¹ú¼ÊÍøÂç·¸×OÍųÉÔ±½« Airbnb Ôì³ÉÚ¿Æ­ÖÐÐĺ󱻲¶

°ä²¼¹¦·ò 2024-12-11

1. ¹ú¼ÊÍøÂç·¸×OÍųÉÔ±½« Airbnb Ôì³ÉÚ¿Æ­ÖÐÐĺ󱻲¶


12ÔÂ9ÈÕ£¬£¬ £¬£¬£¬ £¬£¬£¬Ò»¸ö¹ú¼Ê·¸×ïÍøÂçµÄ°ËÃû³ÉÔ±ÔÚ±ÈÀûʱºÍºÉÀ¼±»²¶£¬£¬ £¬£¬£¬ £¬£¬£¬¸ÃÍøÂçÉæÏÓ´ÓÊܺ¦ÕßÊÖÖÐÇÔÈ¡Êý°ÙÍòÅ·Ôª£¬£¬ £¬£¬£¬ £¬£¬£¬²¢ÉèÁ¢AirbnbڲƭÖÐÐÄ¡£¡£¡£¡£¡£¡£¡£Õâ´ÎÐж¯ÓÉÅ·ÖÞÐ̾¯×é֯Эµ÷£¬£¬ £¬£¬£¬ £¬£¬£¬ÓÚ12ÔÂ3ÈÕÔÚÁ½¹úͬʱ½øÐÐÁËÂÅ´ÎËѲ顣¡£¡£¡£¡£¡£¡£ºÉÀ¼¾¯·½¿ÛÁôÁËËÄÃûÏÓÒÉÈË£¬£¬ £¬£¬£¬ £¬£¬£¬Ö¸¿ØËûÃÇ·¸ÓÐÍøÂç´¹µö¡¢ÔÚÏßڲƭ¡¢ÒøÐÐÔ®ÊǪ̈ڲƭ¡¢Ï´Ç®ºÍ²Î¼Ó·¸×ï×éÖ¯µÈ×ï×´£¬£¬ £¬£¬£¬ £¬£¬£¬²¢³ä¹«ÁËÊý¾ÝÔØÌå¡¢ÊÖ»ú¡¢ÉÝ³ÞÆ·ºÍ´óÁ¿Ïֽ𡣡£¡£¡£¡£¡£¡£¾Ý¾¯·½½éÉÜ£¬£¬ £¬£¬£¬ £¬£¬£¬¸ÃÍøÂç·¸×OÍÅ×âÓÃAirbnb·¿²úºÍºÀ»ª¹«Ô¢×÷Ϊһʱºô½ÐÖÐÐÄ£¬£¬ £¬£¬£¬ £¬£¬£¬¼ÙÒâÒøÐÐÔ±¹¤»ò·´Ú²Æ­¹¤×÷×é³ÉÔ±£¬£¬ £¬£¬£¬ £¬£¬£¬Í¨¹ýµç×ÓÓʼþ¡¢¶ÌÐÅ»òWhatsAppÐÂÎÅÁªÏµÊܺ¦Õߣ¬£¬ £¬£¬£¬ £¬£¬£¬ÓÕÆ­ËûÃǵã»÷´¹µöÍøÕ¾Á´½Ó£¬£¬ £¬£¬£¬ £¬£¬£¬½ø¶øµÁÈ¡ÕË»§×ʽ𡣡£¡£¡£¡£¡£¡£Å·ÖÞÐ̾¯×éÖ¯ÖҸ湫¼ÒÒªÉóÉ÷¶Ô´ýδ¾­ÒªÇóµÄͨѶ£¬£¬ £¬£¬£¬ £¬£¬£¬Ô¤·ÀÊܵ½ÍøÂç´¹µöºÍÔ®ÊǪ̈ڲƭµÄºýŪ£¬£¬ £¬£¬£¬ £¬£¬£¬²¢ÌáÐÑÔÚÏúÊÛ¶þÊÖÉÌÆ·µÄÍøÕ¾ÉϽøÐÐÓ×¶îÖ§¸¶Ê±¿ÉÄÜ´æÔÚÐÅÓþ¿¨/½è¼Ç¿¨ÐÅÏ¢±»µÁµÄ·çÏÕ¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/cybercrime-gang-arrested-after-turning-airbnbs-into-fraud-centers/


