CLOROX ¹À¼Æ 8 Ô·ÝÍøÂç¹¥»÷Ôì³ÉµÄËðʧ½«³¬¹ý 4900 ÍòÃÀÔª

°ä²¼¹¦·ò 2024-02-05

1. CLOROX ¹À¼Æ 8 Ô·ÝÍøÂç¹¥»÷Ôì³ÉµÄËðʧ½«³¬¹ý 4900 ÍòÃÀÔª


2ÔÂ3ÈÕ£¬£¬£¬£¬£¬£¬Õâ¼ÒÇå½à²úÆ·¾ÞÍ· ÓÚ 8 ÔÂÖÐÑ®°ä·¢£¬£¬£¬£¬£¬£¬ËüÊÇÒ»´ÎÍøÂ簲ȫÊÂÎñµÄÊܺ¦Õß £¬£¬£¬£¬£¬£¬¸ÃÊÂÎñÆÈʹËü¹Ø¹ØÁËһЩϵͳ¡£¡£¡£¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬£¬¸ßÀÖÊÏÉÐδ·ÖÏíÍøÂç¹¥»÷µÄ¼¼Êõϸ½Ú¡£¡£¡£¡£¡£¡£¡£¡£ËùÃèÊöµÄÓ°ÏìÅú×¢¸Ã¹«Ë¾¿ÉÄÜÔâ·êÀÕË÷Èí¼þ¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£Æ¾¾ÝÏò SEC Ìá½»µÄÎļþ£¬£¬£¬£¬£¬£¬Clorox ¹À¼Æ 2023 Äê 8 ÔÂÏ®»÷¸Ã¹«Ë¾µÄÍøÂç¹¥»÷Ôì³ÉµÄ¾­¼ÃÓ°ÏìΪ 4900 ÍòÃÀÔª¡£¡£¡£¡£¡£¡£¡£¡£ÕâЩ³É±¾Ô̺¬ÖжÏÔì³ÉµÄËðʧ£¬£¬£¬£¬£¬£¬ÒÔ¼°Ð­Öú¹«Ë¾µ÷²éºÍ²¹¾È¹¥»÷µÄµÚÈý·½È¡Ö¤ºÍÕÕ·÷µÄÓöȡ£¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾»¹Ô¤¼Æ 2024 ²ÆÄêÒµ¼¨½«³öÏÖ¸ºÃæÓ°Ïì¡£¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾²¹³ä˵£¬£¬£¬£¬£¬£¬ÔÚ½ØÖÁ 2023 Äê 12 Ô 31 ÈÕµÄÈý¸öÔºÍÁù¸öÔÂÄÚ£¬£¬£¬£¬£¬£¬ËüûÓмͼÓëÍøÂç¹¥»÷ÓйصÄÈκα£ÏÕÊÕÒæ¡£¡£¡£¡£¡£¡£¡£¡£±£ÏÕÅâ³¥¼òÖ±ÈÏ£¨ÈôÊǺÏÓã©¿ÉÄÜÓëÈ·ÈÏÓйØÓöȵŦ·ò²»Ò»Ö¡£¡£¡£¡£¡£¡£¡£¡£


