ÐÂÍøÂçµöÓ㹤¾ß°ü¡°Xi¨± g¨¯u¡±Òý·¢È«ÇòÄþ¾²¾¯±¨
Ðû²¼Ê±¼ä 2024-11-041. ÐÂÍøÂçµöÓ㹤¾ß°ü¡°Xi¨± g¨¯u¡±Òý·¢È«ÇòÄþ¾²¾¯±¨
11ÔÂ1ÈÕ£¬ÍøÂçÄþ¾²ÁìÓò½üÆÚ·ºÆðÁËÒ»ÖÖÃûΪXi¨± g¨¯uµÄÐÂÐÍÍøÂçµöÓ㹤¾ß°ü£¬×Ô2024Äê9ÔÂÆðÒÑÕë¶Ô°Ä´óÀûÑÇ¡¢ÈÕ±¾¡¢Î÷°àÑÀ¡¢Ó¢¹úºÍÃÀ¹úµÈ¶à¸ö¹ú¼ÒÌᳫ¹¥»÷¡£¸Ã¹¤¾ß°üÒÑѬȾÁè¼Ý2000¸öµöÓãÍøÕ¾£¬Ö÷Òª¹¥»÷¹«¹²²¿ÃÅ¡¢ÓÊÕþ¡¢Êý×Ö·þÎñºÍÒøÐзþÎñµÈ´¹Ö±ÐÐÒµ¡£NetcraftÖ¸³ö£¬ÕâЩ¹¥»÷Õß³£ÀûÓÃCloudflareµÄ·´»úÆ÷È˺ÍÍйܻìÏý¹¦Ð§À´¹æ±Ü¼ì²â¡£Xi¨± g¨¯uÌṩ¹ÜÀíÃæ°å£¬Ê¹ÓÃGolangºÍVue.jsµÈ¼¼Êõ£¬Í¨¹ýTelegram´ÓÐé¼ÙµöÓãÒ³ÃæÇÔÈ¡ÐÅÏ¢¡£ÕâЩÍøÂçµöÓã¹¥»÷Ö÷Ҫͨ¹ý¸»Í¨ÐÅ·þÎñ£¨RCS£©ÏûÏ¢Á÷´«£¬ÓÕµ¼Êܺ¦Õßµã»÷Ëõ¶ÌµÄÁ´½ÓÒÔÌṩ¸öÈËÐÅÏ¢»ò¸¶¿î¡£¹È¸èµÈ¿Æ¼¼¾ÞÍ·ÒѽÓÄÉ´ëÊ©¹¥»÷´ËÀàÕ©Æ£¬°üÂÞÍƳöÔöÇ¿ÐÍթƼì²â¹¦Ð§ºÍÄþ¾²¾¯¸æ£¬²¢¼Æ»®ÔÚÈ«Çò·¶Î§ÄÚÍƹãб£»¤´ëÊ©¡£´ËÍ⣬˼¿ÆTalosÍŶӷ¢ÏÖ£¬Ì¨ÍåµÄFacebookÉÌÒµºÍ¹ã¸æÕÊ»§Óû§Õý³ÉΪÍøÂçµöÓã»î¶¯µÄÄ¿±ê£¬Ö¼ÔÚÁ÷´«ÇÔÈ¡¶ñÒâÈí¼þ¡£ÕâЩ»î¶¯»¹Ã°³äOpenAIµÈÖªÃûÆóÒµ£¬ÓÕµ¼È«ÇòÆóÒµ¸üи¶¿îÐÅÏ¢¡£
https://thehackernews.com/2024/11/new-phishing-kit-xiu-gou-targets-users.html
2. InterlockÀÕË÷Èí¼þ£ºÕë¶ÔFreeBSD·þÎñÆ÷µÄÐÂÐ͹¥»÷Ðж¯
11ÔÂ3ÈÕ£¬InterlockÊÇÒ»¸öÐÂÐ˵ÄÀÕË÷Èí¼þ²Ù×÷£¬×Ô2024Äê9Ôµ×Æô¶¯ÒÔÀ´£¬ÒѶÔÈ«Çò¶à¸ö×éÖ¯Ìᳫ¹¥»÷¡£Ëü½ÓÄÉÒ»ÖÖ²»³£¼ûµÄÒªÁ죬¼´´´½¨×¨ÃÅÕë¶ÔFreeBSD·þÎñÆ÷µÄ¼ÓÃÜÆ÷¡£ÕâÖÖ¼ÓÃÜÆ÷ÔÚFreeBSD 