Èû¶ûάÑÇÕþ¸®ÀûÓøßͨÁãÈÕ©¶´²¿ÊðNoviSpy¼äµýÈí¼þ

Ðû²¼Ê±¼ä 2024-12-18

1. Èû¶ûάÑÇÕþ¸®ÀûÓøßͨÁãÈÕ©¶´²¿ÊðNoviSpy¼äµýÈí¼þ


12ÔÂ16ÈÕ £¬Èû¶ûάÑÇÕþ¸®±»ÆØÀûÓøßͨÁãÈÕ©¶´ £¬ÔÚAndroidÉ豸Éϲ¿ÊðÁËÒ»ÖÖÃûΪ¡°NoviSpy¡±µÄмäµýÈí¼þ £¬ÒÔ¼àÊÓ»î¸ÐÈËÊ¿¡¢¼ÇÕߺͿ¹ÒéÕß¡£´Ë´Î¹¥»÷Éæ¼°µÄ¸ßͨ©¶´CVE-2024-43047µÈ £¬ÔÚ2024Äê10Ô±»Google Project Zero±ê־ΪÁãÈÕ©¶´ £¬²¢ÓÚ´ÎÔÂÔÚAndroidÉϵõ½ÐÞ¸´¡£¹ú¼ÊÌØÉâ×éÖ¯Äþ¾²ÊµÑéÊÒÔÚ·ÖÎöÒ»Ãû¼ÇÕßµÄÊÖ»úʱ·¢ÏÖÁ˸üäµýÈí¼þ¡£¾Ý³Æ £¬Èû¶ûάÑÇÄþ¾²ÐÅÏ¢¾ÖºÍ¾¯·½ÀûÓÃCellebrite½âËø¹¤¾ß £¬Í¨¹ý¸ßͨÁãÈÕ©¶´½âËøÁËAndroidÊÖ»ú £¬²¢²¿ÊðÁËNoviSpy¡£¸Ã¼äµýÈí¼þÓëÈû¶ûάÑÇÄþ¾²»ú¹¹°ó¶¨µÄ·þÎñÆ÷ͨÐÅ £¬ÒÑ°²×°ÔÚÈû¶ûάÑÇÊýʮ̨ÉõÖÁÊý°Ų̀AndroidÉ豸ÉÏ¡£¹È¸èµÄÍþв·ÖÎöС×éÓë¹ú¼ÊÌØÉâ×éÖ¯ºÏ×÷ £¬·¢ÏÖÁ˸ßͨDSPÇý¶¯·¨Ê½ÖеĶà¸ö©¶´ £¬ÕâЩ©¶´¿ÉÄܱ»ÓÃÓÚÈƹýAndroidÄþ¾²»úÖƲ¢ÔÚÄں˼¶±ð°²×°NoviSpy¡£¾¡¹Ü¹È¸èÒÑÏò¸ßͨ³ÂËßÁËÕâЩÎÊÌâ £¬µ«²¿ÃÅ©¶´µÄ²¹¶¡ÉÐδÐû²¼¡£¸ßͨÌåÏÖ £¬ÒÑÏò¿Í»§ÌṩÐÞ¸´·¨Ê½ £¬²¢ÃãÀøÓû§Ó¦ÓÃÄþ¾²¸üС£


https://www.bleepingcomputer.com/news/security/new-android-novispy-spyware-linked-to-qualcomm-zero-day-bugs/


