CleoÎļþ´«ÊäÈí¼þÁãÈÕ©¶´ÔâºÚ¿ÍÀûÓýøÐÐÊý¾Ý͵ÇÔ¹¥»÷
Ðû²¼Ê±¼ä 2024-12-121. CleoÎļþ´«ÊäÈí¼þÁãÈÕ©¶´ÔâºÚ¿ÍÀûÓýøÐÐÊý¾Ý͵ÇÔ¹¥»÷
12ÔÂ10ÈÕ£¬ºÚ¿ÍÕýÔÚ»ý¼«ÀûÓÃCleo¹ÜÀíÎļþ´«ÊäÈí¼þÖеÄз¢ÏÖµÄÁãÈÕ©¶´£¬ÇÖÈëÈ«ÇòÊýǧ¼Ò¹«Ë¾ÍøÂ磬°üÂÞTarget¡¢ÎÖ¶ûÂêµÈÖªÃûÆóÒµ£¬½øÐÐÊý¾Ý͵ÇÔ¹¥»÷¡£¸Ã©¶´´æÔÚÓÚCleo LexiCom¡¢VLTraderºÍHarmony²úÎïÖУ¬ÔÊÐí²»ÊÜÏÞÖƵÄÎļþÉÏ´«ºÍÏÂÔØ£¬µ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£¾¡¹ÜCleo֮ǰÒÑÐÞ¸´ÁËÒ»¸öÏà¹Ø©¶´CVE-2024-50623£¬µ«ÍþвÐÐΪÕßÈÔÈƹýÁËÐÞ¸´¼ÌÐø¹¥»÷¡£ÍøÂçÄþ¾²×¨¼ÒÖ¸³ö£¬ÕâЩ¹¥»÷ÓëеÄTermiteÀÕË÷Èí¼þÍÅ»ïÓйء£HuntressÄþ¾²Ñо¿ÈËÔ±Ê״η¢ÏÖÁ˸鶴µÄÖ÷¶¯¹¥»÷£¬²¢¾¯¸æÓû§½ÓÄɽô¼±Ðж¯£¬°üÂÞ½«ÏµÍ³ÒƵ½·À»ðǽºóÃ棬ÏÞÖÆÍⲿ·ÃÎÊ£¬²¢¼ì²é¿ÉÒÉÎļþ¡£CleoÒÑÈ·ÈÏ©¶´´æÔÚ£¬²¢ÕýÔÚ¿ª·¢Äþ¾²¸üУ¬Í¬Ê±ÌṩÁË»º½â´ëÊ©½¨Òé¡£¾ÝÔ¤¼Æ£¬ÃÀ¹úÓоø´ó¶àÊýÒ×Êܹ¥»÷µÄ·þÎñÆ÷£¬È«Çò·¶Î§ÄÚÒÑÓÐÖÁÉÙÊ®¸ö×éÖ¯Êܵ½Ó°Ïì¡£
https://www.bleepingcomputer.com/news/security/new-cleo-zero-day-rce-flaw-exploited-in-data-theft-attacks/
2. AppLite Banker¶ñÒâÈí¼þÒÔÒøÐÐÓ¦Ó÷¨Ê½ÎªÄ¿±êÌᳫÍøÂçµöÓã»î¶¯
12ÔÂ10ÈÕ£¬Ò»³¡ÅÓ´óµÄÍøÂçµöÓã»î¶¯ÕýÔÚÁ÷´«ÃûΪAppLite BankerµÄжñÒâÈí¼þ±äÖÖ£¬¸Ã¶ñÒâÈí¼þ±»Ê¶±ðΪAntidotÒøÐÐľÂíµÄ¸üа汾£¬Ö÷ÒªÕë¶ÔAndroidÉ豸¡£¹¥»÷Õßͨ¹ýð³äÖªÃû¹«Ë¾ÕÐƸÈËÔ±»òÈËÁ¦×ÊÔ´´ú±í£¬·¢ËÍÍøÂçµöÓãµç×ÓÓʼþÒýµ¼Óû§ÏÂÔØÆÛÕ©ÐÔCRMÓ¦Ó÷¨Ê½£¬½ø¶ø°²×°AppLite¶ñÒâÈí¼þ¡£¸Ã¶ñÒâÈí¼þÄÜÖ´ÐÐƾ֤͵ÇÔ¡¢