10.4ÉϱàÒ룬¾¡¹ÜBleepingComputerµÈÄþ¾²»ú¹¹ÔÚÐéÄâ»úÉϲâÊÔʱδÄÜʹÆäÕýÈ·Ö´ÐС£InterlockÔÚ¹¥»÷Àֳɺ󣬻áÔÚδ֧¸¶Êê½ðµÄÇé¿öÏ£¬ÔÚÆäÊý¾Ýй¶ÍøÕ¾ÉÏÐû²¼±»µÁÊý¾Ý¡£¾ÝÍøÂçÄþ¾²¹«Ë¾Ç÷ÊƿƼ¼³Æ£¬InterlockµÄÄ¿±êÊÇFreeBSD£¬ÒòΪËü¹ã·ºÓ¦ÓÃÓÚ·þÎñÆ÷ºÍÒªº¦»ù´¡ÉèÊ©£¬¹¥»÷Õß¿ÉÒÔÆÆ»µÖØÒª·þÎñ£¬Ë÷Òª¾Þ¶îÊê½ð¡£´ËÍ⣬Ç÷ÊƿƼ¼»¹·¢ÏÖÁ˸òÙ×÷µÄWindows¼ÓÃÜÆ÷Ñù±¾¡£ÔÚ¼ÓÃÜÎļþʱ£¬Interlock»á½«.interlockÀ©Õ¹Ãû¸½¼Óµ½ËùÓмÓÃÜÎļþÃûºó£¬²¢ÔÚÿ¸öÎļþ¼ÐÖд´½¨ÀÕË÷¼Ç¼¡£±»µÁÊý¾Ý±»ÓÃÓÚË«ÖØÀÕË÷¹¥»÷£¬ÍþвÐÐΪÕßÍþв³Æ£¬Èç¹û²»Ö§¸¶Êê½ð£¬ËûÃǾͻá¹ûȻй¶Êý¾Ý¡£¾Ý³Æ£¬InterlockÀÕË÷Èí¼þ²Ù×÷ÒªÇóµÄÊê½ð´ÓÊýÊ®ÍòÃÀÔªµ½Êý°ÙÍòÃÀÔª²»µÈ£¬¾ßÌåÈ¡¾öÓÚ×éÖ¯µÄ¹æÄ£¡£
https://www.bleepingcomputer.com/news/security/meet-interlock-the-new-ransomware-targeting-freebsd-servers/
3. SharePoint RCE©¶´CVE-2024-38094Õý±»ºÚ¿ÍÀûÓýøÐÐÍøÂç¹¥»÷
11ÔÂ2ÈÕ£¬Microsoft SharePointµÄÒ»¸öÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2024-38094£©±»Åû¶²¢ÕýÔÚ±»ºÚ¿ÍÀûÓã¬ÒÔ»ñÈ¡¶Ô¹«Ë¾ÍøÂçµÄ³õʼ·ÃÎÊȨÏÞ¡£¸Ã©¶´ÊÇÒ»¸ö¸ßÑÏÖØÐÔ£¨CVSS v3.1 ÆÀ·Ö£º7.2£©µÄRCE©¶´£¬Ó°Ïì¹ã·ºÊ¹ÓõĻùÓÚWebµÄSharePointƽ̨¡£Î¢ÈíÒÑÓÚ2024Äê7ÔÂ9ÈÕÐû²¼Á˲¹¶¡ÐÞ¸´¸Ã©¶´£¬²¢½«Æä±ê־Ϊ¡°ÖØÒª¡±¡£È»¶ø£¬CISAÉÏÖܽ«¸Ã©¶´Ìí¼Óµ½ÒÑÖªÀûÓ鶴Ŀ¼ʱ£¬²¢Î´Í¸Â¶¾ßÌåµÄÀûÓ÷½Ê½¡£Rapid7Ðû²¼µÄгÂËß½ÒʾÁ˹¥»÷ÕßÈçºÎÀûÓø鶴£¬Ö¸³ö¹¥»÷Õßͨ¹ýδ¾ÊÚȨ·ÃÎÊÒ×Êܹ¥»÷µÄSharePoint·þÎñÆ÷²¢Ö²ÈëWebshell£¬½ø¶øÔÚÍøÂçÖкáÏòÒƶ¯£¬Î£¼°Õû¸öÓò¡£¹¥»÷Õß»¹ÆÆ»µÁ˾ßÓÐÓò¹ÜÀíԱȨÏÞµÄMicrosoft Exchange·þÎñÕÊ»§£¬»ñµÃÌáÉýµÄ·ÃÎÊȨÏÞ£¬²¢°²×°ÁËHoroung AntivirusÈí¼þ£¬Ôì³ÉÄþ¾²·ÀÓù³åÍ»£¬½ûÓÃÄþ¾²·þÎñ£¬Ï÷Èõ¼ì²âÄÜÁ¦¡£ËûÃÇʹÓöàÖÖ¹¤¾ß½øÐÐƾ֤ÊÕ¼¯¡¢Ô¶³Ì·ÃÎÊ¡¢³Ö¾ÃÐÔÉèÖõȲÙ×÷£¬²¢½ûÓÃÁËWindows Defender¡¢¸ü¸ÄÁËʼþÈÕÖ¾£¬ÒÔÖÆÖ¹±»·¢ÏÖ¡£¾¡¹Ü¹¥»÷ÕßÊÔͼɾ³ý±¸·Ý£¬µ«²¢Î´ÀֳɼÓÃÜÊý¾Ý£¬Òò´Ë¹¥»÷ÀàÐÍÉв»Çå³þ¡£
