DARK ANGELS³Æ´ÓоƬÔì×÷ÉÌNEXPERIAÇÔÈ¡1TBÊý¾Ý

°ä²¼¹¦·ò 2024-04-18
1. DARK ANGELS³Æ´ÓоƬÔì×÷ÉÌNEXPERIAÇÔÈ¡1TBÊý¾Ý


4ÔÂ16ÈÕ£¬£¬£¬ £¬£¬Dark Angels (Dunghill) ÀÕË÷Èí¼þ×éÖ¯Ðû³Æ¶ÔÈëÇÖоƬÔì×÷ÉÌ Nexperia ²¢ÇÔÈ¡¸Ã¹«Ë¾ 1 TB Êý¾ÝÕÆ¹Ü¡£¡£¡£ ¡£¡£NexperiaÊÇÒ»¼Ò°ëµ¼ÌåÔì×÷ÉÌ£¬£¬£¬ £¬£¬×ܲ¿Î»ÓÚºÉÀ¼ÄÎ÷ºà¡£¡£¡£ ¡£¡£ËüÔڵ¹úºº±¤ºÍÓ¢¹ú´óÂü³¹Ë¹ÌØÉèÓÐǰ¶Ë¹¤³§¡£¡£¡£ ¡£¡£¸Ã¹«Ë¾µÄ²úÆ·ÁìÓòÔ̺¬Ë«¼«¾§Ìå¹Ü¡¢¶þ¼«¹Ü¡¢ESD ±£» £»£»£»£»£» £»£»¤¡¢TVS ¶þ¼«¹Ü¡¢MOSFET ºÍÂß¼­Æ÷¼þ¡£¡£¡£ ¡£¡£½ØÖÁ 2024 Ä꣬£¬£¬ £¬£¬¸ÃоƬÔì×÷ÉÌÕ¼ÓÐ 14000 ÃûÔ±¹¤¡£¡£¡£ ¡£¡£Dark Angels ÀÕË÷Èí¼þ×éÖ¯½« Nexperia Ôö³¤µ½Æä Tor Ð¹Â¶ÍøÕ¾µÄÊܺ¦ÕßÃûµ¥ÖÓ×£¡£¡£ ¡£¡£¸Ã×éÖ¯°ä²¼ÁËÒ»×éÎļþ×÷Ϊ°²È«·ì϶µÄÖ¤¾Ý£¬£¬£¬ £¬£¬²¢Íþв³Æ£¬£¬£¬ £¬£¬ÈôÊÇÊܺ¦Õß²»Ö§¸¶Êê½ð£¬£¬£¬ £¬£¬¾Í»áй¶ËùÓб»µÁÊý¾Ý¡£¡£¡£ ¡£¡£¸ÃоƬÔì×÷ÉÌ֤ʵ£¬£¬£¬ £¬£¬ËüÓÚ 2024 Äê 3 ÔÂÒâʶµ½Ä³Ð© Nexperia IT ·þÎñÆ÷Ô⵽δ¾­ÊÚȨµÄ½Ó¼û¡£¡£¡£ ¡£¡£ÎªÁËÓ¦¶ÔÕâÒ»ÊÂÎñ£¬£¬£¬ £¬£¬¸Ã¹«Ë¾½«ÊÜÓ°ÏìµÄϵͳÓ뻥ÁªÍø¶Ï¿ªÏνÓ£¬£¬£¬ £¬£¬ÒÔÔ¤·ÀÍþÐ²ÊæÕ¹¡£¡£¡£ ¡£¡£


https://securityaffairs.com/161888/cyber-crime/ransomware-dark-angels-nexperia.html


