Èû¶ûάÑÇÕþ¸®ÀûÓøßͨÁãÈÕ©¶´²¿ÊðNoviSpy¼äµýÈí¼þ
Ðû²¼Ê±¼ä 2024-12-181. Èû¶ûάÑÇÕþ¸®ÀûÓøßͨÁãÈÕ©¶´²¿ÊðNoviSpy¼äµýÈí¼þ
12ÔÂ16ÈÕ£¬Èû¶ûάÑÇÕþ¸®±»ÆØÀûÓøßͨÁãÈÕ©¶´£¬ÔÚAndroidÉ豸Éϲ¿ÊðÁËÒ»ÖÖÃûΪ¡°NoviSpy¡±µÄмäµýÈí¼þ£¬ÒÔ¼àÊÓ»î¸ÐÈËÊ¿¡¢¼ÇÕߺͿ¹ÒéÕß¡£´Ë´Î¹¥»÷Éæ¼°µÄ¸ßͨ©¶´CVE-2024-43047µÈ£¬ÔÚ2024Äê10Ô±»Google Project Zero±ê־ΪÁãÈÕ©¶´£¬²¢ÓÚ´ÎÔÂÔÚAndroidÉϵõ½ÐÞ¸´¡£¹ú¼ÊÌØÉâ×éÖ¯Äþ¾²ÊµÑéÊÒÔÚ·ÖÎöÒ»Ãû¼ÇÕßµÄÊÖ»úʱ·¢ÏÖÁ˸üäµýÈí¼þ¡£¾Ý³Æ£¬Èû¶ûάÑÇÄþ¾²ÐÅÏ¢¾ÖºÍ¾¯·½ÀûÓÃCellebrite½âËø¹¤¾ß£¬Í¨¹ý¸ßͨÁãÈÕ©¶´½âËøÁËAndroidÊÖ»ú£¬²¢²¿ÊðÁËNoviSpy¡£¸Ã¼äµýÈí¼þÓëÈû¶ûάÑÇÄþ¾²»ú¹¹°ó¶¨µÄ·þÎñÆ÷ͨÐÅ£¬ÒÑ°²×°ÔÚÈû¶ûάÑÇÊýʮ̨ÉõÖÁÊý°Ų̀AndroidÉ豸ÉÏ¡£¹È¸èµÄÍþв·ÖÎöС×éÓë¹ú¼ÊÌØÉâ×éÖ¯ºÏ×÷£¬·¢ÏÖÁ˸ßͨDSPÇý¶¯·¨Ê½ÖеĶà¸ö©¶´£¬ÕâЩ©¶´¿ÉÄܱ»ÓÃÓÚÈƹýAndroidÄþ¾²»úÖƲ¢ÔÚÄں˼¶±ð°²×°NoviSpy¡£¾¡¹Ü¹È¸èÒÑÏò¸ßͨ³ÂËßÁËÕâЩÎÊÌ⣬µ«²¿ÃÅ©¶´µÄ²¹¶¡ÉÐδÐû²¼¡£¸ßͨÌåÏÖ£¬ÒÑÏò¿Í»§ÌṩÐÞ¸´·¨Ê½£¬²¢ÃãÀøÓû§Ó¦ÓÃÄþ¾²¸üС£
https://www.bleepingcomputer.com/news/security/new-android-novispy-spyware-linked-to-qualcomm-zero-day-bugs/
2. SRPÁª°îÐÅÓúÏ×÷ÉçÔâÍøÂç¹¥»÷£¬24ÍòÓû§ÐÅÏ¢Òɱ»µÁ
