³¯ÏÊLazarus GroupÀûÓÃChromeÁãÈÕ·ì϶ÌáÒé¹¥»÷

°ä²¼¹¦·ò 2024-10-28
1. ³¯ÏÊLazarus GroupÀûÓÃChromeÁãÈÕ·ì϶ÌáÒé¹¥»÷


10ÔÂ24ÈÕ£¬ £¬£¬£¬ £¬£¬³¯ÏʺڿÍ×éÖ¯Lazarus Group±»Ö¸ÀûÓÃGoogle ChromeµÄÏÖÒѽ¨²¹°²È«·ì϶CVE-2024-4947½øÐÐÁãÈÕ¹¥»÷£¬ £¬£¬£¬ £¬£¬½ÚÔìÊÜϰȾÉ豸¡£¡£¡£¡£¡£¡£¿£¿£¿£¿£¿£¿¨°Í˹»ù¹«Ë¾ÔÚ2024Äê5Ô·¢ÏÖÁËÒ»ÌõÕë¶Ô¶íÂÞ˹¹«ÃñµÄ¹¥»÷Á´£¬ £¬£¬£¬ £¬£¬¹¥»÷ͨ¹ýÐéαµÄ¼ÓÃÜÇ®±ÒÁìÓòÓÎÏ·ÍøÕ¾"detankzone[.]com"´¥·¢·ì϶¡£¡£¡£¡£¡£¡£¸ÃÍøÕ¾¼Ù×°³ÉÈ¥ÖÐÐÄ»¯½ðÈÚ£¨DeFi£©NFTµÄ¶àÈËÔÚÏßÕ½¶·¾º¼¼³¡£¡£¡£¡£¡£¡£¨MOBA£©Ì¹¿ËÓÎÏ·£¬ £¬£¬£¬ £¬£¬ÊµÔòÔ̺¬°µ²Ø¾ç±¾£¬ £¬£¬£¬ £¬£¬ÔÚÓû§ä¯ÀÀÆ÷ÖÐÔËÐзì϶£¬ £¬£¬£¬ £¬£¬Ê¹¹¥»÷Õß»ñµÃ¶ÔÊܺ¦ÕßPCµÄÆëÈ«½ÚÔì¡£¡£¡£¡£¡£¡£´Ë±í£¬ £¬£¬£¬ £¬£¬Lazarus Group»¹±»ÒÉ»óÇÔÈ¡ÁËÒ»¿îºÏ·¨Çø¿éÁ´±ßÍæ±ß׬£¨P2E£©ÓÎÏ·µÄÔ´´úÂëºÍÇ®±Ò£¬ £¬£¬£¬ £¬£¬ÓÃÓÚʵÏÔìä¹¥»÷Ö¸±ê¡£¡£¡£¡£¡£¡£¿£¿£¿£¿£¿£¿¨°Í˹»ùÖ¸³ö£¬ £¬£¬£¬ £¬£¬LazarusÊÇ×î»îÔ¾¡¢×ÔÓµÄAPT¹¥»÷ÕßÖ®Ò»£¬ £¬£¬£¬ £¬£¬¾­¼ÃÀûÒæÊÇÆäÖØÒª¶¯»ú£¬ £¬£¬£¬ £¬£¬ÇÒÆäÕ½ÊõÔÚ²»ÐÝÑݱ䣬 £¬£¬£¬ £¬£¬ÀûÓÃÌìÉúʽÈËΪÖÇÄܵÈм¼ÊõÌáÒé¸ü¸´ÔӵĹ¥»÷¡£¡£¡£¡£¡£¡£