2. AWS¡¢Google ºÍ Azure CLI ¹¤¾ß¿ÉÄÜ»áй¶¹¹½¨ÈÕÖ¾ÖÐµÄÆ¾Ö¤


4ÔÂ16ÈÕ£¬£¬£¬ £¬£¬ÐµÄÍøÂ簲ȫ×êÑз¢ÏÖ£¬£¬£¬ £¬£¬À´×Ô Amazon Web Services (AWS) ºÍ Google Cloud µÄºÅÁîÐнçÃæ (CLI) ¹¤¾ß¿ÉÄܻᶳö¹¹½¨ÈÕÖ¾ÖеÄÃô¸ÐÍ´´¦£¬£¬£¬ £¬£¬´Ó¶ø¸ø×éÖ¯´øÀ´³Á´ó·çÏÕ¡£¡£¡£ ¡£¡£¸Ã·ì϶±»Ôư²È«¹«Ë¾ Orca¶¨ÃûΪLeakyCLI ¡£¡£¡£ ¡£¡£Azure CLI¡¢AWS CLI ºÍ Google Cloud CLI ÉϵÄһЩºÅÁîÄܹ»ÒÔ»·¾³±äÁ¿µÄ´ó¾Ö¶³öÃô¸ÐÐÅÏ¢£¬£¬£¬ £¬£¬ÕâЩÐÅÏ¢Äܹ»ÔÚͨ¹ý GitHub Actions µÈ¹¤¾ß°ä²¼Ê±±»¹¥»÷ÕßÍøÂç¡£¡£¡£ ¡£¡£¶ûºó£¬£¬£¬ £¬£¬Î¢ÈíÔÚ 2023 Äê 11 Ô°䲼µÄ°²È«¸üÐÂÖнâ¾öÁ˸ÃÎÊÌ⣬£¬£¬ £¬£¬²¢ÎªÆä·ÖÅäÁË CVE ±êʶ·û CVE-2023-36052£¨CVSS ÆÀ·Ö£º8.6£©¡£¡£¡£ ¡£¡£¼ò¶øÑÔÖ®£¬£¬£¬ £¬£¬Õâ¸öÉè·¨Óë CLI ºÅÁîÈôºÎÓÃÓÚÏÔʾ£¨Ô¤£©½ç˵µÄ»·¾³±äÁ¿ÒÔ¼°Êä³öµ½³ÖÐø¼¯³ÉºÍ³ÖÐø²¿Êð (CI/CD) ÈÕÖ¾Óйء£¡£¡£ ¡£¡£Orca °µÊ¾£¬£¬£¬ £¬£¬ËüÔÚ GitHub ÉÏ·¢ÏÖÁ˶à¸öÏîÄ¿£¬£¬£¬ £¬£¬ÕâЩÏîÄ¿ÎÞÒâÖÐͨ¹ý Github Actions¡¢CircleCI¡¢TravisCI ºÍ Cloud Build ÈÕ־й¶Á˽ӼûÁîÅÆºÍÆäËûÃô¸ÐÊý¾Ý¡£¡£¡£ ¡£¡£


https://thehackernews.com/2024/04/aws-google-and-azure-cli-tools-could.html


3. ½©Ê¬ÍøÂç³ÖÐøÀûÓà CVE-2023-1389 ½øÐдóÁìÓò´«²¼


4ÔÂ16ÈÕ£¬£¬£¬ £¬£¬ÔÚ2023ÄêºÅÁî×¢Èë·ì϶CVE-2023-1389±»Åû¶£¬£¬£¬ £¬£¬²¢Õë¶Ô TP-Link Archer AX21 (AX1800) µÄ Web ÖÎÀí½çÃæ¿ª·¢Á˽¨¸´·¨Ê½¡£¡£¡£ ¡£¡£FortiGuard Labs ¿ª·¢ÁË IPS ÊðÃûÀ´½â¾öÕâ¸öÎÊÌâ¡£¡£¡£ ¡£¡£×î½ü£¬£¬£¬ £¬£¬ÎÒÃǹ۲쵽Õë¶ÔÕâ¸öÒ»ÄêǰµÄ·ì϶µÄ¶àÆð¹¥»÷£¬£¬£¬ £¬£¬³Áµã¹Ø×¢ Moobot¡¢Miori¡¢»ùÓÚ Golang µÄ´úÀí¡°AGoent¡±ºÍ Gafgyt ±äÌåµÈ½©Ê¬ÍøÂç¡£¡£¡£ ¡£¡£ÕâÊÇͨ¹ý Web ÖÎÀí½çÃæÌṩµÄ¡°locale¡±API ÖÐδ¾­Éí·ÝÑéÖ¤µÄºÅÁî×¢Èë·ì϶¡£¡£¡£ ¡£¡£Gafgyt£¬£¬£¬ £¬£¬Ò²³ÆÎª BASHLITE£¬£¬£¬ £¬£¬ÊÇÒ»ÖÖϰȾ Linux ¼Ü¹¹²Ù×÷ϵͳÒÔÌáÒé DDoS£¨É¢²¼Ê½»Ø¾ø·þÎñ£©¹¥»÷µÄ¶ñÒâÈí¼þ¡£¡£¡£ ¡£¡£ÓëÆ½·²Ò»Ñù£¬£¬£¬ £¬£¬½©Ê¬ÍøÂç²»ÐݵضÔ×¼ÎïÁªÍø·ì϶£¬£¬£¬ £¬£¬²»Ðݳ¢ÊÔÀûÓÃËüÃÇ¡£¡£¡£ ¡£¡£Ö»¹ÜÈ¥Äê·¢ÏÖÁË·ì϶ CVE-2023-1389 ²¢ÌṩÁ˽¨¸´´ëÊ©£¬£¬£¬ £¬£¬µ«ÈÔÓкܶà»î¶¯ÀûÓø÷ì϶£¬£¬£¬ £¬£¬µ¼ÖÂ8827Ì«Ñô¼¯ÍÅ IPS Ò£²â´ïµ½ÏÔ×Å·åÖµ¡£¡£¡£ ¡£¡£Óû§Ó¦¾¯ÌèDDoS½©Ê¬ÍøÂ磬£¬£¬ £¬£¬²¢ÊµÊ±ÀûÓò¹¶¡ÒÔ±£» £»£»£»£»£» £»£»¤ÆäÍøÂç»·¾³ÃâÊÜϰȾ£¬£¬£¬ £¬£¬Ô¤·ÀÆä³ÉΪ¶ñÒâÍþвÕߵĻúеÈË¡£¡£¡£ ¡£¡£


