αװ³ÉÈËΪµ¥µÄÍøÂç´¹ÂÚÓʼþ Qshing

Ðû²¼Ê±¼ä 2024-02-04

1. αװ³ÉÈËΪµ¥µÄÍøÂç´¹ÂÚÓʼþ Qshing 


2ÔÂ2ÈÕ£¬£¬£¬£¬£¬£¬£¬AhnLab Çå¾²Ç鱨ÖÐÐÄ (ASEC) ×î½ü·¢Ã÷Á˹ØÓÚµÄ Qshing µç×ÓÓʼþµÄÈö²¥ÇéÐΡ£¡£¡£¡£¡£¡£Qshing ÊÇ¡°QR Â롱ºÍ¡°ÍøÂç´¹ÂÚ¡±Á½¸ö´ÊµÄ¸´ºÏÃû´Ê£¬£¬£¬£¬£¬£¬£¬É¨Ãè QR Âëʱ»áµ¼ÖÂ×°ÖöñÒâÓ¦ÓóÌÐò»ò½«Óû§Ö¸µ¼ÖÁÍøÂç´¹ÂÚÍøÕ¾¡£¡£¡£¡£¡£¡£ÕýÔÚ·Ö·¢µÄµç×ÓÓʼþÈçͼ1Ëùʾ£¬£¬£¬£¬£¬£¬£¬Î±×°³É2024ÄêµÚÒ»¼¾¶ÈµÄÈËΪÊÕÌõÈ·ÈϺ¯£¬£¬£¬£¬£¬£¬£¬ÄÚÈݰüÀ¨ÌáÐÑÓû§Ê¹ÓÃÊÖ»úɨÃè¶þάÂëÁìÈ¡ÈËΪ½òÌùµÄÐÂÎÅ¡£¡£¡£¡£¡£¡£ÍþвÐÐΪÕßʹÓá°ahnlab.com¡±Î±×°·¢¼þÈ˵ç×ÓÓʼþµØµã£¬£¬£¬£¬£¬£¬£¬µ«ÏÖʵµÄ·¢¼þÈ˵ç×ÓÓʼþµØµã¿ÉÒÔÔÚµç×ÓÓʼþ±êÍ·Öп´µ½¡£¡£¡£¡£¡£¡£È»¶ø£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚÓû§Í¨³£²»»á¼ì²éµç×ÓÓʼþ±êÍ·£¬£¬£¬£¬£¬£¬£¬Òò´ËËûÃǺÜÄÑÒâʶµ½·¢¼þÈ˵ç×ÓÓʼþµØµãÒѱ»Î±Ôì¡£¡£¡£¡£¡£¡£


https://asec.ahnlab.com/en/61104/


2. SeedProd ²å¼þÖеÄÎó²îÓ°Ïì 90 ¶àÍò¸ö WordPress ÍøÕ¾


2ÔÂ1ÈÕ£¬£¬£¬£¬£¬£¬£¬Ò»¸öÊ¢ÐÐµÄ WordPress ²å¼þÖз¢Ã÷ÁËÒ»¸ö¸ßÑÏÖØÐÔȱÏÝ¡£¡£¡£¡£¡£¡£ÊÜÓ°ÏìµÄ²å¼þ£¬£¬£¬£¬£¬£¬£¬SeedProd µÄ Website Builder£¬£¬£¬£¬£¬£¬£¬×°ÖÃÁ¿Áè¼Ý 900,000 ´Î¡£¡£¡£¡£¡£¡£SeedProd µÄ Website Builder ÊÇÒ»¿î¹¦Ð§Ç¿Ê¢ÇÒÓû§ÓÑºÃµÄ WordPress ²å¼þ£¬£¬£¬£¬£¬£¬£¬Ö¼ÔÚ¼ò»¯½¨ÉèºÍ×Ô½çËµÍøÕ¾µÄÀú³Ì¡£¡£¡£¡£¡£¡£SeedProd ÒòÆäÍϷŹ¦Ð§¶ø³ÉΪ WordPress Óû§ÖкÜÊÇÊܽӴýµÄÑ¡Ôñ£¬£¬£¬£¬£¬£¬£¬Ê¹Óû§ÎÞÐè±àд´úÂë¼´¿ÉÇáËÉÉè¼ÆºÍ¹¹½¨×Ô½çËµÍøÕ¾¡£¡£¡£¡£¡£¡£¸ÃȱÏݱ»³ÆÎª CVE-2024-1072£¬£¬£¬£¬£¬£¬£¬ÑÏÖØË®Æ½Îª 8.2 ¼¶£¨Âú·Ö 10 ¼¶£©¡£¡£¡£¡£¡£¡£ÕâÖ֏߯À¼¶Ç¿µ÷ÁËËü¿ÉÄÜÔì³ÉµÄDZÔÚÆÆË𣬣¬£¬£¬£¬£¬£¬ÔÊÐíδ¾­ÊÚȨµÄÖ°Ô±¸Ä¶¯ WordPress ÍøÕ¾µÄ½á¹¹¡£¡£¡£¡£¡£¡£CVE-2024-1072 µÄ»ù´¡Ôµ¹ÊÔ­ÓÉÔÚÓÚ¡°seedprod_lite_new_lpage¡±º¯ÊýÖÐȱÉÙ¹¦Ð§¼ì²é¡£¡£¡£¡£¡£¡£ÕâÖÖȱʧÒâζ×Å×ÝȻδ¾­Éí·ÝÑéÖ¤µÄÓû§Ò²¿ÉÄÜ»áÆ¾Ö¤×Ô¼ºµÄÒâԸŤÇúºÍת»»ÍøÒ³ÄÚÈÝ£¬£¬£¬£¬£¬£¬£¬½«¼´½«ÍƳö»òά»¤µÄÒ³ÃæÊ¹ÓÃΪÎÞ·¨Ê¶±ðµÄÒÔǰ°æ±¾¡£¡£¡£¡£¡£¡£