https://thehackernews.com/2024/10/lazarus-group-exploits-google-chrome.html


2. Fortinet FortiManager RCEÁãÈÕ·ì϶ÔÚÒ°±í±»ÀûÓÃ


10ÔÂ24ÈÕ£¬ £¬£¬£¬ £¬£¬ÍøÂ簲ȫ¹«Ë¾Fortinet½üÈÕÅû¶ÁËÆäÈí¼þ²úÆ·FortiManager´æÔÚÒ»¸ö¹Ø¼üÁãÈÕ·ì϶£¨CVE-2024-47575£©£¬ £¬£¬£¬ £¬£¬¸Ã·ì϶ÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õßͨ¹ýÌØÔìÒªÇóÖ´ÐÐËÁÒâ´úÂë»òºÅÁ £¬£¬£¬ £¬£¬ÇÒÒÑÔÚÒ°±í±»»ý¼«ÀûÓᣡ£¡£¡£¡£¡£¸Ã·ì϶µÄCVSS v3ÆÀ·Ö¸ß´ï9.8£¬ £¬£¬£¬ £¬£¬Ó°Ïì¶à¸ö°æ±¾µÄFortiManager¼°FortiManager Cloud¡£¡£¡£¡£¡£¡£FortinetÒѰ䲼²¹¶¡²¢ÌṩÁ˶àÖÖ½â¾ö²½Öè¡£¡£¡£¡£¡£¡£¾Ý»ã±¨£¬ £¬£¬£¬ £¬£¬¸Ã·ì϶Òѱ»ÓÃÓÚй¼ûô¸ÐÎļþ£¬ £¬£¬£¬ £¬£¬Ô̺¬IPµØÖ·¡¢Æ¾Ö¤ºÍÉ豸ÅäÖ㬠£¬£¬£¬ £¬£¬µ«ÉÐδ·¢ÏÖ¶ñÒâÈí¼þ»òºóÃÅ×°Öᣡ£¡£¡£¡£¡£Íþв×éÖ¯UNC5820×Ô2024Äê6ÔÂ27ÈÕÆð¾ÍÀûÓô˷ì϶£¬ £¬£¬£¬ £¬£¬»ñÈ¡ÁËFortiGateÉ豸ÅäÖÃÊý¾Ý£¬ £¬£¬£¬ £¬£¬Ô̺¬Óû§¼ÓÃÜÃÜÂ룬 £¬£¬£¬ £¬£¬¿ÉÄÜÓÃÓÚ½øÒ»²½·ÛËéºÍºáÏòÒÆ¶¯¡£¡£¡£¡£¡£¡£MandiantÎÞ·¨È·¶¨¹¥»÷ÕßÉí·ÝºÍÖ÷ÕÅ£¬ £¬£¬£¬ £¬£¬½¨ÒéËùÓж³öÔÚ»¥ÁªÍøÉϵÄFortiManager×éÖ¯Á¢¼´½øÐÐȡ֤µ÷²é¡£¡£¡£¡£¡£¡£Fortinet¶½´ÙÓû§Á¢¼´Éý¼¶ÖÁ°²È«°æ±¾£¬ £¬£¬£¬ £¬£¬²¢²ÉÈ¡×èֹδ֪É豸ע²á¡¢Ê¹ÓÃ×Ô½ç˵֤ÊéÉí·ÝÑéÖ¤µÈ½â¾ö²½Öè¡£¡£¡£¡£¡£¡£


https://cybersecuritynews.com/fortimanager-zero-day-vulnerability/#google_vignette