https://www.fortinet.com/blog/threat-research/botnets-continue-exploiting-cve-2023-1389-for-wide-scale-spread


4. LightSpy ºÚ¿Í¶Ô×¼Ó¡¶ÈÆ»¹ûÉ豸Óû§ÇÔÈ¡Ãô¸ÐÊý¾Ý


4ÔÂ17ÈÕ£¬£¬£¬ £¬£¬ºÚ¿Í¶Ô׼ƻ¹ûÉ豸Óû§ÊÇÓÉÓÚËûÃDZ»ÒÔΪӵÓнϸߵÄÉç»á½×¼¶¡£¡£¡£ ¡£¡£Õâ»áµ¼ÖÂÖ¸±ê±ÈÆäËûÈ˸ü¸»ÓУ¬£¬£¬ £¬£¬²¢ÇÒ¿ÉÄÜÒÔijÖÖ·½Ê½ÏòºÚ¿ÍÌṩ¸ü¶à×ʽ𡣡£¡£ ¡£¡£³ý´ËÖ®±í£¬£¬£¬ £¬£¬Æ»¹ûµÄÉú̬ϵͳÊÇ»¥ÓйØÁªµÄ£¬£¬£¬ £¬£¬ÕâÒâζ×ÅËüÓжà¸öºÚ¿ÍÄܹ»½øÈëµÄµã£¬£¬£¬ £¬£¬´Ó¶øµ¼ÖÂÕÊ»§ºÍÉ豸Êܵ½ÇÖº¦¡£¡£¡£ ¡£¡£ºÚÝ®ÍøÂ簲ȫ×êÑÐÈËÔ±×î½ü·¢ÏÖ LightSpy ºÚ¿ÍÔÚ»ý¼«¶Ô×¼Ó¡¶ÈÆ»¹ûÉ豸Óû§ÇÔÈ¡Ãô¸ÐÊý¾Ý¡£¡£¡£ ¡£¡£LightSpy ÊÇÒ»¸öÄ£¿£¿£¿£¿£¿£¿é»¯¼äµý¹¤¾ß°ü£¬£¬£¬ £¬£¬Äܹ»ÇÔÈ¡Êܺ¦ÕßµÄÓ×ÎÒÐÅÏ¢£¬£¬£¬ £¬£¬ÀýÈçÏÖʵ GPS ×ø±ê»ò VOIP ͨ»°¡£¡£¡£ ¡£¡£ÕâÖÖеÄÍþвºÜΣÏÕ£¬£¬£¬ £¬£¬ÓÉÓÚËüÔÊÐíºÚ¿ÍÒÔ¼«¸ßµÄÕýÈ·¶È¸ú×ÙÖ¸±ê£¬£¬£¬ £¬£¬À©´óÕâÖÖ¿í·º¼à¶½¶ÔÕþÖÎÃô¸ÐµØÓò³ÛÃûÊܺ¦ÕßµÄDZÔÚÓ°Ïì¡£¡£¡£ ¡£¡£LightSpy ÓµÓÐ¿í·ºµÄ¼äµýÄÜÁ¦£¬£¬£¬ £¬£¬¿ÉÓÃÓÚ¼à¿ØÉ豸Êý¾Ý¡¢QQ ÐÂÎÅÄÚÈÝ¡¢Î¢ÐÅÐÂÎÅ¡¢Telegram ̸Ìì¼Í¼ºÍ΢ÐÅÖ§¸¶º¹Çà¼Í¼¡£¡£¡£ ¡£¡£


