ÐÂÍøÂç´¹ÂÚ¹¤¾ß°ü¡°Xi¨± g¨¯u¡±Òý·¢È«ÇòÇå¾²¾¯±¨

Ðû²¼Ê±¼ä 2024-11-04

1. ÐÂÍøÂç´¹ÂÚ¹¤¾ß°ü¡°Xi¨± g¨¯u¡±Òý·¢È«ÇòÇå¾²¾¯±¨


11ÔÂ1ÈÕ£¬ £¬£¬£¬£¬ÍøÂçÇå¾²ÁìÓò½üÆÚ·ºÆðÁËÒ»ÖÖÃûΪXi¨± g¨¯uµÄÐÂÐÍÍøÂç´¹ÂÚ¹¤¾ß°ü£¬ £¬£¬£¬£¬×Ô2024Äê9ÔÂÆðÒÑÕë¶Ô°Ä´óÀûÑÇ¡¢ÈÕ±¾¡¢Î÷°àÑÀ¡¢Ó¢¹úºÍÃÀ¹úµÈ¶à¸ö¹ú¼ÒÌᳫ¹¥»÷¡£ ¡£¡£¸Ã¹¤¾ß°üÒÑѬȾÁè¼Ý2000¸ö´¹ÂÚÍøÕ¾£¬ £¬£¬£¬£¬Ö÷Òª¹¥»÷¹«¹²²¿·Ö¡¢ÓÊÕþ¡¢Êý×ÖЧÀͺÍÒøÐÐЧÀ͵ȱÊÖ±ÐÐÒµ¡£ ¡£¡£NetcraftÖ¸³ö£¬ £¬£¬£¬£¬ÕâЩ¹¥»÷Õß³£Ê¹ÓÃCloudflareµÄ·´»úеÈ˺ÍÍйܻìÏý¹¦Ð§À´¹æ±Ü¼ì²â¡£ ¡£¡£Xi¨± g¨¯uÌṩÖÎÀíÃæ°å£¬ £¬£¬£¬£¬Ê¹ÓÃGolangºÍVue.jsµÈÊÖÒÕ£¬ £¬£¬£¬£¬Í¨¹ýTelegram´ÓÐéα´¹ÂÚÒ³ÃæÇÔÊØÐÅÏ¢¡£ ¡£¡£ÕâÐ©ÍøÂç´¹ÂÚ¹¥»÷Ö÷Ҫͨ¹ý¸»Í¨Ñ¶Ð§ÀÍ£¨RCS£©ÐÂÎÅÈö²¥£¬ £¬£¬£¬£¬ÓÕµ¼Êܺ¦Õßµã»÷Ëõ¶ÌµÄÁ´½ÓÒÔÌṩСÎÒ˽¼ÒÐÅÏ¢»ò¸¶¿î¡£ ¡£¡£¹È¸èµÈ¿Æ¼¼¾ÞÍ·ÒѽÓÄɲ½·¥¹¥»÷´ËÀàÕ©Æ­£¬ £¬£¬£¬£¬°üÀ¨ÍƳöÔöÇ¿ÐÍÕ©Æ­¼ì²â¹¦Ð§ºÍÇå¾²ÖÒÑÔ£¬ £¬£¬£¬£¬²¢ÍýÏëÔÚÈ«Çò¹æÄ£ÄÚÍÆ¹ãб£»£»£»£»£»£»£»¤²½·¥¡£ ¡£¡£±ðµÄ£¬ £¬£¬£¬£¬Ë¼¿ÆTalosÍŶӷ¢Ã÷£¬ £¬£¬£¬£¬Ì¨ÍåµÄFacebookÉÌÒµºÍ¹ã¸æÕÊ»§Óû§Õý³ÉÎªÍøÂç´¹ÂڻµÄÄ¿µÄ£¬ £¬£¬£¬£¬Ö¼ÔÚÈö²¥ÇÔÈ¡¶ñÒâÈí¼þ¡£ ¡£¡£ÕâЩ»î¶¯»¹Ã°³äOpenAIµÈ×ÅÃûÆóÒµ£¬ £¬£¬£¬£¬ÓÕµ¼È«ÇòÆóÒµ¸üи¶¿îÐÅÏ¢¡£ ¡£¡£


