LinuxÏµÍ³Ãæ¶ÔÐÂÍþв£ºBootkitty UEFIÆô¶¯¹¤¾ß°ü±»·¢ÏÖ
°ä²¼¹¦·ò 2024-11-291. LinuxÏµÍ³Ãæ¶ÔÐÂÍþв£ºBootkitty UEFIÆô¶¯¹¤¾ß°ü±»·¢ÏÖ
11ÔÂ27ÈÕ£¬Ò»¿îÃûΪBootkittyµÄLinux¶ñÒâÈí¼þ×÷ΪÊ׸öרÃÅÕë¶ÔLinuxϵͳµÄUEFIÆô¶¯¹¤¾ß°üÒѱ»·¢ÏÖ£¬±ê־ȡ¶ÔWindowsµÄÒþÃØÆô¶¯¹¤¾ß°üÍþвÕý²úÉúת±ä¡£Ö»¹ÜĿǰËü½öÔÚijЩUbuntu°æ±¾ºÍÅäÖÃÉÏÆð×÷Óã¬ÇÒ´æÔںܶàδʹÓõÄÖ°ÄܺͼæÈÝÐÔÎÊÌ⣬³£µ¼ÖÂϵͳ±ÀÀ££¬µ«Æä´æÔÚ±ê־ȡUEFIÆô¶¯Ì×¼þÍþвÁìÓòµÄÒ»¸ö³Á´ó·¢Õ¹¡£Bootkittyͨ¹ý¹Ò½ÓUEFI°²È«ÈÏÖ¤ºÍ̸ºÍGRUBº¯ÊýÀ´Èƹý°²È«Æô¶¯ºÍÆëÈ«ÐÔÑéÖ¤£¬´Ó¶ø¼ÓÔØ¶ñÒâ×é¼þ¡£Ëü»¹»áÀ¹½ØLinuxÄں˵Ľâѹ¹ý³Ì²¢¹Ò½ÓÓйغ¯Êý£¬Ê¹¶ñÒâÈí¼þ¿ÉÄܼÓÔØ¶ñÒâÄ£¿é£¬²¢ÔÚϵͳÆô¶¯Ê±×¢Èë¶ñÒâ¿â¡£×êÑÐÈËÔ±Ö¸³ö£¬½«BootkittyÉÏ´«µ½VirusTotalµÄͳһÓû§»¹ÉÏ´«ÁËÒ»¸öÃûΪBCDropperµÄδÊðÃûÄÚºËÄ£¿é£¬µ«Á½ÕßÖ®¼äµÄÁªÏµ½ÏÈõ¡£´ËÀà¶ñÒâÈí¼þµÄ·¢ÏÖÅú×¢£¬Ëæ×ÅLinuxÔÚÆóÒµÖеı鼰£¬¹¥»÷ÕßÔÚ¿ª·¢Ö®Ç°½öÏÞÓÚWindowsµÄLinux¶ñÒâÈí¼þ¡£ÓëBootkittyÓйصÄÈëÇÖÖ¸±êÒÑÔÚGitHubÉϹ²Ïí¡£
https://www.bleepingcomputer.com/news/security/researchers-discover-bootkitty-first-uefi-bootkit-malware-for-linux/
2. TorÏîÄ¿´¹Î£ºôÓõ£º²¿Êð¸ü¶àWebTunnelÇÅÆ¥µÐµ±¾ÖÉó²é
11ÔÂ28ÈÕ£¬TorÏîÄ¿½üÆÚÏòÒþÖÔÉçÇø·¢³ö´¹Î£ºôÓõ£¬ÒªÇó×ÔÔ¸ÕßÔÚ2025Äê3ÔÂ10ÈÕǰÐÖú²¿Êð200¸öеÄWebTunnelÇÅ£¬ÒÔÓ¦¶ÔÈÕÒæÑϸñÈ·µ±¾ÖÉó²éÌôÕ½¡£Ä¿Ç°£¬TorÏîÄ¿ÒÑÔËÓª143¸öWebTunnelÇÅ£¬Ô®ÊÖÊÜÉó²éÏ޶ȵØÓòµÄÓû§½Ó¼û»¥ÁªÍø¡£´Ë¾ÙÖØÒªÕë¶Ô¶íÂÞ˹²»ÐݼÓÇ¿µÄÉó²éÔì¶È£¬¸ÃÔì¶ÈÒÑÓ°Ïìä¯ÀÀÆ÷ÄÚÖõÄÉó²é¶ã±Ü»úÔ죬Èçobfs4ÏνӺÍSnowflake¡£TorÏîÄ¿ÒÔΪ£¬³ÉÁ¢¸ü¶àWebTunnelÇÅÊÇÓ¦¶ÔÉó²éÉý¼¶µÄÓÐЧսÊõ£¬ÓÉÓÚ¿ª·¢Ð½â¾ö¹æ»®±ØÒª¹¦·ò£¬¶øÓû§ÔÚ´ËÆÚ¼ä¿ÉÄÜÃæ¶Ô·çÏÕ¡£WebTunnelsÊÇTorÏîÄ¿ÓÚ2024Äê3ÔÂÍÆ³öµÄÒ»ÖÖÐÂÐÍÇÅÁº£¬Í¨¹ý½«TorÁ÷Á¿ÓëͨÀýÍøÂçÁ÷Á¿»ìºÏ£¬²¢Ê¹Æ÷ÓµÓÐÓÐЧSSL/TLSÖ¤ÊéµÄWeb·þÎñÆ÷¼Ù×°³ÉHTTPSÁ÷Á¿£¬´Ó¶ø¶ã±ÜÉó²é¡£TorÏîÄ¿Æô¶¯ÁËÒ»Ïîл£¬ºôÓõ×ÔÔ¸Õ߲μӳÉÁ¢ºÍÊØ»¤WebTunnelÇÅ£¬ÉèÁ¢Îå×ù»ò¸ü¶àÇŵÄ×ÔÔ¸Õß½«»ñµÃTÐô×÷Ϊ¸Ð¼¤¡£²Î¼ÓÒªÇóÔ̺¬Ã¿¸öIPv4Ò»¸öÇÅ¡¢ÌṩÓÐЧµç×ÓÓʼþ¡¢Î¬³ÖÇÅÁºÔËÐÐÖÁÉÙÒ»ÄêµÈ¡£×ÔÔ¸ÕßÄܹ»²é¿´¹Ù·½Ö¸ÄÏÏàʶ¸ü¶àÐÅÏ¢²¢²Î¼Ó»î¶¯¡£
https://www.bleepingcomputer.com/news/security/tor-needs-200-new-webtunnel-bridges-to-fight-censorship/
3. Ó¢¹úÍþÀÕ¶û´óѧ½²ÊÚÒ½ÔºÔâÍøÂç¹¥»÷£¬·þÎñÖжÏÔ¤Ô¼ÍÆ³Ù
11ÔÂ28ÈÕ£¬Ó¢¹úÖØÒªÒ½ÁƱ£½¡ÌṩÉÌÍþÀÕ¶û´óѧ½²ÊÚÒ½Ôº£¨WUTH£©£¬×÷ΪNHS»ù½ð»áµÄÒ»²¿ÃÅ£¬½üÆÚÔâ·êÁËÍøÂç¹¥»÷£¬µ¼ÖÂϵͳÖжϣ¬Ô¤Ô¼ºÍÔ¤Ô¼·¨Ê½±»ÆÈÍÆ³Ù¡£WUTHÔËÓª×Ŷà¼ÒÒ½Ôº£¬ÌṩÔ̺¬´¹Î£·þÎñ¡¢¼±ÐÔÒ½ÁÆ·þÎñ¡¢³ÁÖ¢¼à»¤¡¢±í¿Æ¡¢¶ù¿Æ¡¢²ú¿Æ·þÎñºÍ°©Ö¢»¤ÀíÔÚÄÚµÄÈ«ÃæÒ½ÁÆ·þÎñ¡£Õâ´ÎÍøÂç¹¥»÷ʹµÃ²¿ÃÅITϵͳÏÂÏß²¢×ªÎªÊÖ¶¯²Ù×÷£¬²»³ÉÔ¤·ÀÏßÔì³ÉÁË·þÎñÖжϺÍÑÓÎó¡£Ò½ÔºÒѸ´ÔÒµÎñÂ½ÐøÐÔÁ÷³Ì£¬Ê¹ÓÃÖ½ÖÊÎļþ´úÌæÊý×ÖÎļþ£¬µ«´¹Î£Ò½ÖÎµÄÆÚ´ý¹¦·òÓÐËùÔö³¤¡£Ò½Ôº¶½´Ù¹«¼Ò½öÔÚÕæÕý´¹Î£Çé¿öÏÂǰÍù¼¹ØïÊÒ¡£Ä¿Ç°£¬Ò½ÔºÈÔÎÞ·¨¹À¼ÆºÎʱÄܸ´ÔÕý³£ÔËÓª£¬ÇÒÉÐδÓÐÈκÎÀÕË÷Èí¼þ×éÖ¯¶ÔÕâ´Î¹¥»÷ÕÆ¹Ü¡£¸ÃÒ½ÁÆ»ú¹¹ÉÐδ¶Ô¹¥»÷ÐÔÖÊÌṩ¸ü¶àÐÅÏ¢¡£