https://securityaffairs.com/158575/security/clorox-attack-costs-exceed-49m.html


2. AnyDesk Ôâµ½ºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬Æä³ö²ú·þÎñÆ÷ÃÜÂë±»³ÁÖÃ


2ÔÂ2ÈÕ£¬£¬£¬£¬£¬£¬AnyDesk ½ñÌì֤ʵ£¬£¬£¬£¬£¬£¬Ëü×î½üÔâ·êÁËÒ»´ÎÍøÂç¹¥»÷£¬£¬£¬£¬£¬£¬ºÚ¿ÍµÃÒÔ½Ó¼û¸Ã¹«Ë¾µÄ³ö²úϵͳ¡£¡£¡£¡£¡£¡£¡£¡£BleepingComputer »ñϤ£¬£¬£¬£¬£¬£¬Ô´´úÂëºÍ˽ÓдúÂëÊðÃûÃÜÔ¿ÔÚ¹¥»÷ÆÚ¼ä±»µÁ¡£¡£¡£¡£¡£¡£¡£¡£AnyDesk ÊÇÒ»ÖÖÔ¶³Ì½Ó¼û½â¾ö¹æ»®£¬£¬£¬£¬£¬£¬ÔÊÐíÓû§Í¨¹ýÍøÂç»ò»¥ÁªÍøÔ¶³Ì½Ó¼ûÍÆËã»ú¡£¡£¡£¡£¡£¡£¡£¡£¸Ã·¨Ê½¼«¶ÈÊÜÆóÒµ»¶Ó­£¬£¬£¬£¬£¬£¬ÆóҵʹÓÃËüÀ´ÌṩԶ³ÌÖ§³Ö»ò½Ó¼ûÍйܷþÎñÆ÷¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÈí¼þÔÚÍþвÐÐΪÕßÖÐÒ²ºÜÊÜ»¶Ó­£¬£¬£¬£¬£¬£¬ËûÃÇʹÓÃËüÀ´ ³ÖÐø½Ó¼ûÊÜ·ÛËéµÄÉ豸ºÍÍøÂç¡£¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾»ã±¨³ÆÕ¼ÓÐ 170,000 Ãû¿Í»§£¬£¬£¬£¬£¬£¬Ô̺¬ 7-11¡¢¿µ¿¨Ë¹ÌØ¡¢ÈýÐÇ¡¢ÂéÊ¡Àí¹¤Ñ§Ôº¡¢Ó¢Î°´ï¡¢Î÷ÃÅ×ӺͽáºÏ¹ú¡£¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/anydesk-says-hackers-breached-its-production-servers-reset-passwords/#google_vignette


3. Uber ±»ºÉÀ¼Êý¾Ý¼à¹Ü»ú¹¹·£¿£¿£¿£¿£¿£¿£¿î 1000 ÍòÅ·Ôª


2ÔÂ1ÈÕ£¬£¬£¬£¬£¬£¬ºÉÀ¼Êý¾Ý±£»£»£»£»£»£»£»¤»ú¹¹·¢ÏÖ Uber δÄܹ«¿ªÆä±£Áô˾»úÊý¾ÝµÄ¹¦·òÒÔ¼°ÄÄЩŷÖÞÒÔ±íµÄÔ±¹¤Äܹ»½Ó¼ûÕâЩÊý¾Ý£¬£¬£¬£¬£¬£¬Òò¶ø¸Ã»ú¹¹±ØÐëÏò Uber Ö§¸¶ 1000 ÍòÅ·ÔªµÄ·£¿£¿£¿£¿£¿£¿£¿î¡£¡£¡£¡£¡£¡£¡£¡£Õâ´Î·£¿£¿£¿£¿£¿£¿£¿îÊÇÆ¾¾Ý 172 Ãû·¨¹ú Uber ˾»úºÍ×ܲ¿Î»ÓÚ°ÍÀèµÄÃñ¼äÉç»á×éÖ¯ Ligue des Droits de l'Homme et du Citoyen (LDH) Ìá³öµÄͶËß¶ø²úÉúµÄ¡£¡£¡£¡£¡£¡£¡£¡£×î³õµÄͶËßÊÇÏò·¨¹úÊý¾Ý¼à¹Ü»ú¹¹Ìá³öµÄ£¬£¬£¬£¬£¬£¬µ«ÓÉÓڸù«Ë¾µÄÅ·ÖÞ×ܲ¿Î»ÓÚ°¢Ä·Ë¹Ìص¤£¬£¬£¬£¬£¬£¬Òò¶øºÉÀ¼¼à¹Ü»ú¹¹³Ðµ£Á˹ÜϽȨ¡£¡£¡£¡£¡£¡£¡£¡£ºÉÀ¼ÃÀÁªÉçÖ÷ϯ°¢À³µÂ¡¤ÎÖ¶û·òÉ­ (Aleid Wolfsen) °µÊ¾£º¡°Uber Óû§ÓÐȨ֪· Uber ÈôºÎ´¦ÖÃËûÃǵÄÊý¾Ý¡£¡£¡£¡£¡£¡£¡£¡£µ«ÊÇ£¬£¬£¬£¬£¬£¬Uber ²¢Ã»ÓжԴ˽øÐÐ×ã¹»Ç峺µÄÚ¹ÊÍ¡£¡£¡£¡£¡£¡£¡£¡£¡± ¡°ÕâÅú×¢ Uber ÉèÖÃÁ˸÷Àà×è°­£¬£¬£¬£¬£¬£¬×èÖ¹Óû§ÐÐʹÆäÒþÖÔȨ£¬£¬£¬£¬£¬£¬¶øÕâÊDZ»²»Èݵġ£¡£¡£¡£¡£¡£¡£¡£¡±


https://www.bankinfosecurity.com/uber-fined-10-million-euros-by-dutch-data-regulator-a-24250?&web_view=true