https://www.bleepingcomputer.com/news/security/microsoft-sharepoint-rce-bug-exploited-to-breach-corporate-network/
4. Âåɼí¶ÊÐס·¿¹ÜÀí¾ÖÔâCactusÀÕË÷Èí¼þÍŻ﹥»÷
11ÔÂ1ÈÕ£¬Âåɼí¶ÊÐס·¿¹ÜÀí¾Ö£¨HACLA£©ÊÇÃÀ¹ú×î´óµÄ¹«¹²×¡·¿¹ÜÀí¾ÖÖ®Ò»£¬ÂôÁ¦¹ÜÀíÁè¼Ý32,000Ì×¹«¹²×¡·¿£¬Äê¶ÈÔ¤ËãÁè¼Ý10ÒÚÃÀÔª£¬ÎªµÍÊÕÈë¼ÒÍ¥¡¢¶ùͯºÍÀÏÄêÈËÌṩ¾¼ÃÊÊÓ÷¿ºÍÔ®Öú¼Æ»®¡£×î½ü£¬CactusÀÕË÷Èí¼þÍÅ»ïÉù³Æ¶ÔHACLAµÄITÍøÂç½øÐÐÁËÈëÇÖ¹¥»÷¡£HACLA֤ʵÁËÕâÒ»ÍøÂç¹¥»÷£¬²¢ÌåÏÖÒÑƸÇëÍⲿȡ֤ITר¼Ò½øÐÐÊÓ²ìºÍÓ¦¶Ô¡£¾¡¹ÜHACLAδ͸¶¹¥»÷µÄ¾ßÌåʱ¼äºÍÐÔÖÊ£¬µ«CactusÀÕË÷Èí¼þÍÅ»ïÉù³ÆÒÑ´ÓÊÜѬȾµÄÍøÂçÖÐÇÔÈ¡ÁË891 GBµÄÎļþ£¬°üÂÞ¸öÈËÉí·ÝÐÅÏ¢¡¢²ÆÕþÎļþ¡¢¸ß¹ÜºÍÔ±¹¤¸öÈËÊý¾Ý¡¢¿Í»§¸öÈËÐÅÏ¢¡¢¹«Ë¾»úÃÜÊý¾ÝºÍͨÐŵȣ¬²¢ÔÚÆäйÃÜÍøÕ¾ÉÏÐû²¼ÁËһЩÃô¸ÐÎļþµÄ½Øͼ×÷Ϊ֤¾Ý¡£´ËÍ⣬HACLAÔÚ2022ÄêÒ²ÔøÔâµ½LockBitÀÕË÷Èí¼þÍÅ»ïµÄ¹¥»÷£¬¹¥»÷ÕßÔÚ³¤´ïÒ»ÄêµÄʱ¼äÀï·ÃÎÊÁËHACLAµÄϵͳ£¬²¢¿ÉÒÔ·ÃÎÊ»áÔ±µÄÃô¸Ð¸öÈËÐÅÏ¢¡£Õþ¸®»ú¹¹ÔھܾøÖ§¸¶ÍøÂç·¸×ï·Ö×ÓÒªÇóµÄÊê½ðºó£¬LockBitÀÕË÷Èí¼þ×é֯й¶ÁËËùÓб»µÁÎļþ¡£
https://www.bleepingcomputer.com/news/security/la-housing-authority-confirms-breach-claimed-by-cactus-ransomware/
5. LastPassÓû§¾¯ÌèÐé¼ÙÖ§³Öµç»°ÊµÊ©Ô¶³Ì·ÃÎÊÕ©Æ
