¼ÓÖÝij¸£Àûƽ̨Ôâµ½¹¥»÷Êýǧ¸öÕË»§ÐÅϢй¶

°ä²¼¹¦·ò 2024-04-29
1. ¼ÓÖÝij¸£Àûƽ̨Ôâµ½¹¥»÷Êýǧ¸öÕË»§ÐÅϢй¶


4ÔÂ27ÈÕ£¬£¬ £¬£¬£¬£¬ÍþвÐÐΪÕßÈëÇÖÁ˼ÓÖÝÒ»¸öרÃÅÓÃÓÚ¸£ÀûÏîÖ÷ÕÅÆ½Ì¨É쵀 19000 ¶à¸öÔÚÏßÕÊ»§¡£¡£¡£¡£¡£¹ÙÔ±Ãǻ㱨³Æ£¬£¬ £¬£¬£¬£¬°²È«·ì϶²úÉúÔÚ 2 Ô 9 ÈÕ£¬£¬ £¬£¬£¬£¬ÆäʱÓÐÈ˵ǼÁËһЩ BenefitsCal Óû§µÄÕË»§¡£¡£¡£¡£¡£ÍþвÐÐΪÕßÀûÓôӵÚÈý·½ÍøÕ¾»ñµÃµÄ³Á¸´Ê¹ÓõÄÃÜÂë¡£¡£¡£¡£¡£BenefitsCal ÊÇÒ»¸öλÓÚ¼ÓÀû¸£ÄáÑÇÖݵÄÍøÂçÆ½Ì¨£¬£¬ £¬£¬£¬£¬Ê¹Óû§¿ÉÄÜÉêÇëºÍ¼à¶½Ò»ÏµÁи£Àû´òË㣬£¬ £¬£¬£¬£¬Ô̺¬Ê³Æ·È¯¡¢ÏÖ½ðÔöÔ®ºÍÒ½ÁƸ£Àû¡£¡£¡£¡£¡£Æ¾¾ÝÈÕÆÚй¶֪ͨ£¬£¬ £¬£¬£¬£¬Ç±ÔÚй¶µÄÐÅÏ¢¿ÉÄÜÔ̺¬Óû§ÐÕÃû¡¢µØÖ·¡¢µ®ÉúÈÕÆÚ¡¢Éç»á°²È«ºÅÂëµÄÆëÈ«»ò×îºóËÄλÊý×Ö¡¢µç×ÓÓʼþµØÖ·¡¢µç»°ºÅÂë¡¢EBT ¿¨ºÅ¡¢°¸¼þ±àºÅ¡¢Medi-Cal ID ºÅÒÔ¼°ÓÐ¹ØÆä´òËã×ʸñºÍ¸£ÀûµÄÐÅÏ¢¡£¡£¡£¡£¡£BenefitsCal ÔÚ֪ͨÊÜÓ°ÏìµÄÓû§²¢ÏòËûÃÇÌṩÄܹ»×öʲôµÄ×¢Ã÷¡£¡£¡£¡£¡£ÎªÁËÓ¦¶ÔÕâÒ»ÊÂÎñ£¬£¬ £¬£¬£¬£¬¸Ã»ú¹¹Í£ÓÃÁËÕË»§²¢Æô¶¯Á˵÷²é£¬£¬ £¬£¬£¬£¬Á˾ÖÏÔʾ¹¥»÷ÕßÔÚ 2023 Äê 3 Ô 1 ÈÕÖÁ 2024 Äê 2 Ô 13 ÈÕÆÚ¼äÕ¼ÓнӼûȨÏÞ¡£¡£¡£¡£¡£ 


https://securityaffairs.com/162408/data-breach/california-state-welfare-platform-accounts-compromise.html


