ÐÂÍøÂç´¹µö¹¤¾ß°ü¡°Xi¨± g¨¯u¡±Òý·¢È«Çò°²È«¾¯±¨

°ä²¼¹¦·ò 2024-11-04

1. ÐÂÍøÂç´¹µö¹¤¾ß°ü¡°Xi¨± g¨¯u¡±Òý·¢È«Çò°²È«¾¯±¨


11ÔÂ1ÈÕ £¬ £¬£¬ £¬£¬ÍøÂ簲ȫÁìÓò½üÆÚ³öÏÖÁËÒ»ÖÖÃûΪXi¨± g¨¯uµÄÐÂÐÍÍøÂç´¹µö¹¤¾ß°ü £¬ £¬£¬ £¬£¬×Ô2024Äê9ÔÂÆðÒÑÕë¶Ô°Ä´óÀûÑÇ¡¢ÈÕ±¾¡¢Î÷°àÑÀ¡¢Ó¢¹úºÍÃÀ¹úµÈ¶à¸ö¹ú¶ÈÌáÒé¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£¸Ã¹¤¾ß°üÒÑϰȾ³¬¹ý2000¸ö´¹µöÍøÕ¾ £¬ £¬£¬ £¬£¬ÖØÒª¹¥»÷¹«¹²²¿ÃÅ¡¢ÓÊÕþ¡¢Êý×Ö·þÎñºÍÒøÐзþÎñµÈ´¹Ö±ÐÐÒµ¡£¡£¡£¡£¡£¡£¡£¡£NetcraftÖ¸³ö £¬ £¬£¬ £¬£¬ÕâЩ¹¥»÷Õß³£ÀûÓÃCloudflareµÄ·´»úеÈ˺ÍÍйܻìºÏÖ°ÄÜÀ´¶ã±Ü¼ì²â¡£¡£¡£¡£¡£¡£¡£¡£Xi¨± g¨¯uÌṩÖÎÀíÃæ°å £¬ £¬£¬ £¬£¬Ê¹ÓÃGolangºÍVue.jsµÈ¼¼Êõ £¬ £¬£¬ £¬£¬Í¨¹ýTelegram´ÓÐéα´¹µöÒ³ÃæÇÔÊØÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£ÕâÐ©ÍøÂç´¹µö¹¥»÷ÖØÒªÍ¨¹ý¸»Í¨ÕÛ·þÎñ£¨RCS£©ÐÂÎÅ´«²¼ £¬ £¬£¬ £¬£¬ÓÕµ¼Êܺ¦Õßµã»÷Ëõ¶ÌµÄÁ´½ÓÒÔÌṩÓ×ÎÒÐÅÏ¢»ò¸¶¿î¡£¡£¡£¡£¡£¡£¡£¡£¹È¸èµÈ¿Æ¼¼¾ÞÍ·ÒѲÉÈ¡´ëÊ©½ø¹¥´ËÀàÚ¿Æ­ £¬ £¬£¬ £¬£¬Ô̺¬ÍƳö¼ÓÇ¿ÐÍÚ¿Æ­¼ì²âÖ°ÄܺͰ²È«ÖÒ¸æ £¬ £¬£¬ £¬£¬²¢´òËãÔÚÈ«ÇòÁìÓòÄÚÍÆ¹ãб£»£» £» £» £»£»¤´ëÊ©¡£¡£¡£¡£¡£¡£¡£¡£´Ë±í £¬ £¬£¬ £¬£¬Ë¼¿ÆTalosÍŶӷ¢ÏÖ £¬ £¬£¬ £¬£¬Ì¨ÍåµÄFacebookóÒ׺͸æ°×ÕÊ»§Óû§Õý³ÉÎªÍøÂç´¹µö»î¶¯µÄÖ¸±ê £¬ £¬£¬ £¬£¬Ö¼ÔÚ´«²¼ÇÔÈ¡¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¡£¡£¡£ÕâЩ»î¶¯»¹¼ÙÒâOpenAIµÈ³ÛÃûÆóÒµ £¬ £¬£¬ £¬£¬ÓÕµ¼È«ÇòÆóÒµ¸üи¶¿îÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£


