¶¿îÐÅÏ¢¡£
https://thehackernews.com/2024/11/new-phishing-kit-xiu-gou-targets-users.html
2. InterlockÀÕË÷Èí¼þ£ºÕë¶ÔFreeBSD·þÎñÆ÷µÄÐÂÐ͹¥»÷Ðж¯
11ÔÂ3ÈÕ£¬InterlockÊÇÒ»¸öÐÂÐ˵ÄÀÕË÷Èí¼þ²Ù×÷£¬×Ô2024Äê9ÔÂµ×Æô¶¯ÒÔÀ´£¬ÒѶÔÈ«Çò¶à¸ö×éÖ¯ÌáÒé¹¥»÷¡£ËüѡȡһÖÖ²»³£¼ûµÄ²½Ö裬¼´´´½¨×¨ÃÅÕë¶ÔFreeBSD·þÎñÆ÷µÄ¼ÓÃÜÆ÷¡£ÕâÖÖ¼ÓÃÜÆ÷ÔÚFreeBSD 10.4ÉϱàÒ룬ֻ¹ÜBleepingComputerµÈ°²È«»ú¹¹ÔÚÐé¹¹»úÉϲâÊÔʱδÄÜʹÆäÕýÈ·Ö´ÐС£InterlockÔÚ¹¥»÷³É¹¦ºó£¬»áÔÚδ֧¸¶Êê½ðµÄÇé¿öÏ£¬ÔÚÆäÊý¾ÝÐ¹Â¶ÍøÕ¾Éϰ䲼±»µÁÊý¾Ý¡£¾ÝÍøÂ簲ȫ¹«Ë¾Ç÷Ïò¿Æ¼¼³Æ£¬InterlockµÄÖ¸±êÊÇFreeBSD£¬ÓÉÓÚËü¿í·ºÀûÓÃÓÚ·þÎñÆ÷ºÍ¹Ø¼ü»ù´¡ÉèÊ©£¬¹¥»÷ÕßÄܹ»·ÛËé³ÁÒª·þÎñ£¬Ë÷Òª¾Þ¶îÊê½ð¡£´Ë±í£¬Ç÷Ïò¿Æ¼¼»¹·¢ÏÖÁ˸òÙ×÷µÄWindows¼ÓÃÜÆ÷Ñù±¾¡£ÔÚ¼ÓÃÜÎļþʱ£¬Interlock»á½«.interlockÀ©´óÃû¸½¼Óµ½ËùÓмÓÃÜÎļþÃûºó£¬²¢ÔÚÿ¸öÎļþ¼ÐÖд´½¨ÀÕË÷¼Í¼¡£±»µÁÊý¾Ý±»ÓÃÓÚË«³ÁÀÕË÷¹¥»÷£¬ÍþвÐÐΪÕßÍþв³Æ£¬ÈôÊDz»Ö§¸¶Êê½ð£¬ËûÃǾͻṫ¿ªÐ¹Â¶Êý¾Ý¡£¾Ý³Æ£¬InterlockÀÕË÷Èí¼þ²Ù×÷ÒªÇóµÄÊê½ð´ÓÊýÊ®ÍòÃÀÔªµ½Êý°ÙÍòÃÀÔª²»µÈ£¬¾ßÌåÈ¡¾öÓÚ×éÖ¯µÄ¹æÄ£¡£
https://www.bleepingcomputer.com/news/security/meet-interlock-the-new-ransomware-targeting-freebsd-servers/
3. SharePoint RCE·ì϶CVE-2024-38094Õý±»ºÚ¿ÍÀûÓýøÐÐÍøÂç¹¥»÷
11ÔÂ2ÈÕ£¬Microsoft SharePointµÄÒ»¸öÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2024-38094£©±»Åû¶²¢ÔÚ±»ºÚ¿ÍÀûÓã¬ÒÔ»ñÈ¡¶Ô¹«Ë¾ÍøÂçµÄ³õʼ½Ó¼ûȨÏÞ¡£¸Ã·ì϶ÊÇÒ»¸ö¸ßÑϳÁÐÔ£¨CVSS v3.1 ÆÀ·Ö£º7.2£©µÄRCE·ì϶£¬Ó°Ïì¿í·ºÊ¹ÓõĻùÓÚWebµÄSharePointƽ̨¡£Î¢ÈíÒÑÓÚ2024Äê7ÔÂ9ÈÕ°ä²¼Á˲¹¶¡½¨¸´¸Ã·ì϶£¬²¢½«ÆäÏóÕ÷Ϊ¡°³ÁÒª¡±¡£È»¶ø£¬CISAÉÏÖܽ«¸Ã·ì϶Ôö³¤µ½ÒÑÖªÀûÓ÷ì϶Ŀ¼ʱ£¬²¢Î´Ð¹Â©¾ßÌåµÄÀûÓ÷½Ê½¡£Rapid7°ä²¼µÄл㱨½ÒʾÁ˹¥»÷ÕßÈôºÎÀûÓø÷ì϶£¬Ö¸³ö¹¥»÷Õßͨ¹ýδ¾ÊÚȨ½Ó¼ûÒ×Êܹ¥»÷µÄSharePoint·þÎñÆ÷²¢Ö²ÈëWebshell£¬½ø¶øÔÚÍøÂçÖкáÏòÒÆ¶¯£¬Î£¼°Õû¸öÓò¡£¹¥»÷Õß»¹·ÛËéÁËÓµÓÐÓòÖÎÀíԱȨÏÞµÄMicrosoft