RustDoorͨ¹ýJustice AV Solutions JAVS Viewer½øÐÐÁ÷´«
Ðû²¼Ê±¼ä 2024-05-271. RustDoorͨ¹ýJustice AV Solutions JAVS Viewer½øÐÐÁ÷´«
5ÔÂ26ÈÕ£¬Rapid7 µÄÑо¿ÈËÔ±¾¯¸æ³Æ£¬ÍþвÐÐΪÕßÔÚ Justice AV Solutions JAVS Viewer Èí¼þµÄ°²×°·¨Ê½ÖÐÌí¼ÓÁ˺óÃÅ¡£¹¥»÷ÕßÄܹ»ÔÚ´Ó JAVS ·þÎñÆ÷·Ö·¢µÄ JAVS Viewer v8.3.7 °²×°·¨Ê½ÖÐ×¢ÈëºóÃÅ¡£Justice AV Solutions (JAVS) ÊÇÒ»¼Ò×ܲ¿Î»ÓÚÃÀ¹úµÄ¹«Ë¾£¬Îª·¨Í¥»·¾³ºÍÆäËû»·¾³£¨°üÂÞ¼àÓü¡¢Òé»áºÍÑݽ²ÊÒ£©ÌṩÊý×ÖÊÓÌý¼Öƽâ¾ö·½°¸¡£JAVS Viewer ÔÚÈ«ÇòÓµÓÐÁè¼Ý 10,000 ¸ö°²×°¡£Ñо¿ÈËÔ±ÌṩµÄºóÃÅÔÊÐí¹¥»÷ÕßÍêÈ«¿ØÖÆÊÜѬȾµÄϵͳ¡£Rapid7 ר¼Ò½¨ÒéÖØÐÂÓ³ÏñÊÜÓ°ÏìµÄϵͳ£¬ÖØÖÃÏà¹Øƾ¾Ý£¬²¢°²×°×îа汾µÄ JAVS Viewer£¨v8.3.8 »ò¸ü¸ß°æ±¾£©¡£Ñо¿ÈËÔ±×¢Òâµ½£¬JAVS Viewer Setup 8.3.7.250-1.exe µÄ°²×°·¨Ê½Ê¹ÓÃÒâÍâµÄ Authenticode Ç©Ãû½øÐÐÊý×ÖÇ©Ãû£¬²¢°üÂÞÒ»¸öÃûΪ fffmpeg.exe µÄ¶þ½øÖÆÎļþ¡£¸Ã¶þ½øÖÆÎļþÖ´ÐбàÂëµÄ PowerShell ½Å±¾£¬Rapid7 ½« fffmpeg.exe ÓëGateDoor / Rustdoor¶ñÒâÈí¼þÁªÏµÆðÀ´£¬¸Ã¶ñÒâÈí¼þÒѱ»Äþ¾²¹«Ë¾ S2W ʶ±ð¡£
https://securityaffairs.com/163683/hacking/supplay-chain-attack-javs-viewer.html
2. SlashNextÐû²¼2024ÄêÉÏ°ëÄêÍøÂçµöÓã×´¿ö³ÂËß