12ÔÂ16ÈÕ£¬SRPÁª°îÐÅÓúÏ×÷Éç½üÈÕÔâÓöÍøÂç¹¥»÷£¬Áè¼Ý240,742È˵ĸöÈËÐÅÏ¢¿ÉÄܱ»µÁ¡£SRPÁª°îÐÅÓúÏ×÷É罨Á¢ÓÚ1960Ä꣬×ܲ¿Î»ÓÚÄÏ¿¨ÂÞÀ´ÄÉÖݱ±°Â¹Å˹Ëþ£¬Îª×ôÖÎÑÇÖݺÍÄÏ¿¨ÂÞÀ´ÄÉÖÝÔ¼200,000Ãû¸öÈËÌṩ½ðÈÚ·þÎñ¡£¾Ý³Æ£¬¹¥»÷Õß×Ô2024Äê9ÔÂ5ÈÕÖÁ11ÔÂ4ÈÕÆÚ¼ä·ÃÎÊÁËÆäϵͳ£¬²¢¿ÉÄÜ»ñÈ¡ÁË°üÂÞÐÕÃû¡¢³öÉúÈÕÆÚ¡¢¼ÝÕÕºÅÂë¡¢Éç»á±£ÕϺÅÂëºÍ²ÆÕþÐÅÏ¢µÈÔÚÄڵĸöÈËÎļþ¡£SRPÁª°îÐÅÓúÏ×÷ÉçÒÑÏòµÂ¿ËÈø˹ÖݺÍÃåÒòÖݵÄ×ܼì²ì³¤°ì¹«ÊÒ³ÂËß´ËÊ£¬²¢Ïò¿ÉÄÜÊÜÓ°ÏìµÄ¸öÈË·¢ËÍÊéÃæ֪ͨ£¬ÌṩһÄêµÄÃâ·ÑÉí·Ý±£»¤·þÎñ¡£¾¡¹ÜÉÐδ·¢ÏÖÐÅÏ¢±»ÀÄÓõÄÖ¤¾Ý£¬µ«ºÏ×÷ÉçÃãÀøÊÜÓ°ÏìÕßÀûÓÃÌṩµÄÃâ·ÑÐÅÓüà¿Ø¡£´Ë´ÎÍøÂç¹¥»÷¿ÉÄÜÓëÀÕË÷Èí¼þ×éÖ¯NitrogenÓйأ¬¸Ã×éÖ¯Éù³ÆÇÔÈ¡ÁËSRPÁª°îÐÅÓúÏ×÷ÉçÔ¼650GBµÄÊý¾Ý£¬²¢ÔÚÆä»ùÓÚTorµÄй©ÍøÕ¾ÉϳöÊÛ¡£
https://www.securityweek.com/srp-federal-credit-union-ransomware-attack-impacts-240000/
3. CISA¾¯¸æWindowsÄں˩¶´¼°Adobe ColdFusion©¶´Õý±»»ý¼«ÀûÓÃ
12ÔÂ16ÈÕ£¬CISAÒÑÏòÃÀ¹úÁª°î»ú¹¹·¢³ö¾¯¸æ£¬ÒªÇó·À·¶Õë¶Ô¸ßÑÏÖØÐÔWindowsÄں˩¶´CVE-2024-35250µÄÁ¬Ðø¹¥»÷¡£¸Ã©¶´ÓÉDEVCOREÑо¿ÍŶӷ¢ÏÖ²¢Í¨¹ýÇ÷ÊƿƼ¼µÄÁãÈռƻ®³ÂË߸ø΢Èí£¬ÊÇÓÉÓÚ²»ÊÜÐÅÈεÄÖ¸ÕëÈ¡ÏûÒýÓÃÈõµãÔì³ÉµÄ£¬ÔÊÐíµ±µØ¹¥»÷ÕßÒÔµÍÅÓ´ó¶È»ñµÃSYSTEMȨÏÞ¡£Î¢ÈíÔÚ6ÔÂÐû²¼Á˲¹¶¡£¬µ«ËĸöÔºóGitHubÉÏÐû²¼ÁË¿´·¨Ñé֤©¶´´úÂ룬±íÃ÷¸Ã©¶´ÕýÔÚ±»»ý¼«ÀûÓá£Í¬Ê±£¬CISA»¹Ìí¼ÓÁËÁíÒ»¸öÑÏÖصÄAdobe