CLOROX Ô¤¼Æ 8 Ô·ÝÍøÂç¹¥»÷Ôì³ÉµÄËðʧ½«Áè¼Ý 4900 ÍòÃÀÔª

Ðû²¼Ê±¼ä 2024-02-05

1. CLOROX Ô¤¼Æ 8 Ô·ÝÍøÂç¹¥»÷Ôì³ÉµÄËðʧ½«Áè¼Ý 4900 ÍòÃÀÔª


2ÔÂ3ÈÕ£¬£¬ £¬£¬£¬£¬£¬Õâ¼ÒÇå½à²úÆ·¾ÞÍ· ÓÚ 8 ÔÂÖÐÑ®Ðû²¼£¬£¬ £¬£¬£¬£¬£¬ËüÊÇÒ»´ÎÍøÂçÇå¾²ÊÂÎñµÄÊܺ¦Õß £¬£¬ £¬£¬£¬£¬£¬¸ÃÊÂÎñÆÈʹËü¹Ø±ÕÁËһЩϵͳ¡£¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬ £¬£¬£¬£¬£¬¸ßÀÖÊÏÉÐδ·ÖÏíÍøÂç¹¥»÷µÄÊÖÒÕϸ½Ú¡£¡£¡£¡£¡£¡£ËùÐÎòµÄÓ°ÏìÅú×¢¸Ã¹«Ë¾¿ÉÄÜÔâÊÜÀÕË÷Èí¼þ¹¥»÷¡£¡£¡£¡£¡£¡£Æ¾Ö¤Ïò SEC Ìá½»µÄÎļþ£¬£¬ £¬£¬£¬£¬£¬Clorox Ô¤¼Æ 2023 Äê 8 ÔÂÏ®»÷¸Ã¹«Ë¾µÄÍøÂç¹¥»÷Ôì³ÉµÄ¾­¼ÃÓ°ÏìΪ 4900 ÍòÃÀÔª¡£¡£¡£¡£¡£¡£ÕâЩ±¾Ç®°üÀ¨ÖÐÖ¹Ôì³ÉµÄËðʧ£¬£¬ £¬£¬£¬£¬£¬ÒÔ¼°Ð­Öú¹«Ë¾ÊÓ²ìºÍµ÷½â¹¥»÷µÄµÚÈý·½È¡Ö¤ºÍÕÕÁϵÄÓöÈ¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾»¹Ô¤¼Æ 2024 ²ÆÄêÒµ¼¨½«·ºÆð¸ºÃæÓ°Ïì¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾Ôö²¹Ëµ£¬£¬ £¬£¬£¬£¬£¬ÔÚ×èÖ¹ 2023 Äê 12 Ô 31 ÈÕµÄÈý¸öÔºÍÁù¸öÔÂÄÚ£¬£¬ £¬£¬£¬£¬£¬ËüûÓмͼÓëÍøÂç¹¥»÷Ïà¹ØµÄÈκΰü¹ÜÊÕÒæ¡£¡£¡£¡£¡£¡£°ü¹ÜÅâ³¥¼òÖ±ÈÏ£¨ÈôÊÇÊÊÓã©¿ÉÄÜÓëÈ·ÈÏÏà¹ØÓöȵÄʱ¼ä·×ÆçÖ¡£¡£¡£¡£¡£¡£


