Òâ´óÀûÆóÒµÊܵ½ÎäÆ÷»¯µÄ USB Á÷´«¼ÓÃܽٳֶñÒâÈí¼þµÄ¹¥»÷

Ðû²¼Ê±¼ä 2024-02-02
1. Òâ´óÀûÆóÒµÊܵ½ÎäÆ÷»¯µÄ USB Á÷´«¼ÓÃܽٳֶñÒâÈí¼þµÄ¹¥»÷


1ÔÂ31ÈÕ£¬Ò»¸öÃûΪUNC4990µÄ³öÓÚ¾­¼Ã¶¯»úµÄÍþвÐÐΪÕßÕýÔÚÀûÓÃÎäÆ÷»¯ USB É豸×÷Ϊ³õʼѬȾý½é£¬ÒÔÒâ´óÀûµÄ×é֯ΪĿ±ê¡£UNC4990 ²Ù×÷ͨ³£Éæ¼°¹ã·ºµÄ USB ѬȾ£¬È»ºó²¿Êð EMPTYSPACE ÏÂÔØ·¨Ê½¡£ÔÚÕâЩ²Ù×÷¹ý³ÌÖУ¬¼¯ÈºÒÀÀµ GitHub¡¢Vimeo ºÍ Ars Technica Æ·¼¶Èý·½ÍøÕ¾À´ÍйܱàÂëµÄ¸½¼Ó½×¶Î£¬²¢ÔÚÖ´ÐÐÁ´µÄÔçÆÚͨ¹ý PowerShell ÏÂÔغͽâÂë¡£UNC4990 ×Ô 2020 Äêµ×¿ªÊ¼»îÔ¾£¬Æ¾¾ÝÒâ´óÀû»ù´¡ÉèÊ©¹ã·ºÓÃÓÚÖ¸»ÓÓë¿ØÖÆ (C2) Ä¿µÄ£¬¾ÝÆÀ¹ÀÔÚÒâ´óÀû¾³ÍâÔËÓª¡£Ä¿Ç°Éв»Çå³þ UNC4990 ÊÇ·ñ½ö³äµ±ÆäËû¼ÓÈëÕߵijõʼ·ÃÎÊ´Ù½øÕß¡£ÍþвÐÐΪÕßµÄ×îÖÕÄ¿±êÒ²²»Çå³þ£¬¾¡¹ÜÔÚÒ»¸öÀý×ÓÖУ¬¾Ý˵ÔÚ¾­¹ýÊýÔµÄÐűê»î¶¯ºó²¿ÊðÁË¿ªÔ´¼ÓÃÜ»õ±ÒÍÚ¿ó·¨Ê½¡£


https://thehackernews.com/2024/01/italian-businesses-hit-by-weaponized.html?&web_view=true


2. CISA ¾¯¸æ iOS¡¢iPadOS ºÍ macOS ÖеÄÑÏÖØ©¶´±»Ö÷¶¯ÀûÓÃ


2ÔÂ1ÈÕ£¬ÃÀ¹úÍøÂçÄþ¾²ºÍ»ù´¡ÉèÊ©Äþ¾²¾Ö (CISA)ƾ¾Ý»îÔ¾ÀûÓõÄÖ¤¾Ý£¬½«Ó°Ïì iOS¡¢iPadOS¡¢macOS¡¢tvOS ºÍ watchOS µÄ¸ßÑÏÖØÐÔȱÏÝÌí¼Óµ½ÆäÒÑÖª¿ÉÀûÓ鶴 ( KEV ) Ŀ¼ÖС£¸Ã©¶´±àºÅΪCVE-2022-48618£¨CVSS ÆÀ·Ö£º7.8£©£¬Éæ¼°ÄÚºË×é¼þÖеĴíÎó¡£Æ»¹ûÔÚÒ»·Ýͨ¸æÖÐÌåÏÖ£¬ ¡°¾ßÓÐÈÎÒâ¶ÁдÄÜÁ¦µÄ¹¥»÷Õß¿ÉÄÜÄܹ»ÈƹýÖ¸ÕëÉí·ÝÑéÖ¤¡±£¬²¢Ôö²¹Ëµ¸ÃÎÊÌâ¡°¿ÉÄÜÒѱ»Õë¶Ô iOS 15.7.1 ֮ǰÐû²¼µÄ iOS °æ±¾ËùÀûÓᱡ£Õâ¼Ò iPhone ÖÆÔìÉÌÌåÏÖ£¬¸ÃÎÊÌâÒÑͨ¹ý¸ïмì²éµÃµ½½â¾ö¡£Ä¿Ç°Éв»Çå³þ¸Ã©¶´ÈçºÎÔÚÏÖʵÊÀ½çµÄ¹¥»÷Öб»ÎäÆ÷»¯¡£ÓÐȤµÄÊÇ£¬¸Ã©¶´µÄ²¹¶¡ÓÚ 2022 Äê 12 Ô 13 ÈÕËæiOS 16.2¡¢iPadOS 16.2¡¢macOS Ventura 13.1¡¢tvOS 16.2ºÍwatchOS 9.2µÄÐû²¼¶øÐû²¼£¬¾¡¹ÜÒ»Äê¶àºóµÄ 2024 Äê 1 Ô 9 ÈղŹûÈ»Åû¶¡£ÖµµÃ×¢ÒâµÄÊÇ£¬Æ»¹ûȷʵÔÚ 2022 Äê 7 Ô 20 ÈÕÐû²¼µÄ iOS 15.6 ºÍ iPadOS 15.6 Öнâ¾öÁËÄÚºËÖеÄÀàËÆȱÏÝ£¨ CVE-2022-32844 £¬CVSS ÆÀ·Ö£º6.3£©¡£