2. SRPÁª°îÐÅÓúÏ×÷ÉçÔâÍøÂç¹¥»÷ £¬24ÍòÓû§ÐÅÏ¢Òɱ»µÁ


12ÔÂ16ÈÕ £¬SRPÁª°îÐÅÓúÏ×÷Éç½üÈÕÔâÓöÍøÂç¹¥»÷ £¬Áè¼Ý240,742È˵ĸöÈËÐÅÏ¢¿ÉÄܱ»µÁ¡£SRPÁª°îÐÅÓúÏ×÷É罨Á¢ÓÚ1960Äê £¬×ܲ¿Î»ÓÚÄÏ¿¨ÂÞÀ´ÄÉÖݱ±°Â¹Å˹Ëþ £¬Îª×ôÖÎÑÇÖݺÍÄÏ¿¨ÂÞÀ´ÄÉÖÝÔ¼200,000Ãû¸öÈËÌṩ½ðÈÚ·þÎñ¡£¾Ý³Æ £¬¹¥»÷Õß×Ô2024Äê9ÔÂ5ÈÕÖÁ11ÔÂ4ÈÕÆÚ¼ä·ÃÎÊÁËÆäϵͳ £¬²¢¿ÉÄÜ»ñÈ¡ÁË°üÂÞÐÕÃû¡¢³öÉúÈÕÆÚ¡¢¼ÝÕÕºÅÂë¡¢Éç»á±£ÕϺÅÂëºÍ²ÆÕþÐÅÏ¢µÈÔÚÄڵĸöÈËÎļþ¡£SRPÁª°îÐÅÓúÏ×÷ÉçÒÑÏòµÂ¿ËÈø˹ÖݺÍÃåÒòÖݵÄ×ܼì²ì³¤°ì¹«ÊÒ³ÂËß´ËÊ £¬²¢Ïò¿ÉÄÜÊÜÓ°ÏìµÄ¸öÈË·¢ËÍÊéÃæ֪ͨ £¬ÌṩһÄêµÄÃâ·ÑÉí·Ý±£»¤·þÎñ¡£¾¡¹ÜÉÐδ·¢ÏÖÐÅÏ¢±»ÀÄÓõÄÖ¤¾Ý £¬µ«ºÏ×÷ÉçÃãÀøÊÜÓ°ÏìÕßÀûÓÃÌṩµÄÃâ·ÑÐÅÓüà¿Ø¡£´Ë´ÎÍøÂç¹¥»÷¿ÉÄÜÓëÀÕË÷Èí¼þ×éÖ¯NitrogenÓйØ £¬¸Ã×éÖ¯Éù³ÆÇÔÈ¡ÁËSRPÁª°îÐÅÓúÏ×÷ÉçÔ¼650GBµÄÊý¾Ý £¬²¢ÔÚÆä»ùÓÚTorµÄй©ÍøÕ¾ÉϳöÊÛ¡£


https://www.securityweek.com/srp-federal-credit-union-ransomware-attack-impacts-240000/