4. ¹ú¼ÊÐ̾¯×éÖ¯ Synergia Ðж¯·ÛËé 1300 ̨ÓÃÓÚ·¸×ïµÄ·þÎñÆ÷


2ÔÂ2ÈÕ£¬£¬£¬£¬£¬£¬´úºÅΪ¡°Synergia¡±µÄ¹ú¼Ê·¨ÂÉÐж¯ÒѹعØÁË 1,300 ¶à¸öÓÃÓÚÀÕË÷Èí¼þ¡¢ÍøÂç´¹µöºÍ¶ñÒâÈí¼þ»î¶¯µÄºÅÁîºÍ½ÚÔì·þÎñÆ÷¡£¡£¡£¡£¡£¡£¡£¡£ºÅÁîºÍ½ÚÔì·þÎñÆ÷ (C2) ÊÇÓÉÍþвÐÐΪÕß²Ù×÷µÄÉ豸£¬£¬£¬£¬£¬£¬ÓÃÓÚ½ÚÔì¹¥»÷ÖÐʹÓõĶñÒâÈí¼þ²¢ÍøÂç´ÓÊÜϰȾÉ豸·¢Ë͵ÄÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£ÕâЩ·þÎñÆ÷ÔÊÐíÍþвÐÐΪÕßÍÆËͶî±íµÄÓÐЧ¸ºÔØ»òºÅÁîÒÔÔÚÊÜϰȾµÄÉ豸ÉÏÖ´ÐУ¬£¬£¬£¬£¬£¬Ê¹ËüÃdzÉΪºÜ¶à¹¥»÷Öв»³É»òȱµÄ¼Ü¹¹¡£¡£¡£¡£¡£¡£¡£¡£¶ÔÓÚijЩ¶ñÒâÈí¼þ£¬£¬£¬£¬£¬£¬Ê¹ºÅÁîºÍ½ÚÔì·þÎñÆ÷ÍÑ»úÄܹ»Ô¤·À½øÒ»²½µÄ¶ñÒâ»î¶¯£¬£¬£¬£¬£¬£¬ÓÉÓÚÍþвÐÐΪÕßÎÞ·¨´ÓÊÜϰȾµÄÉ豸·¢ËÍ»ò½Ó¹ÜÊý¾Ý¡£¡£¡£¡£¡£¡£¡£¡£Synergia Ðж¯ÔÚ 2023 Äê 9 ÔÂÖÁ 11 ÔÂÆÚ¼ä¼ø±ð²¢¹Ø¹ØÁËÖ¸»ÓºÍ½ÚÔì·þÎñÆ÷£¬£¬£¬£¬£¬£¬À´×Ô 55 ¸ö¹ú¶ÈµÄ 60 ¸ö·¨ÂÉ»ú¹¹²Î¼ÓÁ˸ÃÐж¯¡£¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/legal/interpol-operation-synergia-takes-down-1-300-servers-used-for-cybercrime/


