Ô½ÄϺڿÍ×éÖ¯²¿ÊðPXA Stealer£¬Õë¶ÔÅ·ÑÇÕþ¸®½ÌÓý»ú¹¹
Ðû²¼Ê±¼ä 2024-11-191. Ô½ÄϺڿÍ×éÖ¯²¿ÊðPXA Stealer£¬Õë¶ÔÅ·ÑÇÕþ¸®½ÌÓý»ú¹¹
11ÔÂ15ÈÕ£¬Ò»ÃûÉæÏÓÓëÔ½ÄÏÓйصÄÍþвÐÐΪÕßÀûÓÃÃûΪPXA StealerµÄÐÂÐÍPython¶ñÒâÈí¼þ£¬Õë¶ÔÅ·ÖÞºÍÑÇÖÞÕþ¸®¼°½ÌÓý»ú¹¹ÌᳫÐÅÏ¢ÇÔÈ¡»î¶¯¡£¸Ã¶ñÒâÈí¼þÄܽâÃÜä¯ÀÀÆ÷Ö÷ÃÜÂ룬ÇÔÈ¡ÔÚÏßÕË»§Æ¾Ö¤¡¢²ÆÕþÐÅÏ¢¡¢ä¯ÀÀÆ÷cookieµÈÃô¸ÐÐÅÏ¢¡£¹¥»÷Á´Ê¼ÓÚÍøÂçµöÓãµç×ÓÓʼþ£¬°üÂÞZIPÎļþ¸½¼þ£¬´¥·¢¼ÓÔØÆ÷ºÍÅú´¦Öýű¾£¬ÔËÐÐPowerShellÃüÁîÏÂÔØÓÐЧ¸ºÔز¢²¿ÊðÇÔÈ¡·¨Ê½¡£PXA StealerÌرð¹Ø×¢ÇÔÈ¡Facebook cookie£¬ÓÃÓÚÓëFacebook Ads ManagerºÍGraph API½»»¥ÊÕ¼¯ÏêϸÐÅÏ¢¡£´ËÍ⣬ÆäËûÇÔÈ¡¶ñÒâÈí¼þÈçStrelaStealer¡¢RECORDSTEALER¡¢Rhadamanthys¡¢Amnesia StealerºÍGlove StealerµÈÒ²ÔÚ²»Í£Éú³¤ºÍÓ¿ÏÖ£¬Ö¤Ã÷ÁËÇÔÈ¡¶ñÒâÈí¼þµÄÁ÷ÐС£¾¡¹ÜÖ´·¨²¿ÃÅŬÁ¦¹¥»÷£¬µ«´ËÀà»î¶¯ÈÔÁ¬Ðø´æÔÚ¡£
https://thehackernews.com/2024/11/vietnamese-hacker-group-deploys-new-pxa.html
2. GitHubÏîĿƵÔâ¶ñÒâºóÃŹ¥»÷
11ÔÂ16ÈÕ£¬GitHubÏîÄ¿Õý³ÉΪ¶ñÒâÌá½»ºÍÀÈ¡ÇëÇóµÄÄ¿±ê£¬Ö¼ÔÚÏòÕâЩÏîĿעÈëºóÃÅ¡£×î½ü£¬Exo LabsµÄGitHub´æ´¢¿â¾ÍÔâµ½ÁË´ËÀ๥»÷£¬¹¥»÷Õßͨ¹ýÌá½»¿´ËÆÎÞº¦µÄ´úÂë¸ü¸Ä£¬ÊÔͼÔÚ´úÂëÖÐÖ²ÈëºóÃÅ£¬ÒÔÔ¶³ÌÖ´ÐжñÒâ´úÂ롣Ȼ¶ø£¬¸Ã´úÂë¸ü¸Ä²¢Î´±»Åú×¼ºÏ²¢µ½¹Ù·½´æ´¢¿â¡£¹¥»÷ÕßʹÓõÄGitHubÕË»§¡°evildojo666¡±ÏÖÒѱ»É¾³ý£¬¶ø¸ÃÕË»§Ö¸ÏòµÄÄþ¾²Ñо¿Ô±Mike