2. ¶ñÒâ½©Ê¬ÍøÂçSocks5SystemzÖ§³ÖPROXY.AM´úÀí·þÎñ


12ÔÂ9ÈÕ£¬£¬ £¬£¬£¬ £¬£¬£¬Bitsight·¢ÏÖÃûΪSocks5SystemzµÄ¶ñÒâ½©Ê¬ÍøÂçÔÚΪPROXY.AM´úÀí·þÎñÌṩ֧³Ö£¬£¬ £¬£¬£¬ £¬£¬£¬¸Ã·þÎñʹ·¸×ïÕß¿ÉÄÜÔö³¤ÄäÃû²ã²¢Ö´ÐжñÒâ»î¶¯¡£¡£¡£¡£¡£¡£¡£Socks5Systemz×Ô2013ÄêÆð±ãÔÚÍøÂç·¸×ïµØÀ´ÊÀ½çÖÐÐû´«£¬£¬ £¬£¬£¬ £¬£¬£¬Æä¹æÄ£ÔÚ2024Äê1ÔÂÔø¼¤ÔöÖÁÿÌìÔ¼25Íǫ̀»úе£¬£¬ £¬£¬£¬ £¬£¬£¬µ«Ä¿Ç°¹À¼ÆÔÚ85,000µ½100,000̨֮¼ä¡£¡£¡£¡£¡£¡£¡£Í¬Ê±£¬£¬ £¬£¬£¬ £¬£¬£¬PROXY.AMÐû³ÆÕ¼ÓÐÀ´×Ô31¸ö¹ú¶ÈµÄ80,888¸ö´úÀí½Úµã¡£¡£¡£¡£¡£¡£¡£¸Ã½©Ê¬ÍøÂç×î³õÓÉPrivateLoader¡¢SmokeLoaderºÍAmadeyµÈ¼ÓÔØÆ÷¿ªÊÍ£¬£¬ £¬£¬£¬ £¬£¬£¬ÏÖÒÑ·¢Õ¹µ½Socks5Systemz V2°æ±¾¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬ £¬£¬£¬ £¬£¬£¬ÍøÂ簲ȫÁìÓò»¹Ãæ¶ÔÆäËûÍþв£¬£¬ £¬£¬£¬ £¬£¬£¬ÈçGafgyt½©Ê¬ÍøÂç¶ñÒâÈí¼þÀûÓÃÅäÖÃÃýÎóµÄDocker Remote API·þÎñÆ÷½øÐÐDDoS¹¥»÷£¬£¬ £¬£¬£¬ £¬£¬£¬ÒÔ¼°ÔÆÅäÖÃÃýÎó³ÉΪ¹¥»÷ÕßµÄÖ¸±ê¡£¡£¡£¡£¡£¡£¡£À³¶Ù´óѧºÍ´ú¶û·òÌØÀí¹¤´óѧµÄ×êÑÐÈËÔ±·¢ÏÖ¶à´ï215¸öÊ·ý¶³öÁËÃô¸Ðƾ֤£¬£¬ £¬£¬£¬ £¬£¬£¬Éæ¼°¶à¸öÁìÓò£¬£¬ £¬£¬£¬ £¬£¬£¬Ç¿µ÷±ØÒª¸üºÃµÄϵͳÖÎÀíºÍ¾¯ÌèµÄ¼à¶½ÒÔÔ¤·ÀÊý¾Ýй¶¡£¡£¡£¡£¡£¡£¡£