https://gbhackers.com/lightspy-hackers-target-indian-apple-users/


5. ˼¿ÆÖÒ¸æ VPN ºÍ SSH ·þÎñÃæ¶Ô´ó¹æÄ£±©Á¦¹¥»÷


4ÔÂ17ÈÕ£¬£¬£¬ £¬£¬Ë¼¿Æ Talos ×êÑÐÈËÔ±ÖÒ¸æ³Æ£¬£¬£¬ £¬£¬ÖÁÉÙ×Ô 2024 Äê 3 Ô 18 ÈÕÆð£¬£¬£¬ £¬£¬Õë¶Ô¶à¸öÖ¸±êµÄ´ó¹æÄ£Æ¾Ö¤±©Á¦¹¥»÷½«²»ÐݲúÉú£¬£¬£¬ £¬£¬ÆäÖÐÔ̺¬Ð鹹רÓÃÍøÂç (VPN) ·þÎñ¡¢Web ÀûÓ÷¨Ê½Éí·ÝÑéÖ¤½Ó¿ÚºÍ SSH ·þÎñ¡£¡£¡£ ¡£¡£  ÒÔÏÂÊÇÒÑÖªÊÜÓ°Ïì·þÎñµÄÁÐ±í£ºCisco Secure Firewall VPN Checkpoint VPN¡¢Fortinet VPN¡¢SonicWall VPN¡¢RD Web Services¡¢Miktrotik¡¢DraytekºÍUbiquiti¡£¡£¡£ ¡£¡£³É¹¦µÄ±©Á¦¹¥»÷¿ÉÄܻᵼÖÂδ¾­ÊÚȨµÄÍøÂç½Ó¼û¡¢ÕÊ»§Ëø¶¨»ò»Ø¾ø·þÎñ (DoS) Çé¿ö¡£¡£¡£ ¡£¡£ÕâЩ¹¥»÷Ô´×Ô TOR ³ö¿Ú½ÚµãÒÔ¼°ÄäÃûËí·ºÍ´úÀí£¬£¬£¬ £¬£¬ÀýÈ磺VPN Gate¡¢IPIDEA Proxy¡¢BigMama Proxy¡¢Space Proxies¡¢Nexus ProxyºÍProxy Rack¡£¡£¡£ ¡£¡£


https://securityaffairs.com/161943/hacking/brute-force-attacks.html


6. GOLD IONIC ÀÕË÷ÍÅ»ïµÄ¹¥»÷»î¶¯ÏÔÖøÉý¼¶


4ÔÂ16ÈÕ£¬£¬£¬ £¬£¬ÍøÂ簲ȫ×êÑÐÈËÔ¹ØýÔÚ×·×Ù GOLD IONIC ÀÕË÷Èí¼þ×éÖ¯µÄ»î¶¯ÏÔ×ÅÉý¼¶¡£¡£¡£ ¡£¡£×Ô 2023 Äê 8 Ô³öÏÖÒÔÀ´£¬£¬£¬ £¬£¬Õâ¸ö¼¤½øµÄÍþв×éÖ¯ÒÑѸËٶѼ¯ÁËÒ»·ÝÊܺ¦ÕßÃûµ¥¡£¡£¡£ ¡£¡£ËûÃǵĹ¥»÷Õë¶ÔÊÀ½ç¸÷µØµÄ×éÖ¯£¬£¬£¬ £¬£¬²¿Êð¶¨ÔìµÄ¡°INC¡±ÀÕË÷Èí¼þ£¬£¬£¬ £¬£¬¶Ô³ÁÒªÊý¾Ý½øÐмÓÃܲ¢½«Æä¿ÛΪÈËÖÊ¡£¡£¡£ ¡£¡£GOLD IONIC µÄ¹¥»÷²û·¢³öÆä²»·ÖÇàºìÔí°×µÄÐÔÖÊ£¬£¬£¬ £¬£¬Ó°Ïìן÷¸öÐÐÒµµÄÆóÒµºÍ×éÖ¯¡£¡£¡£ ¡£¡£È»¶ø£¬£¬£¬ £¬£¬ËûÃǵijÁµãËÆºõÊÇÃÀ¹úµÄÖ¸±ê£¬£¬£¬ £¬£¬ÆäÖй¤Òµ¡¢Ò½ÁƱ£½¡ºÍ½ÌÓý»ú¹¹Ôâ·êµÄ¹¥»÷ÊýÁ¿¹ý¶à¡£¡£¡£ ¡£¡£ÓÉÓÚÐÔÃüºÍ»¼ÕßÊý¾ÝÐü¶øÎ´¾ö£¬£¬£¬ £¬£¬Ò½ÁƱ£½¡ÐÐÒµÒѾ­Ãæ¶Ô×Ŷà¶àÌôÕ½£¬£¬£¬ £¬£¬»¹Ãæ¶Ô×ÅÀÕË÷Èí¼þµÄÑϳÁ·çÏÕ¡£¡£¡£ ¡£¡£½ÌÓý»ú¹¹¡¢Ãô¸ÐѧÉú¼Í¼ºÍ×êÑеÄÉú»îÕßÒ²·¢ÏÖ×Ô¼ºÔ½À´Ô½³ÉΪ¹¥»÷Ö¸±ê¡£¡£¡£ ¡£¡£


https://securityonline.info/inc-ransomware-surge-new-gold-ionic-group-hits-global-targets/