Bitdefender°ä²¼ShrinkLockerÀÕË÷Èí¼þ½âÃÜÆ÷
°ä²¼¹¦·ò 2024-11-141. Bitdefender°ä²¼ShrinkLockerÀÕË÷Èí¼þ½âÃÜÆ÷
11ÔÂ13ÈÕ£¬Bitdefender°ä²¼ÁËÕë¶ÔShrinkLockerÀÕË÷Èí¼þµÄ½âÃÜÆ÷£¬²¢°ä·¢ÁËһƪ¾ßÌåÚ¹ÊÍÆä¹¤×÷µÀÀíµÄ×êÑв©¿Í¡£ShrinkLockerÀûÓÃWindowsµÄºÏ·¨Ö°ÄÜBitLocker£¬¼±¾ç¼ÓÃÜÔ̺¬ÏµÍ³Çý¶¯Æ÷ÔÚÄÚµÄÕû¸öÇý¶¯Æ÷£¬¶øºóɾ³ý¸´ÔÑ¡Ïî¡£¸ÃÀÕË÷Èí¼þ³õ´ÎÔÚÖж«Ò»¼ÒÒ½ÁƱ£½¡¹«Ë¾µÄÊÂÎñÖб»·¢ÏÖ£¬¹¥»÷Õßͨ¹ýºáÏòÒÆ¶¯ÔÚϵͳÄÚ²¿ÊðShrinkLocker¡£ËüÕë¶ÔÄ«Î÷¸ç¡¢Ó¡¶ÈÄáÎ÷ÑǺÍÔ¼µ©µÄ×éÖ¯£¬Ó°ÏìÁ˸ÖÌú¡¢ÒßÃçÔì×÷µÈÐÐÒµ¼°µÐÔÖʵÌå¡£ÓëÒÀÀµ¸´ÔÓ¼ÓÃÜËã·¨µÄÏÖ´úÀÕË÷Èí¼þ·ÖÆç£¬ShrinkLockerѡȡ¸üµ¥Ò»µÄ²½Ö裬ÏȲé³BitLockerÊÇ·ñÆôÓã¬ÈôδÆôÓÃÔò×°Ö㬲¢Ê¹ÓÃËæ»úÌìÉúµÄÃÜÂë³ÁмÓÃÜϵͳ¡£³ÁÆôºó£¬Óû§ÐèÊäÈëÃÜÂë½âËøÇý¶¯Æ÷£¬Ö§¸¶Êê½ðÒÔ»»È¡½âÃÜÃÜÔ¿¡£¸ÃÀÕË÷Èí¼þµÄµ¥Ò»ÐÔʹÆä¶ÔµÍ¼¶ÍøÂç·¸×ï·Ö×ÓÓµÓÐÎüÒýÁ¦£¬ÇÒÒѱ»¶à¸öÍþвÐÐΪÕ߸ıàÓÃÓÚ¸üµ¥Ò»µÄ¹¥»÷¡£ShrinkLocker¿ÉÔھɰæWindowsºÍServerϵͳÉÏÖ´ÐС£Î¢ÈíÔø°µÊ¾£¬ÒÁÀʵ±¾ÖÖ§³ÖµÄÍþв×éÖ¯ÀÄÓÃBitLockerÖ°ÄܽøÐй¥»÷£¬ÆäËûÍøÂç·¸×ï·Ö×ÓҲʹÓÃÀàËÆ¼¼Êõ¡£
https://therecord.media/bitdefender-releases-decryptor-shrinklocker
2. 1.22ÒÚóÒ×ÁªÏµÐÅÏ¢ÔâB2Bƽ̨DemandScienceÊý¾Ýй¶
11ÔÂ13ÈÕ£¬ÏÖÒÑÈ·ÈÏ£¬×Ô2024Äê2ÔÂÒÔÀ´£¬B2BÐèÒªÌìÉúƽ̨DemandScience£¨Ç°ÉíΪPure Incubation£©µÄ1.22ÒÚÈ˵ÄóÒ×ÁªÏµÐÅÏ¢±»ÇÔÈ¡²¢ÔÚÍøÂç·¸×ïÂÛ̳ÉÏÏúÊÛ¡£ÕâЩÊý¾ÝÔ̺¬È«Ãû¡¢µØÖ·¡¢µç×ÓÓʼþ¡¢µç»°ºÅÂ롢ְλºÍÉ罻ýÌåÁ´½ÓµÈ£¬ÊÇ´Ó¹«¹²ÆðÔ´ºÍµÚÈý·½ÍøÂçµÄ¡£2024Äê2Ô£¬ÃûΪ¡°KryptonZambie¡±µÄÍþвÐÐΪÕßÔÚBreachForumsÉÏÐû³ÆÕâЩÊý¾ÝÊÇ´ÓPure