https://securityaffairs.com/158575/security/clorox-attack-costs-exceed-49m.html


2. AnyDesk Ôâµ½ºÚ¿ÍÈëÇÖ£¬£¬ £¬£¬£¬£¬£¬ÆäÉú²úЧÀÍÆ÷ÃÜÂë±»ÖØÖÃ


2ÔÂ2ÈÕ£¬£¬ £¬£¬£¬£¬£¬AnyDesk ½ñÌì֤ʵ£¬£¬ £¬£¬£¬£¬£¬Ëü×î½üÔâÊÜÁËÒ»´ÎÍøÂç¹¥»÷£¬£¬ £¬£¬£¬£¬£¬ºÚ¿ÍµÃÒÔ»á¼û¸Ã¹«Ë¾µÄÉú²úϵͳ¡£¡£¡£¡£¡£¡£BleepingComputer »ñϤ£¬£¬ £¬£¬£¬£¬£¬Ô´´úÂëºÍ˽ÓдúÂëÊðÃûÃÜÔ¿ÔÚ¹¥»÷ʱ´ú±»µÁ¡£¡£¡£¡£¡£¡£AnyDesk ÊÇÒ»ÖÖÔ¶³Ì»á¿´·¨¾ö¼Æ»®£¬£¬ £¬£¬£¬£¬£¬ÔÊÐíÓû§Í¨¹ýÍøÂç»ò»¥ÁªÍøÔ¶³Ì»á¼ûÅÌËã»ú¡£¡£¡£¡£¡£¡£¸Ã³ÌÐòºÜÊÇÊÜÆóÒµ½Ó´ý£¬£¬ £¬£¬£¬£¬£¬ÆóҵʹÓÃËüÀ´ÌṩԶ³ÌÖ§³Ö»ò»á¼ûÍйÜЧÀÍÆ÷¡£¡£¡£¡£¡£¡£¸ÃÈí¼þÔÚÍþвÐÐΪÕßÖÐÒ²ºÜÊܽӴý£¬£¬ £¬£¬£¬£¬£¬ËûÃÇʹÓÃËüÀ´ Ò»Á¬»á¼ûÊÜÆÆËðµÄ×°±¸ºÍÍøÂç¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾±¨¸æ³ÆÓµÓÐ 170,000 Ãû¿Í»§£¬£¬ £¬£¬£¬£¬£¬°üÀ¨ 7-11¡¢¿µ¿¨Ë¹ÌØ¡¢ÈýÐÇ¡¢ÂéÊ¡Àí¹¤Ñ§Ôº¡¢Ó¢Î°´ï¡¢Î÷ÃÅ×ÓºÍÁªºÏ¹ú¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/anydesk-says-hackers-breached-its-production-servers-reset-passwords/#google_vignette


3. Uber ±»ºÉÀ¼Êý¾Ýî¿Ïµ»ú¹¹·£¿£¿£¿î 1000 ÍòÅ·Ôª


2ÔÂ1ÈÕ£¬£¬ £¬£¬£¬£¬£¬ºÉÀ¼Êý¾Ý±£»£»£»£»£»£»£»¤»ú¹¹·¢Ã÷ Uber δÄܹûÕæÆäÉúÑÄ˾»úÊý¾ÝµÄʱ¼äÒÔ¼°ÄÄЩŷÖÞÒÔÍâµÄÔ±¹¤¿ÉÒÔ»á¼ûÕâЩÊý¾Ý£¬£¬ £¬£¬£¬£¬£¬Òò´Ë¸Ã»ú¹¹±ØÐèÏò Uber Ö§¸¶ 1000 ÍòÅ·ÔªµÄ·£¿£¿£¿î¡£¡£¡£¡£¡£¡£´Ë´Î·£¿£¿£¿îÊÇÆ¾Ö¤ 172 Ãû·¨¹ú Uber ˾»úºÍ×ܲ¿Î»ÓÚ°ÍÀèµÄÃñ¼äÉç»á×éÖ¯ Ligue des Droits de l'Homme et du Citoyen (LDH) Ìá³öµÄͶËß¶ø±¬·¢µÄ¡£¡£¡£¡£¡£¡£×î³õµÄͶËßÊÇÏò·¨¹úÊý¾Ýî¿Ïµ»ú¹¹Ìá³öµÄ£¬£¬ £¬£¬£¬£¬£¬µ«ÓÉÓڸù«Ë¾µÄÅ·ÖÞ×ܲ¿Î»ÓÚ°¢Ä·Ë¹Ìص¤£¬£¬ £¬£¬£¬£¬£¬Òò´ËºÉÀ¼î¿Ïµ»ú¹¹¼ç¸ºÁËͳÁìȨ¡£¡£¡£¡£¡£¡£ºÉÀ¼ÃÀÁªÉçÖ÷ϯ°¢À³µÂ¡¤ÎÖ¶û·òÉ­ (Aleid Wolfsen) ÌåÏÖ£º¡°Uber Óû§ÓÐȨ֪µÀ Uber ÈçÄÇÀïÖÃËûÃǵÄÊý¾Ý¡£¡£¡£¡£¡£¡£¿ÉÊÇ£¬£¬ £¬£¬£¬£¬£¬Uber ²¢Ã»ÓжԴ˾ÙÐÐ×ã¹»ÇåÎúµÄÚ¹ÊÍ¡£¡£¡£¡£¡£¡£¡± ¡°ÕâÅú×¢ Uber ÉèÖÃÁËÖÖÖÖÕϰ­£¬£¬ £¬£¬£¬£¬£¬×èÖ¹Óû§ÐÐʹÆäÒþ˽Ȩ£¬£¬ £¬£¬£¬£¬£¬¶øÕâÊDZ»Õ¥È¡µÄ¡£¡£¡£¡£¡£¡£¡±


https://www.bankinfosecurity.com/uber-fined-10-million-euros-by-dutch-data-regulator-a-24250?&web_view=true


