CleoÎļþ´«ÊäÈí¼þÁãÈÕ·ì϶ÔâºÚ¿ÍÀûÓýøÐÐÊý¾Ý͵ÇÔ¹¥»÷

°ä²¼¹¦·ò 2024-12-12

1. CleoÎļþ´«ÊäÈí¼þÁãÈÕ·ì϶ÔâºÚ¿ÍÀûÓýøÐÐÊý¾Ý͵ÇÔ¹¥»÷


12ÔÂ10ÈÕ £¬£¬£¬£¬£¬£¬£¬£¬ºÚ¿ÍÔÚ»ý¼«ÀûÓÃCleoÖÎÀíÎļþ´«ÊäÈí¼þÖеÄз¢ÏÖµÄÁãÈÕ·ì϶ £¬£¬£¬£¬£¬£¬£¬£¬ÇÖÈëÈ«ÇòÊýǧ¼Ò¹«Ë¾ÍøÂç £¬£¬£¬£¬£¬£¬£¬£¬Ô̺¬Target¡¢ÎÖ¶ûÂêµÈ³ÛÃûÆóÒµ £¬£¬£¬£¬£¬£¬£¬£¬½øÐÐÊý¾Ý͵ÇÔ¹¥»÷¡£¡£¡£¡£¡£¡£¸Ã·ì϶´æÔÚÓÚCleo LexiCom¡¢VLTraderºÍHarmony²úÆ·ÖÐ £¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐí²»ÊÜÏ޶ȵÄÎļþÉÏ´«ºÍÏÂÔØ £¬£¬£¬£¬£¬£¬£¬£¬µ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£¡£Ö»¹ÜCleo֮ǰÒѽ¨¸´ÁËÒ»¸öÓйطì϶CVE-2024-50623 £¬£¬£¬£¬£¬£¬£¬£¬µ«ÍþвÐÐΪÕßÈÔÈÆ¹ýÁ˽¨¸´³ÖÐø¹¥»÷¡£¡£¡£¡£¡£¡£ÍøÂ簲ȫר¼ÒÖ¸³ö £¬£¬£¬£¬£¬£¬£¬£¬ÕâЩ¹¥»÷ÓëеÄTermiteÀÕË÷Èí¼þÍÅ»ïÓйØ¡£¡£¡£¡£¡£¡£Huntress°²È«×êÑÐÈËÔ±³õ´Î·¢ÏÖÁ˸÷ì϶µÄ×Ô¶¯¹¥»÷ £¬£¬£¬£¬£¬£¬£¬£¬²¢ÖÒ¸æÓû§²ÉÈ¡´¹Î£Ðж¯ £¬£¬£¬£¬£¬£¬£¬£¬Ô̺¬½«ÏµÍ³ÒƵ½·À»ðǽºóÃæ £¬£¬£¬£¬£¬£¬£¬£¬ÏÞ¶È±í²¿½Ó¼û £¬£¬£¬£¬£¬£¬£¬£¬²¢²é³­¿ÉÒÉÎļþ¡£¡£¡£¡£¡£¡£CleoÒÑÈ·ÈÏ·ì϶´æÔÚ £¬£¬£¬£¬£¬£¬£¬£¬²¢ÔÚ¿ª·¢°²È«¸üР£¬£¬£¬£¬£¬£¬£¬£¬Í¬Ê±ÌṩÁË»º½â´ëÊ©½¨Òé¡£¡£¡£¡£¡£¡£¾Ý¹À¼Æ £¬£¬£¬£¬£¬£¬£¬£¬ÃÀ¹úÓоø´óÎÞÊýÒ×Êܹ¥»÷µÄ·þÎñÆ÷ £¬£¬£¬£¬£¬£¬£¬£¬È«ÇòÁìÓòÄÚÒÑÓÐÖÁÉÙÊ®¸ö×éÖ¯Êܵ½Ó°Ïì¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/new-cleo-zero-day-rce-flaw-exploited-in-data-theft-attacks/