3. CISA¾¯¸æWindowsÄں˩¶´¼°Adobe ColdFusion©¶´Õý±»»ý¼«ÀûÓÃ


12ÔÂ16ÈÕ £¬CISAÒÑÏòÃÀ¹úÁª°î»ú¹¹·¢³ö¾¯¸æ £¬ÒªÇó·À·¶Õë¶Ô¸ßÑÏÖØÐÔWindowsÄں˩¶´CVE-2024-35250µÄÁ¬Ðø¹¥»÷¡£¸Ã©¶´ÓÉDEVCOREÑо¿ÍŶӷ¢ÏÖ²¢Í¨¹ýÇ÷ÊƿƼ¼µÄÁãÈռƻ®³ÂË߸ø΢Èí £¬ÊÇÓÉÓÚ²»ÊÜÐÅÈεÄÖ¸ÕëÈ¡ÏûÒýÓÃÈõµãÔì³ÉµÄ £¬ÔÊÐíµ±µØ¹¥»÷ÕßÒÔµÍÅÓ´ó¶È»ñµÃSYSTEMȨÏÞ¡£Î¢ÈíÔÚ6ÔÂÐû²¼Á˲¹¶¡ £¬µ«ËĸöÔºóGitHubÉÏÐû²¼ÁË¿´·¨Ñé֤©¶´´úÂë £¬±íÃ÷¸Ã©¶´ÕýÔÚ±»»ý¼«ÀûÓá£Í¬Ê± £¬CISA»¹Ìí¼ÓÁËÁíÒ»¸öÑÏÖصÄAdobe ColdFusion©¶´CVE-2024-20767 £¬¸Ã©¶´ÓÉÓÚ·ÃÎÊ¿ØÖƲ»Í×µ¼Ö £¬ÔÊÐíÔ¶³Ì¹¥»÷Õ߶ÁȡϵͳºÍÆäËûÃô¸ÐÎļþ¡£Áè¼Ý145,000̨ColdFusion·þÎñÆ÷̻¶ÔÚ»¥ÁªÍøÉÏ £¬×é³ÉÖØ´ó·çÏÕ¡£CISA½«ÕâÁ½¸ö©¶´Ìí¼Óµ½ÆäÒÑÖª±»ÀûÓ鶴Ŀ¼ÖÐ £¬²¢±ê־Ϊ±»»ý¼«ÀûÓà £¬ÒªÇóÁª°î»ú¹¹ÔÚÈýÖÜÄÚ±£»¤ÆäÍøÂ硣ͬʱ £¬Ò²½¨Òé˽ÈË×éÖ¯ÓÅÏÈ»º½âÕâЩ©¶´ÒÔ×èÖ¹ÕýÔÚ½øÐеĹ¥»÷¡£Î¢Èí¶ÔÓÚCVE-2024-35250Ò°ÍâÀûÓõĸü¶àÏêϸÐÅÏ¢ÉÐδ·¢±íÆÀÂÛ¡£


https://www.bleepingcomputer.com/news/security/windows-kernel-bug-now-exploited-in-attacks-to-gain-system-privileges/


4. BitterÍøÂç¼äµý×éÖ¯ÀûÓÃÐÂÐÍMiyaRAT¶ñÒâÈí¼þ¹¥»÷ÍÁ¶úÆä¹ú·À×éÖ¯


12ÔÂ17ÈÕ £¬ÍøÂç¼äµýÍþв×éÖ¯Bitter±»·¢ÏÖʹÓÃÐÂÐͶñÒâÈí¼þ¼Ò×åMiyaRAT¹¥»÷ÍÁ¶úÆä¹ú·À×éÖ¯¡£MiyaRATÓëBitter֮ǰʹÓõÄWmRAT¶ñÒâÈí¼þÒ»Æð±»²¿Êð¡£ProofpointÖ¸³ö £¬ÕâÖÖÐÂÐͶñÒâÈí¼þºÜ¿ÉÄÜÊÇÕë¶Ô¸ß¼ÛֵĿ±êµÄ £¬¶øÇÒ½öż¶û±»Ê¹Óá£Bitter×éÖ¯×Ô2013ÄêÒÔÀ´Ò»Ö±»îÔ¾ £¬Ö÷ÒªÕë¶ÔÑÇÖÞÕþ¸®ºÍÖØÒª×éÖ¯¡£ËûÃǹýÈ¥ÔøÀûÓÃMicrosoft Office©¶´ºÍð³äÍâ½»»ú¹¹½øÐÐÍøÂçµöÓã¹¥»÷¡£´Ë´ÎÍÁ¶úÆäµÄ¹¥»÷ʼÓÚÒ»·â°üÂÞÍâ¹úͶ×ÊÏîÄ¿ÓÕ»óµÄµç×ÓÓʼþ £¬ÓʼþÖеÄRARѹËõÎļþ°üÂÞÁËαװ³ÉPDFµÄ¿ì½Ý·½Ê½Îļþ £¬ÒÔ¼°Ç¶ÈëÔÚRARÎļþÖеı¸ÓÃÊý¾ÝÁ÷£¨ADS£©¡£Ò»µ©ÊÕ¼þÈË´ò¿ªLNKÎļþ £¬¾Í»á´¥·¢Òþ²ØÔÚADSÖеÄPowerShell´úÂëÖ´ÐÐ £¬Í¬Ê±´´½¨Ò»¸ö¼Æ»®ÈÎÎñÒÔ¶¨ÆÚÔËÐжñÒâÃüÁî¡£µ±WmRATÎÞ·¨ÓëÃüÁîºÍ¿ØÖÆ·þÎñÆ÷½¨Á¢Í¨ÐÅʱ £¬Bitter»áÏÂÔØMiyaRAT¡£ÕâÁ½ÖÖ¶ñÒâÈí¼þ¶¼ÊÇC++Ô¶³Ì·ÃÎÊľÂí£¨RAT£© £¬ÌṩÊý¾Ýй¶¡¢Ô¶³Ì¿ØÖÆ¡¢ÆÁÄ»½ØͼµÈ¹¦Ð§¡£MiyaRATÔ½·¢ÍêÉÆ £¬¾ßÓиüÏȽøµÄÊý¾ÝºÍͨÐżÓÃÜ¡£