2. Å·ÖÞÐ̾¯×éÖ¯°ä·¢ÔÚ·¨ÂÉÐж¯ÖÐÈ¡µÞLabHost


4ÔÂ26ÈÕ£¬£¬ £¬£¬£¬£¬Å·ÖÞÐ̾¯×éÖ¯°ä·¢£¬£¬ £¬£¬£¬£¬È«Çò×î´óµÄPhaasƽ̨֮һ LabHost ÔÚÈ«Çò·¨ÂÉÐж¯Öб»µ·»Ù¡£¡£¡£¡£¡£À´×Ô²»ÉÙÓÚ 19 ¸ö¹ú¶ÈÈ·µ±¾ÐÄÓÈëÁËÓÉÓ¢¹úÂ׶ؾ¯Ô±ÌüǣͷµÄΪÆÚÒ»ÄêµÄÐж¯£¬£¬ £¬£¬£¬£¬¿ÛÁôÁË 37 ÃûÏÓÒÉÈË£¬£¬ £¬£¬£¬£¬ÆäÖÐÔ̺¬¾Ý³ÆÓë¸Ã·þÎñÔËÓª¼°Æäԭʼ¿ª·¢ÓйصÄÈË¡£¡£¡£¡£¡£È«ÇòÔ¼ÓÐ 10000 ÈËʹÓø÷þÎñ£¬£¬ £¬£¬£¬£¬Ô·ѾùÔÈΪ 249 ÃÀÔª¡£¡£¡£¡£¡£µ÷²é·¢ÏÖÖÁÉÙ 40000 ¸öÓë LabHost Á´½ÓµÄÍøÂç´¹µöÓòÃû£¬£¬ £¬£¬£¬£¬²¢ÓÕÆ­Óû§½»³öÃô¸Ð¾ßÌåÐÅÏ¢¡£¡£¡£¡£¡£ÏàʶÓйØÊÓÆµÖеĴÌÍ´µÄ¸ü¶àÐÅÏ¢£¬£¬ £¬£¬£¬£¬²¢È·±£Äú֪·ÈôºÎÔ¤·À³ÉÎªÍøÂç´¹µö¹¥»÷µÄÊܺ¦Õß¡£¡£¡£¡£¡£ÔÚÆäËûÍøÂç·¸×ïÐÂÎÅÖУ¬£¬ £¬£¬£¬£¬ÃÀ¹ú·¨Âɲ¿ÃÅ¶Ô Samourai Wallet¼ÓÃÜÇ®±Ò»ìºÏ·þÎñµÄÊ×´´ÈËÌá³öϴǮָ¿Ø£¬£¬ £¬£¬£¬£¬Í¬Ê±Áª¹ú½ø¹¥´ËÀà·þÎñ¡£¡£¡£¡£¡£


https://www.welivesecurity.com/en/videos/major-phishing-as-a-service-platform-disrupted-week-security-tony-anscombe/


3. ×êÑÐÍŶӷ¢ÏÖʹÓÃoffice·ì϶Õë¶ÔÎÚ¿ËÀ¼µÄ¹¥»÷»î¶¯


4ÔÂ27ÈÕ£¬£¬ £¬£¬£¬£¬ÍøÂ簲ȫ×êÑÐÈËÔ±·¢ÏÖÁËÕë¶ÔÎÚ¿ËÀ¼µÄÒ»ÏîÓÐÕë¶ÔÐԵĹ¥»÷»î¶¯£¬£¬ £¬£¬£¬£¬¸ÃÐж¯ÀûÓÃÁË Microsoft Office ÖнüÆßÄêµÄij¸ö·ì϶£¬£¬ £¬£¬£¬£¬ÔÚÊÜϰȾµÄϵͳÉÏ´« Cobalt Strike¡£¡£¡£¡£¡£¾Ý Deep Instinct ³Æ£¬£¬ £¬£¬£¬£¬¸Ã¹¥»÷Á´²úÉúÓÚ 2023 Äêµ×£¬£¬ £¬£¬£¬£¬Ñ¡È¡ PowerPoint »ÃµÆÆ¬Îļþ£¨¡°signal-2023-12-20-160512.ppsx¡±£©×÷ΪÆðµã£¬£¬ £¬£¬£¬£¬ÎļþÃû°µÊ¾Ëü¿ÉÄÜÒÑͨ¹ý Signal ¼´Ê±Í¨Ñ¶ÀûÓ÷¨Ê½¹²Ïí¡£¡£¡£¡£¡£Ö»¹ÜÈç´Ë£¬£¬ £¬£¬£¬£¬Ã»ÓÐÏÖʵ֤¾ÝÅú×¢ PPSX ÎļþÊÇÒÔÕâÖÖ·½Ê½·Ö·¢µÄ£¬£¬ £¬£¬£¬£¬Ö»¹ÜÎÚ¿ËÀ¼ÍÆËã»ú´¹Î£ÏìÓ¦Ó××é (CERT-UA) ·¢ÏÖÁËÁ½¸öʹÓøÃÐÂÎÅÀûÓ÷¨Ê½×÷Ϊ¶ñÒâÈí¼þ´«µÝµÄ·ÖÆç»î¶¯´ÓǰµÄÏòÁ¿¡£¡£¡£¡£¡£ÕâÉæ¼°ÀûÓÃCVE-2017-8570£¨CVSS ·ÖÊý£º7.8£©£¬£¬ £¬£¬£¬£¬ÕâÊÇ Office ÖÐÏÖÒѽ¨²¹µÄÔ¶³Ì´úÂëÖ´ÐÐÃýÎ󣬣¬ £¬£¬£¬£¬¸ÃÃýÎó¿ÉÄÜÔÊÐí¹¥»÷ÕßÔÚ˵·þÊܺ¦Õß´ò¿ªÌØÔìÎļþ¡¢¼ÓÔØÔ¶³Ì¾ç±¾ÍйÜÔÚ weavesilk[.]space ÉÏ¡£¡£¡£¡£¡£


