CLOROX Ô¤¼Æ 8 Ô·ÝÍøÂç¹¥»÷Ôì³ÉµÄËðʧ½«Áè¼Ý 4900 ÍòÃÀÔª
Ðû²¼Ê±¼ä 2024-02-051. CLOROX Ô¤¼Æ 8 Ô·ÝÍøÂç¹¥»÷Ôì³ÉµÄËðʧ½«Áè¼Ý 4900 ÍòÃÀÔª
2ÔÂ3ÈÕ£¬Õâ¼ÒÇå½à²úÎï¾ÞÍ· ÓÚ 8 ÔÂÖÐÑ®Ðû²¼£¬ËüÊÇÒ»´ÎÍøÂçÄþ¾²Ê¼þµÄÊܺ¦Õß £¬¸ÃʼþÆÈʹËü¹Ø±ÕÁËһЩϵͳ¡£Ä¿Ç°£¬¸ßÀÖÊÏÉÐδ·ÖÏíÍøÂç¹¥»÷µÄ¼¼Êõϸ½Ú¡£ËùÃèÊöµÄÓ°Ïì±íÃ÷¸Ã¹«Ë¾¿ÉÄÜÔâÊÜÀÕË÷Èí¼þ¹¥»÷¡£Æ¾¾ÝÏò SEC Ìá½»µÄÎļþ£¬Clorox Ô¤¼Æ 2023 Äê 8 ÔÂÏ®»÷¸Ã¹«Ë¾µÄÍøÂç¹¥»÷Ôì³ÉµÄ¾¼ÃÓ°ÏìΪ 4900 ÍòÃÀÔª¡£ÕâЩ³É±¾°üÂÞÖжÏÔì³ÉµÄËðʧ£¬ÒÔ¼°ÐÖú¹«Ë¾ÊÓ²ìºÍµ÷Í£¹¥»÷µÄµÚÈý·½È¡Ö¤ºÍÕÕÁϵÄÓöȡ£¸Ã¹«Ë¾»¹Ô¤¼Æ 2024 ²ÆÄêÒµ¼¨½«·ºÆð¸ºÃæÓ°Ïì¡£¸Ã¹«Ë¾Ôö²¹Ëµ£¬ÔÚ½ØÖÁ 2023 Äê 12 Ô 31 ÈÕµÄÈý¸öÔºÍÁù¸öÔÂÄÚ£¬ËüûÓмǼÓëÍøÂç¹¥»÷Ïà¹ØµÄÈκα£ÏÕÊÕÒæ¡£±£ÏÕÅâ³¥¼òÖ±ÈÏ£¨Èç¹ûÊÊÓã©¿ÉÄÜÓëÈ·ÈÏÏà¹ØÓöȵÄʱ¼ä·×ÆçÖ¡£
https://securityaffairs.com/158575/security/clorox-attack-costs-exceed-49m.html
2. AnyDesk Ôâµ½ºÚ¿ÍÈëÇÖ£¬ÆäÉú²ú·þÎñÆ÷ÃÜÂë±»ÖØÖÃ
2ÔÂ2ÈÕ£¬AnyDesk ½ñÌì֤ʵ£¬Ëü×î½üÔâÊÜÁËÒ»´ÎÍøÂç¹¥»÷£¬ºÚ¿ÍµÃÒÔ·ÃÎʸù«Ë¾µÄÉú²úϵͳ¡£BleepingComputer »ñϤ£¬Ô´´úÂëºÍ˽ÓдúÂëÇ©ÃûÃÜÔ¿ÔÚ¹¥»÷Æڼ䱻µÁ¡£AnyDesk ÊÇÒ»ÖÖÔ¶³Ì·ÃÎʽâ¾ö·½°¸£¬ÔÊÐíÓû§Í¨¹ýÍøÂç»ò»¥ÁªÍøÔ¶³Ì·ÃÎʼÆËã»ú¡£¸Ã·¨Ê½·Ç³£ÊÜÆóÒµ»¶Ó£¬ÆóҵʹÓÃËüÀ´ÌṩԶ³ÌÖ§³Ö»ò·ÃÎÊÍйܷþÎñÆ÷¡£¸ÃÈí¼þÔÚÍþвÐÐΪÕßÖÐÒ²ºÜÊÜ»¶Ó£¬ËûÃÇʹÓÃËüÀ´ Á¬Ðø·ÃÎÊÊÜÆÆ»µµÄÉ豸ºÍÍøÂç¡£¸Ã¹«Ë¾³ÂËß³ÆÓµÓÐ 170,000 Ãû¿Í»§£¬°üÂÞ 7-11¡¢¿µ¿¨Ë¹ÌØ¡¢ÈýÐÇ¡¢ÂéÊ¡Àí¹¤Ñ§Ôº¡¢Ó¢Î°´ï¡¢Î÷ÃÅ×ÓºÍÁªºÏ¹ú¡£
https://www.bleepingcomputer.com/news/security/anydesk-says-hackers-breached-its-production-servers-reset-passwords/#google_vignette