https://securityonline.info/cve-2024-1072-critical-flaw-in-seedprod-plugin-exposes-900k-wordpress-sites/


3. FTC ¾Í´ó¹æÄ£Êý¾Ýй¶ÊÂÎñÓë Blackbaud ¸æ¿¢Ï¢Õù


2ÔÂ2ÈÕ£¬£¬£¬£¬£¬£¬£¬Êý¾ÝºÍÈí¼þЧÀ͹«Ë¾ Blackbaud ½«±»ÒªÇóɾ³ý²»ÐèÒªµÄСÎÒ˽¼ÒÊý¾Ý£¬£¬£¬£¬£¬£¬£¬×÷ΪÁª°îÉÌҵίԱ»áÏ¢ÕùЭÒéµÄÒ»²¿·Ö£¬£¬£¬£¬£¬£¬£¬¸ÃÏ¢ÕùЭÒéÒªÇó¸Ã¹«Ë¾¶Ô²»Á¼Êý¾Ý×ö·¨ÈÏÕæ£¬£¬£¬£¬£¬£¬£¬µ¼ÖºڿÍÇÔÈ¡ÊôÓÚÊý°ÙÍò¿Í»§µÄÃô¸ÐÐÅÏ¢¸Ã»ú¹¹ÖÜËÄÐû²¼¡£¡£¡£¡£¡£¡£Õâ¼Ò×ܲ¿Î»ÓÚÄÏ¿¨ÂÞÀ´ÄÉÖݵĹ«Ë¾±¡ÈõµÄÇå¾²²½·¥ÓëÆäÔÚÒþ˽Õþ²ßÖÐÏò¿Í»§×ö³öµÄÔÊÐíÏàì¶Ü£¬£¬£¬£¬£¬£¬£¬µ¼Ö 2020 Äê 2 ÔÂÎ¥¹æÊÂÎñ±³ºóµÄºÚ¿ÍÄܹ»»á¼û°üÀ¨Êý°ÙÍòÏûºÄÕßδ¼ÓÃÜСÎÒ˽¼ÒÊý¾ÝµÄÎļþ£¬£¬£¬£¬£¬£¬£¬°üÀ¨Éç»áÇå¾²ºÅÂë¡¢²ÆÎñºÍÒ½ÁÆÐÅÏ¢¡¢Áª°îÉÌҵίԱ»áÌåÏÖ£¬£¬£¬£¬£¬£¬£¬¾ÍÒµÐÅÏ¢ºÍÕË»§Æ¾Ö¤ÒÔ¼°´ó×ÚÆäËû¸ß¶ÈСÎÒ˽¼Ò»¯µÄÊý¾Ý¡£¡£¡£¡£¡£¡£Æ¾Ö¤ FTC µÄͶËߣ¬£¬£¬£¬£¬£¬£¬Blackbaud µÄ¿Í»§¡ª¡ªÔ¼Äª 45,000 ¼Ò¹«Ë¾¡¢Ñ§Ð£¡¢·ÇÓªÀû×éÖ¯¡¢Ò½ÁƱ£½¡×éÖ¯ºÍСÎÒ˽¼ÒÏûºÄÕß¡ª¡ªÊ¹ÓÃÆä²ÆÎñ¡¢³ï¿îºÍÖÎÀíÈí¼þЧÀÍ¡£¡£¡£¡£¡£¡£Blackbaud ÔÚ 2022 Äê׬ȡÁËÔ¼ 11 ÒÚÃÀÔª£¬£¬£¬£¬£¬£¬£¬µ«ÔÚÊý¾Ýй¶ºó½öÏòÓÐÏÞÊýÄ¿µÄÊÜÓ°ÏìÏûºÄÕßÌṩÐÅÓÃ¼à¿ØÐ§ÀÍ¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÍøÕ¾ÉÏûÓÐÁгö½²»°ÈË£¬£¬£¬£¬£¬£¬£¬×ܲ¿Ò²Ã»ÓнÓÏßÔ±¡£¡£¡£¡£¡£¡£·¢Ë͸ø¸Ã¹«Ë¾¶à¸ö²¿·Ö£¨ÀýÈçÏúÊ۰칫ÊÒ£©µÄµç×ÓÓʼþûÓÐÁ¬Ã¦»ñµÃ»Ø¸´¡£¡£¡£¡£¡£¡£Áª°îÉÌҵίԱ»áÌåÏÖ£¬£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾ÔÚ·¢Ã÷Î¥¹æÐÐΪºóÆÚ´ýÁ˽üÁ½¸öÔ²żû¸æ¿Í»§£¬£¬£¬£¬£¬£¬£¬È»ºóÓÕÆ­ËûÃǼû¸æÆäÑÏÖØÐÔ£¬£¬£¬£¬£¬£¬£¬²¢³Æ¸Ã¹«Ë¾µÄÊӲ조¼«Æä²»³ä·Ö¡±¡£¡£¡£¡£¡£¡£


