¡°´«È¾ÐԲɷᱻÖÐOtterCookieÐÂÐͶñÒâÈí¼þÍþвÈí¼þ¿ª·¢ÈËÔ±
°ä²¼¹¦·ò 2024-12-271. ¡°´«È¾ÐԲɷᱻÖÐOtterCookieÐÂÐͶñÒâÈí¼þÍþвÈí¼þ¿ª·¢ÈËÔ±
12ÔÂ26ÈÕ£¬³¯ÏÊÍþвÐÐΪÕß½üÆÚÔÚÕë¶ÔÈí¼þ¿ª·¢ÈËÔ±µÄ¡°´«È¾ÐԲɷᱻÖУ¬ÍƳöÁËÒ»ÖÖÃûΪOtterCookieµÄÐÂÐͶñÒâÈí¼þ¡£¾ÝÍøÂ簲ȫ¹«Ë¾Palo Alto NetworksµÄ×êÑÐÈËÔ±³Æ£¬¸Ã»î¶¯×Ô2022Äê12ÔÂÒÔÀ´Ò»Ïò»îÔ¾£¬Í¨¹ýÌṩÐéαµÄ¹¤×÷»úÓö´«²¼¶ñÒâÈí¼þ£¬ÈçBeaverTailºÍInvisibleFerretµÈ¡£¶øNTT Security JapanµÄ»ã±¨Ö¸³ö£¬OtterCookieºÜ¿ÉÄÜÓÚ9ÔÂÍÆ³ö£¬²¢ÔÚ11Ô³öÏÖÁËеıäÖÖ¡£¸Ã¶ñÒâÈí¼þͨ¹ý¼ÓÔØÆ÷´«µÝ£¬»ñÈ¡JSONÊý¾Ý²¢Ö´ÐÐJavaScript´úÂ룬Äܹ»ÓëBeaverTailһ·²¿Êð»òµ¥¶À²¿Êð¡£ËüÀûÓÃGitHub»òBitbucketÏÂÔØµÄNode.jsÏîÄ¿»ònpm°üϰȾָ±ê£¬Ò²Ê¹ÓÃÁËQt»òElectronÀûÓ÷¨Ê½¹¹½¨µÄÎļþ¡£Ò»µ©¼¤»î£¬OtterCookie¾Í»áʹÓÃSocket.IO WebSocket¹¤¾ßÓëºÅÁîºÍ½ÚÔì»ù´¡ÉèÊ©³ÉÁ¢°²È«Í¨Ñ¶£¬²¢Ö´ÐÐÊý¾Ý͵ÇÔµÄshellºÅÁÔ̺¬ÍøÂç¼ÓÃÜÇ®±ÒÇ®°üÃÜÔ¿¡¢Îĵµ¡¢Í¼ÏñµÅ×мÛÖµÐÅÏ¢¡£×îа汾µÄOtterCookie»¹Äܹ»Ð¹Â¶¼ôÌù°åÊý¾Ý£¬²¢¼ì²âµ½ÓÃÓÚ¿úËŵĺÅÁÅú×¢¹¥»÷Õß³ïËã½øÐиüÉîµµ´ÎµÄÉøÈë»òºáÏòÒÆ¶¯¡£
https://www.bleepingcomputer.com/news/security/new-ottercookie-malware-used-to-backdoor-devs-in-fake-job-offers/
2. ÈÕº½ÔâDDoS¹¥»÷Öº½°àÑÓÎó£¬ÏµÍ³ÒѸ´Ô