https://thehackernews.com/2024/11/new-phishing-kit-xiu-gou-targets-users.html


2. InterlockÀÕË÷Èí¼þ£ºÕë¶ÔFreeBSD·þÎñÆ÷µÄÐÂÐ͹¥»÷Ðж¯


11ÔÂ3ÈÕ £¬ £¬£¬ £¬£¬InterlockÊÇÒ»¸öÐÂÐ˵ÄÀÕË÷Èí¼þ²Ù×÷ £¬ £¬£¬ £¬£¬×Ô2024Äê9ÔÂµ×Æô¶¯ÒÔÀ´ £¬ £¬£¬ £¬£¬ÒѶÔÈ«Çò¶à¸ö×éÖ¯ÌáÒé¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£ËüѡȡһÖÖ²»³£¼ûµÄ²½Öè £¬ £¬£¬ £¬£¬¼´´´½¨×¨ÃÅÕë¶ÔFreeBSD·þÎñÆ÷µÄ¼ÓÃÜÆ÷¡£¡£¡£¡£¡£¡£¡£¡£ÕâÖÖ¼ÓÃÜÆ÷ÔÚFreeBSD 10.4ÉϱàÒë £¬ £¬£¬ £¬£¬Ö»¹ÜBleepingComputerµÈ°²È«»ú¹¹ÔÚÐé¹¹»úÉϲâÊÔʱδÄÜʹÆäÕýÈ·Ö´ÐÓ×£¡£¡£¡£¡£¡£¡£¡£InterlockÔÚ¹¥»÷³É¹¦ºó £¬ £¬£¬ £¬£¬»áÔÚδ֧¸¶Êê½ðµÄÇé¿öÏ £¬ £¬£¬ £¬£¬ÔÚÆäÊý¾ÝÐ¹Â¶ÍøÕ¾Éϰ䲼±»µÁÊý¾Ý¡£¡£¡£¡£¡£¡£¡£¡£¾ÝÍøÂ簲ȫ¹«Ë¾Ç÷Ïò¿Æ¼¼³Æ £¬ £¬£¬ £¬£¬InterlockµÄÖ¸±êÊÇFreeBSD £¬ £¬£¬ £¬£¬ÓÉÓÚËü¿í·ºÀûÓÃÓÚ·þÎñÆ÷ºÍ¹Ø¼ü»ù´¡ÉèÊ© £¬ £¬£¬ £¬£¬¹¥»÷ÕßÄܹ»·ÛËé³ÁÒª·þÎñ £¬ £¬£¬ £¬£¬Ë÷Òª¾Þ¶îÊê½ð¡£¡£¡£¡£¡£¡£¡£¡£´Ë±í £¬ £¬£¬ £¬£¬Ç÷Ïò¿Æ¼¼»¹·¢ÏÖÁ˸òÙ×÷µÄWindows¼ÓÃÜÆ÷Ñù±¾¡£¡£¡£¡£¡£¡£¡£¡£ÔÚ¼ÓÃÜÎļþʱ £¬ £¬£¬ £¬£¬Interlock»á½«.interlockÀ©´óÃû¸½¼Óµ½ËùÓмÓÃÜÎļþÃûºó £¬ £¬£¬ £¬£¬²¢ÔÚÿ¸öÎļþ¼ÐÖд´½¨ÀÕË÷¼Í¼¡£¡£¡£¡£¡£¡£¡£¡£±»µÁÊý¾Ý±»ÓÃÓÚË«³ÁÀÕË÷¹¥»÷ £¬ £¬£¬ £¬£¬ÍþвÐÐΪÕßÍþв³Æ £¬ £¬£¬ £¬£¬ÈôÊDz»Ö§¸¶Êê½ð £¬ £¬£¬ £¬£¬ËûÃǾͻṫ¿ªÐ¹Â¶Êý¾Ý¡£¡£¡£¡£¡£¡£¡£¡£¾Ý³Æ £¬ £¬£¬ £¬£¬InterlockÀÕË÷Èí¼þ²Ù×÷ÒªÇóµÄÊê½ð´ÓÊýÊ®ÍòÃÀÔªµ½Êý°ÙÍòÃÀÔª²»µÈ £¬ £¬£¬ £¬£¬¾ßÌåÈ¡¾öÓÚ×éÖ¯µÄ¹æÄ£¡£¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/meet-interlock-the-new-ransomware-targeting-freebsd-servers/


