ÍøÂç·¸×ïÕßÀûÓÃWMI×é¼þBMOFÁ÷´«XMRigÍÚ¿ó¶ñÒâÈí¼þ
Ðû²¼Ê±¼ä 2024-09-129ÔÂ10ÈÕ£¬AhnLab Äþ¾²Ç鱨ÖÐÐÄ£¨ASEC£©½üÆÚ½ÒʾÁËÒ»ÖÖÁîÈ˾¯ÌèµÄÍøÂç·¸×ïÐÂÇ÷ÊÆ£¬¼´·¸×ï·Ö×ÓÇÉÃîÀûÓöþ½øÖƹÜÀí¹¤¾ßÎļþ£¨BMOF£©£¬ÕâÊÇÔÚWindows¹ÜÀí¹æ·¶£¨WMI£©ÖÐÖÁ¹ØÖØÒªµÄ×é¼þ£¬×÷ΪÁ÷´«XMRig¼ÓÃÜ»õ±ÒÍÚ¿ó¶ñÒâÈí¼þµÄÔØÌå¡£BMOFÔ±¾ÓÃÓÚÖ´Ðнű¾µÄ¹¦Ð§±»¶ñÒâÀûÓã¬Í¨¹ý´´½¨¡°ÓÀ¾Ãʼþ¶©ÔÄ¡±»úÖÆ£¬ÊµÏÖ¶ñÒâÈí¼þµÄ³Ö¾Ã»¯´æÔÚÓë×ÔÎÒ»Ö¸´ÄÜÁ¦£¬¼«´óÔöÇ¿Á˹¥»÷Õ߶ÔÊܺ¦ÏµÍ³µÄ¿ØÖÆÁ¦¡£´Ë¹¥»÷ÊÖ·¨³£ÓëBondNet¶ñÒâÈí¼þÐͬ£¬ºóÕßר¹¥SQL·þÎñÆ÷£¬Í¨¹ý©¶´ÀûÓûò±©Á¦Æƽâ»ñÈ¡³õʼ·ÃÎÊȨ£¬ËæºóÀûÓÃBMOFÏÂÔز¢Ö´Ðиü¶à¶ñÒâ×é¼þ£¬×îÖÕ²¿ÊðXMRigÍÚ¿óÈí¼þ¡£XMRig×÷ΪһÖÖ¼ÓÃܽٳֶñÒâÈí¼þ£¬ÇÄÎÞÉùÏ¢µØÕ¼ÓÃÊܺ¦Õßϵͳ×ÊÔ´ÍÚ¾òÃÅÂÞ±Ò£¬¶ÔϵͳÐÔÄÜÓëÄܺÄÔì³ÉÏÔÖø¸ºÃæÓ°Ï죬Ϊ¹¥»÷Õßıȡ·Ç·¨ÀûÒæ¡£
https://securityonline.info/cybercriminals-exploit-legitimate-windows-tool-for-cryptojacking/
2. Ð嵀 PIXHELL Éùѧ¹¥»÷й¶ÁËÒº¾§ÆÁÄ»ÔëÒôµÄÃØÃÜ
9ÔÂ10ÈÕ£¬ÐÂÐÍÉùѧ¹¥»÷¡°PIXHELL¡±Õ¹Ê¾ÁË´Ó¸ôÀëϵͳÖÐÒþÃØй¶ÐÅÏ¢µÄÇ¿´óÄÜÁ¦£¬Ëüͨ¹ýÁ¬½ÓµÄLCDÏÔʾÆ÷·¢³öÈ˶úÄÑÒÔ²ì¾õµÄÉù²¨£¨0-22 kHz£©£¬ÀûÓÃÏñËØģʽµ÷ÖÆͨ±¨±àÂëÐźţ¬ÕâЩÊý¾ÝÄܱ»ËÄÖܵÄÖÇÄÜÉ豸²¶×½¡£¾¡¹ÜÊý¾Ý´«ÊäËÙÂʽÏÂý£¨½ö20 bps£©£¬µ«Ëü×ãÒÔ½øÐÐʵʱ¼üÅ̼Ǽ»òÇÔȡСÎı¾Îļþ¡£PIXHELLÓÉÒÔÉ«ÁÐÄڸǷò±¾¡¤¹ÅÀï°²´óѧµÄMordechai