BellÔò·ñÈÏÓë´ËÊÂÓйأ¬²¢Éù³Æ×Ô¼ºÔâµ½ÁËð³ä¡£´ËÍ⣬»¹ÓÐÆäËûÏîÄ¿Ò²³ÉΪÁËÀàËƵĹ¥»÷Ä¿±ê£¬°üÂÞÁ÷ÐеĿªÔ´ÒôƵºÍÊÓƵÏÂÔØÆ÷¡°yt-dlp¡±¡£ÕâЩ¹¥»÷ʼþÌáÐÑ¿ªÔ´ÏîĿά»¤ÕßÒª×ÐϸÉó²é´«ÈëµÄÀÈ¡ÇëÇ󣬼´Ê¹ËüÃÇÀ´×Ô¿´ËÆ¡°ÉÆÒ⡱µÄТ¾´Õߣ¬Ò²Ó¦Ê¹ÓÃ×Ô¶¯»¯¹¤¾ßºÍ´óÁ¿È˹¤´úÂëÉó²éÀ´È·±£Äþ¾²¡£
https://www.bleepingcomputer.com/news/security/github-projects-targeted-with-malicious-commits-to-frame-researcher/
3. Maxar Space SystemsÔâºÚ¿ÍÈëÇÖ£¬Ô±¹¤¸öÈËÊý¾ÝÔâÇÔÈ¡
11ÔÂ18ÈÕ£¬ÃÀ¹úÎÀÐÇÖÆÔìÉÌMaxar Space SystemsÔâÊܺڿÍÈëÇÖ£¬µ¼ÖÂÔ±¹¤¸öÈËÊý¾Ý±»ÇÔÈ¡¡£ºÚ¿ÍÔÚ2024Äê10ÔÂ11ÈÕ±»·¢ÏÖÇ°ÒÑÇÖÈ빫˾ÍøÂçÔ¼Ò»ÖÜʱ¼ä¡£Maxar Space SystemsÊÇÃÀ¹úº½¿Õº½ÌìÒµµÄÖØÒª¼ÓÈëÕߣ¬Òѽ¨Ôì80¶à¿ÅÔÚ¹ìÎÀÐÇ£¬²¢ÎªNASAµÄPsycheÈÎÎñºÍArtemisÔÂÇò̽Ë÷¼Æ»®ÌṩÁËÒªº¦¼¼Êõ¡£Ð¹Â¶µÄÔ±¹¤ÐÅÏ¢°üÂÞÐÕÃû¡¢¼ÒÍ¥µØÖ·¡¢Éç»á±£ÕϺÅÂëµÈÃô¸ÐÐÅÏ¢£¬µ«ÒøÐÐÕË»§ÐÅϢδÊÜÓ°Ïì¡£ÊÜÓ°ÏìÔ±¹¤¿ÉÏíÊÜIDShieldÉí·Ý±£»¤ºÍÐÅÓüà¿Ø·þÎñ£¬¶øÇ°ÈÎÔ±¹¤¿ÉÔڹ涨ʱ¼äÄÚ×¢²áIDXµÄÉí·Ý͵ÇÔ±£»¤·þÎñ¡£´ËÍ⣬ÓÐÏûÏ¢³ÆºÚ¿Í»¹Éù³ÆÇÔÈ¡ÁËMaxar Technologies¿ª·¢µÄµØÀí¿Õ¼äÇ鱨ƽ̨GeoHIVEµÄÓû§Èº£¬µ«Maxar TechnologiesÉÐδ¶Ô´Ë·¢±íÆÀÂÛ¡£
https://www.bleepingcomputer.com/news/security/us-space-tech-giant-maxar-discloses-employee-data-breach/
4. ²©Í¨¾¯¸æ£ºVMware vCenter ServerÁ½´ó©¶´Õý±»¹¥»÷ÕßÀûÓÃ