https://thehackernews.com/2024/11/new-phishing-kit-xiu-gou-targets-users.html


2. InterlockÀÕË÷Èí¼þ£ºÕë¶ÔFreeBSDЧÀÍÆ÷µÄÐÂÐ͹¥»÷Ðж¯


11ÔÂ3ÈÕ£¬ £¬£¬£¬£¬InterlockÊÇÒ»¸öÐÂÐ˵ÄÀÕË÷Èí¼þ²Ù×÷£¬ £¬£¬£¬£¬×Ô2024Äê9ÔÂβÆô¶¯ÒÔÀ´£¬ £¬£¬£¬£¬ÒѶÔÈ«Çò¶à¸ö×éÖ¯Ìᳫ¹¥»÷¡£ ¡£¡£Ëü½ÓÄÉÒ»ÖÖ²»³£¼ûµÄÒªÁ죬 £¬£¬£¬£¬¼´½¨ÉèרÃÅÕë¶ÔFreeBSDЧÀÍÆ÷µÄ¼ÓÃÜÆ÷¡£ ¡£¡£ÕâÖÖ¼ÓÃÜÆ÷ÔÚFreeBSD 10.4ÉϱàÒ룬 £¬£¬£¬£¬Ö»¹ÜBleepingComputerµÈÇå¾²»ú¹¹ÔÚÐéÄâ»úÉϲâÊÔʱδÄÜʹÆä׼ȷִÐС£ ¡£¡£InterlockÔÚ¹¥»÷ÀÖ³Éºó£¬ £¬£¬£¬£¬»áÔÚδ֧¸¶Êê½ðµÄÇéÐÎÏ£¬ £¬£¬£¬£¬ÔÚÆäÊý¾ÝÐ¹Â¶ÍøÕ¾ÉÏÐû²¼±»µÁÊý¾Ý¡£ ¡£¡£¾ÝÍøÂçÇå¾²¹«Ë¾Ç÷ÊÆ¿Æ¼¼³Æ£¬ £¬£¬£¬£¬InterlockµÄÄ¿µÄÊÇFreeBSD£¬ £¬£¬£¬£¬ÓÉÓÚËüÆÕ±éÓ¦ÓÃÓÚЧÀÍÆ÷ºÍÒªº¦»ù´¡ÉèÊ©£¬ £¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔÆÆËðÖ÷ҪЧÀÍ£¬ £¬£¬£¬£¬Ë÷Òª¾Þ¶îÊê½ð¡£ ¡£¡£±ðµÄ£¬ £¬£¬£¬£¬Ç÷ÊÆ¿Æ¼¼»¹·¢Ã÷Á˸òÙ×÷µÄWindows¼ÓÃÜÆ÷Ñù±¾¡£ ¡£¡£ÔÚ¼ÓÃÜÎļþʱ£¬ £¬£¬£¬£¬Interlock»á½«.interlockÀ©Õ¹Ãû¸½¼Óµ½ËùÓмÓÃÜÎļþÃûºó£¬ £¬£¬£¬£¬²¢ÔÚÿ¸öÎļþ¼ÐÖн¨ÉèÀÕË÷¼Í¼¡£ ¡£¡£±»µÁÊý¾Ý±»ÓÃÓÚË«ÖØÀÕË÷¹¥»÷£¬ £¬£¬£¬£¬ÍþвÐÐΪÕßÍþв³Æ£¬ £¬£¬£¬£¬ÈôÊDz»Ö§¸¶Êê½ð£¬ £¬£¬£¬£¬ËûÃǾͻá¹ûÕæÐ¹Â¶Êý¾Ý¡£ ¡£¡£¾Ý³Æ£¬ £¬£¬£¬£¬InterlockÀÕË÷Èí¼þ²Ù×÷ÒªÇóµÄÊê½ð´ÓÊýÊ®ÍòÃÀÔªµ½Êý°ÙÍòÃÀÔª²»µÈ£¬ £¬£¬£¬£¬Ïêϸȡ¾öÓÚ×éÖ¯µÄ¹æÄ£¡£ ¡£¡£


https://www.bleepingcomputer.com/news/security/meet-interlock-the-new-ransomware-targeting-freebsd-servers/