2. AppLite Banker¶ñÒâÈí¼þÒÔÒøÐÐÀûÓ÷¨Ê½ÎªÖ¸±êÌáÒéÍøÂç´¹µö»î¶¯


12ÔÂ10ÈÕ £¬£¬£¬£¬£¬£¬£¬£¬Ò»³¡¸´ÔÓµÄÍøÂç´¹µö»î¶¯ÔÚ´«²¼ÃûΪAppLite BankerµÄжñÒâÈí¼þ±äÖÖ £¬£¬£¬£¬£¬£¬£¬£¬¸Ã¶ñÒâÈí¼þ±»¼ø±ðΪAntidotÒøÐÐľÂíµÄ¸üа汾 £¬£¬£¬£¬£¬£¬£¬£¬ÖØÒªÕë¶ÔAndroidÉ豸¡£¡£¡£¡£¡£¡£¹¥»÷Õßͨ¹ý¼ÙÒâ³ÛÃû¹«Ë¾ÕÐÆ¸ÈËԱijÈËÁ¦×ÊÔ´´ú±í £¬£¬£¬£¬£¬£¬£¬£¬·¢ËÍÍøÂç´¹µöµç×ÓÓʼþÊèµ¼Óû§ÏÂÔØÚ²Æ­ÐÔCRMÀûÓ÷¨Ê½ £¬£¬£¬£¬£¬£¬£¬£¬½ø¶ø×°ÖÃAppLite¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þÄÜÖ´ÐÐÆ¾Ö¤ÍµÇÔ¡¢ÀÄÓÃÎÞ×è°­·þÎñ¡¢Ô¶³Ì½ÚÔì¡¢ºýŪÐÔ¸²¸ÇµÈ¶àÖÖ¶ñÒâ»î¶¯ £¬£¬£¬£¬£¬£¬£¬£¬²¢Õë¶Ô172¸öÀûÓ÷¨Ê½ £¬£¬£¬£¬£¬£¬£¬£¬Ô̺¬½ðÈÚÆ½Ì¨ºÍ¼ÓÃÜÇ®°ü¡£¡£¡£¡£¡£¡£ÎªÈƹý¼ì²â £¬£¬£¬£¬£¬£¬£¬£¬AppLiteʹÓÃZIPÎļþ²Ù×÷ºÍǶÈëHTML¸²¸Ç²ã»ìºÏ°²È«¹¤¾ß¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þ¹¥»÷ÁìÓò¿í·º £¬£¬£¬£¬£¬£¬£¬£¬Éæ¼°¶àÖÖ˵»°Óû§ £¬£¬£¬£¬£¬£¬£¬£¬²¢ÄÜÇÔÈ¡ËøÆÁƾ֤×Ô¶¯½âËøÆÁÄ» £¬£¬£¬£¬£¬£¬£¬£¬ÊµÏÖÆëÈ«½ÚÔìÊÜϰȾÉ豸¡£¡£¡£¡£¡£¡£°²È«×êÑÐÈËԱǿµ÷×Ô¶¯·ÀÓù³ÁÒªÐÔ £¬£¬£¬£¬£¬£¬£¬£¬½¨ÒéÖ´ÐÐ׳´óµÄÒÆ¶¯É豸ÖÎÀíÕþ²ß²¢¶¨ÆÚ¸üÐÂÉ豸ºÍ°²È«Èí¼þÒÔ·À±¸´ËÀàÍþв¡£¡£¡£¡£¡£¡£