Guri²©Ê¿¿ª·¢£¬ÀûÓÃÁËLCDÆÁÄ»µÄ×ÔÈ»Éù·¢ÉäÌØÐÔ£¬½áºÏÌØÖƶñÒâÈí¼þ£¬Í¨¹ý²îÒìµÄµ÷ÖƼ¼Êõ£¨ÈçOOK¡¢FSK¡¢ASK£©½«Êý¾Ý±àÂëΪÉùÒôÐźš£ÓÉÓÚÕâЩÉùÒôºÍÏñËر仯¶ÔÈËÀàÓû§¶øÑÔ¼¸ºõ²»Ðмû£¬Ê¹µÃ¹¥»÷¼«ÆäÒþ±Î¡£Ãæ¶ÔPIXHELL¹¥»÷£¬¿É½ÓÄɵķÀÓù´ëÊ©°üÂÞ£ºÔÚÃô¸ÐÇøÓò½ûÓÃЯ´øÂó¿Ë·çµÄÉ豸£¬Ôö¼ÓÅä¾°ÔëÉùÒÔ×ÌÈÅÐźţ¬ÒÔ¼°Ê¹ÓÃÉãÏñÍ·¼à¿ØÆÁÄ»»º³åÇøÒÔ¼ì²âÒì³£ÏñËØģʽ¡£ÕâЩ´ëÊ©ÅäºÏ×é³ÉÁËÒ»¸ö¶àÌõÀíµÄÄþ¾²·À»¤Íø£¬Ö¼ÔÚÓÐЧµÖÓù´ËÀàÐÂÐÍÉùѧ²àÐŵÀ¹¥»÷¡£
https://www.bleepingcomputer.com/news/security/new-pixhell-acoustic-attack-leaks-secrets-from-lcd-screen-noise/
3. Kemper Sports ManagementÊý¾Ýй¶£¬Ó°Ïì6.2ÍòÈË
9ÔÂ11ÈÕ£¬¸ß¶û·òÇò³¡¹ÜÀí¼°¾Æµê·þÎñÌṩÉÌKemper Sports ManagementÐû²¼ÁËÒ»ÆðÖØ´óÊý¾Ýй¶Ê¼þ£¬²¨¼°6.2ÍòÃû¸öÈË£¬Ö÷ÒªÉæ¼°ÆäÏÖÈμ°Ç°ÈÎÔ±¹¤µÄÃô¸ÐÐÅÏ¢£¬°üÂÞÐÕÃûºÍÉç»áÄþ¾²ºÅÂë¡£¹«Ë¾ÓÚ2024Äê4ÔÂ1ÈÕ²ì¾õÍøÂçÒì³££¬¾ÊÓ²ìÈ·ÈÏ£¬²»Ã÷ÍþвÕßÒÑ·Ç·¨ÇÖÈëϵͳ²¢»ñÈ¡ÁËÕâЩÐÅÏ¢¡£´Ë´Îй¶Ê¼þÓ°Ï췶Χ¹ã·º£¬²¨¼°KemperSportsÔÚÃÀ¹ú30¸öÖݵÄÁè¼Ý7,500ÃûÔ±¹¤£¬ÁýÕÖÆä140¶à¸ö·ÖÖ§»ú¹¹¡£¾¡¹ÜÄ¿Ç°ÉÐÎÞÖ¤¾Ý±íÃ÷ÐÅÏ¢Òѱ»¶ñÒâÀûÓÃÓÚÉí·Ý͵ÇÔ»òÆÛÕ©»î¶¯£¬KemperSportsÒÑѸËÙ½ÓÄÉÐж¯£¬ÎªÊÜÓ°ÏìµÄ¸öÈËÌṩһÄêµÄÃâ·ÑÐÅÓüà¿Ø¼°Éí·Ý»Ö¸´·þÎñ×÷ΪÅâ³¥¡£ÖµµÃ×¢ÒâµÄÊÇ£¬´Ë´Îʼþ²¢Î´Ã÷È·Ö¸ÏòÈκÎÒÑÖªµÄÀÕË÷Èí¼þ×éÖ¯£¬ÇÒ¹«Ë¾Ç¿µ÷£¬¼´±ãÉæ¼°Êê½ðÖ§¸¶£¬ÆäÒ²²»»á³ÉΪйÃÜÐÅÏ¢µÄ¹ûÈ»¹¤¾ß¡£´ËÏûϢѸËÙÒýÆðÖ´·¨½çµÄ¹Ø×¢£¬¶à¼ÒÂÉʦÊÂÎñËùÒÑÐû²¼ÉùÃ÷£¬Òâͼ´ú±íÊܺ¦ÕßÏòKemperSportsÌᳫ¼¯ÌåËßËÏ¡£
https://www.securityweek.com/data-breach-at-golf-course-management-firm-kempersports-impacts-62000/
4. ÍøÂçµöÓãÐÂÇ÷ÊÆ£ºÓòÃûÇÀ×¢ÓëÆ·ÅÆð³äËÁÅ°