Exchange·þÎñÕÊ»§£¬»ñµÃÌáÉýµÄ½Ó¼ûȨÏÞ£¬²¢×°ÖÃÁËHoroung AntivirusÈí¼þ£¬Ôì³É°²È«·ÀÓùì¶Ü£¬½ûÓð²È«·þÎñ£¬¼õÈõ¼ì²âÄÜÁ¦¡£ËûÃÇʹÓöàÖÖ¹¤¾ß½øÐÐÆ¾Ö¤ÍøÂç¡¢Ô¶³Ì½Ó¼û¡¢ÓƾÃÐÔÉèÖõȲÙ×÷£¬²¢½ûÓÃÁËWindows Defender¡¢¸ü¸ÄÁËÊÂÎñÈÕÖ¾£¬ÒÔÔ¤·À±»·¢ÏÖ¡£Ö»¹Ü¹¥»÷ÕßÊÔͼɾ³ý±¸·Ý£¬µ«²¢Î´³É¹¦¼ÓÃÜÊý¾Ý£¬Òò¶ø¹¥»÷ÀàÐÍÉв»Ã÷ÏÔ¡£
https://www.bleepingcomputer.com/news/security/microsoft-sharepoint-rce-bug-exploited-to-breach-corporate-network/
4. Âåɼí¶ÊÐס·¿ÖÎÀí¾ÖÔâCactusÀÕË÷Èí¼þÍŻ﹥»÷
11ÔÂ1ÈÕ£¬Âåɼí¶ÊÐס·¿ÖÎÀí¾Ö£¨HACLA£©ÊÇÃÀ¹ú×î´óµÄ¹«¹²×¡·¿ÖÎÀí¾ÖÖ®Ò»£¬ÕƹÜÖÎÀí³¬¹ý32,000Ì×¹«¹²×¡·¿£¬Äê¶ÈÔ¤Ë㳬¹ý10ÒÚÃÀÔª£¬ÎªµÍÊÕÈë¼ÒÍ¥¡¢¶ùͯºÍÀÏÄêÈËÌṩ¾¼ÃºÏÓ÷¿ºÍÔöÔ®´òËã¡£×î½ü£¬CactusÀÕË÷Èí¼þÍÅ»ïÐû³Æ¶ÔHACLAµÄITÍøÂç½øÐÐÁËÈëÇÖ¹¥»÷¡£HACLA֤ʵÁËÕâÒ»ÍøÂç¹¥»÷£¬²¢°µÊ¾ÒÑÀñƸ±í²¿È¡Ö¤ITר¼Ò½øÐе÷²éºÍÓ¦¶Ô¡£Ö»¹ÜHACLAδй©¹¥»÷µÄ¾ßÌ幦·òºÍÐÔÖÊ£¬µ«CactusÀÕË÷Èí¼þÍÅ»ïÐû³ÆÒÑ´ÓÊÜϰȾµÄÍøÂçÖÐÇÔÈ¡ÁË891 GBµÄÎļþ£¬Ô̺¬Ó×ÎÒÉí·ÝÐÅÏ¢¡¢²ÆÕþÎļþ¡¢¸ß¹ÜºÍÔ±¹¤Ó×ÎÒÊý¾Ý¡¢¿Í»§Ó×ÎÒÐÅÏ¢¡¢¹«Ë¾»úÃÜÊý¾ÝºÍͨѶµÈ£¬²¢ÔÚÆäйÃÜÍøÕ¾Éϰ䲼ÁËһЩÃô¸ÐÎļþµÄ½ØÍ¼×÷Ϊ֤¾Ý¡£´Ë±í£¬HACLAÔÚ2022ÄêÒ²ÔøÔâµ½LockBitÀÕË÷Èí¼þÍÅ»ïµÄ¹¥»÷£¬¹¥»÷ÕßÔÚ³¤´ïÒ»ÄêµÄ¹¦·òÀï½Ó¼ûÁËHACLAµÄϵͳ£¬²¢Äܹ»½Ó¼û»áÔ±µÄÃô¸ÐÓ×ÎÒÐÅÏ¢¡£µ±¾Ö»ú¹¹ÔڻؾøÖ§¸¶ÍøÂç·¸×ï·Ö×ÓÒªÇóµÄÊê½ðºó£¬LockBitÀÕË÷Èí¼þ×é֯й¶ÁËËùÓб»µÁÎļþ¡£
https://www.bleepingcomputer.com/news/security/la-housing-authority-confirms-breach-claimed-by-cactus-ransomware/
5. LastPassÓû§¾¯ÌèÐéα֧³Öµç»°Ö´ÐÐÔ¶³Ì½Ó¼ûÚ¿Æ
11ÔÂ1ÈÕ£¬LastPass ÊÇÒ»¿îÊ¢ÐеÄÃÜÂëÖÎÀíÆ÷£¬ËüÀûÓà LastPass Chrome À©´ó·¨Ê½À´ÌìÉú¡¢±£Áô¡¢ÖÎÀíºÍ×Ô¶¯Ìî³äÍøÕ¾ÃÜÂë¡£LastPass·¢³öÖҸ棬ڿÆÕßÔÚͨ¹ýÔÚÆäChromeÀ©´ó·¨Ê½Éϰ䲼Ðéα5ÐÇÆÀÂÛ£¬ÍƹãÒ»¸ö¼ÙðµÄ¿Í»§Ö§³Öµç»°ºÅÂë805-206-2892£¬ÒÔÓÕÆLastPassÓû§¡£Ò»µ©Óû§²¦´ò¸Ãµç»°£¬Æ×Ó»á¼ÙÒâLastPass£¬Êèµ¼ËûÃǽӼû¡°dghelp[.]top¡±ÍøÕ¾£¬²¢ÒªÇóÊäÈë´úÂëÏÂÔØÔ¶³ÌÖ§³Ö·¨Ê½£¬¸Ã·¨Ê½ÏÖʵÉÏÊÇConnectWise ScreenConnect´úÀí£¬ÔÊÐíÚ¿ÆÕ߯ëÈ«½Ó¼ûÓû§µÄÍÆËã»ú¡£BleepingComputer·¢ÏÖ£¬¸Ãµç»°ºÅÂëÓëÒ»³¡¸ü´ó¹æÄ£µÄڿƻÓйأ¬¸ÃºÅÂ뻹±»ÓÃ×÷ºÜ¶àÆäËû¹«Ë¾£¨ÈçÑÇÂíÑ·¡¢Adobe¡¢FacebookµÈ£©µÄ¼Ùð֧³Öµç»°ºÅÂ룬²¢ÔÚ¸÷ÀàÍøÕ¾Éϰ䲼¡£LastPassÓû§±»ÌáÐѲ»ÒªÓëÈκÎÈË·ÖÏíËûÃǵÄÖ÷ÃÜÂ룬ÒÔÔ¤·À°µÀï½Ó¼ûÆäÃÜÂë¿âÖд洢µÄËùÓÐÃÜÂëºÍÊý¾Ý¡£
https://www.bleepingcomputer.com/news/security/lastpass-warns-of-fake-support-centers-trying-to-steal-customer-data/
6. ·¨¹úÀ͹¤²¿ÔâÍøÂç¹¥»÷£¬¾ÍÒµÖú·öÄêÇáÈËÊý¾ÝÒÉÔâй¶
11ÔÂ1ÈÕ£¬·¨¹úÀ͹¤²¿°ä·¢£¬Æä¡°´¦ËùʹÍÅ¡±ÍøÂçʹÓõÄÒ»¼Ò·þÎñÌṩÉÌÒÉËÆ½üÆÚÔâ·êÍøÂç¹¥»÷£¬¸ÃÍøÂçÖØÒªÎª16ÖÁ25ËêµÄÄêÇáÈËÌṩ¾ÍÒµºÍÅàѵ½¨ÒéÓëÖ§³Ö¡£Õâ´Î¹¥»÷¿ÉÄÜй¶ÁËÒÑÔÚ¸ÃϵͳÖеǼǵÄÄêÇáÈ˵ÄÓ×ÎÒÊý¾Ý£¬Ô̺¬È«Ãû¡¢µ®ÉúÈÕÆÚ¡¢¹ú¼®¡¢µç×ÓÓʼþºÍÓÊÕþµØÖ·ÒÔ¼°µç»°ºÅÂ룬µ«ÒøÐоßÌåÐÅÏ¢¡¢Éç»á±£ÏպźÍÉí·ÝÖ¤¼þδÊÜÓ°Ïì¡£Ö»¹Ü¼¼Êõµ÷²éÉÐδʵÏÖ£¬¸Ã²¿ÒѲÉÈ¡¶àÏî´ëÊ©½â¾ö·ì϶ÎÊÌ⣬²¢ÒÑÏò·¨¹úÒþÖÔ¼à¹Ü»ú¹¹CNILºÍÍøÂ簲ȫ»ú¹¹ANSSI»ã±¨´ËÊ£¬Í¬Ê±Ïò˾·¨µ±¾ÖÌáÆðͶËß¡£ÊÜÓ°ÏìµÄÄêÇáÈËÔÚ±»´«µÝÇé¿ö£¬²¢ÌáÐÑËûÃǾ¯ÌèÍøÂç´¹µöºÍÉí·Ý͵ÇԵķçÏÕ£¬ÇÐÎðͨ¹ýµç»°¡¢¶ÌÐÅ»òµç×ÓÓʼþй©ÃÜÂë»òÒøÐоßÌåÐÅÏ¢¡£
https://therecord.media/france-data-breach-government-contractor-local-missions


¾©¹«Íø°²±¸11010802024551ºÅ