5ÔÂ24ÈÕ£¬³ÂË߳ƣ¬¹ýÈ¥Áù¸öÔÂÖжñÒâÍøÂçµöÓãÁ´½Ó¡¢ÉÌÒµµç×ÓÓʼþÈëÇÖ (BEC)¡¢¶þάÂëºÍ»ùÓÚ¸½¼þµÄÍþвÔö¼ÓÁË 341%¡£¸ÃÊý¾ÝÀ´×Ô SlashNext µÄÄêÖС¶2024 ÄêÍøÂçµöÓã×´¿ö¡·³ÂËß £¬¸Ã³ÂËß»¹·¢ÏÖ£¬ÔÚ¹ýÈ¥ 12 ¸öÔÂÖУ¬¶ñÒâµç×ÓÓʼþºÍÏûÏ¢ÍþвÔö¼ÓÁË 856%¡£×Ô 2022 Äê 11 ÔÂÍƳö ChatGPT ÒÔÀ´£¬¶ñÒâÍøÂçµöÓãÏûÏ¢¼¤ÔöÁË 4151%¡£Keeper Security Ê×ϯִÐйټæÁªºÏÊ×´´ÈË Darren Guccione ¾¯¸æ³Æ£º²»Á¼ÐÐΪÕß¿ÉÒÔͨ¹ý¶àÖÖ·½Ê½ÀûÓà ChatGPT£¬°üÂÞ´´½¨ÁîÈËÐÅ·þµÄÍøÂçµöÓãµç×ÓÓʼþ¡£ÕâЩ¹¤¾ß²»½ö¿ÉÒÔ×ÊÖú·Ç·¨·Ö×Ó´´½¨¿ÉÐŵÄÍøÂçµöÓãµç×ÓÓʼþ»òÀÕË÷Èí¼þ¹¥»÷µÄ¶ñÒâ´úÂëµÈÄÚÈÝ£¬¶øÇÒËûÃÇ¿ÉÒÔ¿ìËÙÇáËɵØÍê³ÉÕâЩ²Ù×÷¡£·ÀÓùÄÜÁ¦×îÈõµÄ×éÖ¯½«ÌرðÈÝÒ×Êܵ½¹¥»÷£¬ÒòΪ¹¥»÷Á¿¿ÉÄÜ»á¼ÌÐøÔö¼Ó¡£³ÂËß»¹·¢ÏÖ£¬ÔÚ¹ýÈ¥Áù¸öÔÂÖУ¬Æ¾Ö¤ÇÔÈ¡ÍøÂçµöÓã¹¥»÷Ôö¼ÓÁË 217%£¬BEC ¹¥»÷Ôö¼ÓÁË 29%¡£»ùÓÚ CAPTCHA µÄ¹¥»÷Ò²ÔÚÔö¼Ó£¬¹¥»÷ÕßʹÓà CloudFlare µÄ CAPTCHA À´Òþ²Øƾ֤ÊÕ¼¯±í¸ñ¡£´ËÍ⣬ÍøÂç·¸×ï·Ö×ÓÕýÔÚÀûÓà Microsoft SharePoint¡¢AWS ºÍ Salesforce µÈ¿ÉÐÅ·þÎñÀ´Òþ²ØÍøÂçµöÓãºÍ¶ñÒâÈí¼þ¡£»ùÓÚ¶þάÂëµÄ¹¥»÷ÏÖÔÚÕ¼ËùÓжñÒâµç×ÓÓʼþµÄ 11%£¬Í¨³£¼¯³Éµ½ºÏ·¨»ù´¡ÉèÊ©ÖС£
https://www.infosecurity-magazine.com/news/341-rise-advanced-phishing-attacks/?&web_view=true
3. ShrinkLocker ½Ù³Ö BitLocker Õë¶ÔÆóÒµÌᳫ¹¥»÷
5ÔÂ25ÈÕ£¬¿¨°Í˹»ùʵÑéÊÒµÄר¼ÒÒѾȷ¶¨Ê¹ÓÃÒ»ÖÖÃûΪ ShrinkLocker µÄÐÂÀÕË÷Èí¼þ·¨Ê½¶ÔÆóÒµÉ豸½øÐй¥»÷£¬¸Ã·¨Ê½ÀûÓÃÁË BitLocker¡£BitLocker ÊÇ Windows ÖеÄÒ»ÏîÄþ¾²¹¦Ð§£¬¿Éͨ¹ý¼ÓÃܱ£»¤Êý¾Ý¡£ÕâЩ¹¥»÷µÄÄ¿±ê°üÂÞ¹¤ÒµºÍÖÆÒ©¹«Ë¾ÒÔ¼°Õþ¸®»ú¹¹¡£¹¥»÷ÕßʹÓà VBScript ±àдÁËÒ»¸ö¶ñÒâ½Å±¾¡£¸Ã½Å±¾»á¼ì²éÉ豸ÉÏ°²×°µÄ Windows °æ±¾²¢¼¤»îÏàÓ¦µÄ BitLocker ¹¦Ð§¡£ShrinkLocker ¿ÉÒÔѬȾоɰ汾µÄ²Ù×÷ϵͳ£¬×î¸ß¿ÉѬȾ Windows Server 2008¡£¸Ã½Å±¾»áÐ޸IJÙ×÷ϵͳµÄÆô¶¯²ÎÊý£¬È»ºóʵÑéʹÓà BitLocker ¼ÓÃÜÓ²ÅÌ·ÖÇø¡£´´½¨Ò»¸öеÄÆô¶¯·ÖÇø£¬ÒÔ±ãÉÔºó¼ÓÔؼÓÃܵļÆËã»ú¡£¹¥»÷Õß»¹»áɾ³ýÓÃÓÚ±£»¤ BitLocker ¼ÓÃÜÃÜÔ¿µÄÄþ¾²¹¤¾ß£¬×èÖ¹Óû§»Ö¸´ËüÃÇ¡£Ëæºó£¬¶ñÒâ½Å±¾½«ÊÜѬȾ¼ÆËã»úÉÏÉú³ÉµÄϵͳÐÅÏ¢ºÍ¼ÓÃÜÃÜÔ¿·¢Ë͵½¹¥»÷ÕߵķþÎñÆ÷¡£È»ºó£¬Ëü»áͨ¹ýɾ³ýÈÕÖ¾ºÍÖÖÖÖ¿ÉÄÜÓÐÖúÓÚÊӲ칥»÷µÄÎļþÀ´¡°ÑÚ¸ÇÆä×Ù¼£¡±¡£
https://meterpreter.org/new-ransomware-threat-shrinklocker-hijacks-bitlocker-for-corporate-attacks/
4. APT36ÀûÓÃLinux¼äµýÈí¼þ¹¥»÷Ó¡¶ÈµÄ¹ú·À×éÖ¯
5ÔÂ25ÈÕ£¬Ò»¸öÓë°Í»ù˹̹ÀûÒæÏà·ûµÄ¡¢³öÓÚÕþÖζ¯»úµÄºÚ¿Í×éÖ¯ÕýÓëÓ¡¶È¾ü·½Í¬²½·ÅÆú Windows ²Ù×÷ϵͳ£¬²¢½«Öصã·ÅÔÚΪ Linux ±àÂëµÄ¶ñÒâÈí¼þÉÏ¡£¸ÃÍøÂç¼äµý×éÖ¯ÀûÓõç×ÓÓʼþ×÷ΪÓã²æʽÍøÂçµöÓã¹¥»÷µÄÔØÌ壬»¹ÀûÓà Telegram¡¢Discord¡¢Slack ºÍ Google Drive µÈÁ÷ÐÐÍøÂç·þÎñÀ´´æ´¢ºÍ·Ö·¢ÓÕ¶üºÍ¶ñÒâÈí¼þ¡£Ã¿´Î¹¥»÷µÄʱ»ú¶¼ÊÇÓмÆıÐԵģ¬Õâ±íÃ÷ºÚ¿ÍÔÚ·¢¶¯Ã¿´Î¹¥»÷ʱ¶¼½øÐÐÁËÏêϸµÄ¹æ»®£¬²¢ÓÐÌض¨µÄÄ¿±ê¡£×ÔÑо¿ÈËÔ±¿ªÊ¼¸ú×Ù APT36 Ðж¯ÒÔÀ´£¬¸Ã×éÖ¯Ê×´ÎʹÓà ISO Ó³Ïñ×÷Ϊ¹¥»÷ý½é¡£ÔÚÓ¡¶ÈÕþ¸®Ðû²¼Õб깺ÖÃÕ½¶·»úºÍÉý¼¶ÊýÊ®¼ÜËÕ»ôÒÁ 30MKI Õ½¶·»úÖ®¼Ê£¬¸Ã×éÖ¯»¹ÔÚÓã²æʽÍøÂçµöÓãµç×ÓÓʼþÖÐʹÓà ISO Ó³ÏñÀ´¹¥»÷Ó¡¶È¿Õ¾ü¹ÙÔ±¡£ºÚÝ®³Æ£¬¸Ã¼äµý×é֯ģ·ÂÓ¡¶È¹ú·ÀºÍÕ½ÂÔÖÇ¿â¼°Õþ¸®»ú¹¹µÄÍøÕ¾ÓòÃû£¬ÓÕÆÊܺ¦ÕßÏÂÔضñÒâÓÕ¶üÎļþ¡£ÕâЩ×éÖ¯°üÂÞλÓÚеÂÀïµÄ¶ÀÁ¢ÖÇ¿â½սÑо¿ÖÐÐÄ¡¢Ó¡¶È¼ÆËã»úÓ¦¼±ÏìӦС×éºÍ½¾ü¸£Àû½ÌÓýлᡣ
