Microsoft °ä·¢ÔÚ Windows ÖÐÆúÓà 1024 λ RSA ÃÜÔ¿

°ä²¼¹¦·ò 2024-03-20
1. Microsoft °ä·¢ÔÚ Windows ÖÐÆúÓà 1024 λ RSA ÃÜÔ¿


3ÔÂ18ÈÕ£¬£¬£¬£¬£¬Microsoft °ä·¢£¬£¬£¬£¬£¬Windows ´«Êä²ã°²È« (TLS) Öн«ºÜ¿ìÆúÓöÌÓÚ 2048 λµÄ RSA ÃÜÔ¿£¬£¬£¬£¬£¬ÒÔÌṩ¸ü¸ßµÄ°²È«ÐÔ¡£¡£¡£¡£¡£¡£¡£¡£Rivest¨CShamir¨CAdleman (RSA) ÊÇÒ»ÖַǶԳƼÓÃÜϵͳ£¬£¬£¬£¬£¬ËüʹÓÃÒ»¶Ô¹«Ô¿ºÍ˽ԿÀ´¼ÓÃÜÊý¾Ý£¬£¬£¬£¬£¬ÆäÇ¿¶Å×ëÃÜÔ¿µÄ³¤¶ÈÖ±½ÓÓйØ¡£¡£¡£¡£¡£¡£¡£¡£ÕâЩÃÜÔ¿Ô½³¤ £¬£¬£¬£¬£¬¾ÍÔ½ÄÑÆÆ½â¡£¡£¡£¡£¡£¡£¡£¡£1024 λ RSA ÃÜÔ¿µÄÇ¿¶ÈԼΪ 80 룬£¬£¬£¬£¬¶ø 2048 λÃÜÔ¿µÄÇ¿¶ÈԼΪ 112 룬£¬£¬£¬£¬ÕâʹµÃºóÕߵķֻ¯¹¦·ò³¤ÁË 40 ÒÚ±¶¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÁìÓòµÄר¼ÒÒÔΪ 2048 λÃÜÔ¿ ÖÁÉÙÔÚ 2030 Äê֮ǰ¶¼Êǰ²È«µÄ¡£¡£¡£¡£¡£¡£¡£¡£RSA ÃÜÔ¿ÔÚ Windows ÖÐÓÃÓÚ¶àÖÖÓô¦£¬£¬£¬£¬£¬Ô̺¬·þÎñÆ÷Éí·ÝÑéÖ¤¡¢Êý¾Ý¼ÓÃܺÍÈ·±£Í¨Ñ¶µÄÆëÈ«ÐÔ¡£¡£¡£¡£¡£¡£¡£¡£Microsoft ¾ö¶¨½« TLS ·þÎñÆ÷Éí·ÝÑéÖ¤ÖÐʹÓõÄÖ¤ÊéµÄ RSA ÃÜÔ¿×îµÍÒªÇóÌá¸ßµ½ 2048 λ»ò¸ü³¤£¬£¬£¬£¬£¬Õâ¶ÔÓÚ±£»£»£» £»£»£»¤×éÖ¯ÃâÊÜÈõ¼ÓÃܵÄÓ°Ï켫¶È³ÁÒª¡£¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/microsoft/microsoft-announces-deprecation-of-1024-bit-rsa-keys-in-windows/