5.FritzFrog ½©Ê¬ÍøÂç¹¥»÷ Linux ·þÎñÆ÷ÇÔÈ¡ SSH ƾ֤


2ÔÂ2ÈÕ£¬£¬£¬£¬£¬£¬FritzFrog ½©Ê¬ÍøÂç×î³õÓÚ 2020 Äê±»·¢ÏÖ£¬£¬£¬£¬£¬£¬ÊÇÒ»ÖÖÓà Golang ¹¹½¨µÄ¸ß¼¶µã¶Ôµã½©Ê¬ÍøÂ磬£¬£¬£¬£¬£¬Äܹ»ÔÚ»ùÓÚ AMD ºÍ ARM µÄÉ豸ÉÏÔËÐÓ×£¡£¡£¡£¡£¡£¡£¡£Ëæ×Ų»ÐݵĸüУ¬£¬£¬£¬£¬£¬¶ñÒâÈí¼þËæ×Ź¦·òµÄÍÆÒÆ²»ÐÝ·¢Õ¹£¬£¬£¬£¬£¬£¬Ôö³¤ºÍ¼ÓÇ¿ÁËÖ°ÄÜ¡£¡£¡£¡£¡£¡£¡£¡£ÈËÃÇ·¢ÏÖÁË FritzFrog ½©Ê¬ÍøÂçµÄбäÖÖ£¬£¬£¬£¬£¬£¬ËüÀûÓÃLog4Shell ·ì϶À´Õë¶ÔÄÚ²¿ÍøÂçÖеÄËùÓÐÖ÷»ú¡£¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬Í¨¹ýʹÓÃÈõ SSH Í´´¦£¬£¬£¬£¬£¬£¬¶ñÒâÈí¼þ»á¹¥»÷¿Éͨ¹ý»¥ÁªÍø½Ó¼ûµÄ·þÎñÆ÷¡£¡£¡£¡£¡£¡£¡£¡£Akamai Óë¡¶ÍøÂ簲ȫÐÂÎÅ¡··ÖÏí·£º¡°½ÏеıäÌå´Ë¿Ì»á¶ÁÈ¡ÊÜϰȾÖ÷»úÉϵĶà¸öϵͳÎļþ£¬£¬£¬£¬£¬£¬ÒÔ¼ì²âºÜ¿ÉÄÜÈÝÒ×Êܵ½¹¥»÷µÄDZÔÚÖ¸±ê¡£¡£¡£¡£¡£¡£¡£¡£¡±FritzFrog ʹÓõÄΨһϰȾý½éÊÇ SSH±©Á¦ÆÆ½â£»£»£»£»£»£»£»È»¶ø£¬£¬£¬£¬£¬£¬¸Ã¶ñÒâÈí¼þµÄ×îа汾Ôö³¤ÁËÃûΪ¡°Frog4Shell¡±µÄ Log4Shell ·ì϶ÀûÓᣡ£¡£¡£¡£¡£¡£¡£ 


https://gbhackers.com/fritzfrog-botnet-linux-servers/


6. PurpleFox ¶ñÒâÈí¼þϰȾÎÚ¿ËÀ¼ÊýÇ§Ì¨ÍÆËã»ú


2ÔÂ1ÈÕ£¬£¬£¬£¬£¬£¬ÎÚ¿ËÀ¼ÍÆËã»ú´¹Î£ÏìÓ¦Ó××é (CERT-UA) ÖÒ¸æ³Æ£¬£¬£¬£¬£¬£¬PurpleFox ¶ñÒâÈí¼þ»î¶¯ÒÑϰȾ¸Ã¹úÖÁÉÙ 2,000 Ì¨ÍÆËã»ú¡£¡£¡£¡£¡£¡£¡£¡£ÕâÖÖ¿í·ºÏ°È¾¼òÖ±ÇÐÓ°ÏìÒÔ¼°ËüÊÇ·ñÓ°ÏìÁ˹ú¶È×éÖ¯»òͨ³£È˵ÄÍÆËã»úÉÐδȷ¶¨£¬£¬£¬£¬£¬£¬µ«¸Ã»ú¹¹ÒѾ­·ÖÏíÁËÓйØÈôºÎ¶¨Î»Ï°È¾ºÍɾ³ý¶ñÒâÈí¼þµÄ¾ßÌåÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£PurpleFox£¨»ò¡°DirtyMoe¡±£©ÊÇÒ»ÖÖ Ä£¿£¿£¿£¿£¿£¿£¿é»¯ Windows ½©Ê¬ÍøÂç¶ñÒâÈí¼þ £¬£¬£¬£¬£¬£¬ÓÚ 2018 Äê³õ´Î·¢ÏÖ£¬£¬£¬£¬£¬£¬´øÓÐ rootkit Ä£¿£¿£¿£¿£¿£¿£¿é£¬£¬£¬£¬£¬£¬ÔÊÐíÆäÔÚÉ豸³ÁÐÂÆô¶¯ÆÚ¼ä°µ²Ø²¢³ÖÐø´æÔÚ¡£¡£¡£¡£¡£¡£¡£¡£ËüÄܹ»ÓÃ×÷ÏÂÔØ·¨Ê½£¬£¬£¬£¬£¬£¬ÔÚÊÜϰȾµÄϵͳÉÏÒýÈë¸ü׳´óµÄµÚ¶þ½×¶ÎÓÐЧ¸ºÔØ£¬£¬£¬£¬£¬£¬ÎªÆäÔËÓªÉÌÌṩºóÃÅÖ°ÄÜ£¬£¬£¬£¬£¬£¬»¹Äܹ»³äÈÎÉ¢²¼Ê½»Ø¾ø·þÎñ£¨DDoS£©»úеÈË¡£¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/purplefox-malware-infects-thousands-of-computers-in-ukraine/?&web_view=true