3. SharePoint RCE·ì϶CVE-2024-38094Õý±»ºÚ¿ÍÀûÓýøÐÐÍøÂç¹¥»÷


11ÔÂ2ÈÕ £¬ £¬£¬ £¬£¬Microsoft SharePointµÄÒ»¸öÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2024-38094£©±»Åû¶²¢ÔÚ±»ºÚ¿ÍÀûÓà £¬ £¬£¬ £¬£¬ÒÔ»ñÈ¡¶Ô¹«Ë¾ÍøÂçµÄ³õʼ½Ó¼ûȨÏÞ¡£¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶ÊÇÒ»¸ö¸ßÑϳÁÐÔ£¨CVSS v3.1 ÆÀ·Ö£º7.2£©µÄRCE·ì϶ £¬ £¬£¬ £¬£¬Ó°Ïì¿í·ºÊ¹ÓõĻùÓÚWebµÄSharePointƽ̨¡£¡£¡£¡£¡£¡£¡£¡£Î¢ÈíÒÑÓÚ2024Äê7ÔÂ9ÈÕ°ä²¼Á˲¹¶¡½¨¸´¸Ã·ì϶ £¬ £¬£¬ £¬£¬²¢½«ÆäÏóÕ÷Ϊ¡°³ÁÒª¡±¡£¡£¡£¡£¡£¡£¡£¡£È»¶ø £¬ £¬£¬ £¬£¬CISAÉÏÖܽ«¸Ã·ì϶Ôö³¤µ½ÒÑÖªÀûÓ÷ì϶Ŀ¼ʱ £¬ £¬£¬ £¬£¬²¢Î´Ð¹Â©¾ßÌåµÄÀûÓ÷½Ê½¡£¡£¡£¡£¡£¡£¡£¡£Rapid7°ä²¼µÄл㱨½ÒʾÁ˹¥»÷ÕßÈôºÎÀûÓø÷ì϶ £¬ £¬£¬ £¬£¬Ö¸³ö¹¥»÷Õßͨ¹ýδ¾­ÊÚȨ½Ó¼ûÒ×Êܹ¥»÷µÄSharePoint·þÎñÆ÷²¢Ö²ÈëWebshell £¬ £¬£¬ £¬£¬½ø¶øÔÚÍøÂçÖкáÏòÒÆ¶¯ £¬ £¬£¬ £¬£¬Î£¼°Õû¸öÓò¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß»¹·ÛËéÁËÓµÓÐÓòÖÎÀíԱȨÏÞµÄMicrosoft Exchange·þÎñÕÊ»§ £¬ £¬£¬ £¬£¬»ñµÃÌáÉýµÄ½Ó¼ûȨÏÞ £¬ £¬£¬ £¬£¬²¢×°ÖÃÁËHoroung AntivirusÈí¼þ £¬ £¬£¬ £¬£¬Ôì³É°²È«·ÀÓùì¶Ü £¬ £¬£¬ £¬£¬½ûÓð²È«·þÎñ £¬ £¬£¬ £¬£¬¼õÈõ¼ì²âÄÜÁ¦¡£¡£¡£¡£¡£¡£¡£¡£ËûÃÇʹÓöàÖÖ¹¤¾ß½øÐÐÆ¾Ö¤ÍøÂç¡¢Ô¶³Ì½Ó¼û¡¢ÓƾÃÐÔÉèÖõȲÙ×÷ £¬ £¬£¬ £¬£¬²¢½ûÓÃÁËWindows Defender¡¢¸ü¸ÄÁËÊÂÎñÈÕÖ¾ £¬ £¬£¬ £¬£¬ÒÔÔ¤·À±»·¢ÏÖ¡£¡£¡£¡£¡£¡£¡£¡£Ö»¹Ü¹¥»÷ÕßÊÔͼɾ³ý±¸·Ý £¬ £¬£¬ £¬£¬µ«²¢Î´³É¹¦¼ÓÃÜÊý¾Ý £¬ £¬£¬ £¬£¬Òò¶ø¹¥»÷ÀàÐÍÉв»Ã÷ÏÔ¡£¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/microsoft-sharepoint-rce-bug-exploited-to-breach-corporate-network/