https://thehackernews.com/2024/02/cisa-warns-of-active-exploitation-of.html


3. ¿¨°Í˹»ù2024ÄêÔ¤²â£ºÀÕË÷Èí¼þºáÐÐ


2ÔÂ1ÈÕ£¬¿¨°Í˹»ùÐû²¼Á˹¤Òµ¿ØÖÆϵͳÍøÂçÓ¦¼±ÏìӦС×é (ICS CERT) 2024 ÄêµÄÔ¤²â£¬¸ÅÊöÁ˹¤ÒµÆóÒµÔÚδÀ´Ò»ÄêÃæÁÙµÄÖ÷ÒªÍøÂçÄþ¾²ÌôÕ½¡£ÕâЩԤ²âÇ¿µ÷ÁËÀÕË÷Èí¼þÍþвµÄÁ¬Ðø´æÔÚ¡¢ÊÀ½çÕþÖκڿÍÐж¯Ö÷ÒåµÄÐËÆ𡢶ԡ°½ø¹¥ÐÔÍøÂçÄþ¾²¡±×´¿öµÄÕ¹Íû£¬ÒÔ¼°ÎïÁ÷ºÍÔËÊäÍþвµÄÀå¸ïÐÔת±ä¡ £»Ø¹Ë 2023 Ä꣬¿¨°Í˹»ùÔ¤²â¹¤ÒµÍøÂçÄþ¾²¸ñʽ½«¼ÌÐøÉú³¤£¬²¢·ºÆ𼸸öÒªº¦Ç÷ÊÆ¡£IIoT ºÍ SmartXXX ϵͳ¶ÔЧÂʵÄ×·ÇóÍƶ¯Á˹¥»÷ÃæµÄÀ©´ó£¬¶øÄÜÔ´ÔËÓªÉ̼۸ñµÄì­Éýµ¼ÖÂÓ²¼þ³É±¾ÉÏÉý£¬´ÙʹսÂÔתÏòÔÆ·þÎñ¡£Õþ¸®¶Ô¹¤ÒµÁ÷³ÌµÄÔ½À´Ô½¶àµÄ¼ÓÈëÒ²´øÀ´ÁËеķçÏÕ£¬°üÂÞÓÉÓÚÔ±ÈËΪ¸ñ²»×ãºÍÂôÁ¦ÈεÄÅû¶ʵ¼ù²»×ã¶øµ¼ÖÂÊý¾Ýй¶µÄµ£ÓÇ¡£2024 Ä깤ҵÆóÒµÃæÁÙµÄÍøÂçÄþ¾²ÐÎÊÆ°üÂÞ£ºÕë¶Ô¸ß¼ÛֵʵÌåµÄÀÕË÷Èí¼þ¡¢ÊÀ½çÕþÖο¹ÒéºÚ¿ÍÐж¯Ö÷ÒåºÍ¸ü΢ÃîµÄÍþвºÍ¼ì²âÌôÕ½µÈ¡£


https://www.darkreading.com/vulnerabilities-threats/kasperskys-ics-cert-predictions-for-2024-ransomware-rampage-cosmopolitical-hacktivism-and-beyond