https://therecord.media/ftc-settles-with-blackbaud-over-data-handling-breach


4. ÎÚ¿ËÀ¼¾ü·½ÔâÊܶíÂÞ˹ APT PowerShell ¹¥»÷


2ÔÂ2ÈÕ£¬£¬£¬£¬£¬£¬£¬Õâ´Î¹¥»÷ºÜ¿ÉÄÜÊÇÓÉÓë Shuckworm Ïà¹ØµÄ¶ñÒâÍþвÐÐΪÕßʵÑéµÄ£¬£¬£¬£¬£¬£¬£¬¸Ã×éÖ¯ÀúÊ·ÉÏÔø³öÓÚµØÔµÕþÖΡ¢Ìع¤ºÍÆÆËðÀûÒæµÄÄîÍ·Õë¶ÔÎÚ¿ËÀ¼Ìᳫ¹ý¹¥»÷»î¶¯¡£¡£¡£¡£¡£¡£Securonix ÒÔ STEADY#URSA µÄÃû³Æ¸ú×ٵĶñÒâ»î¶¯½ÓÄÉÁËз¢Ã÷µÄ»ùÓÚ SUBTLE-PAWS PowerShell µÄºóÃÅÀ´ÉøÍ¸ºÍΣº¦Ä¿µÄϵͳ¡£¡£¡£¡£¡£¡£ÕâÖÖÀàÐ͵ĺóÃÅÔÊÐíÍþвÐÐΪÕß»ñµÃδ¾­ÊÚȨµÄ»á¼û¡¢Ö´ÐÐÏÂÁî²¢ÔÚÊÜѬȾµÄϵͳÖмá³Ö³¤ÆÚÐÔ¡£¡£¡£¡£¡£¡£¹¥»÷ÒªÁìÉæ¼°Í¨¹ýÍøÂç´¹ÂÚµç×ÓÓʼþ´«Ë͵ÄѹËõÎļþÀ´·Ö·¢¶ñÒâ¸ºÔØ¡£¡£¡£¡£¡£¡£¶ñÒâÈí¼þµÄ·Ö·¢ºÍºáÏòÒÆ¶¯ÊÇͨ¹ý USB Çý¶¯Æ÷¾ÙÐе쬣¬£¬£¬£¬£¬£¬Òò´ËÎÞÐèÖ±½Ó»á¼ûÍøÂç¡£¡£¡£¡£¡£¡£¸Ã±¨¸æÖ¸³ö£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚÎÚ¿ËÀ¼µÄÐÇÁ´µÈÆøÏ¶Í¨Ñ¶£¬£¬£¬£¬£¬£¬£¬ÕâÖÖÒªÁ콫»á±äµÃÄÑÌâ¡£¡£¡£¡£¡£¡£¸Ã»î¶¯Óë Shuckworm ¶ñÒâÈí¼þÓÐÏàËÆÖ®´¦£¬£¬£¬£¬£¬£¬£¬²¢ÇÒÈÚºÏÁË֮ǰÕë¶ÔÎÚ¿ËÀ¼¾ü·½µÄÍøÂç»î¶¯ÖÐÊӲ쵽µÄ²î±ðÕ½ÂÔ¡¢ÊÖÒպͳÌÐò (TTP)¡£¡£¡£¡£¡£¡£Securonix ÍþвÑо¿ºÍÊý¾Ý¿ÆÑ§/È˹¤ÖÇÄܸ±×ܲà Oleg Kolesnikov Ú¹ÊÍ˵£¬£¬£¬£¬£¬£¬£¬SUBTLE-PAWS µÄÆæÒìÖ®´¦ÔÚÓÚÆä¡°Ïàµ±ÆæÒ족µØÒÀÀµ´ÅÅÌÍâ/PowerShell stager Ö´ÐУ¬£¬£¬£¬£¬£¬£¬×èÖ¹Á˹ŰåµÄ¶þ½øÖÆÓÐÓøºÔØ¡£¡£¡£¡£¡£¡£Ëü»¹½ÓÄÉÁËÌØÁíÍâ»ìÏýºÍ¹æ±ÜÊÖÒղ㡣¡£¡£¡£¡£¡£