ColdFusion©¶´CVE-2024-20767£¬¸Ã©¶´ÓÉÓÚ·ÃÎÊ¿ØÖƲ»Í×µ¼Ö£¬ÔÊÐíÔ¶³Ì¹¥»÷Õ߶ÁȡϵͳºÍÆäËûÃô¸ÐÎļþ¡£Áè¼Ý145,000̨ColdFusion·þÎñÆ÷̻¶ÔÚ»¥ÁªÍøÉÏ£¬×é³ÉÖØ´ó·çÏÕ¡£CISA½«ÕâÁ½¸ö©¶´Ìí¼Óµ½ÆäÒÑÖª±»ÀûÓ鶴Ŀ¼ÖУ¬²¢±ê־Ϊ±»»ý¼«ÀûÓã¬ÒªÇóÁª°î»ú¹¹ÔÚÈýÖÜÄÚ±£»¤ÆäÍøÂ硣ͬʱ£¬Ò²½¨Òé˽ÈË×éÖ¯ÓÅÏÈ»º½âÕâЩ©¶´ÒÔ×èÖ¹ÕýÔÚ½øÐеĹ¥»÷¡£Î¢Èí¶ÔÓÚCVE-2024-35250Ò°ÍâÀûÓõĸü¶àÏêϸÐÅÏ¢ÉÐδ·¢±íÆÀÂÛ¡£
https://www.bleepingcomputer.com/news/security/windows-kernel-bug-now-exploited-in-attacks-to-gain-system-privileges/
4. BitterÍøÂç¼äµý×éÖ¯ÀûÓÃÐÂÐÍMiyaRAT¶ñÒâÈí¼þ¹¥»÷ÍÁ¶úÆä¹ú·À×éÖ¯
12ÔÂ17ÈÕ£¬ÍøÂç¼äµýÍþв×éÖ¯Bitter±»·¢ÏÖʹÓÃÐÂÐͶñÒâÈí¼þ¼Ò×åMiyaRAT¹¥»÷ÍÁ¶úÆä¹ú·À×éÖ¯¡£MiyaRATÓëBitter֮ǰʹÓõÄWmRAT¶ñÒâÈí¼þÒ»Æð±»²¿Êð¡£ProofpointÖ¸³ö£¬ÕâÖÖÐÂÐͶñÒâÈí¼þºÜ¿ÉÄÜÊÇÕë¶Ô¸ß¼ÛֵĿ±êµÄ£¬¶øÇÒ½öż¶û±»Ê¹Óá£Bitter×éÖ¯×Ô2013ÄêÒÔÀ´Ò»Ö±»îÔ¾£¬Ö÷ÒªÕë¶ÔÑÇÖÞÕþ¸®ºÍÖØÒª×éÖ¯¡£ËûÃǹýÈ¥ÔøÀûÓÃMicrosoft Office©¶´ºÍð³äÍâ½»»ú¹¹½øÐÐÍøÂçµöÓã¹¥»÷¡£´Ë´ÎÍÁ¶úÆäµÄ¹¥»÷ʼÓÚÒ»·â°üÂÞÍâ¹úͶ×ÊÏîÄ¿ÓÕ»óµÄµç×ÓÓʼþ£¬ÓʼþÖеÄRARѹËõÎļþ°üÂÞÁËαװ³ÉPDFµÄ¿ì½Ý·½Ê½Îļþ£¬ÒÔ¼°Ç¶ÈëÔÚRARÎļþÖеı¸ÓÃÊý¾ÝÁ÷£¨ADS£©¡£Ò»µ©ÊÕ¼þÈË´ò¿ªLNKÎļþ£¬¾Í»á´¥·¢Òþ²ØÔÚADSÖеÄPowerShell´úÂëÖ´ÐУ¬