https://www.bankinfosecurity.com/pakistani-aligned-apt36-targets-indian-defense-organizations-a-25296?&web_view=true
5. ¼Ùð Pegasus ¼äµýÈí¼þ²¡¶¾³ä³â¼´Ê±Í¨Ñ¶Æ½Ì¨ºÍ°µÍø
5ÔÂ25ÈÕ£¬CloudSEK ·¢ÏÖ£¬¼Ùð Pegasus ¼äµýÈí¼þµÄÔ´´úÂëÕýÔÚ±í²ãÍøÂç¡¢°µÍøºÍ¼´Ê±Í¨Ñ¶Æ½Ì¨ÉϳöÊÛ¡£¼ÌÆ»¹û¹«Ë¾×î½ü·¢³öÓйء°¹ÍÓ¶ÐͼäµýÈí¼þ¡±¹¥»÷µÄ¾¯¸æºó£¬ÔÆÄþ¾²ÌṩÉÌ CloudSEK ¶ÔÃ÷ÍøºÍ°µÍøÖÐÓë¼äµýÈí¼þÏà¹ØµÄÍþв½øÐÐÁËÊӲ졣¸Ã¹«Ë¾·ÖÎöÁËԼĪ 25,000 Ìõ Telegram Ìû×Ó£¬·¢ÏÖÐí¶àÌû×ÓÉù³Æ³öÊÛ Pegasus µÄÕæʵԴ´úÂë¡£Pegasus ÊÇÓÉÒÔÉ«Áй«Ë¾ NSO Group ÉÌÒµ»¯µÄ¼äµýÈí¼þ¡£ÕâЩÌû×Ó´ó¶à×ñÑÌṩ·Ç·¨·þÎñµÄͨÓÃÄ£°å£¬ÆäÖо³£Ìáµ½ Pegasus ºÍ NSO ¹¤¾ß¡£Í¨¹ýÓë 150 ¶àÃûDZÔÚÂô¼Ò»¥¶¯£¬Ñо¿ÈËÔ±ÉîÈëÁ˽âÁËÖÖÖÖÑù±¾ºÍÖ¸±ê£¬°üÂÞËùνµÄ Pegasus Ô´´úÂë¡¢ÏÖ³¡ÑÝʾ¡¢Îļþ½á¹¹ºÍ¿ìÕÕ¡£ÔÚ·ÖÎöÁËÀ´×Ô°µÍøÔ´µÄ 15 ¸öÔ´´úÂëÑù±¾ºÍ 30 ¶à¸öÖ¸±êºó£¬CloudSEK ·¢ÏÖ¼¸ºõËùÓÐÑù±¾¶¼ÊÇÆÛÕ©ÐÔµÄÇÒÎÞЧµÄ¡£ÍþвÐÐΪÕß´´½¨ÁË×Ô¼ºµÄ¹¤¾ßºÍ½Å±¾£¬²¢ÒÔ Pegasus µÄÃûÒå·Ö·¢£¬ÀûÓÃÆä¶ñÃû»ñÈ¡¾¼ÃÀûÒæ¡£ÕâÒ»Ç÷ÊÆÔÚ¶à¸öµØÏÂÂÛ̳ÖÐÒ²ÓÐËùÌåÏÖ£¬·¸×ïÕßÔÚÕâЩÂÛ̳ÉÏÓªÏúºÍ·Ö·¢Ñù±¾£¬Àû
Óà Pegasus µÄÃûÒå»ñÈ¡½ðÇ®ÀûÒ棬²¢ÔڵرíÍøÂç´úÂë¹²Ïíƽ̨ÉÏÁ÷´«Óë Pegasus Ðé¼Ù¹ØÁªµÄËæ»úÉú³ÉµÄÔ´´úÂë¡£
https://www.infosecurity-magazine.com/news/fake-pegasus-spyware-dark-web/