https://www.infosecurity-magazine.com/news/applite-malware-targets-banking/


3. Microsoft 365Öжϵ¼Ö Office WebÀûÓ÷¨Ê½ºÍÖÎÀíÖÐÐÄ̱»¾


12ÔÂ10ÈÕ £¬£¬£¬£¬£¬£¬£¬£¬Î¢ÈíÔÚµ÷²éһ·ӰÏìOffice WebÀûÓúÍMicrosoft 365ÖÎÀíÖÐÐĵĴóÃæ»ýÇÒ³ÖÐøµÄMicrosoft 365ÖжÏÊÂÎñ¡£¡£¡£¡£¡£¡£Óû§»ã±¨ÔÚÏνÓOutlook¡¢OneDriveºÍÆäËûOffice 365ÀûÓ÷¨Ê½ºÍ·þÎñʱ³öÏÖÎÊÌâ £¬£¬£¬£¬£¬£¬£¬£¬²¢ÊÕµ½·þÎñÖжϵÄÐÂÎÅ¡£¡£¡£¡£¡£¡£Î¢ÈíÖ¸³ö £¬£¬£¬£¬£¬£¬£¬£¬ÎÊÌâ¿ÉÄÜÓëÉí·ÝÑéÖ¤»ù´¡ÉèÊ©ÖеÄÁîÅÆÌìÉúÓÐ¹Ø £¬£¬£¬£¬£¬£¬£¬£¬²¢ÔÚÉó²é×î½üµÄ±ä¶¯ÒÔÈ·¶¨µ××ÓÔ­Òò¡£¡£¡£¡£¡£¡£×÷Ϊ½â¾ö²½Öè £¬£¬£¬£¬£¬£¬£¬£¬Î¢Èí½¨ÒéÊÜÓ°ÏìµÄÓû§Ê¹ÓÃ×ÀÃæÀûÓ÷¨Ê½½Ó¼ûMicrosoft 365ÀûÓ÷¨Ê½ºÍÎĵµ¡£¡£¡£¡£¡£¡£´Ëǰ £¬£¬£¬£¬£¬£¬£¬£¬Microsoft 365Ò²Ôø²úÉú¹ýÈ«ÇòÖжÏÊÂÎñ £¬£¬£¬£¬£¬£¬£¬£¬Ô̺¬Ó°Ïì¶àÏî·þÎñºÍÖ°ÄܵÄÇé¿ö¡£¡£¡£¡£¡£¡£¶øÔÚ7Ô £¬£¬£¬£¬£¬£¬£¬£¬Ò»´Î´ó¹æÄ£ÖжÏÔòÊÇÓÉÉ¢²¼Ê½»Ø¾ø·þÎñ£¨DDoS£©¹¥»÷ÒýÆðµÄ¡£¡£¡£¡£¡£¡£Ä¿Ç° £¬£¬£¬£¬£¬£¬£¬£¬Î¢ÈíÔÚ²âÊÔÒ»¸öDZÔڵĽ¨¸´·¨Ê½ £¬£¬£¬£¬£¬£¬£¬£¬²¢ÒѲ¿ÊðÁËÒ»¸ö½¨¸´·¨Ê½ÒÔ»º½âÖжÏÎÊÌâ¡£¡£¡£¡£¡£¡£Î¢Èí°µÊ¾ £¬£¬£¬£¬£¬£¬£¬£¬Õâ´ÎÖжÏÊÇÓÉÓÚ×î½üµÄ·þÎñµ÷»»µ¼Ö¼ø±ðÁîÅÆµ½ÆÚ¹¦·ò³öÏÖÎÊÌâ £¬£¬£¬£¬£¬£¬£¬£¬´Ó¶øµ¼ÖÂÉí·ÝÑéÖ¤ÒªÇóʧ°Ü¡£¡£¡£¡£¡£¡£¾­¹ýÒ»¶Î¹¦·òµÄ¼à¿Ø·þÎñÒ£²âºó £¬£¬£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾È·ÈϸÃÎÊÌâÏÖÒѽâ¾ö¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/microsoft/microsoft-365-outage-takes-down-office-web-apps-admin-center/


4. MetaÆìÏÂËÄ´óÉ罻ƽ̨ÔâÈ«ÇòÁìÓò¹¥»÷Ö·þÎñÖжÏ


12ÔÂ11ÈÕ £¬£¬£¬£¬£¬£¬£¬£¬È«ÇòÁìÓòÄÚµÄFacebook¡¢Instagram¡¢ThreadsºÍWhatsAppÔâ·êÁËÑϳÁ¹¥»÷ £¬£¬£¬£¬£¬£¬£¬£¬µ¼Ö·þÎñÖÐ¶Ï £¬£¬£¬£¬£¬£¬£¬£¬·ÖÆçµØÓòµÄÓû§Êܵ½ÁË·ÖÆçˮƽµÄÓ°Ïì¡£¡£¡£¡£¡£¡£¾ÝDownDetector³Æ £¬£¬£¬£¬£¬£¬£¬£¬ÖжϲúÉúÔÚÃÀ¹ú¶«²¿¹¦·òÏÂÎç12:40×óÓÒ £¬£¬£¬£¬£¬£¬£¬£¬ºÜ¶àÓû§ÎÞ·¨Í¨¹ýÍøÕ¾ºÍÀûÓ÷¨Ê½½Ó¼ûÕâЩ·þÎñ £¬£¬£¬£¬£¬£¬£¬£¬Ò²ÎÞ·¨Í¨¹ýWhatsApp·¢ËÍÐÂÎÅ¡£¡£¡£¡£¡£¡£µ±Óû§³¢ÊÔ½Ó¼ûFacebookʱ £¬£¬£¬£¬£¬£¬£¬£¬»áÊÕµ½ÃýÎóÌáÐÑ¡£¡£¡£¡£¡£¡£¹ÌÈ»MetaµÄÒµÎñÆ½Ì¨×´Ì¬Ò³ÃæÃ»ÓÐÏÔʾ´ó¹æÄ£·þÎñÖÐ¶Ï £¬£¬£¬£¬£¬£¬£¬£¬µ«MetaÈÏ¿ÉÁËÖжϵIJúÉú £¬£¬£¬£¬£¬£¬£¬£¬²¢°µÊ¾ÔÚÖÂÁ¦¸´Ô­·þÎñ¡£¡£¡£¡£¡£¡£²¿ÃŵØÓòµÄ·þÎñÔÚÃÀ¹ú¶«²¿¹¦·òÏÂÎç1:20×óÓÒÆðÍ·¸´Ô­ £¬£¬£¬£¬£¬£¬£¬£¬µ«ÈÔÓÐЧ»§»ã±¨ÎÞ·¨½Ó¼ûƽ̨¡£¡£¡£¡£¡£¡£´Ëǰ £¬£¬£¬£¬£¬£¬£¬£¬MetaÔøÔÚ3Ô·ݺÍ2021ÄêÔâ·ê¹ýÀàËÆµÄ·þÎñÖжÏ¡£¡£¡£¡£¡£¡£½ØÖÁÃÀ¹ú¶«²¿¹¦·ò12ÔÂ11ÈÕÏÂÎç7:21 £¬£¬£¬£¬£¬£¬£¬£¬Meta°µÊ¾ÖжÏÎÊÌâÒѸù»ù½â¾ö £¬£¬£¬£¬£¬£¬£¬£¬²¢ÏòÊÜÓ°ÏìµÄÓû§°µÊ¾Ç¸Òâ¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/technology/facebook-instagram-whatsapp-hit-by-massive-worldwide-outage/


5. ¹ú¼ÊÐж¯¡°Operation PowerOFF¡±³ÁÈ­½ø¹¥DDoS³ö×â·þÎñ


12ÔÂ11ÈÕ £¬£¬£¬£¬£¬£¬£¬£¬¹ú¼ÊÐж¯¡°Operation PowerOFF¡¹Øë¶ÔÍøÂç·¸×ïÖеÄÉ¢²¼Ê½»Ø¾ø·þÎñ£¨DDoS£©¹¥»÷»ñµÃÁËÏÔÖø³É¾Í¡£¡£¡£¡£¡£¡£À´×Ô15¸ö¹ú¶ÈµÄ·¨ÂÉ»ú¹¹ºÏ×÷ £¬£¬£¬£¬£¬£¬£¬£¬³É¹¦ÏÂÏßÁË27¸öDDoS³ö×â·þÎñƽ̨ £¬£¬£¬£¬£¬£¬£¬£¬¿ÛÁôÁËÈýÃûÖÎÀíÔ± £¬£¬£¬£¬£¬£¬£¬£¬²¢È·¶¨ÁËÕâЩƽ̨µÄ300Ãû¿Í»§¡£¡£¡£¡£¡£¡£ÕâЩƽ̨ÀûÓý©Ê¬ÍøÂç¶ÔÔÚÏßÖ¸±êÌáÒé¹¥»÷ £¬£¬£¬£¬£¬£¬£¬£¬¿ÉÄܵ¼Ö·þÎñÖжϺÍÒµÎñËðʧ £¬£¬£¬£¬£¬£¬£¬£¬³ö¸ñÊÇÔÚÍøÉϹºÎï¶¥·åÆÚ¡£¡£¡£¡£¡£¡£Å·ÖÞÐ̾¯×é֯Эµ÷ÁËÕâ´ÎÐж¯ £¬£¬£¬£¬£¬£¬£¬£¬Éæ¼°¶à¸ö¹ú¶È £¬£¬£¬£¬£¬£¬£¬£¬Õë¶Ô²Î¼Ó´ËÀà·¸×ïµÄ¸÷¸ö²ãÃæµÄÈËÔ±¡£¡£¡£¡£¡£¡£ÆäÖÐ £¬£¬£¬£¬£¬£¬£¬£¬ºÉÀ¼¾¯·½¿ÛÁôÁËËÄÃûÉæÏÓÖ´ÐÐDDoS¹¥»÷µÄÏÓÒÉÈË £¬£¬£¬£¬£¬£¬£¬£¬²¢È·¶¨ÁËÔ¼200ÃûÉæÏÓʹÓñ»²é»ñDDoS·þÎñµÄºÉÀ¼ÈË¡£¡£¡£¡£¡£¡£Õâ´ÎÐж¯µÄ³É¹¦µÃÒæÓÚÅ·ÖÞÐ̾¯×éÖ¯µÄ·ÖÎöÖ§³Ö¡¢¼ÓÃÜ×·×ÙÐÅÏ¢ÒÔ¼°½áºÏÍøÂç·¸×ï×´¶¯³ö¸ñ¹¤×÷×éר¼ÒµÄЭÖú¡£¡£¡£¡£¡£¡£´Ëǰ £¬£¬£¬£¬£¬£¬£¬£¬¡°Operation PowerOFF¡±ÒѶÔDDoS×âÁÞÁìÓò½øÐÐÁËÂŴνø¹¥ £¬£¬£¬£¬£¬£¬£¬£¬Ô̺¬²é·â´óÐÍÆ½Ì¨Dstat.ccºÍÈëÇÖ²¢¹Ø¹ØDigitalStress·þÎñ¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/operation-poweroff-shuts-down-27-ddos-for-hire-platforms/