3. SharePoint RCEÎó²îCVE-2024-38094Õý±»ºÚ¿ÍʹÓþÙÐÐÍøÂç¹¥»÷


11ÔÂ2ÈÕ£¬ £¬£¬£¬£¬Microsoft SharePointµÄÒ»¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2024-38094£©±»Åû¶²¢ÕýÔÚ±»ºÚ¿ÍʹÓ㬠£¬£¬£¬£¬ÒÔ»ñÈ¡¶Ô¹«Ë¾ÍøÂçµÄ³õʼ»á¼ûȨÏÞ¡£ ¡£¡£¸ÃÎó²îÊÇÒ»¸ö¸ßÑÏÖØÐÔ£¨CVSS v3.1 ÆÀ·Ö£º7.2£©µÄRCEÎó²î£¬ £¬£¬£¬£¬Ó°ÏìÆÕ±éʹÓõĻùÓÚWebµÄSharePointƽ̨¡£ ¡£¡£Î¢ÈíÒÑÓÚ2024Äê7ÔÂ9ÈÕÐû²¼Á˲¹¶¡ÐÞ¸´¸ÃÎó²î£¬ £¬£¬£¬£¬²¢½«Æä±ê¼ÇΪ¡°Ö÷Òª¡±¡£ ¡£¡£È»¶ø£¬ £¬£¬£¬£¬CISAÉÏÖܽ«¸ÃÎó²îÌí¼Óµ½ÒÑ֪ʹÓÃÎó²îĿ¼ʱ£¬ £¬£¬£¬£¬²¢Î´Í¸Â¶ÏêϸµÄʹÓ÷½·¨¡£ ¡£¡£Rapid7Ðû²¼µÄб¨¸æÕ¹ÏÖÁ˹¥»÷ÕßÔõÑùʹÓøÃÎó²î£¬ £¬£¬£¬£¬Ö¸³ö¹¥»÷Õßͨ¹ýδ¾­ÊÚȨ»á¼ûÒ×Êܹ¥»÷µÄSharePointЧÀÍÆ÷²¢Ö²ÈëWebshell£¬ £¬£¬£¬£¬½ø¶øÔÚÍøÂçÖкáÏòÒÆ¶¯£¬ £¬£¬£¬£¬Î£¼°Õû¸öÓò¡£ ¡£¡£¹¥»÷Õß»¹ÆÆËðÁ˾ßÓÐÓòÖÎÀíԱȨÏÞµÄMicrosoft ExchangeЧÀÍÕÊ»§£¬ £¬£¬£¬£¬»ñµÃÌáÉýµÄ»á¼ûȨÏÞ£¬ £¬£¬£¬£¬²¢×°ÖÃÁËHoroung AntivirusÈí¼þ£¬ £¬£¬£¬£¬Ôì³ÉÇå¾²·ÀÓù³åÍ»£¬ £¬£¬£¬£¬½ûÓÃÇ徲ЧÀÍ£¬ £¬£¬£¬£¬Ï÷Èõ¼ì²âÄÜÁ¦¡£ ¡£¡£ËûÃÇʹÓöàÖÖ¹¤¾ß¾ÙÐÐÆ¾Ö¤ÍøÂç¡¢Ô¶³Ì»á¼û¡¢³¤ÆÚÐÔÉèÖõȲÙ×÷£¬ £¬£¬£¬£¬²¢½ûÓÃÁËWindows Defender¡¢¸ü¸ÄÁËÊÂÎñÈÕÖ¾£¬ £¬£¬£¬£¬ÒÔ×èÖ¹±»·¢Ã÷¡£ ¡£¡£Ö»¹Ü¹¥»÷ÕßÊÔͼɾ³ý±¸·Ý£¬ £¬£¬£¬£¬µ«²¢Î´ÀֳɼÓÃÜÊý¾Ý£¬ £¬£¬£¬£¬Òò´Ë¹¥»÷ÀàÐÍÉв»ÇåÎú¡£ ¡£¡£


https://www.bleepingcomputer.com/news/security/microsoft-sharepoint-rce-bug-exploited-to-breach-corporate-network/