4. Europcar·ñÈÏ5000ÍòÓû§Êý¾Ýй¶£¬³ÆÊý¾ÝÊǼٵÄ


1ÔÂ31ÈÕ£¬Æû³µ×âÁÞ¹«Ë¾ Europcar ÌåÏÖ£¬ÔÚÍþвÐÐΪÕßÉù³Æ³öÊÛ 5000 Íò¿Í»§µÄ¸öÈËÐÅÏ¢ºó£¬¸Ã¹«Ë¾²¢Î´ÔâÊÜÊý¾Ýй¶£¬¶øÇÒ¹²ÏíµÄ¿Í»§Êý¾ÝÊÇαÔìµÄ¡£ÓÐÈËÉù³ÆÔÚÒ»¸öÁ÷ÐеĺڿÍÂÛ̳ÉϳöÊÛ 48,606,700 Europcar.com ¿Í»§µÄÊý¾Ý¡£¸ÃÌû×Ó°üÂÞ 31 Ãû Europcar ¿Í»§µÄ±»µÁÊý¾ÝÑù±¾£¬°üÂÞÐÕÃû¡¢µØÖ·¡¢³öÉúÈÕÆÚ¡¢¼ÝʻִÕÕºÅÂëºÍÆäËûÐÅÏ¢¡£Europcar ¸æËß BleepingComputer ËûÃÇÏàÐÅÕâЩÊý¾ÝÊÇʹÓÃÈ˹¤ÖÇÄÜ´´½¨µÄ£¬µ« Hunt Ö¸³ö£¬Ò»Ð©µç×ÓÓʼþµØÖ·ÊÇÕæʵµÄ£¬·ºÆðÔÚ Have I Been Pwned ¼à¿ØµÄ֮ǰµÄÊý¾Ýй¶Ê¼þÖС£ÕýÈçÄþ¾²Ñо¿ÈËÔ±NexusFuzzyÖ¸³öµÄÄÇÑù £¬ ÏÖÓеÄÏîÄ¿ ÔÊÐíÈκÎÈË´´½¨¿´ÆðÀ´¼¸ºõÓëÐé¼ÙÊý¾Ýй¶Ñù±¾Öй²ÏíµÄÊý¾ÝһģһÑùµÄÊý¾Ý¡£ËäÈ» ÍþвÐÐΪÕßÒѾ­Ê¹ÓÃÈ˹¤ÖÇÄÜ ×÷ΪÆäÕ©Æ­ºÍ¹¥»÷µÄÒ»²¿ÃÅ£¬¶øÇÒ Î´À´¿ÉÄÜ»áÀ©´óÆäʹÓ÷¶Î§£¬µ«ÕâһʼþËƺõ²¢²»ÊÇÆäÖÐÖ®Ò»¡£


https://www.bleepingcomputer.com/news/security/europcar-denies-data-breach-of-50-million-users-says-data-is-fake/


5. Êý°Ù¸ö±»µÁµÄ RIPE ƾ֤ÔÚ°µÍøÉϳöÊÛ


2ÔÂ1ÈÕ£¬RIPE ÊÇÖж«¸÷¹úÒÔ¼°Å·Ö޺ͷÇÖÞ¸÷¹úµÄ IP µØÖ·¼°ÆäËùÓÐÕßÊý¾Ý¿â£¬×î½üÒѳÉΪÈÈÃÅÄ¿±ê£¬ÒòΪ¹¥»÷ÕßΪÁËÊÕ¼¯ÐÅÏ¢¶øÆÆ»µÁËÕÊ»§µÇ¼¡£²»Á¼ÐÐΪÕßÀûÓûñµÃµÄ RIPE ºÍÆäËûÃÅ»§µÄй¶ƾ¾ÝÀ´Ì½²âÊܺ¦Õß¿ÉÄÜÓÐÌØȨ·ÃÎʵÄÆäËûÓ¦Ó÷¨Ê½ºÍ·þÎñ¡£Æ¾¾ÝÎÒÃǵÄÆÀ¹À£¬´ËÀà¼ÆıÔö¼ÓÁËËûÃÇÀÖ³ÉÈëÇÖÄ¿±êÆóÒµºÍµçÐÅÔËÓªÉÌÍøÂçµÄ»ú»á¡£±¾ÔÂÔçЩʱºò£¬  Orange Spain ÔâÊÜÁË»¥ÁªÍøÖжÏ£¬Ô­ÒòÊǺڿÍÇÖÈëÁ˸ù«Ë¾µÄ RIPE ÕÊ»§£¬´íÎóÅäÖÃÁË BGP ·ÓÉºÍ RPKI ÅäÖá£Resecurity ×ܹ²ÔÚ RIPE ºÍÆäËûÇøÓòÍøÂ磨°üÂÞ APNIC¡¢AFRINIC ºÍ LACNIC£©Öз¢ÏÖÁË 1,572 ¸ö¿Í»§ÕÊ»§£¬ÕâЩÕÊ»§ÒòÉæ¼°Redline¡¢Vidar¡¢Lumma¡¢Azorult ºÍ Taurus µÈ ÖªÃûÃÜÂëÇÔÈ¡·¨Ê½µÄ¶ñÒâÈí¼þ»î¶¯¶øÊܵ½Ë𺦡£