https://www.bleepingcomputer.com/news/security/bitter-cyberspies-target-defense-orgs-with-new-miyarat-malware/


5. LedgerÍøÂçµöÓãÐÂÆ­¾Ö£ºÎ±×°Êý¾Ýй¶ÇÔÈ¡»Ö¸´¶ÌÓï


12ÔÂ17ÈÕ £¬Ò»ÏîÕë¶ÔLedgerÓ²¼þ¼ÓÃÜ»õ±ÒÇ®°üµÄÍøÂçµöÓã»î¶¯ÕýÔÚËÁÅ°¡£¸Ã»î¶¯Í¨¹ýαװ³ÉÊý¾Ýй¶֪ͨµÄÓʼþ £¬ÓÕÆ­Óû§ÑéÖ¤Æä»Ö¸´¶ÌÓï £¬½ø¶øÇÔÈ¡Óû§µÄ¼ÓÃÜ»õ±Ò¡£LedgerÊÇÒ»¿îÓÃÓÚ´æ´¢¡¢¹ÜÀíºÍ³öÊÛ¼ÓÃÜ»õ±ÒµÄÓ²¼þÇ®°ü £¬Æä×ʽðÓÉ24×Ö¡¢12×Ö»ò18×ֵĻָ´¶ÌÓï±£»¤¡£È»¶ø £¬¹¥»÷ÕßÀûÓÃÓû§¶ÔÊý¾Ýй¶µÄµ£ÓÇ £¬·¢ËÍ¿´ËÆÀ´×ÔLedger¹Ù·½µÄµöÓãÓʼþ £¬ÒªÇóÓû§ÔÚµöÓãÒ³ÃæÉÏÑéÖ¤»Ö¸´¶ÌÓï¡£ÕâЩÓʼþʵ¼ÊÉÏÊÇͨ¹ýSendGridµç×ÓÓʼþÓªÏúƽ̨·¢Ë͵Ä £¬µöÓãÒ³ÃæÔòαװ³ÉLedgerÍøÕ¾ £¬ÒªÇóÓû§ÊäÈë»Ö¸´¶ÌÓï½øÐÐÄþ¾²¼ì²é¡£Ò»µ©Óû§ÊäÈë £¬µöÓãÒ³Ãæ¾Í»á½«ËùÓÐÊäÈëµÄ»Ö¸´¶ÌÓï·¢Ë͵½ÍøÕ¾ºó¶Ë´æ´¢ £¬¹¥»÷Õß±ãÄÜÍêÈ«·ÃÎʲ¢ÇÔÈ¡Óû§µÄ¼ÓÃÜ»õ±Ò×ʽð¡£Õë¶Ô´Ë»î¶¯ £¬Ledger³ÖÓÐÕßÓ¦Ìá¸ß¾¯Ìè £¬ÇÐÎðÔÚÈκÎÓ¦ÓûòÍøÕ¾ÉÏÊäÈë»Ö¸´¶ÌÓï¡£µ±Éæ¼°¼ÓÃÜ»õ±ÒºÍ½ðÈÚ×ʲúʱ £¬ÇëʼÖÕÔÚä¯ÀÀÆ÷ÖÐÊäÈëÒª·ÃÎʵÄÓòÃû¡£ÇëºöÂÔÈκÎÉù³ÆÀ´×ÔLedgerµÄµç×ÓÓʼþ £¬ÓÈÆäÊÇÉù³ÆÄúÊܵ½Êý¾Ýй¶ӰÏì»òÒªÇóÑéÖ¤»Ö¸´¶ÌÓïµÄÓʼþ¡£