https://thehackernews.com/2024/12/socks5systemz-botnet-powers-illegal.html


3. ¶íÂÞ˹ºÚ¿ÍÒÉËÆ¶Ô×¼ÎÚ¿ËÀ¼¹ú·ÀÆóÒµ·¢Õ¹Ð¼äµý»î¶¯


12ÔÂ9ÈÕ£¬£¬ £¬£¬£¬ £¬£¬£¬¾Ýл㱨³Æ£¬£¬ £¬£¬£¬ £¬£¬£¬ÒÉËÆ¶íÂÞ˹ºÚ¿ÍÔÚÕë¶ÔÎÚ¿ËÀ¼¾üʺ͹ú·ÀÆóÒµ·¢Õ¹Ðµļäµý»î¶¯¡£¡£¡£¡£¡£¡£¡£ÎÚ¿ËÀ¼¾ü·½ÍÆËã»úÓ¦¼±ÏìÓ¦Ó××éMIL.CERT-UA×·×Ùµ½¸Ã»î¶¯±³ºóµÄÍþвÐÐΪÕßΪUAC-0185£¨Ò²³ÆÎªUNC4221£©£¬£¬ £¬£¬£¬ £¬£¬£¬¸Ã×éÖ¯×Ô2022ÄêÒÔÀ´Ò»Ïò»îÔ¾£¬£¬ £¬£¬£¬ £¬£¬£¬ÖØÒªÍ¨¹ýÐÂÎÅÀûÓ÷¨Ê½ºÍ±¾µØ¾üÊÂϵͳÇÔÈ¡ÎÚ¿ËÀ¼¾üÊÂÈËÔ±µÄƾ֤¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß·¢ËÍÍøÂç´¹µöµç×ÓÓʼþ£¬£¬ £¬£¬£¬ £¬£¬£¬¼Ù×°³É»ù¸¨ºÏ·¨¹ú·À»áÒéµÄÔ¼Ç룬£¬ £¬£¬£¬ £¬£¬£¬²¢Ñ¡ÔñÐԵضÔÎÚ¿ËÀ¼¹ú·À¹¤Òµ×ÛºÏÌåºÍ¹ú·À¶ÓÁÐÔ±¹¤µÄÍÆËã»ú·¢ÆðÍøÂç¹¥»÷¡£¡£¡£¡£¡£¡£¡£Ö»¹ÜÎÚ¿ËÀ¼ÉÐ佫¸Ã×éÖ¯¹é×ïÓÚij¸öÌØ¶¨¹ú¶È£¬£¬ £¬£¬£¬ £¬£¬£¬µ«×êÑÐÈËÔ±´ËÇ°Ôø½«ÆäÓë¶íÂÞ˹ÁªÏµÆðÀ´¡£¡£¡£¡£¡£¡£¡£¸Ã×é֯ʹÓóÛÃû¹¤¾ßÈçMeshAgentºÍUltraVNCϰȾÊܺ¦ÕßµÄÉ豸£¬£¬ £¬£¬£¬ £¬£¬£¬²¢Í¨¹ý¶àÖÖ·½Ê½ÈëÇÖϵͳ£¬£¬ £¬£¬£¬ £¬£¬£¬Ô̺¬ÀûÓÃÔ̺¬¶ñÒâºêµÄµç×ÓÓʼþ»î¶¯¡£¡£¡£¡£¡£¡£¡£ÎÚ¿ËÀ¼¾ü·½ºÍ¹ú·ÀÆóÒµÊǺڿ͵ij£¼ûÖ¸±ê£¬£¬ £¬£¬£¬ £¬£¬£¬´ËÇ°Ò²ÔøÔâ·êÆäËûÓë¶íÂÞ˹ÓÐÁªÏµµÄºÚ¿Í×éÖ¯µÄ¹¥»÷¡£¡£¡£¡£¡£¡£¡£


https://therecord.media/suspected-russian-hackers-target-ukrainian-enterprises-espionage