12ÔÂ26ÈÕ£¬ÈÕ±¾Æì½¢º½¿Õ¹«Ë¾ÈÕ±¾º½¿Õ(JAL)Ôâ·êÁËÒ»´ÎÍøÂ簲ȫÊÂÎñ£¬µ¼ÖÂÆä²¿ÃŹúÄں͹ú¼Êº½°à³öÏÖÑÓÎó¡£ÊÂÎñÆðÒòÊÇÆäÓÃÓÚÓë±í²¿ÏµÍ³½øÐÐÊý¾ÝͨѶµÄÍøÂçÉ豸Ôâ·êÁËÉ¢²¼Ê½»Ø¾ø·þÎñ(DDoS)¹¥»÷£¬µ¼ÖÂϵÍÂä÷Á¿¼¤Ôö²¢³öÏÖ¹ÊÕÏ¡£¹¥»÷»¹Ó°ÏìÁ˳˿ÍÐÐÀîÖÎÀíϵͳºÍÒÆ¶¯ÀûÓ÷¨Ê½£¬µ«ÈÕº½°µÊ¾Ã»Óпͻ§ÐÅϢй¶¡¢ÍÆËã»ú²¡¶¾ÇÖº¦»ò·ÉÐа²È«ÎÊÌâ¡£ÊÜÓ°ÏìµÄϵͳÒÑÁÙʱ¹Ø¹Ø£¬²¢ÔÝÍ£Á˵±ÈÕÆô³ÌµÄ»úƱÏúÊۺͲ¿ÃÅÔÚÏß·þÎñ¡£Ö»¹ÜÓÐ40¶à¸öº½°àÑÓÎ󣬵«ÈÕº½°µÊ¾µÚ¶þÌìµÄº½°à´òËãÕý³£ÔËÐС£º½¿ÕÒµÈÔÊÇÈ«ÇòºÚ¿ÍµÄÈȵãÖ¸±ê£¬´ËÇ°Ò²Ôø²úÉú¶àÆðÕë¶Ôº½¿Õ¹«Ë¾ºÍ»ú³¡µÄÍøÂç¹¥»÷ÊÂÎñ£¬ÕâЩϮ»÷´ó¶à³öÓÚ¾¼Ã¶¯»ú£¬µ«Ò²ÓÐÕþÖζ¯»úµÄ°¸Àý¡£
https://therecord.media/japan-airlines-resumes-operations-after-cyberattack
3. °ÍÎ÷ºÚ¿ÍÒòÉæÏÓÚ²ÆÀÕË÷ÔÚÃÀ¹úÔâÖ¸¿Ø
12ÔÂ26ÈÕ£¬Ò»Ãû°ÍÎ÷¹«ÃñJunior Barros De OliveiraÒòÉæÏÓºÚ¿ÍÈëÇÖ²¢Ú²ÆÀÕË÷Ò»¼ÒλÓÚÐÂÔóÎ÷µÄ¹«Ë¾¶ø±»ÃÀ¹ú˾·¨²¿¸æ×´¡£¾Ý¸æ×´ÊéÏÔʾ£¬µÂ°ÂÀûάÀÓÚ2020Äê3ÔÂÈëÇÖÁ˸ù«Ë¾µÄ°ÍÎ÷×Ó¹«Ë¾ÍøÂ磬ÇÔÈ¡ÁËÔ¼30ÍòÃû¿Í»§µÄ»úÃÜÐÅÏ¢¡£Í¬Äê9Ô£¬ËûʹÓû¯ÃûÏò¸Ã¹«Ë¾Ê×ϯִÐйٷ¢Ë͵ç×ÓÓʼþ£¬ÒªÇóÖ§¸¶300±ÈÌØ±Ò£¨µ±ÊмÛÖµÔ¼320ÍòÃÀÔª£©×÷Ϊ²»ÏúÊÛÊý¾ÝµÄǰÌá¡£Ò»¸öÔºó£¬ËûÓÖ½«Ò»ÑùµÄÐÅϢת·¢¸øÁ˸ù«Ë¾ÔÚ°ÍÎ÷µÄÊ×ϯִÐйٺÍÒ»Ãû¸ß¹Ü£¬²¢°µÊ¾Ô¸ÒâÒÔ75±ÈÌØ±Ò£¨ÆäʱԼºÏ80ÍòÃÀÔª£©µÄÕ÷ѯ·ÑÔ®ÊÖËûÃǽâ¾ö°²È«·ì϶¡£µÂ°ÂÀûάÀÒò¶ø±»Ö¸¿ØËÄÏîÉæ¼°´ÓÊܱ£»¤µÄÍÆËã»ú»ñÊØÐÅÏ¢µÄÚ²ÆÀÕË÷×ïºÍËÄÏîÍþвÐÔͨѶ×ï¡£ÈôÊÇ×ïÃû³ÉÁ¢£¬Ëû½«Ãæ¶Ô×î¸ß¿É´ï20ÄêµÄ½ûïÀºÍ¸ß´ï100ÍòÃÀÔªµÄ·£¿î£¬»òÊÕÒæÓëËðʧ¼ÛÖµµÄÁ½±¶£¨ÒԽϸßÕßΪ׼£©¡£
https://thehackernews.com/2024/12/brazilian-hacker-charged-for-extorting.html