IncubationµÄ¶³öϵͳÖÐÇÔÈ¡µÄ¡£DemandScienceÆäʱ·ñ¶¨´æÔÚй¶£¬²¢°µÊ¾ÆäϵͳδÊܹ¥»÷¡£È»¶ø£¬µ½2024Äê8ÔÂ15ÈÕ£¬KryptonZambieÃâ·Ñй¶ÁËÊý¾Ý¼¯¡£ÌØÂåÒÁ¡¤ºàÌØÔÚ²©¿ÍÎÄÕÂÖÐÈ·ÈÏÊý¾ÝÕæÊµ¿¿µÃס£¬²¢Ö¸³öй¶µÄÊý¾ÝÀ´×ÔDemandScienceÁ½ÄêǰÒÑÍËÒÛµÄϵͳ¡£ºàÌØ»¹È·ÈÏй¶µÄÊý¾ÝÖÐÔ̺¬Ëû×Ô¼ºµÄ¼Í¼¡£±»µÁÊý¾Ý¼¯ÖеÄËùÓÐ1.22ÒÚ¸öΨһµç×ÓÓʼþµØÖ·ÒÑÔö³¤µ½¡°Have I Been Pwned¡±ÖУ¬ÊÜÓ°ÏìµÄ¶©ÔÄÕß½«ÊÕµ½Í¨Öª¡£
https://www.bleepingcomputer.com/news/security/leaked-info-of-122-million-linked-to-b2b-data-aggregator-breach/
3. ÒÁÀʺڿÍ×éÖ¯TA455Õë¶Ôº½¿Õº½ÌìÐÐÒµÌáÒéÍøÂç´¹µö¹¥»÷
11ÔÂ14ÈÕ£¬×ÔÈ¥Äê9ÔÂÆð£¬Ò»ÏîÕë¶ÔLinkedInµÈƽ̨Óû§µÄÍøÂç´¹µö»î¶¯ÆðÍ·»îÔ¾£¬¸Ã»î¶¯ÓÉÓëÒÁÀÊÓйصÄÍþвÐÐΪÕßTA455ÌáÒé¡£TA455ѡȡÓã²æÊ½ÍøÂç´¹µö²½Ö裬¼ÙÒ⺽¿Õº½ÌìÐÐÒµµÄÕÐÆ¸ÈËÔ±ÓëÊܺ¦Õß³ÉÁ¢ÁªÏµ£¬²¢ÓÕµ¼ËûÃÇÏÂÔØÃûΪ¡°SIgnedConnection.zip¡±µÄѹËõÎļþ¡£Í¬Ê±£¬ÍþвÐÐΪÕß»¹ÌṩPDFÖ¸ÄÏ£¬Áìµ¼Êܺ¦ÕßÈôºÎ°²È«ÏÂÔØºÍ´ò¿ª¸ÃÎļþ¡£È»¶ø£¬¸ÃѹËõÎļþÏÖʵÉÏÔ̺¬Ò»¸ö¿ÉÖ´ÐÐÎļþ£¬Í¨¹ýDLL²àÔØ½«ÃûΪ¡°secure32.dll¡±µÄ¶ñÒâDLLÎļþ¼ÓÔØµ½Êܺ¦ÕßϵͳÖУ¬Ê¹¹¥»÷Õß¿ÉÄÜÔËÐÐδ±»¼ì²âµ½µÄ´úÂë¡£Ëæºó£¬¶ñÒâÈí¼þÆô¶¯Ï°È¾Á´£¬×îÖÕ²¿ÊðÓÉÁíÒ»¸öÒÁÀÊÍþвÐÐΪÕßCharming Kitten¿ª·¢µÄSnail Resin¶ñÒâÈí¼þ£¬²¢´ò¿ªÃûΪ¡°SlugResin¡±µÄºóÃÅ¡£TA455ʹÓöàÖÖÌӱܼì²âµÄ²½Ö裬Ô̺¬ÔÚGitHubÉ϶ԺÅÁîºÍ½ÚÔ죨C2£©Í¨Ñ¶½øÐбàÂ룬ÒÔ¼°·ÂÕÕLazarus GroupµÄÕ½Êõ£¬Ê¹µÃ¹éÒò±äµÃ¸´ÔÓ¡£ÓÉÓÚTA455ÖØÒªÕë¶Ôº½¿Õº½ÌìרҵÈËÊ¿£¬Òò¶ø¸ÃÁìÓòµÄLinkedInµÈƽ̨Óû§Ó¦¾¯ÌèÀ´×Ôδ֪ÆðÔ´µÄÐÂÎźÍÁªÏµ¡£