4. CISA½«Windows CLFS·ì϶CVE-2024-49138²ÎÓëÒÑÖªÀûÓ÷ì϶Ŀ¼


12ÔÂ11ÈÕ£¬£¬ £¬£¬£¬ £¬£¬£¬ÃÀ¹úÍøÂ簲ȫºÍ»ù´¡ÉèÊ©°²È«¾Ö£¨CISA£©Òѽ«Microsoft WindowsͨÓÃÈÕÖ¾Îļþϵͳ(CLFS)Çý¶¯·¨Ê½ÖеÄÒ»¸ö·ì϶CVE-2024-49138£¨CVSSÆÀ·Ö7.8£©ÁÐÈëÆäÒÑÖªÀûÓ÷ì϶£¨KEV£©Ä¿Â¼¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶ÔÚ΢Èí2024Äê12ÔµIJ¹¶¡ÐÇÆÚ¶þ°²È«¸üÐÂÖеõ½½¨¸´£¬£¬ £¬£¬£¬ £¬£¬£¬ÊÇÕâ´Î¸üеÄ71¸ö·ì϶֮һ£¬£¬ £¬£¬£¬ £¬£¬£¬ÇÒ±»ÏóÕ÷ΪÔÚ±»»ý¼«ÀûÓõÄÁãÈÕ·ì϶¡£¡£¡£¡£¡£¡£¡£Ö»¹Ü΢Èíδ¹«¿ªÓйش˷ì϶±»ÀûÓõľßÌå¹¥»÷ÐÅÏ¢£¬£¬ £¬£¬£¬ £¬£¬£¬µ«¹¥»÷Õß¿ÉÀûÓÃËü»ñÈ¡SYSTEMȨÏÞ¡£¡£¡£¡£¡£¡£¡£²¼¸æÖ¸³ö£¬£¬ £¬£¬£¬ £¬£¬£¬CLFSÇý¶¯·¨Ê½´æÔÚ»ùÓڶѵĻº³åÇøÒç¶Âí½Å£¬£¬ £¬£¬£¬ £¬£¬£¬ÔÊÐí±¾µØ¹¥»÷ÕßÌáÉýȨÏÞ¡£¡£¡£¡£¡£¡£¡£Æ¾¾ÝÓµÓÐÔ¼ÊøÁ¦µÄ²Ù×÷Ö¸Áî22-01£¬£¬ £¬£¬£¬ £¬£¬£¬Áª¹ú»ú¹¹±ØÐëÔÚ»®¶¨½ØÖ¹ÈÕÆÚǰ½â¾öÒÑ·¢Ïֵķì϶£¬£¬ £¬£¬£¬ £¬£¬£¬ÒÔ±£»£»£»£»£»£» £»£»¤ÍøÂçÃâÊÜÀûÓÃĿ¼Öзì϶µÄ¹¥»÷¡£¡£¡£¡£¡£¡£¡£CISAÒªÇóÁª¹ú»ú¹¹ÔÚ2024Äê12ÔÂ31ÈÕǰ½¨¸´´Ë·ì϶£¬£¬ £¬£¬£¬ £¬£¬£¬Í¬Ê±×¨¼ÒÒ²½¨Òé¸öÈË×éÖ¯Éó²é¸ÃĿ¼²¢½â¾öÆä»ù´¡ÉèÊ©ÖеÄÓйطì϶¡£¡£¡£¡£¡£¡£¡£


https://securityaffairs.com/171851/hacking/u-s-cisa-adds-microsoft-windows-clfs-driver-flaw-to-its-known-exploited-vulnerabilities-catalog.html


5. WordPress²å¼þWPForms·¢ÏÖ¸ßÑϳÁÐÔ·ì϶£¬£¬ £¬£¬£¬ £¬£¬£¬Ó°Ï쳬600ÍòÍøÕ¾


12ÔÂ10ÈÕ£¬£¬ £¬£¬£¬ £¬£¬£¬WordPress²å¼þWPFormsÖдæÔÚÒ»¸ö±àºÅΪCVE-2024-11205µÄ¸ßÑϳÁÐÔ·ì϶£¬£¬ £¬£¬£¬ £¬£¬£¬¿ÉÄÜÓ°Ï쳬¹ý600Íò¸öÍøÕ¾¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶ÔÊÐí¾­¹ýÉí·ÝÑéÖ¤µÄÓû§£¨Ô̺¬¶©ÔÄÕߣ©ËÁÒâ·¢³öStripeÍË¿î»òÈ¡µÞ¶©ÔÄÒªÇ󡣡£¡£¡£¡£¡£¡£ÎÊÌâÔ´ÓÚ²»µ±Ê¹Óú¯Êý¡°wpforms_is_admin_ajax()¡±£¬£¬ £¬£¬£¬ £¬£¬£¬Î´Ç¿ÔìÖ´ÐÐÖ°Äܲ鳭ÒÔÏ޶ȽӼû¡£¡£¡£¡£¡£¡£¡£·ì϶ӰÏìWPForms 1.8.4ÖÁ1.9.2.1°æ±¾£¬£¬ £¬£¬£¬ £¬£¬£¬ÒÑÔÚ1.9.2.2°æ±¾Öн¨¸´¡£¡£¡£¡£¡£¡£¡£WPFormsÊÇÒ»¸öÊ¢ÐеÄÍÏ·ÅʽWordPress±íµ¥¹¹½¨Æ÷£¬£¬ £¬£¬£¬ £¬£¬£¬Ö§³Ö¶àÖÖÖ§¸¶Æ½Ì¨¡£¡£¡£¡£¡£¡£¡£°²È«×êÑÐÔ±¡°vullu164¡±·¢Ïָ÷ì϶²¢»ã±¨¸øWordfence£¬£¬ £¬£¬£¬ £¬£¬£¬»ñµÃÉͽ𡣡£¡£¡£¡£¡£¡£WordfenceÈ·ÈÏ·ì϶ºó֪ͨ¹©¸øÉÌAwesome Motive£¬£¬ £¬£¬£¬ £¬£¬£¬ºóÕß°ä²¼½¨¸´°æ±¾¡£¡£¡£¡£¡£¡£¡£È»¶ø£¬£¬ £¬£¬£¬ £¬£¬£¬ÓÉÓÚԼĪһ°ëʹÓÃWPFormsµÄÍøÕ¾Î´Ê¹ÓÃ×îа汾£¬£¬ £¬£¬£¬ £¬£¬£¬Òò¶øÖÁÉÙÓÐ300Íò¸öÍøÕ¾ÈÔÃæ¶Ô·çÏÕ¡£¡£¡£¡£¡£¡£¡£Ö»¹ÜÉÐδ¼ì²âµ½Ò°±íÀûÓ㬣¬ £¬£¬£¬ £¬£¬£¬µ«ÈÔ½¨Ò龡¿ìÉý¼¶»ò½ûÓøòå¼þ¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/wpforms-bug-allows-stripe-refunds-on-millions-of-wordpress-sites/