https://thehackernews.com/2024/04/ukraine-targeted-in-cyberattack.html


4. Okta ÖÒ¸æ¿Í»§¿ÉÄÜÔâ·êǰËùδÓеÄײ¿â¹¥»÷


4ÔÂ27ÈÕ£¬£¬ £¬£¬£¬£¬Okta ÖÒ¸æ³Æ£¬£¬ £¬£¬£¬£¬Õë¶ÔÆäÉí·ÝºÍ½Ó¼ûÖÎÀí½â¾ö¹æ»®µÄײ¿â¹¥»÷³öÏÖÁËǰËùδÓеļ¤Ôö¡£¡£¡£¡£¡£ÍþвÐÐΪÕßͨ¹ý×Ô¶¯³¢ÊÔͨ³£´ÓÍøÂç·¸×ï·Ö×ÓÄÇÀï²É°ìµÄÓû§ÃûºÍÃÜÂëÁбí£¬£¬ £¬£¬£¬£¬Ê¹ÓÃÆ¾Ö¤Ìî³äÀ´µÇ¼¡£¡£¡£¡£¡£Okta ÔÚ½ñÌìµÄÒ»·Ý²¼¸æÖаµÊ¾£¬£¬ £¬£¬£¬£¬ÕâЩ¹¥»÷ËÆºõÔ´×Ô Cisco Talos ֮ǰ»ã±¨µÄ±©Á¦ÆÆ½âºÍÃÜÂëÅçÉä¹¥»÷ÖÐʹÓõÄÒ»Ñù»ù´¡ÉèÊ©¡£¡£¡£¡£¡£ÔÚ Okta ¹Û²ìµ½µÄËùÓй¥»÷ÖУ¬£¬ £¬£¬£¬£¬ÒªÇó¾ùÀ´×Ô TOR ÄäÃûÍøÂçºÍ¸÷Ààסլ´úÀí£¨ÀýÈç NSOCKS¡¢Luminati ºÍ DataImpulse£©¡£¡£¡£¡£¡£Okta °µÊ¾£¬£¬ £¬£¬£¬£¬¼à²âµ½µÄ¹¥»÷Õë¶ÔÔÚ Okta Classic Engine ÉÏÔËÐÐÇÒ ThreatInsight ÅäÖÃΪ½öÉóºËģʽ¶ø²»ÊÇÈÕÖ¾ºÍÇ¿ÔìģʽµÄ×éÖ¯³ö¸ñÈÝÒס£¡£¡£¡£¡£Í¬Ñù£¬£¬ £¬£¬£¬£¬²»»Ø¾øÄäÃû´úÀí½Ó¼ûµÄ×éÖ¯Ò²¿´µ½Á˸ü¸ßµÄ¹¥»÷³É¹¦ÂÊ¡£¡£¡£¡£¡£Okta °µÊ¾£¬£¬ £¬£¬£¬£¬Ö»ÓÐÒ»Óײ¿Ãſͻ§µÄ¹¥»÷»ñµÃÁ˳ɹ¦¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/okta-warns-of-unprecedented-credential-stuffing-attacks-on-customers/


