Ï£À°¹úÓÐÓÊÕþ¹«Ë¾ELTAÒòÔâµ½ÀÕË÷¹¥»÷ËùÓзþÎñÔÝÍ£

°ä²¼¹¦·ò 2022-03-25

Ï£À°¹úÓÐÓÊÕþ¹«Ë¾ELTAÒòÔâµ½ÀÕË÷¹¥»÷ËùÓзþÎñÔÝÍ£


¾ÝýÌå3ÔÂ22ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬Ï£À°¹úÓÐÓÊÕþ¹«Ë¾ELTAÔâµ½ÁËÀÕË÷¹¥»÷ ¡£¡£¡£¡£¡£ELTAÔÚÉÏÖÜÈÕ¼ì²âµ½°²È«ÊÂÎñ£¬£¬£¬£¬£¬£¬²¢Á¢¼´×ö³öÏìÓ¦²¢¶ÔÕû¸öÊý¾ÝÖÐÐĽøÐиôÀë ¡£¡£¡£¡£¡£¸Ã¹«Ë¾³Æ£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÀûÓÃÆäϵͳÖÐÒ»¸ö佨¸´µÄ·ì϶À´×°ÖöñÒâÈí¼þ£¬£¬£¬£¬£¬£¬¸Ã¶ñÒâÈí¼þͨ¹ýHTTPS·´Ïòshell½Ó¼û¹¤×÷Õ¾ ¡£¡£¡£¡£¡£Õâ´Î¹¥»÷µ¼Ö¸Ã×éÖ¯µÄ´ó²¿ÃÅϵͳ´¦ÓÚÀëÏß״̬£¬£¬£¬£¬£¬£¬ELTA²»ÄܽøÐÐÓʼġ¢Õ˵¥Ö§¸¶»ò´¦ÖýðÈÚÂòÂô¶©µ¥£¬£¬£¬£¬£¬£¬ÇÒÉÐδȷ¶¨ºÎʱ¿É¸´Ô­Õý³£ÔËÓª ¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/greeces-public-postal-service-offline-due-to-ransomware-attack/


AnonymousÍÅ»ïÐû³ÆÒÑÈëÇÖÈðʿȸ³²¼¯ÍŵÄÄÚÍø


ýÌå3ÔÂ22ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬ºÚ¿ÍÍÅ»ïAnonymousÐû³ÆÒÑÈëÇÖÁËÈðʿȸ³²¼¯ÍÅ£¨Nestl¨¨£©µÄÄÚÍø£¬£¬£¬£¬£¬£¬²¢ÇÔÈ¡ÁË10 GBµÄÃô¸ÐÊý¾Ý ¡£¡£¡£¡£¡£3ÔÂ21ÈÕ£¬£¬£¬£¬£¬£¬Anonymous°ä²¼ÍÆÎÄÏòȸ³²ÐûÕ½£¬£¬£¬£¬£¬£¬°µÊ¾½«¶ÔÆä½øÐÐÍøÂç¹¥»÷ ¡£¡£¡£¡£¡£3ÔÂ22ÈÕ£¬£¬£¬£¬£¬£¬¸ÃÍÅ»ï³ÆÒÑÇÔÈ¡¹«Ë¾Óʼþ¡¢ÃÜÂëºÍóÒ׿ͻ§ÓйصÄÊý¾Ý£¬£¬£¬£¬£¬£¬²¢¹«¿ªÁËȸ³²µÄ5Íò¸öÆóÒµ¿Í»§µÄÊý¾Ý ¡£¡£¡£¡£¡£Ö®ºó£¬£¬£¬£¬£¬£¬È¸³²·ñ¶¨ÆäÔâµ½Á˹¥»÷£¬£¬£¬£¬£¬£¬²¢³ÆÐ¹Â¶Êý¾ÝÀ´×Ô½ñÄê2Ô·ݣ¬£¬£¬£¬£¬£¬ÆäʱһЩB2BÐÔÖʵIJâÊÔÊý¾ÝÎÞÒâÖÐÔÚij¸öóÒײâÊÔÍøÕ¾ÉϽӼû ¡£¡£¡£¡£¡£


https://therecord.media/nestle-denies-cyberattack-says-stolen-data-came-from-business-test-website/