4. ͨÓö¯Á¦¹«Ë¾ÔâÍøÂç´¹µö¹¥»÷£¬ÊýʮԱ¹¤¸£ÀûÕË»§±»ÈëÇÖ
12ÔÂ26ÈÕ£¬º½¿Õº½ÌìºÍ¹ú·À¾ÞͷͨÓö¯Á¦¹«Ë¾Ôâ·êÁËÒ»´Î³É¹¦µÄÍøÂç´¹µö¹¥»÷£¬µ¼ÖÂÊýÊ®¸öÔ±¹¤¸£ÀûÕË»§±»ÈëÇÖ¡£¹¥»÷Õßͨ¹ýµÚÈý·½ÍйܵĵǼÃÅ»§½Ó¼û²¢¸ü¸ÄÁËÔ±¹¤¸£ÀûÕË»§£¬ÕâЩÕË»§Ô̺¬ÁËÔ±¹¤µÄÐÕÃû¡¢µ®ÉúÈÕÆÚ¡¢µ±¾ÖÐû¸æµÄÉí·ÝÖ¤ºÅÂë¡¢Éç»á°²È«ºÅÂë¡¢ÒøÐÐÕË»§ÐÅÏ¢ºÍ²Ð¼²Çé¿öµÈÃô¸ÐÐÅÏ¢¡£¾ÝͨÓö¯Á¦¹«Ë¾Ð¹Â©£¬¹²ÓÐ37ÈËÊܵ½Ó°Ï죬¹¥»÷ÕßÔÚijЩÇé¿öÏ»¹¸ü¸ÄÁ˱»µÁÕË»§µÄÒøÐÐÕË»§ÐÅÏ¢¡£Í¨Óö¯Á¦¹«Ë¾ÔÚ·¢ÏÖÕâһδ¾ÊÚȨµÄ»î¶¯ºóµ±¼´ÔÝÍ£Á˶Ը÷þÎñµÄ½Ó¼û£¬²¢ÏòÊÜÓ°ÏìµÄÈËÔ±ÌṩÁËÁ½ÄêµÄÃâ·ÑÐÅÓþ¼à¿Ø¡£´Ë±í£¬Í¨Óö¯Á¦¹«Ë¾»¹ÌáÐÑÊÜÓ°ÏìµÄÓ×ÎÒ³ÁÖÃËûÃǵĸ»´ïÕË»§µÇ¼ƾ֤£¬²¢Ô¤·ÀÔÚ¶à¸öÕË»§ÖÐʹÓÃÒ»ÑùµÄƾ֤¡£½ñÄêÔçЩʱ³½£¬¸»´ï¹«Ë¾Ò²ÔøÔâ·ê¹ýÁ½´ÎÊý¾Ýй¶ÊÂÎñ£¬Ó°ÏìÁËÊýÍòÓ×ÎÒ¡£
https://www.securityweek.com/defense-giant-general-dynamics-says-employees-targeted-in-phishing-attack/
5. WDACÔâÀûÓ㬹¥»÷Õ߿ɽûÓÃEDR´«¸ÐÆ÷·¢Æð¹¥»÷
12ÔÂ25ÈÕ£¬°²È«×¨¼Ò·¢ÏÖÁËÒ»ÖÖÀûÓÃWindows DefenderÀûÓ÷¨Ê½½ÚÔ죨WDAC£©µÄ¹¥»÷¼¼Êõ£¬Äܹ»½ûÓÃWindowsÉ豸ÉϵĶ˵ã¼ì²âºÍÏìÓ¦£¨EDR£©´«¸ÐÆ÷£¬Ê¹¹¥»÷Õß¿ÉÄÜÈÆ¹ý°²È«¼ì²â²¢¶Ôϵͳ·¢Æð¹¥»÷¡£WDACÊÇWindows 10ºÍWindows Server 