4. Âåɼí¶ÊÐס·¿ÖÎÀí¾ÖÔâCactusÀÕË÷Èí¼þÍŻ﹥»÷


11ÔÂ1ÈÕ£¬ £¬£¬£¬£¬Âåɼí¶ÊÐס·¿ÖÎÀí¾Ö£¨HACLA£©ÊÇÃÀ¹ú×î´óµÄ¹«¹²×¡·¿ÖÎÀí¾ÖÖ®Ò»£¬ £¬£¬£¬£¬ÈÏÕæÖÎÀíÁè¼Ý32,000Ì×¹«¹²×¡·¿£¬ £¬£¬£¬£¬Äê¶ÈÔ¤ËãÁè¼Ý10ÒÚÃÀÔª£¬ £¬£¬£¬£¬ÎªµÍÊÕÈë¼ÒÍ¥¡¢¶ùͯºÍÍíÄêÈËÌṩ¾­¼ÃÊÊÓ÷¿ºÍÔ®ÖúÍýÏë¡£ ¡£¡£×î½ü£¬ £¬£¬£¬£¬CactusÀÕË÷Èí¼þÍÅ»ïÉù³Æ¶ÔHACLAµÄITÍøÂç¾ÙÐÐÁËÈëÇÖ¹¥»÷¡£ ¡£¡£HACLA֤ʵÁËÕâÒ»ÍøÂç¹¥»÷£¬ £¬£¬£¬£¬²¢ÌåÏÖÒÑÔ¼ÇëÍⲿȡ֤ITר¼Ò¾ÙÐÐÊÓ²ìºÍÓ¦¶Ô¡£ ¡£¡£Ö»¹ÜHACLAδ͸¶¹¥»÷µÄÏêϸʱ¼äºÍÐÔ×Ó£¬ £¬£¬£¬£¬µ«CactusÀÕË÷Èí¼þÍÅ»ïÉù³ÆÒÑ´ÓÊÜѬȾµÄÍøÂçÖÐÇÔÈ¡ÁË891 GBµÄÎļþ£¬ £¬£¬£¬£¬°üÀ¨Ð¡ÎÒ˽¼ÒÉí·ÝÐÅÏ¢¡¢²ÆÎñÎļþ¡¢¸ß¹ÜºÍÔ±¹¤Ð¡ÎÒ˽¼ÒÊý¾Ý¡¢¿Í»§Ð¡ÎÒ˽¼ÒÐÅÏ¢¡¢¹«Ë¾ÉñÃØÊý¾ÝºÍͨѶµÈ£¬ £¬£¬£¬£¬²¢ÔÚÆäйÃÜÍøÕ¾ÉÏÐû²¼ÁËһЩÃô¸ÐÎļþµÄ½ØÍ¼×÷Ϊ֤¾Ý¡£ ¡£¡£±ðµÄ£¬ £¬£¬£¬£¬HACLAÔÚ2022ÄêÒ²ÔøÔâµ½LockBitÀÕË÷Èí¼þÍÅ»ïµÄ¹¥»÷£¬ £¬£¬£¬£¬¹¥»÷ÕßÔÚ³¤´ïÒ»ÄêµÄʱ¼äÀï»á¼ûÁËHACLAµÄϵͳ£¬ £¬£¬£¬£¬²¢¿ÉÒÔ»á¼û»áÔ±µÄÃô¸ÐСÎÒ˽¼ÒÐÅÏ¢¡£ ¡£¡£Õþ¸®»ú¹¹ÔھܾøÖ§¸¶ÍøÂç·¸·¨·Ö×ÓÒªÇóµÄÊê½ðºó£¬ £¬£¬£¬£¬LockBitÀÕË÷Èí¼þ×é֯й¶ÁËËùÓб»µÁÎļþ¡£ ¡£¡£


https://www.bleepingcomputer.com/news/security/la-housing-authority-confirms-breach-claimed-by-cactus-ransomware/


5. LastPassÓû§Ð¡ÐÄÐéα֧³Öµç»°ÊµÑéÔ¶³Ì»á¼ûÕ©Æ­


11ÔÂ1ÈÕ£¬ £¬£¬£¬£¬LastPass ÊÇÒ»¿îÊ¢ÐеÄÃÜÂëÖÎÀíÆ÷£¬ £¬£¬£¬£¬ËüʹÓà LastPass Chrome À©Õ¹³ÌÐòÀ´ÌìÉú¡¢ÉúÑÄ¡¢ÖÎÀíºÍ×Ô¶¯Ìî³äÍøÕ¾ÃÜÂë¡£ ¡£¡£LastPass·¢³öÖÒÑÔ£¬ £¬£¬£¬£¬Õ©Æ­ÕßÕýÔÚͨ¹ýÔÚÆäChromeÀ©Õ¹³ÌÐòÉÏÐû²¼Ðéα5ÐÇ̸ÂÛ£¬ £¬£¬£¬£¬ÍƹãÒ»¸öð³äµÄ¿Í»§Ö§³Öµç»°ºÅÂë805-206-2892£¬ £¬£¬£¬£¬ÒÔÓÕÆ­LastPassÓû§¡£ ¡£¡£Ò»µ©Óû§²¦´ò¸Ãµç»°£¬ £¬£¬£¬£¬Æ­×Ó»áð³äLastPass£¬ £¬£¬£¬£¬Ö¸µ¼ËûÃÇ»á¼û¡°dghelp[.]top¡±ÍøÕ¾£¬ £¬£¬£¬£¬²¢ÒªÇóÊäÈë´úÂëÏÂÔØÔ¶³ÌÖ§³Ö³ÌÐò£¬ £¬£¬£¬£¬¸Ã³ÌÐòÏÖʵÉÏÊÇConnectWise ScreenConnectÊðÀí£¬ £¬£¬£¬£¬ÔÊÐíÕ©Æ­ÕßÍêÈ«»á¼ûÓû§µÄÅÌËã»ú¡£ ¡£¡£BleepingComputer·¢Ã÷£¬ £¬£¬£¬£¬¸Ãµç»°ºÅÂëÓëÒ»³¡¸ü´ó¹æÄ£µÄÕ©Æ­»î¶¯Óйأ¬ £¬£¬£¬£¬¸ÃºÅÂ뻹±»ÓÃ×÷Ðí¶àÆäËû¹«Ë¾£¨ÈçÑÇÂíÑ·¡¢Adobe¡¢FacebookµÈ£©µÄð³äÖ§³Öµç»°ºÅÂ룬 £¬£¬£¬£¬²¢ÔÚÖÖÖÖÍøÕ¾ÉÏÐû²¼¡£ ¡£¡£LastPassÓû§±»ÌáÐѲ»ÒªÓëÈκÎÈË·ÖÏíËûÃǵÄÖ÷ÃÜÂ룬 £¬£¬£¬£¬ÒÔ×èֹ˽Ï»á¼ûÆäÃÜÂë¿âÖд洢µÄËùÓÐÃÜÂëºÍÊý¾Ý¡£ ¡£¡£