https://www.darkreading.com/cyberattacks-data-breaches/ukraine-military-targeted-with-russian-apt-powershell-attack


5. Îå½Ç´óÂ¥ÕýÔÚÊÓ²ìÀÕË÷Èí¼þ×é֯͵ÇÔÃô¸ÐÎļþµÄÇéÐÎ


1ÔÂ31ÈÕ£¬£¬£¬£¬£¬£¬£¬Îå½Ç´óÂ¥½²»°È˸æËß CyberScoop£¬£¬£¬£¬£¬£¬£¬ÈÏÕæÅä¾°ÊÓ²ìµÄ¹ú·À²¿°ì¹«ÊÒÕýÔÚÓëÖ´·¨²¿·ÖÏàÖú£¬£¬£¬£¬£¬£¬£¬ÊÓ²ìÒ»¸ö¶à²úÀÕË÷Èí¼þ×éÖ¯µÄÖ¸¿Ø£¬£¬£¬£¬£¬£¬£¬¸Ã×éÖ¯Éù³ÆËûÃÇÇÔÈ¡Á˰üÀ¨ÓëÃÀ¹ú¾ü·½ÓйصÄÃô¸ÐÊý¾ÝµÄÎļþ¡£¡£¡£¡£¡£¡£ÃûΪALPHV»òBlackCatµÄÀÕË÷Èí¼þ×éÖ¯ÖܶþÔçЩʱ¼äÌåÏÖ£¬£¬£¬£¬£¬£¬£¬ËûÃÇ´Ó Technica ÇÔÈ¡²¢Íþвй¶ 300 GB µÄÊý¾Ý¡£¡£¡£¡£¡£¡£Technica ÊÇÒ»¼Ò×ܲ¿Î»ÓÚ¸¥¼ªÄáÑÇÖÝµÄ IT ЧÀ͹«Ë¾£¬£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾×Ô³ÆÓëÁª°îÕþ¸®ÏàÖú£¬£¬£¬£¬£¬£¬£¬¡°ËûÃǵÄʹÃüÊÇÖ§³Ö¡¢ÊØÎÀºÍ±£» £»£»£»£»£»¤ÃÀ¹ú¹«Ãñ¡£¡£¡£¡£¡£¡£¡±¸Ã¹«Ë¾Ã»Óлظ´¶à·â×·ÇóÖÃÆÀµÄµç×ÓÓʼþ£¬£¬£¬£¬£¬£¬£¬Ò²ÎÞ·¨Í¨¹ýµç»°ÁªÏµµ½¸Ã¹«Ë¾¡£¡£¡£¡£¡£¡£ALPHV Éù³ÆÍ¨¹ýÉæÏÓÆÆËð Technica£¬£¬£¬£¬£¬£¬£¬»ñµÃÁËÓë¹ú·À·´Ç鱨ºÍÇå¾²¾ÖÏà¹ØµÄÊý¾Ý£¬£¬£¬£¬£¬£¬£¬¸Ã»ú¹¹ÈÏÕæ¾ÙÐÐÅä¾°ÊÓ²ìºÍÄÚ²¿ÍþвÆÊÎö¡£¡£¡£¡£¡£¡£ÎªÁËÖ§³ÖÆä˵·¨£¬£¬£¬£¬£¬£¬£¬ALPHV Ðû²¼Á˶þÊ®¶àÕžݳƱ»µÁÎļþµÄÆÁÄ»½ØÍ¼£¬£¬£¬£¬£¬£¬£¬ÆäÖаüÀ¨ÊýÊ®È˵ÄÐÕÃû¡¢Éç»áÇå¾²ºÅÂë¡¢ÔÊÐí¼¶±ðÒÔ¼°½ÇÉ«ºÍÊÂÇéËùÔÚ¡£¡£¡£¡£¡£¡£ÕâЩÆÁÄ»½ØÍ¼°üÀ¨Õ˵¥·¢Æ±¡¢´ÓÁª°îÊÓ²ì¾Öµ½ÃÀ¹ú¿Õ¾üµÈʵÌåµÄÌõÔ¼£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°ÓëÃÀ¹úÕþ¸®Ç©ÊðÌõÔ¼µÄ˽ÈËʵÌåºÍÉèÊ©µÄÏà¹ØÐÅÏ¢¡£¡£¡£¡£¡£¡£