Í¬Ê±´´½¨Ò»¸ö¼Æ»®ÈÎÎñÒÔ¶¨ÆÚÔËÐжñÒâÃüÁî¡£µ±WmRATÎÞ·¨ÓëÃüÁîºÍ¿ØÖÆ·þÎñÆ÷½¨Á¢Í¨ÐÅʱ£¬Bitter»áÏÂÔØMiyaRAT¡£ÕâÁ½ÖÖ¶ñÒâÈí¼þ¶¼ÊÇC++Ô¶³Ì·ÃÎÊľÂí£¨RAT£©£¬ÌṩÊý¾Ýй¶¡¢Ô¶³Ì¿ØÖÆ¡¢ÆÁÄ»½ØͼµÈ¹¦Ð§¡£MiyaRATÔ½·¢ÍêÉÆ£¬¾ßÓиüÏȽøµÄÊý¾ÝºÍͨÐżÓÃÜ¡£
https://www.bleepingcomputer.com/news/security/bitter-cyberspies-target-defense-orgs-with-new-miyarat-malware/
5. LedgerÍøÂçµöÓãÐÂƾ֣ºÎ±×°Êý¾Ýй¶ÇÔÈ¡»Ö¸´¶ÌÓï
12ÔÂ17ÈÕ£¬Ò»ÏîÕë¶ÔLedgerÓ²¼þ¼ÓÃÜ»õ±ÒÇ®°üµÄÍøÂçµöÓã»î¶¯ÕýÔÚËÁÅ°¡£¸Ã»î¶¯Í¨¹ýαװ³ÉÊý¾Ýй¶֪ͨµÄÓʼþ£¬ÓÕÆÓû§ÑéÖ¤Æä»Ö¸´¶ÌÓ½ø¶øÇÔÈ¡Óû§µÄ¼ÓÃÜ»õ±Ò¡£LedgerÊÇÒ»¿îÓÃÓÚ´æ´¢¡¢¹ÜÀíºÍ³öÊÛ¼ÓÃÜ»õ±ÒµÄÓ²¼þÇ®°ü£¬Æä×ʽðÓÉ24×Ö¡¢12×Ö»ò18×ֵĻָ´¶ÌÓï±£»¤¡£È»¶ø£¬¹¥»÷ÕßÀûÓÃÓû§¶ÔÊý¾Ýй¶µÄµ£ÓÇ£¬·¢ËÍ¿´ËÆÀ´×ÔLedger¹Ù·½µÄµöÓãÓʼþ£¬ÒªÇóÓû§ÔÚµöÓãÒ³ÃæÉÏÑéÖ¤»Ö¸´¶ÌÓï¡£ÕâЩÓʼþʵ¼ÊÉÏÊÇͨ¹ýSendGridµç×ÓÓʼþÓªÏúƽ̨·¢Ë͵ģ¬µöÓãÒ³ÃæÔòαװ³ÉLedgerÍøÕ¾£¬ÒªÇóÓû§ÊäÈë»Ö¸´¶ÌÓï½øÐÐÄþ¾²¼ì²é¡£Ò»µ©Óû§ÊäÈ룬µöÓãÒ³Ãæ¾Í»á½«ËùÓÐÊäÈëµÄ»Ö¸´¶ÌÓï·¢Ë͵½ÍøÕ¾ºó¶Ë´æ´¢£¬¹¥»÷Õß±ãÄÜÍêÈ«·ÃÎʲ¢ÇÔÈ¡Óû§µÄ¼ÓÃÜ»õ±Ò×ʽð¡£Õë¶Ô´Ë»î¶¯£¬Ledger³ÖÓÐÕßÓ¦Ìá¸ß¾¯Ì裬ÇÐÎðÔÚÈκÎÓ¦ÓûòÍøÕ¾ÉÏÊäÈë»Ö¸´¶ÌÓï¡£µ±Éæ¼°¼ÓÃÜ»õ±ÒºÍ½ðÈÚ×ʲúʱ£¬ÇëʼÖÕÔÚä¯ÀÀÆ÷ÖÐÊäÈëÒª·ÃÎʵÄÓòÃû¡£ÇëºöÂÔÈκÎÉù³ÆÀ´×ÔLedgerµÄµç×ÓÓʼþ£¬ÓÈÆäÊÇÉù³ÆÄúÊܵ½Êý¾Ýй¶ӰÏì»òÒªÇóÑéÖ¤»Ö¸´¶ÌÓïµÄÓʼþ¡£