https://www.darkreading.com/cyberattacks-data-breaches/iranian-cybercriminals-aerospace-workers-linkedin
4. ÃÀ¹úÒ©·¿½áºÏ»á£¨AAP£©ÔâEmbargoÀÕË÷Èí¼þ¹¥»÷
11ÔÂ13ÈÕ£¬ÃÀ¹úÒ©·¿½áºÏ»á£¨AAP£©³ÉΪ×îÐÂÒ»¼ÒÊý¾ÝÔâµ½ÍøÂç·¸×ï·Ö×ÓÇÔÈ¡ºÍ¼ÓÃܵÄÃÀ¹úÒ½ÁƱ£½¡×éÖ¯¡£AAP³ÉÁ¢ÓÚ2009Ä꣬ÖÎÀí×ÅÈ«ÃÀ2000¶à¼Ò¶ÀÁ¢Ò©·¿¡£EmbargoÀÕË÷Èí¼þÐж¯µÄ·¸×ï·Ö×ÓÐû³Æ¶ÔÕâ´ÎÏ®»÷ÕÆ¹Ü£¬ËûÃÇÇÔÈ¡ÁËAAPµÄ1.469TBÊý¾Ý²¢ÒªÇ󸶿îÄÜÁ¦¸´ÔÐÅÏ¢¡£EmbargoÊÇÒ»¸öÏà¶Ô½ÏеÄÀÕË÷Èí¼þ×éÖ¯£¬ÓÚ½ñÄê6Ô³õ´Î±»×êÑÐÈËÔ±°ÑÎȵ½¡£Ö»¹ÜAAPÉÐδÕýʽȷÈÏÔâµ½¹¥»÷£¬µ«ÆäÍøÕ¾ÒÑÖÒ¸æËùÓÐЧ»§ÃÜÂë×î½ü¾ù±»Ç¿Ôì³ÁÖ㬵«Î´Ú¹ÊÍÔÒò»òÌá¼°ÍøÂç¹¥»÷¡£Í¬Ê±£¬EmbargoÐû³ÆAAPÒÑÖ§¸¶130ÍòÃÀÔªÀ´½âÃÜϵͳ£¬²¢ÒªÇóÔÙÖ§¸¶130ÍòÃÀÔªÀ´¸²¸Ç±»µÁÎļþ¡£ÈôÊǸÃ˵·¨Êôʵ£¬ÄÇôEmbargoÌá³öµÄÒªÇ󽫳¬¹ýÃÀ¹úÁª¹úµ÷²é¾Ö½ñÄêÔçЩʱ³½°ä²¼µÄ¾ùÔÈˮƽ¡£Ä¿Ç°Éв»Ã÷ÏÔÀÕË÷Èí¼þ×éÖ¯´ÓAAPÇÔÈ¡ÁËÄÄЩÊý¾Ý£¬µ«¸ÃÒ©·¿ÍøÂç±ØÐëÔÚ11ÔÂ20ÈÕ֮ǰ֧¸¶Ôü×ҵġ°Óà¶î¡±£¬²»È»ÆäÊý¾Ý½«±»Ð¹Â¶µ½ÍøÉÏ¡£
https://www.theregister.com/2024/11/13/embargo_ransomware_breach_aap/
5. D-LinkÍ£²úNASÉ豸ÔâCVE-2024-10914·ì϶¹¥»÷
11ÔÂ13ÈÕ£¬°²È«×êÑÐÔ±Netsecfish·¢ÏÖÁËÒ»¸öÑϳÁ·ì϶£¨CVE-2024-10914£©£¬¸Ã·ì϶ӰÏì¶àÖÖÒÑÍ£²úµÄD-LinkÍøÂ總¼Ó´æ´¢£¨NAS£©É豸¡£¹¥»÷Õß¿Éͨ¹ý·¢ËͶñÒâHTTP