https://cyberscoop.com/technica-pentagon-alphv-ransomware/?&web_view=true


6. ÄÏ·ÇÌú·¹«Ë¾ÒòÍøÂç´¹ÂÚÕ©Æ­ËðʧÁè¼Ý 100 ÍòÃÀÔª


2ÔÂ3ÈÕ£¬£¬£¬£¬£¬£¬£¬ÄÏ·Ç¿ÍÔËÌú·¾Ö (PRASA)ÔÚÆäÄê¶È±¨¸æÖÐÌåÏÖ£¬£¬£¬£¬£¬£¬£¬ÔâÓöÍøÂç´¹ÂÚÕ©Æ­£¬£¬£¬£¬£¬£¬£¬ËðʧԼ 3060 ÍòÀ¼ÌØ£¨160 ÍòÃÀÔª£©¡£¡£¡£¡£¡£¡£ÒÑ×·»ØÏ®»÷±³ºóµÄ·¸·¨·Ö×ÓËùµÁ×ʽðµÄÒ»°ë¶àÒ»µã¡£¡£¡£¡£¡£¡£Æ¾Ö¤Ìú·²¿·ÖµÄ±¨¸æ£¬£¬£¬£¬£¬£¬£¬´Ë´Î¹¥»÷¿ÉÄÜÊÇÒ»ÃûÔ±¹¤ËùΪ£¬£¬£¬£¬£¬£¬£¬ËûΪԱ¹¤½¨ÉèÁËÓÄÁéÕË»§£¬£¬£¬£¬£¬£¬£¬ÒÔ͵ȡ×ʽ𡣡£¡£¡£¡£¡£ÌúÂ·ÍøÂçºÍÔËÊäÏµÍ³ÃæÁÙ¶àÖÖÍøÂçÍþв£¬£¬£¬£¬£¬£¬£¬ÍþвÆäÔËÓªÍêÕûÐÔºÍÊý¾ÝÇå¾²¡£¡£¡£¡£¡£¡£ÌúÂ·ÏµÍ³ÍøÂçÖÐÖð½¥½ÓÄÉÎïÁªÍø (IoT) ×°±¸Ò²´øÀ´ÁËÎó²î£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÄÜ»áʹÓÃÕâЩÎó²îÀ´»ñµÃδ¾­ÊÚȨµÄ»á¼û»òʹÓÃÊý¾Ý¡£¡£¡£¡£¡£¡£ÎªÁËÓ¦¶ÔÕâÒ»ÌôÕ½£¬£¬£¬£¬£¬£¬£¬Ìú·ÔËÓªÉÌÓëÊÖÒÕר¼Ò½¨ÉèÁËÏàÖúͬ°é¹ØÏµ£¬£¬£¬£¬£¬£¬£¬ÒÔÔöÇ¿ÆäÍøÂçÇå¾²µ¯ÐÔ¡£¡£¡£¡£¡£¡£


https://www.darkreading.com/endpoint-security/south-african-railways-reports-1m-phishing?&web_view=true