4. Âåɼí¶ÊÐס·¿ÖÎÀí¾ÖÔâCactusÀÕË÷Èí¼þÍŻ﹥»÷


11ÔÂ1ÈÕ £¬ £¬£¬ £¬£¬Âåɼí¶ÊÐס·¿ÖÎÀí¾Ö£¨HACLA£©ÊÇÃÀ¹ú×î´óµÄ¹«¹²×¡·¿ÖÎÀí¾ÖÖ®Ò» £¬ £¬£¬ £¬£¬ÕƹÜÖÎÀí³¬¹ý32,000Ì×¹«¹²×¡·¿ £¬ £¬£¬ £¬£¬Äê¶ÈÔ¤Ë㳬¹ý10ÒÚÃÀÔª £¬ £¬£¬ £¬£¬ÎªµÍÊÕÈë¼ÒÍ¥¡¢¶ùͯºÍÀÏÄêÈËÌṩ¾­¼ÃºÏÓ÷¿ºÍÔöÔ®´òËã¡£¡£¡£¡£¡£¡£¡£¡£×î½ü £¬ £¬£¬ £¬£¬CactusÀÕË÷Èí¼þÍÅ»ïÐû³Æ¶ÔHACLAµÄITÍøÂç½øÐÐÁËÈëÇÖ¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£HACLA֤ʵÁËÕâÒ»ÍøÂç¹¥»÷ £¬ £¬£¬ £¬£¬²¢°µÊ¾ÒÑÀñƸ±í²¿È¡Ö¤ITר¼Ò½øÐе÷²éºÍÓ¦¶Ô¡£¡£¡£¡£¡£¡£¡£¡£Ö»¹ÜHACLAδй©¹¥»÷µÄ¾ßÌ幦·òºÍÐÔÖÊ £¬ £¬£¬ £¬£¬µ«CactusÀÕË÷Èí¼þÍÅ»ïÐû³ÆÒÑ´ÓÊÜϰȾµÄÍøÂçÖÐÇÔÈ¡ÁË891 GBµÄÎļþ £¬ £¬£¬ £¬£¬Ô̺¬Ó×ÎÒÉí·ÝÐÅÏ¢¡¢²ÆÕþÎļþ¡¢¸ß¹ÜºÍÔ±¹¤Ó×ÎÒÊý¾Ý¡¢¿Í»§Ó×ÎÒÐÅÏ¢¡¢¹«Ë¾»úÃÜÊý¾ÝºÍͨѶµÈ £¬ £¬£¬ £¬£¬²¢ÔÚÆäйÃÜÍøÕ¾Éϰ䲼ÁËһЩÃô¸ÐÎļþµÄ½ØÍ¼×÷Ϊ֤¾Ý¡£¡£¡£¡£¡£¡£¡£¡£´Ë±í £¬ £¬£¬ £¬£¬HACLAÔÚ2022ÄêÒ²ÔøÔâµ½LockBitÀÕË÷Èí¼þÍÅ»ïµÄ¹¥»÷ £¬ £¬£¬ £¬£¬¹¥»÷ÕßÔÚ³¤´ïÒ»ÄêµÄ¹¦·òÀï½Ó¼ûÁËHACLAµÄϵͳ £¬ £¬£¬ £¬£¬²¢Äܹ»½Ó¼û»áÔ±µÄÃô¸ÐÓ×ÎÒÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£µ±¾Ö»ú¹¹ÔڻؾøÖ§¸¶ÍøÂç·¸×ï·Ö×ÓÒªÇóµÄÊê½ðºó £¬ £¬£¬ £¬£¬LockBitÀÕË÷Èí¼þ×é֯й¶ÁËËùÓб»µÁÎļþ¡£¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/la-housing-authority-confirms-breach-claimed-by-cactus-ransomware/


5. LastPassÓû§¾¯ÌèÐéα֧³Öµç»°Ö´ÐÐÔ¶³Ì½Ó¼ûÚ¿Æ­


11ÔÂ1ÈÕ £¬ £¬£¬ £¬£¬LastPass ÊÇÒ»¿îÊ¢ÐеÄÃÜÂëÖÎÀíÆ÷ £¬ £¬£¬ £¬£¬ËüÀûÓà LastPass Chrome À©´ó·¨Ê½À´ÌìÉú¡¢±£Áô¡¢ÖÎÀíºÍ×Ô¶¯Ìî³äÍøÕ¾ÃÜÂë¡£¡£¡£¡£¡£¡£¡£¡£LastPass·¢³öÖÒ¸æ £¬ £¬£¬ £¬£¬Ú¿Æ­ÕßÔÚͨ¹ýÔÚÆäChromeÀ©´ó·¨Ê½Éϰ䲼Ðéα5ÐÇÆÀÂÛ £¬ £¬£¬ £¬£¬ÍƹãÒ»¸ö¼ÙðµÄ¿Í»§Ö§³Öµç»°ºÅÂë805-206-2892 £¬ £¬£¬ £¬£¬ÒÔÓÕÆ­LastPassÓû§¡£¡£¡£¡£¡£¡£¡£¡£Ò»µ©Óû§²¦´ò¸Ãµç»° £¬ £¬£¬ £¬£¬Æ­×Ó»á¼ÙÒâLastPass £¬ £¬£¬ £¬£¬Êèµ¼ËûÃǽӼû¡°dghelp[.]top¡±ÍøÕ¾ £¬ £¬£¬ £¬£¬²¢ÒªÇóÊäÈë´úÂëÏÂÔØÔ¶³ÌÖ§³Ö·¨Ê½ £¬ £¬£¬ £¬£¬¸Ã·¨Ê½ÏÖʵÉÏÊÇConnectWise ScreenConnect´úÀí £¬ £¬£¬ £¬£¬ÔÊÐíÚ¿Æ­Õ߯ëÈ«½Ó¼ûÓû§µÄÍÆËã»ú¡£¡£¡£¡£¡£¡£¡£¡£BleepingComputer·¢ÏÖ £¬ £¬£¬ £¬£¬¸Ãµç»°ºÅÂëÓëÒ»³¡¸ü´ó¹æÄ£µÄÚ¿Æ­»î¶¯ÓÐ¹Ø £¬ £¬£¬ £¬£¬¸ÃºÅÂ뻹±»ÓÃ×÷ºÜ¶àÆäËû¹«Ë¾£¨ÈçÑÇÂíÑ·¡¢Adobe¡¢FacebookµÈ£©µÄ¼Ùð֧³Öµç»°ºÅÂë £¬ £¬£¬ £¬£¬²¢ÔÚ¸÷ÀàÍøÕ¾Éϰ䲼¡£¡£¡£¡£¡£¡£¡£¡£LastPassÓû§±»ÌáÐѲ»ÒªÓëÈκÎÈË·ÖÏíËûÃǵÄÖ÷ÃÜÂë £¬ £¬£¬ £¬£¬ÒÔÔ¤·À°µÀï½Ó¼ûÆäÃÜÂë¿âÖд洢µÄËùÓÐÃÜÂëºÍÊý¾Ý¡£¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/lastpass-warns-of-fake-support-centers-trying-to-steal-customer-data/