4. ¹ú¼ÊÐ̾¯×éÖ¯ Synergia Ðж¯´Ý»Ù 1300 ̨ÓÃÓÚ·¸·¨µÄЧÀÍÆ÷


2ÔÂ2ÈÕ£¬£¬ £¬£¬£¬£¬£¬´úºÅΪ¡°Synergia¡±µÄ¹ú¼ÊÖ´·¨Ðж¯ÒѹرÕÁË 1,300 ¶à¸öÓÃÓÚÀÕË÷Èí¼þ¡¢ÍøÂç´¹ÂںͶñÒâÈí¼þ»î¶¯µÄÏÂÁîºÍ¿ØÖÆÐ§ÀÍÆ÷¡£¡£¡£¡£¡£¡£ÏÂÁîºÍ¿ØÖÆÐ§ÀÍÆ÷ (C2) ÊÇÓÉÍþвÐÐΪÕß²Ù×÷µÄ×°±¸£¬£¬ £¬£¬£¬£¬£¬ÓÃÓÚ¿ØÖƹ¥»÷ÖÐʹÓõĶñÒâÈí¼þ²¢ÍøÂç´ÓÊÜѬȾװ±¸·¢Ë͵ÄÐÅÏ¢¡£¡£¡£¡£¡£¡£ÕâЩЧÀÍÆ÷ÔÊÐíÍþвÐÐΪÕßÍÆËÍÌØÁíÍâÓÐÓøºÔØ»òÏÂÁîÒÔÔÚÊÜѬȾµÄ×°±¸ÉÏÖ´ÐУ¬£¬ £¬£¬£¬£¬£¬Ê¹ËüÃdzÉΪÐí¶à¹¥»÷Öв»¿É»òȱµÄ¼Ü¹¹¡£¡£¡£¡£¡£¡£¹ØÓÚijЩ¶ñÒâÈí¼þ£¬£¬ £¬£¬£¬£¬£¬Ê¹ÏÂÁîºÍ¿ØÖÆÐ§ÀÍÆ÷ÍÑ»ú¿ÉÒÔ±ÜÃâ½øÒ»²½µÄ¶ñÒâ»î¶¯£¬£¬ £¬£¬£¬£¬£¬ÓÉÓÚÍþвÐÐΪÕßÎÞ·¨´ÓÊÜѬȾµÄ×°±¸·¢ËÍ»òÎüÊÕÊý¾Ý¡£¡£¡£¡£¡£¡£Synergia Ðж¯ÔÚ 2023 Äê 9 ÔÂÖÁ 11 ÔÂʱ´úʶ±ð²¢¹Ø±ÕÁËÖ¸»ÓºÍ¿ØÖÆÐ§ÀÍÆ÷£¬£¬ £¬£¬£¬£¬£¬À´×Ô 55 ¸ö¹ú¼ÒµÄ 60 ¸öÖ´·¨»ú¹¹¼ÓÈëÁ˸ÃÐж¯¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/legal/interpol-operation-synergia-takes-down-1-300-servers-used-for-cybercrime/