5. ¾É´úÂëÖеÄÐÂÃýÎóºÍÕë¶Ô KASLR µÄ²àͨ·


4ÔÂ26ÈÕ£¬£¬ £¬£¬£¬£¬¼´½«ÍƳöµÄ Windows 11 °æ±¾ 24H2 ĿǰÔÚͨ¹ý Windows Insider ´òËã½øÐй«¿ªÔ¤ÀÀ¡£¡£¡£¡£¡£ÕâÆªÎÄÕ½éÉÜÁË·¢ÏÖ 24H2 ÖÐÒýÈëµÄ¶à¸öÄں˷ì϶²¢±àд·ì϶ÀûÓ÷¨Ê½µÄ¹ý³Ì£¬£¬ £¬£¬£¬£¬Ô̺¬ÈƹýÄÚºË ASLR (KASLR) µÄÐÂÇ¿»¯¡£¡£¡£¡£¡£ÕâÀïÃèÊöµÄËùÓзì϶¶¼´æÔÚÓÚ NT ÄÚºË×ÔÉí (ntoskrnl.exe) ÖУ¬£¬ £¬£¬£¬£¬Î»ÓÚ¿ÉÓÉÈκιý³ÌŲÓõÄϵͳŲÓÃÖУ¬£¬ £¬£¬£¬£¬ÎÞÂÛÆäȨÏÞ¼¶±ð»òɳÏäÈôºÎ¡£¡£¡£¡£¡£ÔÚ 24H2 ¶Ô NT Äں˵ĸ÷¸ö²¿ÃŽøÐÐÄæÏò¹¤³Ìʱ£¬£¬ £¬£¬£¬£¬ÎÒ·¢ÏÖÁËÁ½¸ö·ì϶£¬£¬ £¬£¬£¬£¬ÕâÁ½¸ö·ì϶¶¼ÊÇÓû§Ä£Ê½ÄÚ´æµÄË«³Á»ñÈ¡¡£¡£¡£¡£¡£ÕâЩÃýÎó³ö¸ñÓÐȤ£¬£¬ £¬£¬£¬£¬ÓÉÓÚËüÃdzʴ˿ÌÒÔǰ°²È«µÄ³Ö¾Ã´æÔڵĴúÂëÖÓ×£¡£¡£¡£¡£ÔÚÒÔǰµÄ Windows °æ±¾ÖУ¬£¬ £¬£¬£¬£¬ÓÉÓںܶàϵͳŲÓÃÔÚÆäÊä³öÖÐÔ̺¬ÄÚºËÖ¸Õ룬£¬ £¬£¬£¬£¬Òò¶øÕ½Ê¤ KASLR ÊÇ΢²»¼°Â·µÄ¡£¡£¡£¡£¡£È»¶ø£¬£¬ £¬£¬£¬£¬ÔÚ 24H2 ÖУ¬£¬ £¬£¬£¬£¬ÕâЩÄں˵ØÖ·Ð¹Â©²»Ôٿɹ©·ÇÌØÈ¨Å²ÓÃÕßʹÓᣡ£¡£¡£¡£ÔÚûÓо­µäµÄ KASLR ÈÆ¹ýµÄÇé¿öÏ£¬£¬ £¬£¬£¬£¬ÎªÁËÈ·¶¨Äں˵IJ¼¾Ö£¬£¬ £¬£¬£¬£¬±ØÒªÒ»ÖÖм¼Êõ¡£¡£¡£¡£¡£ÎÒÌý˵¹ýÒ»ÖÖÔÚ Linux ÉÏʹÓõļ¼Êõ£¬£¬ £¬£¬£¬£¬³ÆÎªEntryBleed£¬£¬ £¬£¬£¬£¬ËüʹÓüÆÊ±ÅÔ·À´È·¶¨Äں˵ĵØÖ·£¬£¬ £¬£¬£¬£¬²¢¾ö¶¨×êÑÐÊÇ·ñÄܹ»ÔÚ Windows ÉÏʹÓÃÀàËÆµÄ¼¼Êõ¡£¡£¡£¡£¡£