3. FogÓëAkiraÀÕË÷Èí¼þÀûÓÃSonicWall VPN·ì϶ƵÈÔÈëÇÔìóÒµÍøÂç


10ÔÂ27ÈÕ£¬ £¬£¬£¬ £¬£¬FogºÍAkiraÀÕË÷Èí¼þÔËÓªÉÌÕýÔ½À´Ô½¶àµØÀûÓÃSonicWall VPNÕÊ»§ÈëÇÔìóÒµÍøÂ磬 £¬£¬£¬ £¬£¬¹Ø¼ü·ì϶CVE-2024-40766±»ÒÔΪÊÇÆäÈëÇÖµÄÖØÒªÍ¨Â·¡£¡£¡£¡£¡£¡£SonicWallÓÚ2024Äê8ÔÂÏÂÑ®½¨¸´Á˸÷ì϶£¬ £¬£¬£¬ £¬£¬µ«Ò»Öܺó±ãÖÒ¸æ³Æ·ì϶Òѱ»»ý¼«ÀûÓᣡ£¡£¡£¡£¡£±±¼«Àǰ²È«×êÑÐÈËÔ±·¢ÏÖ£¬ £¬£¬£¬ £¬£¬AkiraÀÕË÷Èí¼þ´ÓÊô»ú¹¹ÒÑÀûÓø÷ì϶»ñÈ¡³õʼ½Ó¼ûȨÏÞ¡£¡£¡£¡£¡£¡£¾ÝArctic Wolf»ã±¨£¬ £¬£¬£¬ £¬£¬AkiraºÍFogÖÁÉÙ½øÐÐÁË30´ÎÈëÇÖ£¬ £¬£¬£¬ £¬£¬¾ùʼÓÚͨ¹ýSonicWall VPNÕÊ»§Ô¶³Ì½Ó¼û¡£¡£¡£¡£¡£¡£ÆäÖУ¬ £¬£¬£¬ £¬£¬75%µÄ°¸¼þÓëAkiraÓйأ¬ £¬£¬£¬ £¬£¬ÆäÓàΪFogËùΪ¡£¡£¡£¡£¡£¡£ÕâÁ½¸ö×éÖ¯ËÆºõ¹²Ïí»ù´¡ÉèÊ©£¬ £¬£¬£¬ £¬£¬Åú×¢ÈÔ´æÔÚ·ÇÕýʽºÏ×÷¡£¡£¡£¡£¡£¡£ËùÓб»¹¥ÆÆµÄ¶Ëµã¶¼ÔËÐÐÒ×Êܹ¥»÷µÄ佨²¹°æ±¾£¬ £¬£¬£¬ £¬£¬ÇÒ´ÓÈëÇÖµ½Êý¾Ý¼ÓÃܵŦ·òͨ³£½Ï¶Ì£¬ £¬£¬£¬ £¬£¬×î¿ì½öÐè1.5-2Ó×ʱ¡£¡£¡£¡£¡£¡£ÍþвÐÐΪÕßͨ¹ýVPN/VPS½Ó¼û¶Ëµã²¢»ìºÏÕæÊµIPµØÖ·¡£¡£¡£¡£¡£¡£ÊÜϰȾ×é֯δÆôÓöà³É·ÖÉí·ÝÑéÖ¤£¬ £¬£¬£¬ £¬£¬Ò²Î´ÔÚĬÈ϶˿ÚÉÏÔËÐзþÎñ¡£¡£¡£¡£¡£¡£ÈëÇÖ¹ý³ÌÖУ¬ £¬£¬£¬ £¬£¬¹Û²ìµ½Ìض¨ÐÂÎÅÊÂÎñIDÅú×¢Ô¶³ÌÓû§µÇ¼ºÍIP·ÖÅä³É¹¦¡£¡£¡£¡£¡£¡£ÍþвÐÐΪÕßÖØÒªÕë¶ÔÐé¹¹»ú¼°Æä±¸·ÝÌáÒé¼±¾ç¼ÓÃܹ¥»÷£¬ £¬£¬£¬ £¬£¬²¢ÇÔÈ¡ÎĵµºÍרÓÐÈí¼þ£¬ £¬£¬£¬ £¬£¬µ«²»¹Ø×¢³¬¹ýÁù¸öÔ»ò30¸öÔµÄÎļþ¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/fog-ransomware-targets-sonicwall-vpns-to-breach-corporate-networks/