Okta³ÆÆäÔâµ½LAPSUS$µÄ¹¥»÷£¬£¬£¬£¬£¬£¬½ü2.5%¿Í»§ÊÜÓ°Ïì


¾Ý3ÔÂ22ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬½Ó¼ûÖÎÀíϵͳ¹©¸øÉÌOkta°µÊ¾£¬£¬£¬£¬£¬£¬Ô¼2.5%µÄ¿Í»§Êܵ½ÀÕË÷ÍÅ»ïLapsus$µÄ¹¥»÷µÄÓ°Ïì ¡£¡£¡£¡£¡£Okta֤ʵ£¬£¬£¬£¬£¬£¬ËûÃÇÔÚ1Ô·ݲúÉúÁËһ·°²È«ÊÂÎñ£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÔÚ1ÔÂ16ÈÕÖÁ21ÈÕÆÚ¼äÄڿɽӼûÆäÒ»ÃûÖ§³Ö¹¤³ÌʦµÄ±Ê¼Ç±¾µçÄÔ£¬£¬£¬£¬£¬£¬¸Ã±Ê¼Ç±¾¿ÉΪ¿Í»§³ÁÖÃÃÜÂë ¡£¡£¡£¡£¡£¶øLapsus$»ØÓ¦³Æ£¬£¬£¬£¬£¬£¬ËûÃDz¢Ã»ÓÐÈëÇÖOktaÔ±¹¤µÄ±Ê¼Ç±¾µçÄÔ£¬£¬£¬£¬£¬£¬¶øÊÇthin¿Í»§¶Ë ¡£¡£¡£¡£¡£²¢¶ÔOktaµÄÉêÃ÷Ìá³öÒìÒ飬£¬£¬£¬£¬£¬³ÆËûÃÇÒѵǼµ½³¬µÈÓû§£¬£¬£¬£¬£¬£¬²¢Äܹ»³ÁÖÃÔ¼95%µÄ¿Í»§µÄÃÜÂëºÍMFA ¡£¡£¡£¡£¡£


https://thehackernews.com/2022/03/microsoft-and-okta-confirm-breach-by.html


¶íÂÞ˹MiratorgÔâµ½ÀûÓÃBitLocker¼ÓÃܵÄÀÕË÷¹¥»÷


ýÌå3ÔÂ22ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬¶íÂÞ˹ÊÞÒ½ºÍÖ²Îï¼ìÒ߼ල»ú¹¹Rosselkhoznadzor²¼¸æ³Æ£¬£¬£¬£¬£¬£¬×ܲ¿Î»ÓÚĪ˹¿ÆµÄÈâÀà³ö²úÉÌMiratorg Agribusiness HoldingÔâµ½ÍøÂç¹¥»÷ ¡£¡£¡£¡£¡£¸Ã»ú¹¹³Æ£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÀûÓÃÁËWindowsµÄBitLocker¼ÓÃܹ«Ë¾Îļþ£¬£¬£¬£¬£¬£¬ÕâÄÚÈÝÉÏÊÇÀÕË÷¹¥»÷£¬£¬£¬£¬£¬£¬µ«¹¥»÷µÄÖ¸±êËÆºõÊǸã·ÛËé¶ø·Ç»ñÀû ¡£¡£¡£¡£¡£Í×ЭµãλÓÚVetIS£¬£¬£¬£¬£¬£¬Ò»¸ö¸ÃÁìÓòµÄ¹«Ë¾Ê¹ÓõĹú¶ÈÐÅϢϵͳ£¬£¬£¬£¬£¬£¬ÕâºÜ¿ÉÄÜÊÇÒ»´Î¹©¸øÁ´¹¥»÷ ¡£¡£¡£¡£¡£Miratorg°ä·¢ÉêÃ÷£¬£¬£¬£¬£¬£¬³ÆËüÒѾ­ÔÚÖÂÁ¦¸´Ô­Õý³£ÔËÓª ¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/top-russian-meat-producer-hit-with-windows-bitlocker-encryption-attack/


Censys³ÆDeadBoltÔÚÉÏÖÜÒÑϰȾÉÏǧ̨QNAP NASÉ豸


3ÔÂ21ÈÕ£¬£¬£¬£¬£¬£¬Censys°ä²¼»ã±¨³ÆQNAPÉ豸³ÉΪÐÂÒ»²¨DeadBoltÀÕË÷¹¥»÷µÄÖ¸±ê ¡£¡£¡£¡£¡£»ã±¨Ö¸³ö£¬£¬£¬£¬£¬£¬×îÐµĹ¥»÷ÆðÍ·ÓÚ3ÔÂ16ÈÕ£¬£¬£¬£¬£¬£¬Æäʱ×ܹ²373̨É豸±»Ï°È¾£¬£¬£¬£¬£¬£¬µ½3ÔÂ19ÈÕ¸ÃÊý¾ÝÉÏÉýµ½ÁË1146¸ö ¡£¡£¡£¡£¡£¾Ý×îб¨Â·³Æ£¬£¬£¬£¬£¬£¬3ÔÂ22ÈÕ½ü1500̨NASÉ豸Òѱ»Ï°È¾ ¡£¡£¡£¡£¡£Õâ´Î»î¶¯Óë½ñÄê1Ô·ݵĵÚÒ»ÂÖ¹¥»÷ÀàËÆ£¬£¬£¬£¬£¬£¬ÒÀÈ»ÊÇÀÕË÷0.03 BTCÊê½ð£¨Ô¼1277ÃÀÔª£© ¡£¡£¡£¡£¡£µÚÒ»ÂÖ¹¥»÷ÔÚ1ÔÂ26ÈÕ´ïµ½·åÖµ£¬£¬£¬£¬£¬£¬ÓÐ4988̨ϰȾDeadboltµÄQNAPÉ豸 ¡£¡£¡£¡£¡£1Ôµף¬£¬£¬£¬£¬£¬QNAP¶ÔÆäNASÉ豸½øÐÐÁËÇ¿Ôì¹Ì¼þ¸üÐÂÒÔÕмܴËÀ๥»÷ ¡£¡£¡£¡£¡£


https://securityaffairs.co/wordpress/129373/malware/qnap-nas-deadbolt-ransomware.html