2. ¶ñÒâÈí¼þ»î¶¯ÀÄÓà Google ÍøÕ¾À´ÇÔÈ¡Êý¾Ý Azorult


3ÔÂ19ÈÕ£¬£¬£¬£¬£¬Netskope Íþв³¢ÊÔÊҵݲȫ×êÑÐÈËÔ±ÆØ¹âÁËÒ»¸ö¸´ÔӵĶñÒâÈí¼þ»î¶¯£¬£¬£¬£¬£¬¸Ã»î¶¯ÀûÓà Google ºÏ×÷ƽ̨µÄ¿ÉÐŶÈÀ´Ìṩ׳´óµÄа汾 Azorult ÐÅÏ¢ÇÔÈ¡·¨Ê½¡£¡£¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þÓÉÓÚÆäÌӱܼì²âºÍÇÔÈ¡¸÷ÀàÃô¸ÐÐÅÏ¢µÄÏȽøÄÜÁ¦¶ø×é³ÉÁ˳Á´óµÄÍøÂ簲ȫ·çÏÕ¡£¡£¡£¡£¡£¡£¡£¡£Azorult ÊÇÒ»¸ö¶ñÒⷨʽ£¬£¬£¬£¬£¬Ö¼ÔÚÇÔÈ¡ÄúµÄ¸öÈËÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£ËüµÄÖ¸±êÊÇÓû§Ãû¡¢ÃÜÂë¡¢ä¯ÀÀº¹Çà¼Í¼£¬£¬£¬£¬£¬ÉõÖÁ¼ÓÃÜÇ®±ÒÇ®°üÊý¾Ý¡£¡£¡£¡£¡£¡£¡£¡£Òź¶µÄÊÇ£¬£¬£¬£¬£¬Azorult ͵ÇÔ°¸¼þ³ÊÉÏÉýÇ÷Ïò£¬£¬£¬£¬£¬ÓÈÆäÊÇÔÚÒ½ÁƱ£½¡ÐÐÒµ¡£¡£¡£¡£¡£¡£¡£¡£Azorult ±»ÒÔΪÊÇ´ÓǰһÄêÖй¥»÷Ò½ÁƱ£½¡ÐÐÒµµÄ¶¥¼¶¶ñÒâÈí¼þ¼Ò×åÖ®Ò»¡£¡£¡£¡£¡£¡£¡£¡£È»¶ø£¬£¬£¬£¬£¬Æä×î½üµÄ»î¶¯½«Æäа¶ñ»î¶¯ÍÆÏòÁËеĸ߶È£¬£¬£¬£¬£¬Ñ¡È¡¶à·½ÃæµÄ²½ÖèÀ´´«µÝÆäÓÐЧ¸ºÔØ£¬£¬£¬£¬£¬Í¬Ê±Ìӱܼì²â¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷µÄ³õʼ½×¶ÎÉæ¼°HTML ×ß˽£¬£¬£¬£¬£¬ÕâÖÖ¼¼ÊõÔÚÍøÂç¹¥»÷ÕßÖÐÔ½À´Ô½Ê¢ÐС£¡£¡£¡£¡£¡£¡£¡£´Ë²½Öèͨ¹ýʹÓúϷ¨µÄ HTML5 Ö°ÄÜºÍ Javascript Ö±½ÓÔÚ¿Í»§¶Ë¹¹½¨¶ñÒâ¸ºÔØ£¬£¬£¬£¬£¬ÆæÃîµØÈÆ¹ýWeb ½ÚÔì¡£¡£¡£¡£¡£¡£¡£¡£ÆæÃîµÄÊÇ£¬£¬£¬£¬£¬¸Ã»î¶¯²¢Î´½«ÓÐЧ¸ºÔØÇ¶Èëµ½ Javascript ×ÔÉíÖУ¬£¬£¬£¬£¬¶øÊÇǶÈëµ½±í²¿Íйܵĵ¥¶À JSON ÎļþÖУ¬£¬£¬£¬£¬´Ó¶øÔö³¤Á˶î±íµÄÒþÃØ²ã¡£¡£¡£¡£¡£¡£¡£¡£


https://securityonline.info/sneaky-malware-campaign-abuses-google-sites-to-deliver-data-stealing-azorult/