9ÔÂ11ÈÕ£¬Zscaler ThreatLabz×îгÂËß½ÒʾÁËÍøÂçµöÓã»î¶¯ÕýÒÔÇ°ËùδÓеÄËÙ¶ÈÔö³¤£¬ÌرðÊÇͨ¹ýÓòÃûÇÀ×¢ºÍÆ·ÅÆð³äÊֶΡ£ÔÚ2024Äê2ÔÂÖÁ7ÔÂÆڼ䣬Ñо¿ÍŶӷÖÎöÁËÁè¼Ý3Íò¸öÓëÈ«ÇòÖªÃûÆ·ÅÆÏàËƵÄÓòÃû£¬·¢ÏÖÆäÖÐÈý·Ö֮һΪ¶ñÒâÓòÃû£¬ÓÈÒԹȸ衢΢ÈíºÍÑÇÂíÑ·µÈ¿Æ¼¼¾ÞͷΪð³äÖØÔÖÇø£¬Õ¼±È½üËÄ·ÖÖ®Èý¡£ÕâЩ¹¥»÷ÕßÀûÓÃÆ·ÅÆÖªÃû¶ÈºÍÓû§ÐÅÈΣ¬Í¨¹ýÇá΢ƴд´íÎóµÄÓòÃûÓÕÆÓû§½øÈë¶ñÒâÍøÕ¾£¬ÀûÓñ»µÁƾ֤ѸËÙ±äÏÖ¡£»¥ÁªÍø·þÎñÐÐÒµ³ÉΪÍøÂçµöÓãµÄÖ÷ҪĿ±ê£¬Õ¼±È½üÈý³É£¬×¨Òµ·þÎñÓëÔÚÏß¹ºÎïÍøÕ¾½ôËæÆäºó£¬ÒòÆä´¦ÖôóÁ¿Ãô¸ÐºÍ²ÆÕþÊý¾Ý¶ø±¸ÊÜÇàíù¡£ÖµµÃ×¢ÒâµÄÊÇ£¬½ü°ëµöÓãÓòÃû½ÓÄÉÃâ·ÑµÄLet's Encrypt TLSÖ¤ÊéαװºÏ·¨£¬ÀûÓá°¹ÒËø¡±·ûºÅÎóµ¼Óû§£¬ÌÓ±Üä¯ÀÀÆ÷Äþ¾²¾¯¸æ¡£¼øÓÚÓòÃûÇÀ×¢ºÍÆ·ÅÆð³ä»î¶¯Á¬Ðø·ÅËÁ£¬ÌáÉýÓû§·À·¶ÒâʶºÍ¼ÓÇ¿ÆóÒµÍøÂçÄþ¾²´ëÊ©¿Ì²»ÈÝ»º¡£
https://securityonline.info/cybercriminals-increasingly-target-google-microsoft-and-amazon-in-sophisticated-phishing-schemes/
5. LearnPressÆØ©¶´CVE-2024-8522£¬Íþв³¬9Íò¸öÍøÕ¾Äþ¾²
9ÔÂ11ÈÕ£¬LearnPressÊÇÒ»¿î¹ãÊÜ»¶ÓµÄWordPressÔÚÏ߿γ̹ÜÀí¹¤¾ß²å¼þ£¬½üÆÚ±»·¢ÏÖ´æÔÚÒ»¸ö¸ßΣSQL×¢È멶´£¬±àºÅΪCVE-2024-8522£¬ÆäCVSSÆÀ·Ö¸ß´ï10£¬±íÃ÷¸Ã©¶´¾ßÓм«¸ßµÄÑÏÖØÐÔ¡£´Ë©¶´Ç±²ØÓÚLearnPressµÄREST API¶ËµãÖУ¬¾ßÌå¹ØÁªµ½¡°c_only_fields¡±²ÎÊýµÄ´¦Öò»Í×£¬Òòȱ·¦×ã¹»µÄתÒå´ëÊ©ºÍSQL²éѯ׼±¸£¬Ê¹µÃδ¾Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÄܹ»×¢Èë¶ñÒâSQL´úÂ룬½ø¶ø¿ÉÄÜ·ÃÎʲ¢ÇÔÈ¡´æ´¢ÔÚWordPressÊý¾Ý¿âÖеÄÃô¸ÐÐÅÏ¢£¬ÈçÓû§Æ¾Ö¤¡¢¸öÈËÊý¾Ý¼°¿Î³Ì×ÊÁÏ¡£