https://www.bleepingcomputer.com/news/security/new-fake-ledger-data-breach-emails-try-to-steal-crypto-wallets/
6. ˼¿ÆÊý¾ÝÔâй¶£º2.9GBÊý¾ÝÔÚBreach ForumsÆعâ
12ÔÂ16ÈÕ£¬ºÚ¿ÍÔÚBreach ForumsÉÏй¶ÁËÊôÓÚ˼¿Æ¹«Ë¾µÄ2.9GBÊý¾Ý£¬ÕâÊÇ4.5TBÊý¾Ý¼¯µÄÒ»²¿ÃÅ¡£¾ÝºÚ¿ÍÉù³Æ£¬ÕâЩÊý¾ÝÊÇ˼¿ÆÔÚ2024Äê10ÔÂδ½øÐÐÈκÎÃÜÂë±£»¤»òÄþ¾²ÈÏÖ¤µÄÇé¿öÏÂ̻¶µÄ¡£´Ë´Îй¶Ê¼þÓÉÎÛÃûÕÑÖøµÄºÚ¿Í¼æÂÛ̳ËùÓÐÕßIntelBrokerÌᳫ£¬Ëû´ËÇ°ÔøÊÔͼ³öÊÛ°üÂÞÀ´×ÔVerizon¡¢AT&TºÍMicrosoftµÈ¹«Ë¾µÄÃô¸ÐÐÅÏ¢ÔÚÄÚµÄÊý¾Ý¼¯¡£Ë¼¿Æ¶Ô´ËÊÂ×÷³ö»ØÓ¦£¬·ñÈÏÆäºËÐÄϵͳÊܵ½¹¥»÷£¬²¢½«ÎÊÌâ¹é¾ÌÓÚÃæÏò¹«ÖÚµÄDevHub×ÊÔ´ÅäÖôíÎó¡£È»¶ø£¬IntelBroker¼á³ÖÈÏΪÆäÔÚ10ÔÂ18ÈÕ֮ǰ¶¼¿ÉÒÔ·ÃÎÊÕâЩÊý¾Ý£¬²¢ÌṩÁËÖ¤¾ÝÀ´Ö¤Ã÷ÆäÖ÷ÕÅ¡£Ð¹Â¶µÄÊý¾Ý°üÂÞ˼¿Æ¶à¸öÖØÒª²úÎïµÄÏà¹ØÐÅÏ¢£¬ÈçCisco ISE¡¢Cisco SASE¡¢Cisco WebexµÈ¡£´ËÍ⣬IntelBroker»¹Òò¶à´ÎÊý¾Ýй¶Ê¼þ¶ø×ÅÃû£¬°üÂÞÈëÇÖApple Inc.¡¢AMDÒÔ¼°Å·ÖÞÐ̾¯×éÖ¯µÈ¡£´Ë´Îй¶Ê¼þÔÙ´ÎÌáÐѸ÷×éÖ¯Òª±£³ÖÄþ¾²Êµ¼ù²¢±£»¤Ãô¸ÐÊý¾Ý£¬¶øÊ£ÓàµÄ4.5TBÊý¾Ý¼¯ÊÇ·ñ»á±»³öÊÛ¡¢Ð¹Â¶»ò½â¾öÈÔÓдýÊӲ졣
https://hackread.com/hackers-leak-partial-cisco-data-4-5tb-exposed-records/