https://exploits.forsale/24h2-nt-exploit/


6. ICICIÒøÐÐй¶17000Ãû¿Í»§µÄÐÅÓþ¿¨Êý¾Ý


4ÔÂ28ÈÕ£¬£¬ £¬£¬£¬£¬ICICI ÒøÐÐÊÇÓ¡¶Èµ±ÏȵĸöÈËÒøÐÐÖ®Ò»£¬£¬ £¬£¬£¬£¬Òâ±íµØ½«ÊýǧÕÅÐÂÐÅÓþ¿¨µÄÊý¾Ý¶³ö¸ø·ÇÔ¤ÆÚ½Ó¹ÜÕߵĿͻ§¡£¡£¡£¡£¡£ICICI ÒøÐÐÓÐÏÞ¹«Ë¾ÊÇÒ»¼ÒÓ¡¶È¿ç¹úÒøÐкͽðÈÚ·þÎñ¹«Ë¾£¬£¬ £¬£¬£¬£¬×ܲ¿Î»ÓÚÃÏÂò¡£¡£¡£¡£¡£ËüΪÆóÒµºÍÁãÊÛ¿Í»§Ìṩ¿í·ºµÄÒøÐкͽðÈÚ·þÎñ¡£¡£¡£¡£¡£¸ÃÒøÐÐÔÚÓ¡¶È¸÷µØÕ¼ÓÐ 6000 ¼Ò·ÖÐÐºÍ 17000 ̨ ATM »ú£¬£¬ £¬£¬£¬£¬ÒµÎñ±é¼° 17 ¸ö¹ú¶È¡£¡£¡£¡£¡£ÓÉÓÚÆäÒÆ¶¯ÒøÐÐÀûÓ÷¨Ê½¡°iMobile¡±Öеļ¼ÊõÃýÎ󣬣¬ £¬£¬£¬£¬¸ÃÒøÐж³½áÁË 17,000 ÕÅÐÅÓþ¿¨¡£¡£¡£¡£¡£¸Ã¹ÊÕϵ¼ÖÂÓû§¿É»ñÈ¡ÆäËû¿Í»§µÄ¾ßÌåÐÅÏ¢¡£¡£¡£¡£¡£Â¶³öµÄ²ÆÕþÐÅÏ¢Ô̺¬ÐÅÓþ¿¨ºÅ¡¢ÓÐЧÆÚºÍ¿¨ÑéÖ¤Öµ (CVV)¡£¡£¡£¡£¡£ÔÚһЩ¿Í»§ÔÚÉ罻ýÌåÉϻ㱨¸ÃÎÊÌâºó£¬£¬ £¬£¬£¬£¬¸ÃÒøÐÐÒâʶµ½ÁËÕâÒ»ÎÊÌâ¡£¡£¡£¡£¡£¸ÃÒøÐаµÊ¾£¬£¬ £¬£¬£¬£¬¸ÃÊÂÎñÓ°ÏìÁ˸ÃÒøÐÐÔ¼ 0.1% µÄÐÅÓþ¿¨¡£¡£¡£¡£¡£ICICI ÒøÐÐÔÚÏòÊÜÓ°ÏìµÄ¿Í»§¿¯ÐÐеÄÐÅÓþ¿¨¡£¡£¡£¡£¡£2023 Äê 4 Ô£¬£¬ £¬£¬£¬£¬Cybernews µÄ×êÑÐÈËÔ±»ã±¨³Æ£¬£¬ £¬£¬£¬£¬ICICI ÒøÐÐй¶ÁËÊý°ÙÍòÌõÔ̺¬Ãô¸ÐÊý¾ÝµÄ¼Í¼£¬£¬ £¬£¬£¬£¬Ô̺¬¸ÃÒøÐпͻ§µÄ²ÆÕþÐÅÏ¢ºÍÓ×ÎÒÎļþ¡£¡£¡£¡£¡£


https://securityaffairs.com/162479/security/icici-bank-technical-glitch.html