3. Õë¶ÔÎÚ¿ËÀ¼µÄРLinux ¶ñÒâÈí¼þ±äÖÖAcidPour


3ÔÂ19ÈÕ£¬£¬£¬£¬£¬SentinelLabs µÄ×êÑÐÈËÔ±·¢ÏÖÁËËáÓê¶ñÒâÈí¼þµÄÒ»ÖÖбäÖÖ£¬£¬£¬£¬£¬³ÆÎª¡°Acid Pour¡±£¬£¬£¬£¬£¬ÒÑÔÚÎÚ¿ËÀ¼³öÏÖ¡£¡£¡£¡£¡£¡£¡£¡£ÕâÒ»·¢ÏÖÊÇÔÚÖÜÄ©ÓÉ SentinelLabs µÄ¸±×ܲà JA Guerrero-Saade ͨ¹ý X£¨ÒÔǰµÄ Twitter£©·ÖÏíµÄ¼û½âµÃ³öµÄ¡£¡£¡£¡£¡£¡£¡£¡£×î³õµÄ AcidRain ¶ñÒâÈí¼þÓÚ 2022 Äê 3 Ô³öÏÖ£¬£¬£¬£¬£¬³ö¸ñÊÇÔÚ¡°Viasat ºÚ¿Í¹¥»÷¡±ÆÚ¼äʹÓ㬣¬£¬£¬£¬¸ÃºÚ¿Í¹¥»÷ÔÚ¶íÂÞ˹ÈëÇÖÎÚ¿ËÀ¼ÆðͷʱÖжÏÁË KA-SAT Surfbeam2 µ÷Ôì½âµ÷Æ÷¡£¡£¡£¡£¡£¡£¡£¡£SentinelLabs µÄÊ×ϯÍþв×êÑÐÔ±TomHegel·¢ÏÖÁËרΪ Linux x86 É豸±àÒëµÄбäÌå¡£¡£¡£¡£¡£¡£¡£¡£¹ÌÈ» AcidPour Óë AcidRain ÔÚijЩ×Ö·û´®ÖÐÓµÓÐÀàËÆÖ®´¦£¬£¬£¬£¬£¬µ«ËüÔÚ´úÂë¿âÖдæÔÚÏÔ×Ųî¾à£¬£¬£¬£¬£¬´úÂë¿âÊÇÕë¶Ô x86 ¼Ü¹¹¶ø²»ÊÇ MIPS ±àÒëµÄ¡£¡£¡£¡£¡£¡£¡£¡£ÖµÍ×ÌùÐĵÄÊÇ£¬£¬£¬£¬£¬ºÏÓÃÓÚ x86 É豸µÄÊ¢ÐÐ Linux ¿¯ÐаæÔ̺¬ Ubuntu¡¢Mint¡¢Fedora ºÍ Debian¡£¡£¡£¡£¡£¡£¡£¡£ÁíÒ»·½Ã棬£¬£¬£¬£¬MIPS£¨ÎÞ»¥ËøÁ÷Ë®Ï߽׶εÄ΢´¦ÖÃÆ÷£©ÊÇÒ»ÖÖÖ¸Á¼Ü¹¹£¨ISA£©£¬£¬£¬£¬£¬ËüÐÔÖÊÉϽç˵ÁË´¦ÖÃÆ÷Àí½â²¢ÓÃÓÚÖ´ÐÐÖ¸ÁîµÄ˵»°¡£¡£¡£¡£¡£¡£¡£¡£Óë x86 ÀàËÆ£¬£¬£¬£¬£¬ËüÊÇÒ»×鹨ÓÚ´¦ÖÃÆ÷ÈôºÎÔËÐеĹ涨ºÍ¹æ·¶¡£¡£¡£¡£¡£¡£¡£¡£


https://www.hackread.com/acidrain-linux-malware-variant-acidpour-ukraine/#google_vignette