11ÔÂ1ÈÕ£¬LastPass ÊÇÒ»¿îÁ÷ÐеÄÃÜÂë¹ÜÀíÆ÷£¬ËüÀûÓà LastPass Chrome À©Õ¹·¨Ê½À´Éú³É¡¢Éú´æ¡¢¹ÜÀíºÍ×Ô¶¯Ìî³äÍøÕ¾ÃÜÂë¡£LastPass·¢³ö¾¯¸æ£¬Õ©ÆÕßÕýÔÚͨ¹ýÔÚÆäChromeÀ©Õ¹·¨Ê½ÉÏÐû²¼Ðé¼Ù5ÐÇÆÀÂÛ£¬ÍƹãÒ»¸ö¼ÙðµÄ¿Í»§Ö§³Öµç»°ºÅÂë805-206-2892£¬ÒÔÓÕÆLastPassÓû§¡£Ò»µ©Óû§²¦´ò¸Ãµç»°£¬Æ×Ó»áð³äLastPass£¬Òýµ¼ËûÃÇ·ÃÎÊ¡°dghelp[.]top¡±ÍøÕ¾£¬²¢ÒªÇóÊäÈë´úÂëÏÂÔØÔ¶³ÌÖ§³Ö·¨Ê½£¬¸Ã·¨Ê½Êµ¼ÊÉÏÊÇConnectWise ScreenConnectÊðÀí£¬ÔÊÐíÕ©ÆÕßÍêÈ«·ÃÎÊÓû§µÄ¼ÆËã»ú¡£BleepingComputer·¢ÏÖ£¬¸Ãµç»°ºÅÂëÓëÒ»³¡¸ü´ó¹æÄ£µÄթƻÓйأ¬¸ÃºÅÂ뻹±»ÓÃ×÷Ðí¶àÆäËû¹«Ë¾£¨ÈçÑÇÂíÑ·¡¢Adobe¡¢FacebookµÈ£©µÄ¼Ùð֧³Öµç»°ºÅÂ룬²¢ÔÚÖÖÖÖÍøÕ¾ÉÏÐû²¼¡£LastPassÓû§±»ÌáÐѲ»ÒªÓëÈκÎÈË·ÖÏíËûÃǵÄÖ÷ÃÜÂ룬ÒÔÖÆֹ˽Ï·ÃÎÊÆäÃÜÂë¿âÖд洢µÄËùÓÐÃÜÂëºÍÊý¾Ý¡£
https://www.bleepingcomputer.com/news/security/lastpass-warns-of-fake-support-centers-trying-to-steal-customer-data/
6. ·¨¹úÀ͹¤²¿ÔâÍøÂç¹¥»÷£¬¾ÍÒµ°ï·öÄêÇáÈËÊý¾ÝÒÉÔâй¶
11ÔÂ1ÈÕ£¬·¨¹úÀ͹¤²¿Ðû²¼£¬Æä¡°µØ·½Ê¹ÍÅ¡±ÍøÂçʹÓõÄÒ»¼Ò·þÎñÌṩÉÌÒÉËƽüÆÚÔâÊÜÍøÂç¹¥»÷£¬¸ÃÍøÂçÖ÷ҪΪ16ÖÁ25ËêµÄÄêÇáÈËÌṩ¾ÍÒµºÍÅàѵ½¨ÒéÓëÖ§³Ö¡£´Ë´Î¹¥»÷¿ÉÄÜй¶ÁËÒÑÔÚ¸ÃϵͳÖйҺŵÄÄêÇáÈ˵ĸöÈËÊý¾Ý£¬°üÂÞÈ«Ãû¡¢³öÉúÈÕÆÚ¡¢¹ú¼®¡¢µç×ÓÓʼþºÍÓÊÕþµØÖ·ÒÔ¼°µç»°ºÅÂ룬µ«ÒøÐÐÏêϸÐÅÏ¢¡¢Éç»á±£ÕϺźÍÉí·ÝÖ¤¼þδÊÜÓ°Ïì¡£¾¡¹Ü¼¼ÊõÊÓ²ìÉÐδÍê³É£¬¸Ã²¿ÒѽÓÄɶàÏî´ëÊ©½â¾ö©¶´ÎÊÌ⣬²¢ÒÑÏò·¨¹úÒþ˽¼à¹Ü»ú¹¹CNILºÍÍøÂçÄþ¾²»ú¹¹ANSSI³ÂËß´ËÊ£¬Í¬Ê±Ïò˾·¨Õþ¸®ÌáÆðͶËß¡£ÊÜÓ°ÏìµÄÄêÇáÈËÕýÔÚ±»Í¨±¨Çé¿ö£¬²¢ÌáÐÑËûÃǾ¯ÌèÍøÂçµöÓãºÍÉí·Ý͵ÇԵķçÏÕ£¬ÇÐÎðͨ¹ýµç»°¡¢¶ÌÐÅ»òµç×ÓÓʼþ͸¶ÃÜÂë»òÒøÐÐÏêϸÐÅÏ¢¡£
https://therecord.media/france-data-breach-government-contractor-local-missions