2016ÒýÈëµÄ¼¼Êõ£¬Ö¼ÔÚ½ÚÔìWindowsÉ豸ÉϵĿÉÖ´ÐдúÂë¡£¹¥»÷ÕßÄܹ»Ôì¶©ºÍ²¿ÊðרÃÅÉè¼ÆµÄWDACÕ½Êõ£¬×èÖ¹EDR´«¸ÐÆ÷ÔÚϵͳÆô¶¯Ê±¼ÓÔØ£¬Ê¹ÆäÎÞ·¨¹¤×÷¡£¹¥»÷·½Ê½Ô̺¬Õë¶Ôµ¥¸öÉ豸ºÍÕû¸öÓò£¬Õ¼ÓÐÓòÖÎÀíԱȨÏ޵Ĺ¥»÷ÕßÄܹ»ÔÚÕû¸ö×éÖ¯ÄÚ·Ö·¢¶ñÒâWDACÕ½Êõ£¬ÏµÍ³ÐԵؽûÓÃËùÓж˵ãÉϵÄEDR´«¸ÐÆ÷¡£¹¥»÷Éæ¼°Õ½Êõ¸éÖᢳÁÆôÖն˺ͽûÓÃEDRÈý¸öÖØÒª½×¶Î¡£°²È«ÈËÔ±´´½¨ÁË¡°Krueger¡±¸ÅÏëÑéÖ¤¹¤¾ßÀ´¼ì²âÕâÖÖ¹¥»÷¡£»º½âÕ½ÊõÔ̺¬Í¨¹ýGPOÖ´ÐÐWDACÕ½Êõ¡¢ÀûÓÃ×îÓ×ȨÏÞ×¼ÔòºÍÖ´Ðа²È«µÄÖÎÀíʵ¼Ê¡£Ãæ¶ÔгöÏֵĹ¥»÷¼¼Êõ£¬±ØÒª²ÉÈ¡¶àµµ´ÎµÄÍøÂ簲ȫ²½Ö裬²¢Ê±¿Ìά³Ö¾¯Ìè¡£
https://cybersecuritynews.com/attack-weaponizes-windows-defender/#google_vignette
6. ΢ÈíÖҸ棺ʹÓÃýÌå×°ÖÃWindows 11 24H2¿ÉÖÂÎÞ·¨½Ó¹Ü°²È«¸üÐÂ
12ÔÂ26ÈÕ£¬Î¢Èí·¢³öÖҸ棬ָ³öʹÓÃýÌåÖ§³Ö×°ÖÃWindows 11°æ±¾24H2ʱ´æÔÚÒ»¸öÎÊÌ⣬¿ÉÄܵ¼Ö²Ù×÷ϵͳÎÞ·¨½ÓÊܽøÒ»²½µÄ°²È«¸üС£¾ßÌå¶øÑÔ£¬ÔÚ2024Äê10ÔÂ8ÈÕÖÁ11ÔÂ12ÈÕÆÚ¼ä£¬Ê¹ÓÃCDºÍUSBÉÁ´æÇý¶¯Æ÷×°ÖÃÔ̺¬´ËÆÚ¼ä°²È«¸üеÄWindows 11°æ±¾24H2ʱ£¬É豸¿ÉÄÜ»áÏÝÈëÎÞ·¨½ÓÊܺóÐøWindows°²È«¸üеÄ״̬¡£²»Í⣬Õâ¸ö·ì϶²»»áÓ°Ïìͨ¹ýWindows¸üлòMicrosoft¸üÐÂÄ¿Â¼ÍøÕ¾ÀûÓõݲȫ¸üУ¬Ò²²»»áÔÚʹÓÃ×îеÄ2024Äê12Ô°²È«¸üÐÂʱ³öÏÖ¡£Î¢ÈíÔÚÖÂÁ¦ÓÚÓÀÔ¶½¨¸´´ËÎÊÌ⣬²¢½¨ÒéʹÓûùÓÚýÌåµÄWindows 11 24H2×°ÖõÄÓû§ÀûÓÃ2024Äê12ÔÂ10ÈÕ°ä²¼µÄ°²È«¸üУ¬ÒÔÔ¤·ÀºóÐø¸üÐÂÎÊÌâ¡£´Ë±í£¬Windows 11 24H2»¹Ãæ¶Ô×ÅһϵÁÐÆäËûÎÊÌ⣬Ô̺¬ÒôƵÎÊÌâ¡¢ÓÎÏ·»úÄÜÎÊÌâ¡¢±ÀÀ£ºÍËÀ»úµÈ£¬ÉõÖÁÔÚÌØ¶¨µÄÓ²¼þºÍÈí¼þÅäÖÃÉϱ»ÁÙʱ×èÖ¹¡£
https://www.bleepingcomputer.com/news/security/windows-11-installation-media-bug-causes-security-update-failures/


¾©¹«Íø°²±¸11010802024551ºÅ