4. Ð嵀 DEEP#GOSU ¶ñÒâÈí¼þ»î¶¯ÀûÓø߼¶Õ½Êõ¶Ô×¼ Windows Óû§


3ÔÂ18ÈÕ£¬£¬£¬£¬£¬¸Ã¹¥»÷»î¶¯ÀûÓà PowerShell ºÍ VBScript ¶ñÒâÈí¼þÀ´Ï°È¾ Windows ϵͳ²¢»ñÈ¡Ãô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£ÍøÂ簲ȫ¹«Ë¾ Securonix ½«¸Ã»î¶¯³ÆÎª¡°DEEP#GOSU¡±£¬£¬£¬£¬£¬°µÊ¾¸Ã»î¶¯¿ÉÄÜÓ볯Ïʹú¶ÈÖ§³ÖµÄÃûΪKimsukyµÄ×éÖ¯ÓйØ¡£¡£¡£¡£¡£¡£¡£¡£DEEP#GOSUÖÐʹÓõĶñÒâÈí¼þÓÐЧ¸ºÔØ´ú±íÁËÒ»ÖÖ¸´ÔӵĶà½×¶ÎÍþв£¬£¬£¬£¬£¬Ö¼ÔÚÔÚ Windows ϵͳÉϰÂÃØÔËÐУ¬£¬£¬£¬£¬ÓÈÆäÊÇ´ÓÍøÂç¼à¿ØµÄ½Ç¶ÈÀ´¿´¡£¡£¡£¡£¡£¡£¡£¡£ËüµÄÖ°ÄÜÔ̺¬¼üÅ̼ͼ¡¢¼ôÌù°å¼à¿Ø¡¢¶¯Ì¬ÓÐЧ¸ºÔØÖ´ÐкÍÊý¾Ýй¶£¬£¬£¬£¬£¬ÒÔ¼°Ê¹Óà RAT Èí¼þ½øÐÐÆëȫԶ³Ì½Ó¼û¡¢´òË㹤×÷ÒÔ¼°Ê¹ÓÃ×÷Òµ×Ô¶¯Ö´ÐÐ PowerShell ¾ç±¾µÄÓÆ¾ÃÐÔ¡£¡£¡£¡£¡£¡£¡£¡£Ï°È¾¹ý³ÌµÄÒ»¸öÖµÍ×ÌùÐĵķ½ÃæÊÇ£¬£¬£¬£¬£¬ËüÀûÓà Dropbox »ò Google Docs µÈºÏ·¨·þÎñ½øÐкÅÁîºÍ½ÚÔì (C2)£¬£¬£¬£¬£¬´Ó¶øÔÊÐíÍþвÐÐΪÕßÔÚδ¼ì²âµ½µÄÇé¿öÏÂÈÚÈëͨÀýÍøÂçÁ÷Á¿¡£¡£¡£¡£¡£¡£¡£¡£


https://thehackernews.com/2024/03/new-deepgosu-malware-campaign-targets.html


5. ºÚ¿ÍÔÚÍøÂç¹¥»÷ÖÐʹÓñøÆ÷»¯ SVG Îļþ


3ÔÂ18ÈÕ£¬£¬£¬£¬£¬ÍøÂç·¸×ï·Ö×Ó³ÁÐÂÀûÓÿÉÀ©´óʸÁ¿Í¼ÐÎ (SVG) ÎļþÀ´´«²¼¶ñÒâÈí¼þ£¬£¬£¬£¬£¬ÕâÖÖ¼¼ÊõËæ×Å AutoSmuggle ¹¤¾ßµÄ³öÏÖ¶øµÃµ½ÁËÏÔ×Å·¢Õ¹¡£¡£¡£¡£¡£¡£¡£¡£AutoSmuggle ÓÚ 2022 Äê 5 ÔÂÍÆ³ö£¬£¬£¬£¬£¬ÓÐÖúÓÚÔÚ HTML »ò SVG ÄÚÈÝÖÐǶÈë¶ñÒâÎļþ£¬£¬£¬£¬£¬Ê¹¹¥»÷Õ߸üÈÝÒ×ÈÆ¹ý°²È«´ëÊ©¡£¡£¡£¡£¡£¡£¡£¡£ÀÄÓà SVG Îļþ´«²¼¶ñÒâÈí¼þµÄÇé¿öÄܹ»×·Òäµ½ 2015 Ä꣬£¬£¬£¬£¬ÀÕË÷Èí¼þÊÇ×îÏÈͨ¹ý´Ëý½é´«²¼µÄÀÕË÷Èí¼þÖ®Ò»¡£¡£¡£¡£¡£¡£¡£¡£2017 Äê 1 Ô£¬£¬£¬£¬£¬SVG Îļþ±»ÓÃÀ´Í¨¹ý URL ÏÂÔØ Ursnif ¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¡£¡£¡£2022 Äê²úÉúÁ˳Á´ó·ÉÔ¾£¬£¬£¬£¬£¬Æäʱ SVG ͨ¹ýǶÈëʽ .zip ´æµµ´«²¼QakBotµÈ¶ñÒâÈí¼þ£¬£¬£¬£¬£¬Õ¹Ê¾ÁË´Ó±íÊÖÏÂÔØµ½ HTML ×ß˽¼¼ÊõµÄת±ä¡£¡£¡£¡£¡£¡£¡£¡£2022 Äê AutoSmuggle ÔÚ GitHub Éϵİ䲼±ê־ȡһ¸öתÕ۵㡣¡£¡£¡£¡£¡£¡£¡£¸Ã¹¤¾ß½«¿ÉÖ´ÐÐÎļþ»ò´æµµÇ¶Èëµ½ SVG/HTML ÎļþÖУ¬£¬£¬£¬£¬¶øºóÔÚÊܺ¦Õß´ò¿ªÊ±½âÃܲ¢Ö´ÐС£¡£¡£¡£¡£¡£¡£¡£´Ë²½ÖèÆæÃîµØ±Ü¿ªÁËͨ³£»£»£» £»£»£»á¼ì²âºÍ¸ôÀëÖ±½Óµç×ÓÓʼþ¸½¼þµÄ°²È«µç×ÓÓʼþÍø¹Ø(SEG)¡£¡£¡£¡£¡£¡£¡£¡£