4. BlackBastaÀÕË÷Èí¼þÐж¯ÀûÓÃMicrosoft Teams½øÐÐÉç»á¹¤³Ì¹¥»÷


10ÔÂ25ÈÕ£¬ £¬£¬£¬ £¬£¬BlackBastaÀÕË÷Èí¼þÐж¯×Ô2022Äê4ÔÂÒÔÀ´Ò»Ïò»îÔ¾£¬ £¬£¬£¬ £¬£¬¶ÔÈ«ÇòÊý°ÙÆðÆóÒµ¹¥»÷ÕÆ¹Ü¡£¡£¡£¡£¡£¡£¸Ã×é֯ͨ¹ý·ì϶¡¢ºÏ×÷¡¢¶ñÒâÈí¼þ½©Ê¬ÍøÂçºÍÉç»á¹¤³ÌѧµÈ¶àÖÖ²½Öè·ÛËéÍøÂç¡£¡£¡£¡£¡£¡£×î½ü£¬ £¬£¬£¬ £¬£¬BlackBastaµÄ´ÓÊô»ú¹¹½«Éç»á¹¤³Ì¹¥»÷×ªÒÆµ½ÁËMicrosoft TeamsÉÏ£¬ £¬£¬£¬ £¬£¬ËûÃǼÙÒ⹫˾ITÔ®ÊǪ̈ÁªÏµÔ±¹¤£¬ £¬£¬£¬ £¬£¬Ð­Öú½â¾öÀ¬»øÓʼþÎÊÌâ¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÊ×ÏÅ×õç×ÓÓʼþ¸²Ã»Ô±¹¤µÄÊÕ¼þÏ䣬 £¬£¬£¬ £¬£¬¶øºóÒÔ±í²¿Óû§µÄÉí·Ýͨ¹ýMicrosoft TeamsÁªÏµÔ±¹¤£¬ £¬£¬£¬ £¬£¬ÕâЩÕÊ»§ÊÇÔÚEntra ID×â»§Ï´´½¨µÄ£¬ £¬£¬£¬ £¬£¬Ãû³Æ¿´ÆðÀ´ÏñÊÇÔ®ÊǪ̈¡£¡£¡£¡£¡£¡£ÔÚ̸ÌìÖУ¬ £¬£¬£¬ £¬£¬¹¥»÷Õß·¢ËͶþάÂë»òÓÕÆ­Óû§×°ÖÃAnyDeskÔ¶³ÌÖ§³Ö¹¤¾ß»òÆô¶¯Windows Quick AssistÔ¶³Ì½ÚÔìºÍÆÁÄ»¹²Ïí¹¤¾ß£¬ £¬£¬£¬ £¬£¬ÒÔ±ãÔ¶³Ì½Ó¼ûÓû§µÄ¹«Ë¾É豸¡£¡£¡£¡£¡£¡£Ò»µ©Ïνӣ¬ £¬£¬£¬ £¬£¬¹¥»÷Õß»á×°Öø÷ÀàÓÐÐ§ÔØºÉ£¬ £¬£¬£¬ £¬£¬ÈçScreenConnect¡¢NetSupport ManagerºÍCobalt Strike£¬ £¬£¬£¬ £¬£¬ÒÔ³ÖÐøÔ¶³Ì½Ó¼ûÓû§µÄ¹«Ë¾É豸£¬ £¬£¬£¬ £¬£¬²¢ºáÏòÀ©É¢µ½ÆäËûÉ豸£¬ £¬£¬£¬ £¬£¬Í¬Ê±ÌáÉýȨÏÞ¡¢ÇÔÈ¡Êý¾Ý£¬ £¬£¬£¬ £¬£¬²¢×îÖÕ²¿ÊðÀÕË÷Èí¼þ¼ÓÃÜÆ÷¡£¡£¡£¡£¡£¡£ReliaQuest½¨Òé×éÖ¯ÏÞ¶ÈMicrosoft TeamsÖÐÀ´×Ô±í²¿Óû§µÄͨѶ£¬ £¬£¬£¬ £¬£¬²¢ÆôÓÃÈÕÖ¾¼Í¼ÒÔ²éÕÒ¿ÉÒÉ̸Ìì¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/black-basta-ransomware-poses-as-it-support-on-microsoft-teams-to-breach-networks/


5. ÑÇÂíÑ·²é·âAPT29ºÚ¿Í×éÖ¯¹¥»÷ÓòÃû


10ÔÂ25ÈÕ£¬ £¬£¬£¬ £¬£¬ÑÇÂíÑ·ÒѲé·â¶íÂÞ˹APT29ºÚ¿Í×éÖ¯ÓÃÓÚµ±¾ÖºÍ¾üÊÂ×éÖ¯Õë¶ÔÐÔ¹¥»÷µÄÓòÃû¡£¡£¡£¡£¡£¡£APT29£¬ £¬£¬£¬ £¬£¬Óֳơ°Cozy Bear¡±ºÍ¡°Midnight Blizzard¡±£¬ £¬£¬£¬ £¬£¬Óë¶íÂÞ˹¶Ô±íµý±¨¾ÖÓÐÁªÏµ£¬ £¬£¬£¬ £¬£¬ÉÆÓÚʹÓÃÍøÂç´¹µöºÍ¶ñÒâÈí¼þÇÔÈ¡Ãô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£Õâ´Î¹¥»÷ÖУ¬ £¬£¬£¬ £¬£¬APT29ͨ¹ý¼Ù×°³ÉAWSÓòÃûµÄÍøÂç´¹µöÒ³Ãæ£¬ £¬£¬£¬ £¬£¬ÓÕÆ­Ö¸±êÏàÐŲ¢Ê¹ÓöñÒâÔ¶³Ì×ÀÃæºÍ̸ÏνÓÎļþ£¬ £¬£¬£¬ £¬£¬ÒÔÇÔÈ¡Windowsƾ֤ºÍÊý¾Ý¡£¡£¡£¡£¡£¡£Ö»¹ÜÑÇÂíÑ·³ÎÇåÆäÔÆÆ½Ì¨²¢·ÇÖ±½ÓÖ¸±ê£¬ £¬£¬£¬ £¬£¬µ«ÈÔÁ¢¼´Æô¶¯Á˲é·â¼ÙÒâAWSÓòÃûµÄ·¨Ê½¡£¡£¡£¡£¡£¡£APT29ÒԸ߶ȸ´ÔӵĹ¥»÷ÎÅÃû£¬ £¬£¬£¬ £¬£¬Õë¶ÔÈ«Çòµ±¾Ö¡¢ÖÇ¿âºÍ×êÑлú¹¹£¬ £¬£¬£¬ £¬£¬ÇÒ×î½ü»î¶¯ÁìÓò¿í·º£¬ £¬£¬£¬ £¬£¬Ô̺¬Ïò¸ü¶àÖ¸±ê·¢ËÍÍøÂç´¹µöµç×ÓÓʼþ¡£¡£¡£¡£¡£¡£ÎÚ¿ËÀ¼ÍÆËã»úÓ¦¼±·´Ó³Ó××éÒ²°ä²¼ÁËÓйØÖҸ棬 £¬£¬£¬ £¬£¬²¢½¨Òé²ÉÈ¡¶àÏî´ëÊ©Ï÷¼õ¹¥»÷Ãæ£¬ £¬£¬£¬ £¬£¬Èç×èÖ¹¡°.rdp¡±Îļþ¡¢ÏÞ¶ÈRDPÏνӵÈ¡£¡£¡£¡£¡£¡£APT29ÈÔÊǶíÂÞ˹×î׳´óµÄÍøÂçÍþв֮һ£¬ £¬£¬£¬ £¬£¬´ÓǰһÄêÖÐÔøÈëÇÖ¶à¸ö³ÁÒªÈí¼þ¹©¸øÉÌ£¬ £¬£¬£¬ £¬£¬²¢ÀûÓ÷þÎñÆ÷·ì϶ÈëÇÖÈ«Çò³ÁÒª×éÖ¯¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/amazon-seizes-domains-used-in-rogue-remote-desktop-campaign-to-steal-data/