ÀÄÓÃÎÞÕÏ°·þÎñ¡¢Ô¶³Ì¿ØÖÆ¡¢ÆÛÆÐÔÁýÕֵȶàÖÖ¶ñÒâ»î¶¯£¬²¢Õë¶Ô172¸öÓ¦Ó÷¨Ê½£¬°üÂÞ½ðÈÚƽ̨ºÍ¼ÓÃÜÇ®°ü¡£ÎªÈƹý¼ì²â£¬AppLiteʹÓÃZIPÎļþ²Ù×÷ºÍǶÈëHTMLÁýÕÖ²ã»ìÏýÄþ¾²¹¤¾ß¡£¸Ã¶ñÒâÈí¼þ¹¥»÷·¶Î§¹ã·º£¬Éæ¼°¶àÖÖÓïÑÔÓû§£¬²¢ÄÜÇÔÈ¡ËøÆÁƾ֤×Ô¶¯½âËøÆÁÄ»£¬ÊµÏÖÍêÈ«¿ØÖÆÊÜѬȾÉ豸¡£Äþ¾²Ñо¿ÈËԱǿµ÷Ö÷¶¯·ÀÓùÖØÒªÐÔ£¬½¨Òéʵʩǿ´óµÄÒƶ¯É豸¹ÜÀíÕþ²ß²¢¶¨ÆÚ¸üÐÂÉ豸ºÍÄþ¾²Èí¼þÒÔ·À·¶´ËÀàÍþв¡£
https://www.infosecurity-magazine.com/news/applite-malware-targets-banking/
3. Microsoft 365Öжϵ¼Ö Office WebÓ¦Ó÷¨Ê½ºÍ¹ÜÀíÖÐÐÄ̱»¾
12ÔÂ10ÈÕ£¬Î¢ÈíÕýÔÚÊÓ²ìÒ»ÆðÓ°ÏìOffice WebÓ¦ÓúÍMicrosoft 365¹ÜÀíÖÐÐĵĴóÃæ»ýÇÒÁ¬ÐøµÄMicrosoft 365ÖжÏʼþ¡£Óû§³ÂËßÔÚÁ¬½ÓOutlook¡¢OneDriveºÍÆäËûOffice 365Ó¦Ó÷¨Ê½ºÍ·þÎñʱ·ºÆðÎÊÌ⣬²¢ÊÕµ½·þÎñÖжϵÄÏûÏ¢¡£Î¢ÈíÖ¸³ö£¬ÎÊÌâ¿ÉÄÜÓëÉí·ÝÑéÖ¤»ù´¡ÉèÊ©ÖеÄÁîÅÆÉú³ÉÓйأ¬²¢ÕýÔÚÉó²é×î½üµÄ±ä»¯ÒÔÈ·¶¨»ù´¡ÔÒò¡£×÷Ϊ½â¾öÒªÁ죬΢Èí½¨ÒéÊÜÓ°ÏìµÄÓû§Ê¹ÓÃ×ÀÃæÓ¦Ó÷¨Ê½·ÃÎÊMicrosoft 365Ó¦Ó÷¨Ê½ºÍÎĵµ¡£´ËÇ°£¬Microsoft 365Ò²Ôø·¢Éú¹ýÈ«ÇòÖжÏʼþ£¬°üÂÞÓ°Ïì¶àÏî·þÎñºÍ¹¦Ð§µÄÇé¿ö¡£¶øÔÚ7Ô£¬Ò»´Î´ó¹æÄ£ÖжÏÔòÊÇÓÉÂþÑÜʽ¾Ü¾ø·þÎñ£¨DDoS£©¹¥»÷ÒýÆðµÄ¡£Ä¿Ç°£¬Î¢ÈíÕýÔÚ²âÊÔÒ»¸öDZÔÚµÄÐÞ¸´·¨Ê½£¬²¢ÒѲ¿ÊðÁËÒ»¸öÐÞ¸´·¨Ê½ÒÔ»º½âÖжÏÎÊÌ⡣΢ÈíÌåÏÖ£¬´Ë´ÎÖжÏÊÇÓÉÓÚ×î½üµÄ·þÎñ±ä»»µ¼ÖÂʶ±ðÁîÅƵ½ÆÚʱ¼ä·ºÆðÎÊÌ⣬´Ó¶øµ¼ÖÂÉí·ÝÑéÖ¤ÇëÇóʧ°Ü¡£¾¹ýÒ»¶Îʱ¼äµÄ¼à¿Ø·þÎñÒ£²âºó£¬¸Ã¹«Ë¾È·ÈϸÃÎÊÌâÏÖÒѽâ¾ö¡£