https://www.bleepingcomputer.com/news/security/lastpass-warns-of-fake-support-centers-trying-to-steal-customer-data/


6. ·¨¹úÀ͹¤²¿ÔâÍøÂç¹¥»÷£¬ £¬£¬£¬£¬¾ÍÒµ°ï·öÄêÇáÈËÊý¾ÝÒÉÔâй¶


11ÔÂ1ÈÕ£¬ £¬£¬£¬£¬·¨¹úÀ͹¤²¿Ðû²¼£¬ £¬£¬£¬£¬Æä¡°µØ·½Ê¹ÍÅ¡±ÍøÂçʹÓõÄÒ»¼ÒЧÀÍÌṩÉÌÒÉËÆ½üÆÚÔâÊÜÍøÂç¹¥»÷£¬ £¬£¬£¬£¬¸ÃÍøÂçÖ÷ҪΪ16ÖÁ25ËêµÄÄêÇáÈËÌṩ¾ÍÒµºÍÅàѵ½¨ÒéÓëÖ§³Ö¡£ ¡£¡£´Ë´Î¹¥»÷¿ÉÄÜй¶ÁËÒÑÔÚ¸ÃϵͳÖйҺŵÄÄêÇáÈ˵ÄСÎÒ˽¼ÒÊý¾Ý£¬ £¬£¬£¬£¬°üÀ¨È«Ãû¡¢³öÉúÈÕÆÚ¡¢¹ú¼®¡¢µç×ÓÓʼþºÍÓÊÕþµØµãÒÔ¼°µç»°ºÅÂ룬 £¬£¬£¬£¬µ«ÒøÐÐÏêϸÐÅÏ¢¡¢Éç»á°ü¹ÜºÅºÍÉí·ÝÖ¤¼þδÊÜÓ°Ïì¡£ ¡£¡£Ö»¹ÜÊÖÒÕÊÓ²ìÉÐδÍê³É£¬ £¬£¬£¬£¬¸Ã²¿ÒѽÓÄɶàÏî²½·¥½â¾öÎó²îÎÊÌ⣬ £¬£¬£¬£¬²¢ÒÑÏò·¨¹úÒþ˽î¿Ïµ»ú¹¹CNILºÍÍøÂçÇå¾²»ú¹¹ANSSI±¨¸æ´ËÊ£¬ £¬£¬£¬£¬Í¬Ê±Ïò˾·¨Õþ¸®ÌáÆðͶËß¡£ ¡£¡£ÊÜÓ°ÏìµÄÄêÇáÈËÕýÔÚ±»×ª´ïÇéÐΣ¬ £¬£¬£¬£¬²¢ÌáÐÑËûÃÇСÐÄÍøÂç´¹ÂÚºÍÉí·Ý͵ÇÔµÄΣº¦£¬ £¬£¬£¬£¬ÇÐÎðͨ¹ýµç»°¡¢¶ÌÐÅ»òµç×ÓÓʼþ͸¶ÃÜÂë»òÒøÐÐÏêϸÐÅÏ¢¡£ ¡£¡£


https://therecord.media/france-data-breach-government-contractor-local-missions