6. CencoraÊý¾Ý鶵¼ÖÂ11¼ÒÖÆÒ©¹«Ë¾µÄÃÀ¹ú»¼ÕßÐÅÏ¢±»Ð¹Â¶
5ÔÂ25ÈÕ£¬È«ÇòһЩ×î´óµÄÖÆÒ©¹«Ë¾Åû¶ÁËÊý¾Ýй¶Ê¼þ£¬ÔÒòÊÇ 2024 Äê 2 Ô¶ÔÆäÖÆÒ©ºÍÉÌÒµ·þÎñºÏ×÷»ï°é Cencora ÌᳫµÄÍøÂç¹¥»÷¡£Cencora£¨Ç°ÉíΪ AmerisourceBergen£©ÊÇÒ»¼ÒרÃÅ´ÓÊÂÒ©Æ··ÖÏú¡¢×¨ÒµÒ©·¿¡¢×ÉѯºÍÁÙ´²ÊÔÑéÖ§³ÖµÄÒ½Ò©·þÎñÌṩÉÌ¡£¸Ã¹«Ë¾×ܲ¿Î»ÓÚ±öϦ·¨ÄáÑÇÖÝ£¬ÒµÎñ±é¼° 50 ¸ö¹ú¼Ò£¬ÓµÓÐ 46,000 ÃûÔ±¹¤£¬2023 ÄêÓªÊÕΪ 2620 ÒÚÃÀÔª¡£2024 Äê 2 Ô£¬Cencora ÔÚÏòÃÀ¹ú֤ȯ½»Ò×ίԱ»áÌá½»µÄ 8-K ±í¸ñÖÐÅû¶ÁËÊý¾Ýй¶Ê¼þ £¬³Æδ¾ÊÚȨµÄ¸÷·½·ÃÎÊÁËÆäÐÅϢϵͳ²¢ÇÔÈ¡Á˸öÈËÊý¾Ý¡£Æäʱ£¬¸Ã¹«Ë¾Ñ¡Ôñ²»·ÖÏíÓйظÃʼþ¼°Æä¶Ô¿Í»§µÄDZÔÚÓ°ÏìµÄÈκÎÆäËûÐÅÏ¢¡£´ËÍ⣬ûÓÐÈκÎÀÕË÷Èí¼þ×éÖ¯ÈϿɶԴ˴ι¥»÷ÂôÁ¦¡£½ñÌ죬¼ÓÖÝ×ܼì²ì³¤°ì¹«ÊÒÐû²¼ÁËÃÀ¹úһЩ×î´óµÄÖÆÒ©¹«Ë¾ÔÚ¹ýÈ¥¼¸ÌìÌá½»µÄ¶à·ÝÊý¾Ýй¶֪ͨÑù±¾£¬ÕâЩ¹«Ë¾¾ù½«ÆäÊý¾Ýй¶¹é¾ÌÓÚ 2 ÔÂ·ÝµÄ Cencora ʼþ¡£Êý¾Ýй¶֪ͨ¾¯¸æ³Æ£¬Cencora µÄÄÚ²¿ÊÓ²ìÓÚ 2024 Äê 4 Ô 10 ÈÕ½áÊø£¬ÊÓ²ì֤ʵÒÔÏÂÐÅÏ¢Òѱ»Ð¹Â¶£ºÈ«Ãû¡¢µØÖ·¡¢½¡¿µÕï¶Ï¡¢Ò©ÎïºÍ´¦·½¡£ÐÅÖÐÖ¸³ö£¬½ØÖÁÄ¿Ç°£¬Ã»ÓÐÖ¤¾Ý±íÃ÷ÇÔÈ¡µÄÐÅÏ¢ÒÑÔÚ»¥ÁªÍøÉϹûÈ»Åû¶»ò±»ÓÃÓÚÆÛÕ©Ä¿µÄ¡£ÎªÁËÓ¦¶ÔÊÜÓ°Ïì¸öÈËÃæÁٵĽϸ߷çÏÕ£¬Cencora ½«Í¨¹ý Experian ΪÊÜÖúÕßÌṩÁ½ÄêµÄÃâ·ÑÉí·Ý±£»¤ºÍÐÅÓüà¿Ø·þÎñ£¬ÊÜÖúÕß¿ÉÒÔʹÓÃÕâЩ·þÎñÖ±µ½ 2024 Äê 8 Ô 30 ÈÕ¡£
https://www.bleepingcomputer.com/news/security/cencora-data-breach-exposes-us-patient-info-from-11-drug-companies/