¼øÓÚLearnPressÓµÓÐÁè¼Ý90,000¸ö»îÔ¾°²×°Á¿£¬ÆäÓ°Ï췶Χ¹ã·ºÇÒÉîÔ¶£¬¹¥»÷ÕßÉõÖÁ¿ÉÄÜÀûÓôË©¶´Ð޸Ļòɾ³ýÊý¾Ý¿âÄÚÈÝ£¬ÍêÈ«¿ØÖÆÊÜÓ°ÏìµÄÍøÕ¾¡£¼øÓڸ鶴µÄ¼òÒ×ÀûÓÃÐԺ͸ßΣº¦ÐÔ£¬ËùÓÐʹÓÃLearnPressµÄWordPressÍøÕ¾¾ùÃæÁÙÖ±½Ó·çÏÕ¡£LearnPress¿ª·¢ÍŶÓÒÑѸËÙÏìÓ¦£¬Ðû²¼ÁË4.2.7.1°æ±¾ÒÔÐÞ¸´´Ë©¶´¡£Òò´Ë£¬Ç¿ÁÒ½¨ÒéËùÓÐÓû§Á¢¼´¸üÐÂÖÁ×îа汾£¬ÒÔÓÐЧ·À·¶Ç±ÔÚµÄÄþ¾²Íþв¡£
https://securityonline.info/cve-2024-8522-cvss-10-learnpress-sqli-flaw-leaves-90k-wordpress-sites-at-risk/
6. ÍøÂçÕ©ÆÐÂÄ¿±ê£ºÌØÀÊÆÕÊý×Ö½»Ò׿¨ÔâµöÓãÍøվΧ¹¥
9ÔÂ11ÈÕ£¬ÍøÂç·¸×ï·Ö×ÓÕýÀûÓõöÓãÍøÕ¾¡¢Ðé¼ÙÓòÃû¼°Éç»á¹¤³ÌÊֶΣ¬Õë¶ÔÌØÀÊÆÕµÄÊý×Ö½»Ò׿¨Ìᳫ¹¥»÷£¬ÆóͼÇÔÈ¡ÆäÃô¸ÐÊý¾Ý¡£ÌØÀÊÆÕµÄÐÂÊý×Ö½»Ò׿¨ÒòÆäÌṩµÄ¶À¼ÒÊý×Ö×ʲúºÍÕæʵÌåÑé¶ø±¸ÊܹØ×¢£¬È´Ò²Òò´Ë³ÉΪ·Ç·¨·Ö×ÓµÄÄ¿±ê¡£¾ÝVeritiÍøÂçÄþ¾²¹«Ë¾³ÂËߣ¬Õ©ÆÕßͨ¹ý¹¹½¨Óë¹Ù·½ÍøÖ·¸ß¶ÈÏàËƵÄÐé¼ÙURL£¬ÈçʹÓá°.xyz¡±ºó׺»ò¹ÊÒâƴд´íÎó£¨Èç¡°trunpcards¡±£©£¬ÓÕµ¼Óû§·ÃÎʲ¢Ð¹Â¶ÐÅÏ¢»ò°²×°¶ñÒâÈí¼þ¡£ËûÃÇÀûÓõç×ÓÓʼþÍøÂçµöÓ㣬·¢ËÍ¿´ËÆÀ´×ԺϷ¨ÇþµÀµÄÏÞʱÓÅ»ÝÓʼþ£¬ÄÚº¬¶ñÒâÁ´½Ó£¬ÓÕÆÓû§µã»÷¡£ÌØÀÊÆÕ¼°ÆäÖ§³ÖÕß²¢·ÇÊ״γÉΪÍøÂç·¸×ïµÄÄ¿±ê£¬¹ýÈ¥Ò²Ôø·¢Éú¹ýÀàËÆÕ©Æʼþ£¬Èçͨ¹ýÐé¼ÙÍøÕ¾ÇÔÈ¡¾è¿î¡¢ÀûÓÃÐé¼ÙÓö´ÌʼþÆÈ¡¼ÓÃÜ»õ±ÒµÈ¡£Ãæ¶ÔÕâЩ·çÏÕ£¬Êý×ÖÊղؿ¨Ï²ºÃÕßÐè±£³Ö¸ß¶È¾¯Ì裬½ÓÄÉ·À·¶´ëÊ©£¬ÈçʹÓÃ֪ʶÅжÏÐÅÏ¢Õæα¡¢¼ì²éURLµÄHTTPS±êʶ¼°Æ´Ð´×¼È·ÐÔ¡¢ÖÆÖ¹µã»÷δ¾ÑéÖ¤µÄÓʼþÁ´½Ó£¬²¢Ö÷¶¯·ÃÎʹٷ½ÍøÕ¾¡£
https://hackread.com/fake-domains-trump-supporters-trading-card-scam/