https://www.darkreading.com/cyberattacks-data-breaches/looted-ripe-credentials-for-sale-on-dark-web


6. ½­É­×ԿسÆÀÕË÷Èí¼þ¹¥»÷Ôì³É 2700 ÍòÃÀÔªËðʧ

1ÔÂ31ÈÕ£¬½­É­×Կعú¼Ê¹«Ë¾ (Johnson Controls International) È·ÈÏ£¬2023 Äê 9 ÔµÄÒ»´ÎÀÕË÷Èí¼þ¹¥»÷¸ø¸Ã¹«Ë¾Ôì³ÉÁË 2700 ÍòÃÀÔªµÄÓöÈ£¬²¢µ¼ÖºڿÍÇÔÈ¡¹«Ë¾Êý¾Ýºó·¢ÉúÊý¾Ýй¶¡£½­É­×Ô¿ØÊÇÒ»¼Ò¿ª·¢ºÍÖÆÔ칤ҵ¿ØÖÆϵͳ¡¢Äþ¾²É豸¡¢¿Õµ÷ºÍÏû·ÀÄþ¾²É豸µÄ¿ç¹úÆóÒµ¼¯ÍÅ¡£ÕýÈç BleepingComputer Ê״ᨵÀµÄÄÇÑù£¬ ½­É­×Ô¿Ø ÔÚÆäÑÇÖÞ·þÎñ´¦×î³õÔâµ½ÈëÇÖºó£¬ÓÚ 9 Ô·ÝÔâÊÜÁËÀÕË÷Èí¼þ¹¥»÷£¬¹¥»÷Õ߱鲼Õû¸öÍøÂç¡£´Ë´Î¹¥»÷ÆÈʹ¸Ã¹«Ë¾¹Ø±ÕÁË´ó²¿ÃÅ IT »ù´¡ÉèÊ©£¬´Ó¶øÓ°ÏìÁËÃæÏò¿Í»§µÄϵͳ¡£Dark Angels ÀÕË÷Èí¼þÍÅ»ïÊǴ˴ι¥»÷µÄÄ»ºóºÚÊÖ£¬²¢Éù³Æ´Ó Johnson Controls ÇÔÈ¡ÁËÁè¼Ý 27 TB µÄ»úÃÜÊý¾Ý¡£Ëæºó£¬ÍþвÐÐΪÕßË÷Òª 5100 ÍòÃÀÔªµÄÊê½ð£¬ÒÔɾ³ýÊý¾Ý²¢ÌṩÎļþ½âÃÜÆ÷¡£Dark Angels ÊÇÒ»¸öÀÕË÷Èí¼þÍŻÓÚ 2022 Äê 5 ÔÂÌᳫ£¬Ê¹ÓûùÓÚÏÖÒѽâÉ¢µÄ Babuk ºÍ Ragnar Locker ²Ù×÷µÄй¶Դ´úÂëµÄ¼ÓÃÜÆ÷¡£¸Ã¹«Ë¾ÈÏ¿É·þÎñÖжÏ£¬ºóÀ´½«Ô­Òò¹éÒòÓÚ¡°ÍøÂçÄþ¾²Ê¼þ¡±£¬µ«Ã»ÓÐÌṩÓйع¥»÷ÀàÐÍ»òµ¼ÖÂÊý¾Ýй¶µÄ¿ÉÄÜÐÔµÄÏêϸÐÅÏ¢¡£


https://www.bleepingcomputer.com/news/security/johnson-controls-says-ransomware-attack-cost-27-million-data-stolen/