GETÒªÇó£¬ÏòÔÚÏß¶³öµÄÒ×Êܹ¥»÷É豸עÈëËÁÒâshellºÅÁî¡£D-LinkÔÚÉÏÖÜÎ尵ʾ²»»á½¨¸´´Ë·ì϶£¬²¢½¨Òé¿Í»§²Ã¼õÊÜÓ°ÏìµÄÉ豸»òÉý¼¶µ½½ÏеIJúÆ·¡£È»¶ø£¬ShadowserverÍþв¼à¿Ø·þÎñ·¢ÏÖ£¬´Ó11ÔÂ12ÈÕÆðÍ·£¬ÒÑÓÐÍþвÐÐΪÕ߯ðÍ·¶Ô×¼¸Ã·ì϶¡£ShadowserverÖÒ¸æ³Æ£¬Ó¦½«´Ó»¥ÁªÍøÉÏÒÆ³ýÒ×Êܹ¥»÷µÄEOL/EOSÉ豸¡£NetsecfishÔÚ»¥ÁªÍøÉ¨ÃèÖз¢ÏÖÁ˳¬¹ý41,000¸öÒ×Êܹ¥»÷É豸µÄΨһIPµØÖ·¡£´Ë±í£¬½ñÄê4Ô£¬Netsecfish»¹»ã±¨ÁËÁíÒ»¸öÓ°ÏìÏÕЩһÑùD-Link NASÐͺŵķì϶£¨CVE-2024-3273£©¡£ÓÉÓÚÕâЩÉ豸ûÓÐ×Ô¶¯¸üÐÂÖ°ÄÜ»ò¿Í»§±íÁªÖ°ÄÜÀ´ÍÆË;¯±¨£¬Òò¶ø½¨ÒéÄÇЩʹÓñ¨·ÏÉ豸µÄÈ˾¡¿ìÏÞ¶È»¥ÁªÍø½Ó¼û£¬ÒÔÔ¤·À³ÉΪÀÕË÷Èí¼þ¹¥»÷µÄÖ¸±ê¡£D-LinkÇ¿µ÷£¬³ÖÐøÊ¹ÓÃÕâЩÉ豸¿ÉÄÜ»á¶ÔÏνӵÄÉ豸Ôì³É·çÏÕ£¬²¢ÖÒ¸æÏû·ÑÕßÈ·±£É豸ӵÓÐ×îеĹ̼þ¡£
https://www.bleepingcomputer.com/news/security/critical-bug-in-eol-d-link-nas-devices-now-exploited-in-attacks/
6. Ï£²©ÒÁ¸ùÊÐÔâÍøÂç¹¥»÷£¬ºÚ¿ÍË÷ÒªÊê½ð²¢Ö¼¼Êõ¹ÊÕÏ
11ÔÂ13ÈÕ£¬Íþ˹¿µÐÇÖÝÏ£²©ÒÁ¸ùÊб¾ÖÜÔâÓöÁËÍøÂç¹¥»÷£¬µ¼Ö¼¼Êõ¹ÊÕÏ£¬²¢ÊÕµ½Á˺ڿ͵ÄÊê½ðÒªÇó¡£×Ô10ÔÂÏÂÑ®ÒÔÀ´£¬¸ÃÊÐÒ»ÏòÔÚÓ¦¶ÔÕâЩÎÊÌ⣬²¢ÔÚÖÜÈÕ֤ʵÁ˺ڿÍδ¾ÊÚȨ½Ó¼ûÁ˸ÃÊеÄÍøÂç¡£Ö»¹Ü¸ÃÊÐûÓÐй©Êê½ðÊý¶î»òÌá³öÒªÇóµÄ×éÖ¯Ãû³Æ£¬µ«ËûÃÇÒÑÏò·¨Âɲ¿ÃŻ㱨ÁË´ËÊÂÎñ£¬²¢ÓëÍøÂ簲ȫר¼ÒºÏ×÷½â¾ö¹¥»÷ÒýÆðµÄÎÊÌ⡣ͬʱ£¬ËûÃǸôÀëÁ˲¿ÃÅÍøÂçÒÔ±£»¤ÆäËûÍøÂç²¢×èÖ¹ºÚ¿ÍÈëÇÖ¡£Õâ´Î¹¥»÷¶Ô¹«¹²°²È«·þÎñÔì³ÉÁ˿϶¨Ó°Ï죬µ«»ùÓÚÔÆµÄ·þÎñÈÔÔÚÔËÐУ¬Ô±¹¤Äܹ»½øÐÐÔÚÏß»¥»»¡£Ï£²©ÒÁ¸ùÊÐλÓÚÃܶûÎÖ»ùÒÔ±±Ô¼Ò»Ó×ʱ³µ³Ì´¦£¬´ÓǰÁ½ÄêÖУ¬Íþ˹¿µÐÇÖݵ±¾Ö»ú¹¹ÔøÂÅ´ÎÔâ·êÀÕË÷Èí¼þ¹¥»÷£¬Òò¶ø¸ÃÖݶԴËÀ๥»÷ά³Ö¸ß¶È¾¯Ìè¡£
https://therecord.media/sheboygan-wisconsin-hackers-demand-ransom


¾©¹«Íø°²±¸11010802024551ºÅ