ESET·¢ÏÖMustang PandaÀûÓÃеÄHodurµÄ¹¥»÷»î¶¯


3ÔÂ23ÈÕ£¬£¬£¬£¬£¬£¬ESET°ä²¼Á˹ØÓÚAPT×éÖ¯Mustang Panda¹¥»÷»î¶¯µÄ·ÖÎö»ã±¨ ¡£¡£¡£¡£¡£Õâ´Î»î¶¯ÖØÒªÕë¶Ô¶«ÑǺͶ«ÄÏÑÇ£¬£¬£¬£¬£¬£¬ÒÔ¼°²¿ÃÅÅ·Ö޺ͷÇÖÞµØÓò£¬£¬£¬£¬£¬£¬ÒÑÖªµÄÖ¸±êÐÐ񵃾¼°×êÑлú¹¹¡¢»¥ÁªÍø·þÎñÌṩÉÌ(ISP)ºÍλÓÚ¶«ÑǺͶ«ÄÏÑǵÄÅ·ÖÞ±í½»Ê¹ÍÅ ¡£¡£¡£¡£¡£¹¥»÷»î¶¯×îÔçÄܹ»×·Òäµ½2021Äê8Ô£¬£¬£¬£¬£¬£¬Ê¹ÓÃÁËÓëÅ·ÖÞ×îÐÂʱÊÂÓйصĵö¶ü ¡£¡£¡£¡£¡£×îÖÕÖ¼ÔÚ×°ÖÃÒ»¸öÃûΪHodurµÄкóÃÅ£¬£¬£¬£¬£¬£¬ËüÓëÈ¥Äê7ÔÂÅû¶µÄPlugX£¨±ðÃûKorplug£©±äÌåTHORÀàËÆ ¡£¡£¡£¡£¡£


https://www.welivesecurity.com/2022/03/23/mustang-panda-hodur-old-tricks-new-korplug-variant/




°²È«¹¤¾ß


PSRansom


ÊÇÓµÓÐ C2 ·þÎñÆ÷Ö°ÄÜµÄ PowerShell ÀÕË÷Èí¼þÄ£ÄâÆ÷ ¡£¡£¡£¡£¡£


https://github.com/JoelGMSec/PSRansom


RDWA recon


ÓÃÓÚ´Ó Microsoft Ô¶³Ì×ÀÃæ Web ½Ó¼û (RDWA) ÀûÓ÷¨Ê½ÖÐÌáÊØÐÅÏ¢µÄ python ¾ç±¾ ¡£¡£¡£¡£¡£


https://github.com/p0dalirius/RDWArecon


Cloak


ÊÇÒ»Öֿɲå°Î´«Ê䣬£¬£¬£¬£¬£¬¿É¼ÓÇ¿ OpenVPN µÈ´«Í³´úÀí¹¤¾ß£¬£¬£¬£¬£¬£¬ÒÔ¶ã±Ü¸´ÔÓµÄÉó²éºÍÊý¾ÝÕç±ð ¡£¡£¡£¡£¡£


https://github.com/cbeuw/Cloak


Zscan


Intranet¶Ë¿ÚɨÃèÒÇ¡¢±¬ÆÆ¹¤¾ßºÍÆäËûʵÓ÷¨Ê½µÄ¿ªÔ´¼¯ÖÐ ¡£¡£¡£¡£¡£


https://github.com/zyylhn/zscan/




°²È«·ÖÎö


Windows 10 KB5011543 ¸üа䲼


https://www.bleepingcomputer.com/news/microsoft/windows-10-kb5011543-update-released-with-search-highlights-feature/


°×¹¬·ÖÏíÇåµ¥ÒÔÓ¦¶Ô¶íÂÞË¹ÍøÂç¹¥»÷


https://www.bleepingcomputer.com/news/security/white-house-shares-checklist-to-counter-russian-cyberattacks/


DEV-0537 Õë¶Ô×éÖ¯½øÐÐÊý¾Ýй¶ºÍ·ÛËéµÄ·¸×ï·Ö×Ó


https://www.microsoft.com/security/blog/2022/03/22/dev-0537-criminal-actor-targeting-organizations-for-data-exfiltration-and-destruction/


FIDO ÔÚÌáÒé¶Ô WebAuthn ½øÐе÷Õû


https://threatpost.com/fido-knife-murder-passwords/179031/


2022 ÄêÈõÃÜÂë»ã±¨¶Ô IT °²È«µÄÒâ˼µÄǰ 5¼þÊÂ


https://www.bleepingcomputer.com/news/security/the-top-5-things-the-2022-weak-password-report-means-for-it-security/