6. Krispy KremeÔâÍøÂç¹¥»÷ £¬£¬£¬£¬£¬£¬£¬£¬Ó°ÏìÔÚÏß¶©¹ººÍÔËÓª


12ÔÂ11ÈÕ £¬£¬£¬£¬£¬£¬£¬£¬ÃÀ¹úÌðÌðȦÁ¬ËøµêKrispy KremeÔÚ2024Äê11ÔÂÔâ·êÁËÍøÂç¹¥»÷ £¬£¬£¬£¬£¬£¬£¬£¬µ¼ÖÂÆäÔÚÃÀ¹úµÄÔÚÏß¶©¹ºÏµÍ³ÖÐ¶Ï £¬£¬£¬£¬£¬£¬£¬£¬Ó°ÏìÁ˲¿ÃÅÒµÎñÔËÓª¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾Õ¼ÓÐ1,521¼ÒÃŵêºÍ¶à¶àÔ±¹¤ £¬£¬£¬£¬£¬£¬£¬£¬²¢ÓëÂóµ±À͵ȺÏ×÷ͬ°éÓлý¼«¹ØÏµ¡£¡£¡£¡£¡£¡£Êý×Ö¶©µ¥Õ¼¹«Ë¾ÏúÊÛ¶îµÄ15.5% £¬£¬£¬£¬£¬£¬£¬£¬¶Ô¹«Ë¾Òµ¼¨ÓгÁÒªÓ°Ïì¡£¡£¡£¡£¡£¡£ÔÚ¹¥»÷²úÉúºó £¬£¬£¬£¬£¬£¬£¬£¬Krispy KremeÁ¢¼´×·Çó¶¥¼âÍøÂ簲ȫר¼ÒµÄÔ®ÊÖ £¬£¬£¬£¬£¬£¬£¬£¬²¢²ÉÈ¡´ëÊ©½ÚÔìºÍ²¹¾ÈÊÂÎñ £¬£¬£¬£¬£¬£¬£¬£¬µ«µ÷²éÈÔÔÚ½øÐÐÖÐ £¬£¬£¬£¬£¬£¬£¬£¬¾ßÌåÓ°ÏìÉдýÆÀ¹À¡£¡£¡£¡£¡£¡£Õâ´Î¹¥»÷¶Ô¹«Ë¾µÄÒµÎñ²úÉúÁ˳Á´óÓ°Ïì £¬£¬£¬£¬£¬£¬£¬£¬²¢½«³ÖÐøµ½¸´Ô­ÊµÏÖΪֹ¡£¡£¡£¡£¡£¡£Í¬Ê± £¬£¬£¬£¬£¬£¬£¬£¬¹«Ë¾Ô¤¼ÆÊý×ÖÏúÊÛÊÕÈëµÄËðʧ¡¢ÍøÂ簲ȫר¼ÒºÍÕÕ·÷µÄÓöÈÒÔ¼°ÏµÍ³¸´Ô­¹¤×÷Óйصijɱ¾½«²úÉú³Á´óµÄ²ÆÕþÓ°Ïì¡£¡£¡£¡£¡£¡£Êг¡¶Ô´ËÐÂÎÅ×ö³öÁ˸ºÃæ·´Ó³ £¬£¬£¬£¬£¬£¬£¬£¬Krispy KremeµÄ¹É¼Û×ÅÂäÁË2%¡£¡£¡£¡£¡£¡£Ä¿Ç°Éв»Ã÷ÏÔÕâÊÇÒ»´ÎÀÕË÷Èí¼þ¹¥»÷»¹ÊÇÆäËûÀàÐ͵Ĺ¥»÷ £¬£¬£¬£¬£¬£¬£¬£¬Ò²Ã»ÓÐÀÕË÷Èí¼þ×éÖ¯¶ÔÕâ´Î¹¥»÷ÕÆ¹Ü¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/krispy-kreme-cyberattack-impacts-online-orders-and-operations/