https://www.bleepingcomputer.com/news/microsoft/microsoft-365-outage-takes-down-office-web-apps-admin-center/
4. MetaÆìÏÂËÄ´óÉ罻ƽ̨ÔâÈ«Çò·¶Î§¹¥»÷Ö·þÎñÖжÏ
12ÔÂ11ÈÕ£¬È«Çò·¶Î§ÄÚµÄFacebook¡¢Instagram¡¢ThreadsºÍWhatsAppÔâÊÜÁËÑÏÖع¥»÷£¬µ¼Ö·þÎñÖжϣ¬²îÒìµØÓòµÄÓû§Êܵ½Á˲îÒìˮƽµÄÓ°Ïì¡£¾ÝDownDetector³Æ£¬ÖжϷ¢ÉúÔÚÃÀ¹ú¶«²¿Ê±¼äÏÂÎç12:40×óÓÒ£¬Ðí¶àÓû§ÎÞ·¨Í¨¹ýÍøÕ¾ºÍÓ¦Ó÷¨Ê½·ÃÎÊÕâЩ·þÎñ£¬Ò²ÎÞ·¨Í¨¹ýWhatsApp·¢ËÍÏûÏ¢¡£µ±Óû§ÊµÑé·ÃÎÊFacebookʱ£¬»áÊÕµ½´íÎóÌáʾ¡£ËäÈ»MetaµÄÒµÎñƽ̨״̬ҳÃæûÓÐÏÔʾ´ó¹æÄ£·þÎñÖжϣ¬µ«MetaÈÏ¿ÉÁËÖжϵķ¢Éú£¬²¢ÌåÏÖÕýÔÚŬÁ¦»Ö¸´·þÎñ¡£²¿ÃŵØÓòµÄ·þÎñÔÚÃÀ¹ú¶«²¿Ê±¼äÏÂÎç1:20×óÓÒ¿ªÊ¼»Ö¸´£¬µ«ÈÔÓÐÓû§³ÂËßÎÞ·¨·ÃÎÊƽ̨¡£´ËÇ°£¬MetaÔøÔÚ3Ô·ݺÍ2021ÄêÔâÓö¹ýÀàËƵķþÎñÖжϡ£½ØÖÁÃÀ¹ú¶«²¿Ê±¼ä12ÔÂ11ÈÕÏÂÎç7:21£¬MetaÌåÏÖÖжÏÎÊÌâÒÑ»ù±¾½â¾ö£¬²¢ÏòÊÜÓ°ÏìµÄÓû§ÌåÏÖǸÒâ¡£
https://www.bleepingcomputer.com/news/technology/facebook-instagram-whatsapp-hit-by-massive-worldwide-outage/
5. ¹ú¼ÊÐж¯¡°Operation PowerOFF¡±ÖØȹ¥»÷DDoS³ö×â·þÎñ
12ÔÂ11ÈÕ£¬¹ú¼ÊÐж¯¡°Operation PowerOFF¡±Õë¶ÔÍøÂç·¸×ïÖеÄÂþÑÜʽ¾Ü¾ø·þÎñ£¨DDoS£©¹¥»÷È¡µÃÁËÏÔÖø½á¹û¡£À´×Ô15¸ö¹ú¼ÒµÄÖ´·¨»ú¹¹ºÏ×÷£¬ÀÖ³ÉÏÂÏßÁË27¸öDDoS³ö×â·þÎñƽ̨£¬´þ²¶ÁËÈýÃû¹ÜÀíÔ±£¬²¢È·¶¨ÁËÕâЩƽ̨µÄ300Ãû¿Í»§¡£ÕâЩƽ̨ÀûÓý©Ê¬ÍøÂç¶ÔÔÚÏßÄ¿±êÌᳫ¹¥»÷£¬¿ÉÄܵ¼Ö·þÎñÖжϺÍÒµÎñËðʧ£¬ÌرðÊÇÔÚÍøÉϹºÎïá¯ÁëÆÚ¡£Å·ÖÞÐ̾¯×é֯е÷ÁË´Ë´ÎÐж¯£¬Éæ¼°¶à¸ö¹ú¼Ò£¬Õë¶Ô¼ÓÈë´ËÀà·¸×ïµÄ¸÷¸ö²ãÃæµÄÈËÔ±¡£ÆäÖУ¬ºÉÀ¼¾¯·½´þ²¶ÁËËÄÃûÉæÏÓʵʩDDoS¹¥»÷µÄÏÓÒÉÈË£¬²¢È·¶¨ÁËÔ¼200ÃûÉæÏÓʹÓñ»²é»ñDDoS·þÎñµÄºÉÀ¼ÈË¡£´Ë´ÎÐж¯µÄÀֳɵÃÒæÓÚÅ·ÖÞÐ̾¯×éÖ¯µÄ·ÖÎöÖ§³Ö¡¢¼ÓÃÜ×·×ÙÐÅÏ¢ÒÔ¼°ÁªºÏÍøÂç·¸×ïÐж¯ÌرðÊÂÇé×éר¼ÒµÄÐÖú¡£´ËÇ°£¬¡°Operation PowerOFF¡±ÒѶÔDDoS×âÁÞÁìÓò½øÐÐÁ˶à´Î¹¥»÷£¬°üÂÞ²é·â´óÐÍƽ̨Dstat.ccºÍÈëÇÖ²¢¹Ø±ÕDigitalStress·þÎñ¡£
https://www.bleepingcomputer.com/news/security/operation-poweroff-shuts-down-27-ddos-for-hire-platforms/
6. Krispy KremeÔâÍøÂç¹¥»÷£¬Ó°ÏìÔÚÏ߶©¹ººÍÔËÓª
12ÔÂ11ÈÕ£¬ÃÀ¹úÌðÌðȦÁ¬ËøµêKrispy KremeÔÚ2024Äê11ÔÂÔâÊÜÁËÍøÂç¹¥»÷£¬µ¼ÖÂÆäÔÚÃÀ¹úµÄÔÚÏ߶©¹ºÏµÍ³Öжϣ¬Ó°ÏìÁ˲¿ÃÅÒµÎñÔËÓª¡£¸Ã¹«Ë¾ÓµÓÐ1,521¼ÒÃŵêºÍÖÚ¶àÔ±¹¤£¬²¢ÓëÂóµ±À͵ȺÏ×÷»ï°éÓлý¼«¹Øϵ¡£Êý×Ö¶©µ¥Õ¼¹«Ë¾ÏúÊÛ¶îµÄ15.5%£¬¶Ô¹«Ë¾Òµ¼¨ÓÐÖØÒªÓ°Ïì¡£ÔÚ¹¥»÷·¢Éúºó£¬Krispy KremeÁ¢¼´Ñ°Ç󶥼âÍøÂçÄþ¾²×¨¼ÒµÄ×ÊÖú£¬²¢½ÓÄÉ´ëÊ©¿ØÖƺ͵÷ͣʼþ£¬µ«ÊÓ²ìÈÔÔÚ½øÐÐÖУ¬¾ßÌåÓ°ÏìÉдýÆÀ¹À¡£´Ë´Î¹¥»÷¶Ô¹«Ë¾µÄÒµÎñ·¢ÉúÁËÖØ´óÓ°Ï죬²¢½«Á¬Ðøµ½»Ö¸´Íê³ÉΪֹ¡£Í¬Ê±£¬¹«Ë¾Ô¤¼ÆÊý×ÖÏúÊÛÊÕÈëµÄËðʧ¡¢ÍøÂçÄþ¾²×¨¼ÒºÍÕÕÁϵÄÓöÈÒÔ¼°ÏµÍ³»Ö¸´ÊÂÇéÏà¹ØµÄ³É±¾½«·¢ÉúÖØ´óµÄ²ÆÕþÓ°Ïì¡£Êг¡¶Ô´ËÏûÏ¢×ö³öÁ˸ºÃæ·´Ó³£¬Krispy KremeµÄ¹É¼ÛϵøÁË2%¡£Ä¿Ç°Éв»Çå³þÕâÊÇÒ»´ÎÀÕË÷Èí¼þ¹¥»÷»¹ÊÇÆäËûÀàÐ͵Ĺ¥»÷£¬Ò²Ã»ÓÐÀÕË÷Èí¼þ×éÖ¯¶Ô´Ë´Î¹¥»÷ÂôÁ¦¡£
https://www.bleepingcomputer.com/news/security/krispy-kreme-cyberattack-impacts-online-orders-and-operations/