11ÔÂ18ÈÕ£¬²©Í¨½üÈÕ·¢³ö¾¯¸æ£¬Ö¸³ö¹¥»÷ÕßÕýÔÚÀûÓÃVMware vCenter ServerµÄÁ½¸öÄþ¾²Â©¶´£¬ÆäÖÐ֮һΪÑÏÖصÄÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2024-38812£©£¬ÓÉTZLÄþ¾²Ñо¿ÈËÔ±ÔÚÖйú2024 Matrix CupºÚ¿Í´óÈüÆÚ¼ä³ÂËß¡£¸Ã©¶´Ô´ÓÚvCenterµÄDCE/RPCÐÒéʵÏÖÖеĶÑÒç³öÎÊÌ⣬ӰÏìVMware vSphereºÍVMware Cloud FoundationµÈ²úÎï¡£ÁíÒ»¸ö©¶´£¨CVE-2024-38813£©ÎªÈ¨ÏÞÌáÉý©¶´£¬Í¬ÑùÓɸÃÑо¿ÈËÔ±·¢ÏÖ£¬¹¥»÷Õß¿ÉÀûÓÃÌØÖÆÍøÂçÊý¾Ý°üÌáÉýÖÁrootȨÏÞ¡£²©Í¨È·ÈÏÕâÁ½¸ö©¶´Òѱ»ÀûÓ㬲¢ÓÚ9ÔÂÐû²¼ÁËÄþ¾²¸üУ¬µ«Ëæºó·¢ÏÖCVE-2024-38812µÄ²¹¶¡²¢Î´ÍêÈ«½â¾öÎÊÌ⣬²¢Ç¿ÁÒ½¨Òé¹ÜÀíÔ±Ó¦ÓÃв¹¶¡¡£ÊÜÓ°Ïì¿Í»§Ó¦Á¢¼´Ó¦ÓÃ×îиüÐÂÒÔ·À·¶¹¥»÷¡£´ËÍ⣬²©Í¨»¹Ðû²¼ÁËÔö²¹Í¨¸æ£¬Ìṩ¸ü¶àÄþ¾²¸üÐÂÐÅÏ¢ºÍ¿ÉÄÜÓ°ÏìÒÑÉý¼¶Óû§µÄÒÑÖªÎÊÌâ¡£
https://www.bleepingcomputer.com/news/security/critical-rce-bug-in-vmware-vcenter-server-now-exploited-in-attacks/
5. DocuSignÍøÂçµöÓãթƼ¤Ôö£¬Ã°³äÃÀÕþ¸®»ú¹¹ÇÔÈ¡Êý¾Ý
11ÔÂ18ÈÕ£¬DocuSignÍøÂçµöÓãÕ©ÆÊýÁ¿½üÆÚ¼¤Ôö98%£¬¹¥»÷ÕßÀûÓÃÐÅÈÎÇÔÈ¡Êý¾Ý£¬Ã°³äÃÀ¹úÕþ¸®»ú¹¹ÈçÎÀÉúÓ빫ÖÚ·þÎñ²¿(HHS)ºÍÂíÀïÀ¼Öݽ»Í¨²¿(MDOT)µÈ·¢Ë͵öÓãURL¡£ÕâЩµöÓãURL±»Éè¼Æ³ÉÄ£·Â¹Ù·½Í¨ÐÅ£¬Ê¹ÓÃÕæÕýµÄDocuSignÕÊ»§ºÍAPIαװ³ÉÕæʵÇëÇó¡£Ò»µ©Ä¿±ê´ò¿ª¶ñÒâÎĵµ£¬¾Í»á±»ÒªÇóÌṩÃô¸ÐÐÅÏ¢»òÊÚȨÆÛÕ©½»Òס£ÓÉÓÚÇëÇó¿´Ëƹٷ½£¬ÊÕ¼þÈ˸ü¿ÉÄÜδ¾³¹µ×ÑéÖ¤¾Í×ñÊØÇëÇó£¬Î£¼°¹«Ë¾Äþ¾²¡£ÃÀ¹ú¹«Ãñ¡¢Õþ¸®»ú¹¹ºÍÊÐÕþ°ì¹«ÊÒÊÇÕâЩ¹¥»÷µÄÖ÷ҪĿ±ê¡£×¨¼Ò½¨ÒéÆóҵʵʩ¶à²ãÄþ¾²¼Æı£¬ÒòΪÊܺ¦Õß×ñѵÄÊÇËûÃǽÓÊܹýÅàѵ²¢±»ÆÚÍû×ñѵÄÁ÷³Ì£¬ÎÊÌâÔÚÓÚÎÞ·¨ÑéÖ¤ÇëÇóÀ´Ô´£¬ÐèÒªÖØп¼ÂÇÈçºÎÌṩǩÃûÇëÇ󣬲¢¿ÉÄܽÓÄÉÇ¿´óµÄÉí·ÝÑéÖ¤ÒªÁì¡£
https://hackread.com/us-govt-agencies-impersonate-docusign-phishing-scams/
6. ÃÀÒûÓÃˮϵͳ´æÍøÂçÄþ¾²Â©¶´£¬»òÖ·þÎñÖжÏ
11ÔÂ18ÈÕ£¬ÃÀ¹ú»·¾³±£»¤Êð£¨EPA£©¼à²ì³¤°ì¹«ÊÒ£¨OIG£©Ðû²¼µÄгÂËßÏÔʾ£¬ÎªÃÀ¹úÔ¼1.1ÒÚÈËÌṩ·þÎñµÄ300¶à¸öÒûÓÃˮϵͳ´æÔÚ©¶´£¬¿ÉÄܵ¼Ö·þÎñÖжϡ£ÆÀ¹Àº¸Ç1062¸öÒûÓÃˮϵͳ£¬·¢ÏÖÆäÖÐËÄ·ÖÖ®Ò»¿ÉÄܳÉΪ¹¥»÷Êܺ¦Õߣ¬µ¼Ö¹¦Ð§É¥Ê§¡¢¾Ü¾ø·þÎñµÈÇé¿ö¼°¿Í»§ÐÅϢй¶¡£97¸ö¹©Ë®ÏµÍ³´æÔÚÑÏÖغ͸߶ÈÑÏÖØÎÊÌ⣬ÁýÕÖÔ¼2700ÍòÈË£»211¸öϵͳÊÜÖжȺ͵ͶÈȱÏÝÓ°Ï죬ÁýÕÖÔ¼8300ÍòÈË¡£OIGÖ¸³ö£¬Èô¶ñÒâÐÐΪÕßÀûÓ鶴£¬¿ÉÄÜÆÆ»µ·þÎñ»òÔì³ÉÎïÀíË𻵡£ÆÀ¹ÀÉæ¼°Áè¼Ý75000¸öIPºÍ14400¸öÓòµÄ·ÖÎö¡£´ËÍ⣬EPAȱ·¦Ïò¸Ã»ú¹¹Í¨±¨ÍøÂçÄþ¾²Ê¼þµÄ³ÂËßϵͳ£¬²¢ÒÀÀµÆäËû»ú¹¹½øÐдËÀà³ÂËߣ¬Í¬Ê±È±·¦ÓëÆäËûÁª°îºÍÖÝÕþ¸®µÄе÷¼Ç¼¡£´ËÇ°£¬ÒÑÓÐË®Îñ¹«Ë¾ÔâÊÜÍøÂç¹¥»÷£¬µ«¹©Ë®·þÎñδÊÜÓ°Ïì¡£½ñÄê5Ô£¬EPAÔø¾¯¸æ³¬70%¹©Ë®ÏµÍ³²»Çкϡ¶Äþ¾²ÒûÓÃË®·¨¡·£¬´æÔÚÑÏÖØÄþ¾²ÎÊÌâ¡£
https://www.securityweek.com/300-drinking-water-systems-in-us-exposed-to-disruptive-damaging-hacker-attacks/