6. ·¨¹úÀ͹¤²¿ÔâÍøÂç¹¥»÷ £¬ £¬£¬ £¬£¬¾ÍÒµÖú·öÄêÇáÈËÊý¾ÝÒÉÔâй¶


11ÔÂ1ÈÕ £¬ £¬£¬ £¬£¬·¨¹úÀ͹¤²¿°ä·¢ £¬ £¬£¬ £¬£¬Æä¡°´¦ËùʹÍÅ¡±ÍøÂçʹÓõÄÒ»¼Ò·þÎñÌṩÉÌÒÉËÆ½üÆÚÔâ·êÍøÂç¹¥»÷ £¬ £¬£¬ £¬£¬¸ÃÍøÂçÖØÒªÎª16ÖÁ25ËêµÄÄêÇáÈËÌṩ¾ÍÒµºÍÅàѵ½¨ÒéÓëÖ§³Ö¡£¡£¡£¡£¡£¡£¡£¡£Õâ´Î¹¥»÷¿ÉÄÜй¶ÁËÒÑÔÚ¸ÃϵͳÖеǼǵÄÄêÇáÈ˵ÄÓ×ÎÒÊý¾Ý £¬ £¬£¬ £¬£¬Ô̺¬È«Ãû¡¢µ®ÉúÈÕÆÚ¡¢¹ú¼®¡¢µç×ÓÓʼþºÍÓÊÕþµØÖ·ÒÔ¼°µç»°ºÅÂë £¬ £¬£¬ £¬£¬µ«ÒøÐоßÌåÐÅÏ¢¡¢Éç»á±£ÏպźÍÉí·ÝÖ¤¼þδÊÜÓ°Ïì¡£¡£¡£¡£¡£¡£¡£¡£Ö»¹Ü¼¼Êõµ÷²éÉÐδʵÏÖ £¬ £¬£¬ £¬£¬¸Ã²¿ÒѲÉÈ¡¶àÏî´ëÊ©½â¾ö·ì϶ÎÊÌâ £¬ £¬£¬ £¬£¬²¢ÒÑÏò·¨¹úÒþÖÔ¼à¹Ü»ú¹¹CNILºÍÍøÂ簲ȫ»ú¹¹ANSSI»ã±¨´ËÊ £¬ £¬£¬ £¬£¬Í¬Ê±Ïò˾·¨µ±¾ÖÌáÆðͶËß¡£¡£¡£¡£¡£¡£¡£¡£ÊÜÓ°ÏìµÄÄêÇáÈËÔÚ±»´«µÝÇé¿ö £¬ £¬£¬ £¬£¬²¢ÌáÐÑËûÃǾ¯ÌèÍøÂç´¹µöºÍÉí·Ý͵ÇԵķçÏÕ £¬ £¬£¬ £¬£¬ÇÐÎðͨ¹ýµç»°¡¢¶ÌÐÅ»òµç×ÓÓʼþй©ÃÜÂë»òÒøÐоßÌåÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£


https://therecord.media/france-data-breach-government-contractor-local-missions