5.FritzFrog ½©Ê¬ÍøÂç¹¥»÷ Linux ЧÀÍÆ÷ÇÔÈ¡ SSH ƾ֤


2ÔÂ2ÈÕ£¬£¬ £¬£¬£¬£¬£¬FritzFrog ½©Ê¬ÍøÂç×î³õÓÚ 2020 Äê±»·¢Ã÷£¬£¬ £¬£¬£¬£¬£¬ÊÇÒ»ÖÖÓà Golang ¹¹½¨µÄ¸ß¼¶µã¶Ôµã½©Ê¬ÍøÂ磬£¬ £¬£¬£¬£¬£¬¿ÉÒÔÔÚ»ùÓÚ AMD ºÍ ARM µÄ×°±¸ÉÏÔËÐС£¡£¡£¡£¡£¡£Ëæ×ÅÒ»Ö±µÄ¸üУ¬£¬ £¬£¬£¬£¬£¬¶ñÒâÈí¼þËæ×Åʱ¼äµÄÍÆÒÆÒ»Ö±Éú³¤£¬£¬ £¬£¬£¬£¬£¬Ìí¼ÓºÍÔöÇ¿Á˹¦Ð§¡£¡£¡£¡£¡£¡£ÈËÃÇ·¢Ã÷ÁË FritzFrog ½©Ê¬ÍøÂçµÄбäÖÖ£¬£¬ £¬£¬£¬£¬£¬ËüʹÓÃLog4Shell Îó²îÀ´Õë¶ÔÄÚ²¿ÍøÂçÖеÄËùÓÐÖ÷»ú¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬ £¬£¬£¬£¬£¬Í¨¹ýʹÓÃÈõ SSH ƾ֤£¬£¬ £¬£¬£¬£¬£¬¶ñÒâÈí¼þ»á¹¥»÷¿Éͨ¹ý»¥ÁªÍø»á¼ûµÄЧÀÍÆ÷¡£¡£¡£¡£¡£¡£Akamai Óë¡¶ÍøÂçÇå¾²ÐÂÎÅ¡··ÖÏíµÀ£º¡°½ÏеıäÌåÏÖÔÚ»á¶ÁÈ¡ÊÜѬȾÖ÷»úÉϵĶà¸öϵͳÎļþ£¬£¬ £¬£¬£¬£¬£¬ÒÔ¼ì²âºÜ¿ÉÄÜÈÝÒ×Êܵ½¹¥»÷µÄDZÔÚÄ¿µÄ¡£¡£¡£¡£¡£¡£¡±FritzFrog ʹÓõÄΨһѬȾǰÑÔÊÇ SSH±©Á¦ÆÆ½â£»£»£»£»£»£»£»È»¶ø£¬£¬ £¬£¬£¬£¬£¬¸Ã¶ñÒâÈí¼þµÄ×îа汾Ìí¼ÓÁËÃûΪ¡°Frog4Shell¡±µÄ Log4Shell Îó²îʹÓᣡ£¡£¡£¡£¡£ 


https://gbhackers.com/fritzfrog-botnet-linux-servers/


6. PurpleFox ¶ñÒâÈí¼þѬȾÎÚ¿ËÀ¼Êýǧ̨ÅÌËã»ú


2ÔÂ1ÈÕ£¬£¬ £¬£¬£¬£¬£¬ÎÚ¿ËÀ¼ÅÌËã»ú½ôÆÈÏìӦС×é (CERT-UA) ÖÒÑԳƣ¬£¬ £¬£¬£¬£¬£¬PurpleFox ¶ñÒâÈí¼þ»î¶¯ÒÑѬȾ¸Ã¹úÖÁÉÙ 2,000 ̨ÅÌËã»ú¡£¡£¡£¡£¡£¡£ÕâÖÖÆÕ±éѬȾ¼òÖ±ÇÐÓ°ÏìÒÔ¼°ËüÊÇ·ñÓ°ÏìÁ˹ú¼Ò×éÖ¯»òͨË×È˵ÄÅÌËã»úÉÐδȷ¶¨£¬£¬ £¬£¬£¬£¬£¬µ«¸Ã»ú¹¹ÒѾ­·ÖÏíÁËÓйØÔõÑù¶¨Î»Ñ¬È¾ºÍɾ³ý¶ñÒâÈí¼þµÄÏêϸÐÅÏ¢¡£¡£¡£¡£¡£¡£PurpleFox£¨»ò¡°DirtyMoe¡±£©ÊÇÒ»ÖÖ Ä£¿£¿£¿é»¯ Windows ½©Ê¬ÍøÂç¶ñÒâÈí¼þ £¬£¬ £¬£¬£¬£¬£¬ÓÚ 2018 ÄêÊ״η¢Ã÷£¬£¬ £¬£¬£¬£¬£¬´øÓÐ rootkit Ä£¿£¿£¿é£¬£¬ £¬£¬£¬£¬£¬ÔÊÐíÆäÔÚ×°±¸ÖØÐÂÆô¶¯Ê±´úÒþ²Ø²¢Ò»Á¬±£´æ¡£¡£¡£¡£¡£¡£Ëü¿ÉÒÔÓÃ×÷ÏÂÔØ³ÌÐò£¬£¬ £¬£¬£¬£¬£¬ÔÚÊÜѬȾµÄϵͳÉÏÒýÈë¸üǿʢµÄµÚ¶þ½×¶ÎÓÐÓøºÔØ£¬£¬ £¬£¬£¬£¬£¬ÎªÆäÔËÓªÉÌÌṩºóÃŹ¦Ð§£¬£¬ £¬£¬£¬£¬£¬»¹¿ÉÒԳ䵱ÂþÑÜʽ¾Ü¾øÐ§ÀÍ£¨DDoS£©»úеÈË¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/purplefox-malware-infects-thousands-of-computers-in-ukraine/?&web_view=true