https://gbhackers.com/hackers-using-weaponized-svg-files-in-cyber-attacks/


6. Nissan Oceania ÒÑÈ·ÈÏÈ¥ÄêÔâ·êµÄÊý¾Ýй¶ӰÏìÔ¼ 10 ÍòÈË


3ÔÂ18ÈÕ£¬£¬£¬£¬£¬Nissan Oceania ÒÑÈ·ÈÏ 2023 Äê 12 ÔÂÔâ·êµÄÊý¾Ýй¶ӰÏìÁËÔ¼ 10 ÍòÈË£¬£¬£¬£¬£¬²¢ÒÑÆðÍ·ÏòËûÃÇ·¢³ö֪ͨ¡£¡£¡£¡£¡£¡£¡£¡££¬£¬£¬£¬£¬¸Ã¹«Ë¾£¨Ô̺¬ÈÕ²úÆû³µ¹«Ë¾ÒÔ¼°°Ä´óÀûÑǺÍÐÂÎ÷À¼µÄÈÕ²ú½ðÈÚ·þÎñ¹«Ë¾£©Ð¹Â©£¬£¬£¬£¬£¬Î´¾­ÊÚȨµÄµÚÈý·½½Ó¼ûÁËÆä±¾µØ IT ·þÎñÆ÷²¢µ¼ÖÂÍ£»£»£» £»£»£»ú¡£¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾Ö¸³ö£º¡°ÎÒÃÇÁ¢¼´²ÉÈ¡Ðж¯¶ôÔìÎ¥¹æÐÐΪ£¬£¬£¬£¬£¬²¢ÊµÊ±ÏòÓйص±¾Ö»ú¹¹·¢³ö¾¯±¨£¬£¬£¬£¬£¬Ô̺¬°Ä´óÀûÑǺÍÐÂÎ÷À¼¹ú¶ÈÍøÂ簲ȫÖÐÐĺÍÒþÖÔ¼à¹Ü»ú¹¹¡£¡£¡£¡£¡£¡£¡£¡£¡±Æäʱ£¬£¬£¬£¬£¬ËûÃÇÎÞ·¨È·ÈÏÊÂÎñµÄÑϳÁˮƽºÍÀàÐÍ£¬£¬£¬£¬£¬µ«¼¸Öܺ󣬣¬£¬£¬£¬Akira ÀÕË÷Èí¼þ×éÖ¯Ðû³Æ¶ÔÕâ´Î¹¥»÷ÕÆ¹Ü£¬£¬£¬£¬£¬²¢Ð¹Â¶Á˾ݳƴӸù«Ë¾ÇÔÈ¡µÄÊý¾Ý¡£¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾Ëæºó¶½´Ù¿Í»§×¢ÒâÒì³£»£»£» £»£»£»î¶¯ºÍ¿ÉÄܵÄÚ¿Æ­£¬£¬£¬£¬£¬Í¬Ê±Óëµ±¾Öµ±¾ÖºÍ±í²¿ÍøÂçȡ֤ר¼ÒºÏ×÷³ÖÐøµ÷²é¡£¡£¡£¡£¡£¡£¡£¡£


https://www.helpnetsecurity.com/2024/03/18/nissan-data-breach/