6. Black BastaÀÕË÷Èí¼þÀûÓÃMS TeamsºÍµç×ÓÓʼþºäÕ¨´«²¼¶ñÒâÈí¼þ


12ÔÂ10ÈÕ£¬£¬ £¬£¬£¬ £¬£¬£¬Black BastaÀÕË÷Èí¼þ×éÖ¯½üÆÚ¸´ËÕ£¬£¬ £¬£¬£¬ £¬£¬£¬²¢ÌáÒéÁËÒ»³¡Õë¶ÔÈ«Çò×éÖ¯µÄ¸´ÔÓÉç»á¹¤³Ì»î¶¯¡£¡£¡£¡£¡£¡£¡£Rapid7×êÑÐÈËÔ±¶Ô´Ë½øÐÐÁ˾ßÌåµ÷²é£¬£¬ £¬£¬£¬ £¬£¬£¬²¢°ä²¼ÁËÒ»·Ýл㱨¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õßͨ¹ýµç×ÓÓʼþºäÕ¨¡¢Microsoft Teams¼ÙÒâÒÔ¼°ÀûÓÃQuickAssistºÍAnyDeskµÈ¹¤¾ß»ñȡԶ³Ì½Ó¼ûȨÏÞ£¬£¬ £¬£¬£¬ £¬£¬£¬ÈƹýMFA²¢Ö´ÐжñÒâ¸ºÔØ¡£¡£¡£¡£¡£¡£¡£ÔÚ´«²¼Black BastaÀÕË÷Èí¼þ֮ǰ£¬£¬ £¬£¬£¬ £¬£¬£¬ÍþвÐÐΪÕ߻ᲿÊðZbotºÍDarkGateµÈ¹¤¾ßÀ´»ñȡƾ֤¡¢Ð¹Â¶Êý¾ÝºÍά³ÖÓÆ¾ÃÐÔ¡£¡£¡£¡£¡£¡£¡£ËûÃÇʹÓÃÁ˸üеļ¼Êõ£¬£¬ £¬£¬£¬ £¬£¬£¬Èç×Ô½ç˵´ò°ü·¨Ê½»ìºÏÓÐÐ§ÔØºÉ¡¢Í¨¹ýrundll32.exeÖ´ÐÐDLLÒÔ¼°¸ß¼¶¶ã±ÜÕ½Êõ¡£¡£¡£¡£¡£¡£¡£ÎªÁË»º½â´ËÀ๥»÷µÄ·çÏÕ£¬£¬ £¬£¬£¬ £¬£¬£¬×é֯Ӧѡȡ¸ü׳´óµÄÃÜÂëÕ½Êõ¡¢Ìṩ°²È«Åàѵ²¢Ö´ÐÐÏȽøµÄ·ÀÓù´ëÊ©¡£¡£¡£¡£¡£¡£¡£Õâ´Î¹¥»÷»î¶¯Ê¼ÓÚµç×ÓÓʼþºäÕ¨£¬£¬ £¬£¬£¬ £¬£¬£¬Í¨¹ýÓÕÆ­Óû§ÊÚÓèÔ¶³Ì½Ó¼ûȨÏÞ£¬£¬ £¬£¬£¬ £¬£¬£¬×îÖÕÖ¸±êÊDz¿ÊðBlack BastaÀÕË÷Èí¼þ¼ÓÃܹؼüÊý¾Ý²¢Ë÷ÒªÊê½ð¡£¡£¡£¡£¡£¡£¡£


https://hackread.com/black-basta-gang-ms-teams-email-bombing-malware/