https://www.bleepingcomputer.com/news/security/new-fake-ledger-data-breach-emails-try-to-steal-crypto-wallets/


6. ˼¿ÆÊý¾ÝÔâй¶£º2.9GBÊý¾ÝÔÚBreach ForumsÆعâ


12ÔÂ16ÈÕ £¬ºÚ¿ÍÔÚBreach ForumsÉÏй¶ÁËÊôÓÚ˼¿Æ¹«Ë¾µÄ2.9GBÊý¾Ý £¬ÕâÊÇ4.5TBÊý¾Ý¼¯µÄÒ»²¿ÃÅ¡£¾ÝºÚ¿ÍÉù³Æ £¬ÕâЩÊý¾ÝÊÇ˼¿ÆÔÚ2024Äê10ÔÂδ½øÐÐÈκÎÃÜÂë±£»¤»òÄþ¾²ÈÏÖ¤µÄÇé¿öÏÂ̻¶µÄ¡£´Ë´Îй¶Ê¼þÓÉÎÛÃûÕÑÖøµÄºÚ¿Í¼æÂÛ̳ËùÓÐÕßIntelBrokerÌᳫ £¬Ëû´ËÇ°ÔøÊÔͼ³öÊÛ°üÂÞÀ´×ÔVerizon¡¢AT&TºÍMicrosoftµÈ¹«Ë¾µÄÃô¸ÐÐÅÏ¢ÔÚÄÚµÄÊý¾Ý¼¯¡£Ë¼¿Æ¶Ô´ËÊÂ×÷³ö»ØÓ¦ £¬·ñÈÏÆäºËÐÄϵͳÊܵ½¹¥»÷ £¬²¢½«ÎÊÌâ¹é¾ÌÓÚÃæÏò¹«ÖÚµÄDevHub×ÊÔ´ÅäÖôíÎó¡£È»¶ø £¬IntelBroker¼á³ÖÈÏΪÆäÔÚ10ÔÂ18ÈÕ֮ǰ¶¼¿ÉÒÔ·ÃÎÊÕâЩÊý¾Ý £¬²¢ÌṩÁËÖ¤¾ÝÀ´Ö¤Ã÷ÆäÖ÷ÕÅ¡£Ð¹Â¶µÄÊý¾Ý°üÂÞ˼¿Æ¶à¸öÖØÒª²úÎïµÄÏà¹ØÐÅÏ¢ £¬ÈçCisco ISE¡¢Cisco SASE¡¢Cisco WebexµÈ¡£´ËÍâ £¬IntelBroker»¹Òò¶à´ÎÊý¾Ýй¶Ê¼þ¶ø×ÅÃû £¬°üÂÞÈëÇÖApple Inc.¡¢AMDÒÔ¼°Å·ÖÞÐ̾¯×éÖ¯µÈ¡£´Ë´Îй¶Ê¼þÔÙ´ÎÌáÐѸ÷×éÖ¯Òª±£³ÖÄþ¾²Êµ¼ù²¢±£»¤Ãô¸ÐÊý¾Ý £¬¶øÊ£ÓàµÄ4.5TBÊý¾Ý¼¯ÊÇ·ñ»á±»³öÊÛ¡¢Ð¹Â¶»ò½â¾öÈÔÓдýÊӲ졣


https://hackread.com/hackers-leak-partial-cisco-data-4-5tb-exposed-records/