6. RansomHubºÚ¿Í×éÖ¯Ðû³Æ¶ÔÄ«Î÷¸ç13¸ö»ú³¡ÔËÓªÉÌÌáÒé¹¥»÷


10ÔÂ26ÈÕ£¬ £¬£¬£¬ £¬£¬ºÚ¿Í×éÖ¯RansomHub×î½üÐû³Æ¶ÔÄ«Î÷¸ç13¸ö»ú³¡ÔËÓªÉÌGrupo Aeroportuario del Centro Norte£¨OMA£©µÄÍøÂç¹¥»÷ÕÆ¹Ü£¬ £¬£¬£¬ £¬£¬²¢ÍþвÈôÊDz»Ö§¸¶Êê½ð£¬ £¬£¬£¬ £¬£¬½«Ð¹Â¶3TB±»µÁÊý¾Ý¡£¡£¡£¡£¡£¡£OMAÔËÓª×ÅÄ«Î÷¸çÖв¿ºÍ±±²¿µØÓòµÄ»ú³¡£¡£¡£¡£¡£¡£¬ £¬£¬£¬ £¬£¬½ñÄêÒѽӴý³¬1900ÍòÃû³Ë¿Í¡£¡£¡£¡£¡£¡£Õâ´ÎÍøÂçÊÂÎñÆÈʹOMAתÏò±¸ÓÃϵͳÒÔά³ÖÔËÓª£¬ £¬£¬£¬ £¬£¬µ«ÏÔʾº½°àº½Õ¾Â¥µØÎ»µÄÆÁÄ»ÈÔÎÞ·¨Ê¹Óᣡ£¡£¡£¡£¡£OMA°µÊ¾ÔÚÓë±í²¿ÍøÂ簲ȫר¼ÒºÏ×÷µ÷²éÊÂÎñÁìÓò£¬ £¬£¬£¬ £¬£¬²¢ÒÑÖ𲽸´Ô­Ä³Ð©·þÎñ£¬ £¬£¬£¬ £¬£¬µ«¶Ô¹«Ë¾ÔËÓªºÍ²ÆÕþÇé¿öδÔì³É³Á´ó²»ÀûÓ°Ïì¡£¡£¡£¡£¡£¡£Î¢Èí±¾ÖÜÖ¸³ö£¬ £¬£¬£¬ £¬£¬RansomHubÈÔÊÇÀÕË÷Èí¼þÁìÓò×î»îÔ¾µÄÍþв֮һ£¬ £¬£¬£¬ £¬£¬¶à¸öÆäËûÍþвÐÐΪÕßÒ²³ÖÐøÊ¹ÓÃÆä¶ñÒâÈí¼þ½øÐй¥»÷¡£¡£¡£¡£¡£¡£


https://therecord.media/ransomhub-gang-behind-attack-mexican-airport-operator