https://www.bleepingcomputer.com/news/security/uk-hospital-network-postpones-procedures-after-cyberattack/
4. Å·ÖÞ¶à¹ú½áºÏ½ø¹¥·¸·¨Á÷ýÌåÍøÂ磬ȡµÞµÁ°æ²¢¼ÓÇ¿ÍøÂç·¸×ï·À±¸
11ÔÂ28ÈÕ£¬Å·ÖÞÐ̾¯×éÖ¯½áºÏ¶à¹ú·¨ÂÉ»ú¹¹£¬³É¹¦È¡µÞÁËÒ»¸ö·¸·¨Á÷ýÌåÍøÂ磬¿ÛÁôÁ˽üÊ®¼¸ÃûÉæ°¸ÈËÔ±¡£¸ÃÍøÂçµÁ°æÁ˳¬¹ý2500¸öµçÊÓÆµÂ·£¬ÏòÈ«Çò³¬¹ý2200ÍòÈËÌṩ·þÎñ£¬Ã¿ÄêÔì³É100ÒÚÅ·ÔªµÄËðʧ¡£Å·ÖÞÐ̾¯×éÖ¯ÔÚÐж¯Öе÷²éÁË102ÃûÏÓÒÉÈË£¬²¢Ö¸¿ØÉæ¼°Ï´Ç®ºÍÍøÂç·¸×ï¡£·¨ÂÉ»ú¹¹½øÐÐÁËÂÅ´ÎÍ»»÷²é³£¬²é»ñÁË·þÎñÆ÷ºÍIPTVÉ豸£¬²¢ÔÚͻϮÆÚ¼ä·¢ÏÖÁ˶¾Æ·¡¢±øÆ÷ÒÔ¼°´óÁ¿¼ÓÃÜÇ®±ÒºÍÏÖ½ð¡£Õâ´ÎÐж¯µÃµ½Á˱£¼ÓÀûÑÇ¡¢¿ËÂÞµØÑÇ¡¢·¨¹úµÈ¶à¸öÅ·ÖÞ¹ú¶È·¨ÂÉ»ú¹¹µÄÖ§³Ö£¬Òâ´óÀû¹ÙÔ±³ÆÆäΪ¸Ã¹úÊ·ÉÏ×î´ó¹æÄ£µÄ½ø¹¥ÒôÏñµÁ°æÐж¯¡£´Ë±í£¬Å·ÖÞÐ̾¯×éÖ¯ºÍ¹ú¼ÊÐ̾¯×éÖ¯ÒÑ´òËãÔÚ2024ÄêÔ½·¢»ý¼«×Ô¶¯µØ½ø¹¥ÍøÂç·¸×½üÆÚ»¹°ä·¢ÁËÉæ¼°40¶à¸ö¹ú¶ÈµÄ¡°HAECHI¡±Ðж¯£¬¿ÛÁôÁË5500¶àÃûÏÓÒÉÈË£¬²¢½É»ñÁËÔ¼4ÒÚÃÀÔª¡£¹ú¼ÊÐ̾¯×éÖ¯ÃØÊ鳤°µÊ¾£¬ÍøÂç·¸×ïµÄºó¹û¿ÉÄÜÊǸ²ÃðÐԵ쬹ú¼Ê¾¯Ô±ºÏ×÷ÖÁ¹Ø³ÁÒª¡£
https://therecord.media/11-arrested-europol-streaming-shutdown
5. ZelloÒªÇóÀÏÓû§³ÁÖÃÃÜÂ룬ÒÉÒò°²È«·ì϶
11ÔÂ27ÈÕ£¬ZelloÊÇÒ»ÏîÕ¼ÓÐ1.4ÒÚÓû§µÄÒÆ¶¯·þÎñ£¬½üÆÚÏòÓû§·¢³ö°²È«ÖҸ棬ҪÇóËùÓÐÔÚ2024Äê11ÔÂ2ÈÕ֮ǰ´´½¨µÄÕË»§³ÁÖÃÃÜÂë¡£ÕâÒ»´ëÊ©ËÆºõÊǶÔDZÔÚ°²È«·ì϶µÄÔ¤·À´ëÊ©¡£¶à¶àÓû§ÔÚ11ÔÂ15ÈÕÊÕµ½ÁËÕâһ֪ͨ£¬µ«ZelloδÌṩ½øÒ»²½µÄÐÅÏ¢»òÚ¹ÊÍ¡£Óû§±»Êèµ¼ÖÁÖ§³ÖÒ³ÃæÏàʶÈôºÎ¸ü¸ÄÃÜÂ룬²¢±»½¨Òé¸ü¸ÄÔÚÆäËûÔÚÏß·þÎñÖпÉÄÜʹÓùýµÄÒ»ÑùÃÜÂë¡£Ö»¹ÜĿǰÉв»Ã÷ÏÔÊÇ·ñ²úÉúÁËÊý¾Ýй¶»òƾ֤Ìî³ä¹¥»÷£¬µ«Í¨ÖªÅú×¢ÍþвÐÐΪÕß¿ÉÄÜÒÑ»ñÈ¡¿Í»§ÃÜÂëµÄ½Ó¼ûȨÏÞ¡£Ë¼¿¼µ½Zello³ö¸ñÖ¸³öÊÜÓ°ÏìµÄÊÇ11ÔÂ2ÈÕǰµÄÕË»§£¬°²È«ÊÂÎñºÜ¿ÉÄܲúÉúÔڴ˹¦·òµã×ó½ü¡£ÖµÍ×ÌùÐĵÄÊÇ£¬ZelloÔÚ2020ÄêÔø¾Àú¹ýÒ»´ÎÊý¾Ýй¶£¬µ¼Ö¿ͻ§µÄµç×ÓÓʼþµØÖ·ºÍÉ¢ÁÐÃÜÂë±»µÁ¡£
https://www.bleepingcomputer.com/news/security/zello-asks-users-to-reset-passwords-after-security-incident/
6. WotNotÊý¾Ýй¶ÊÂÎñ£ºAI¹©¸øÁ´ÖеÄÊý¾Ý°²È«ÓëÒþÖÔ·çÏÕ
11ÔÂ28ÈÕ£¬Ó¡¶ÈÈËΪÖÇÄܲݴ´¹«Ë¾WotNot½üÆÚ²úÉúÁËһ·ÑϳÁµÄÊý¾Ýй¶ÊÂÎñ£¬ÆäGoogle Cloud Storage´æ´¢Í°ÒòÅäÖÃÃýÎó¶øÂ¶³ö£¬µ¼ÖÂ346,381¸öÎļþ±»Î´¾ÊÚȨ½Ó¼û£¬ÆäÖÐÔ̺¬»¤ÕÕ¡¢Ò½ÁƼͼ¡¢¼òÀúµÈÃô¸ÐÓ×ÎÒÊý¾Ý¡£WotNot×÷Ϊһ¼ÒΪÆóÒµ¶¨Ôì̸Ìì»úеÈËµÄÆ½Ì¨£¬Æä¿Í»§º¸ÇÁËĬ¿Ë¹«Ë¾¡¢¼ÓÖÝ´óѧµÈ³ÛÃûÆóÒµºÍ»ú¹¹¡£Õâ´Îй¶¶ÔÊÜÓ°ÏìµÄÓ×ÎÒ×é³ÉÁ˳Á´ó°²È«ºÍÒþÖÔÍþв£¬ÎªÍøÂç·¸×ï·Ö×ÓÌṩÁËÉí·Ý͵ÇÔ¡¢Ú²ÆµÈ»î¶¯µÄ¹¤¾ß°ü¡£¸ÃÊÂÎñ½ÒʾÁËAI·þÎñÒýÈëµÄÓ°×ÓIT×ÊÔ´·çÏÕ£¬¼´²»ÊÜ×éÖ¯Ö±½Ó½ÚÔìµÄϵͳ¿ÉÄÜ´øÀ´µÄÊý¾ÝÁ÷²»ÊܽÚÔìÎÊÌâ¡£WotNotµÄ°¸ÀýÅú×¢£¬µ¥¸ö¹©¸øÉ̵ݲȫ·ì϶¿ÉÄÜΣ¼°ÏÂÓζà¼Ò¹«Ë¾ºÍÊýǧÃûÓ×ÎÒµÄÊý¾Ý¡£Òò¶ø£¬ÆóÒµ±ØÐëÒâʶµ½¶ÔÊý¾Ý°²È«µÄÔðÈβ»½öÏÞÓÚÄÚ²¿ÏµÍ³£¬»¹Ó¦³¹µ×Éó²éAIÖ´ÐÐÁ´ÖÐÿ¸öºÏ×÷ͬ°éµÄ°²È«Êµ¼Ê¡£Cybernews×êÑÐÈËÔ±ÓÚ9ÔÂ9ÈÕÏòWotNotÅû¶ÁËÊý¾Ýй¶ÎÊÌ⣬µ«¸Ã¹«Ë¾»¨ÁËÁ½¸ö¶àÔ²ŹعØÁ˶Ôй¶Êý¾ÝµÄ½Ó¼û¡£
https://cybernews.com/security/wotnot-exposes-346k-sensitive-customer-files/


¾©¹«Íø°²±¸11010802024551ºÅ