3. Uber ±»ºÉÀ¼Êý¾Ý¼à¹Ü»ú¹¹·£¿î 1000 ÍòÅ·Ôª
2ÔÂ1ÈÕ£¬ºÉÀ¼Êý¾Ý±£»¤»ú¹¹·¢ÏÖ Uber δÄܹûÈ»ÆäÉú´æ˾»úÊý¾ÝµÄʱ¼äÒÔ¼°ÄÄЩŷÖÞÒÔÍâµÄÔ±¹¤¿ÉÒÔ·ÃÎÊÕâЩÊý¾Ý£¬Òò´Ë¸Ã»ú¹¹±ØÐëÏò Uber Ö§¸¶ 1000 ÍòÅ·ÔªµÄ·£¿î¡£´Ë´Î·£¿îÊÇƾ¾Ý 172 Ãû·¨¹ú Uber ˾»úºÍ×ܲ¿Î»ÓÚ°ÍÀèµÄÃñ¼äÉç»á×éÖ¯ Ligue des Droits de l'Homme et du Citoyen (LDH) Ìá³öµÄͶË߶ø·¢ÉúµÄ¡£×î³õµÄͶËßÊÇÏò·¨¹úÊý¾Ý¼à¹Ü»ú¹¹Ìá³öµÄ£¬µ«ÓÉÓڸù«Ë¾µÄÅ·ÖÞ×ܲ¿Î»ÓÚ°¢Ä·Ë¹Ìص¤£¬Òò´ËºÉÀ¼¼à¹Ü»ú¹¹¸ºµ£Á˹ÜϽȨ¡£ºÉÀ¼ÃÀÁªÉçÖ÷ϯ°¢À³µÂ¡¤ÎÖ¶û·òÉ (Aleid Wolfsen) ÌåÏÖ£º¡°Uber Óû§ÓÐȨ֪µÀ Uber ÈçºÎ´¦ÖÃËûÃǵÄÊý¾Ý¡£µ«ÊÇ£¬Uber ²¢Ã»ÓжԴ˽øÐÐ×ã¹»ÇåÎúµÄ½âÊÍ¡£¡± ¡°Õâ±íÃ÷ Uber ÉèÖÃÁËÖÖÖÖÕÏ°£¬×èÖ¹Óû§ÐÐʹÆäÒþ˽Ȩ£¬¶øÕâÊDZ»½ûÖ¹µÄ¡£¡±
https://www.bankinfosecurity.com/uber-fined-10-million-euros-by-dutch-data-regulator-a-24250?&web_view=true
4. ¹ú¼ÊÐ̾¯×éÖ¯ Synergia Ðж¯´Ý»Ù 1300 ̨ÓÃÓÚ·¸×ïµÄ·þÎñÆ÷
2ÔÂ2ÈÕ£¬´úºÅΪ¡°Synergia¡±µÄ¹ú¼ÊÖ´·¨Ðж¯ÒѹرÕÁË 1,300 ¶à¸öÓÃÓÚÀÕË÷Èí¼þ¡¢ÍøÂçµöÓãºÍ¶ñÒâÈí¼þ»î¶¯µÄÃüÁîºÍ¿ØÖÆ·þÎñÆ÷¡£ÃüÁîºÍ¿ØÖÆ·þÎñÆ÷ (C2) ÊÇÓÉÍþвÐÐΪÕß²Ù×÷µÄÉ豸£¬ÓÃÓÚ¿ØÖƹ¥»÷ÖÐʹÓõĶñÒâÈí¼þ²¢ÊÕ¼¯´ÓÊÜѬȾÉ豸·¢Ë͵ÄÐÅÏ¢¡£ÕâЩ·þÎñÆ÷ÔÊÐíÍþвÐÐΪÕßÍÆËÍÌرðµÄÓÐЧ¸ºÔØ»òÃüÁîÒÔÔÚÊÜѬȾµÄÉ豸ÉÏÖ´ÐУ¬Ê¹ËüÃdzÉΪÐí¶à¹¥»÷Öв»ÐлòȱµÄ¼Ü¹¹¡£¶ÔÓÚijЩ¶ñÒâÈí¼þ£¬Ê¹ÃüÁîºÍ¿ØÖÆ·þÎñÆ÷ÍÑ»ú¿ÉÒÔ·ÀÖ¹½øÒ»²½µÄ¶ñÒâ»î¶¯£¬ÒòΪÍþвÐÐΪÕßÎÞ·¨´ÓÊÜѬȾµÄÉ豸·¢ËÍ»ò½ÓÊÕÊý¾Ý¡£Synergia Ðж¯ÔÚ 2023 Äê 9 ÔÂÖÁ 11 ÔÂÆÚ¼äʶ±ð²¢¹Ø±ÕÁËÖ¸»ÓºÍ¿ØÖÆ·þÎñÆ÷£¬À´×Ô 55 ¸ö¹ú¼ÒµÄ 60 ¸öÖ´·¨»ú¹¹¼ÓÈëÁ˸ÃÐж¯¡£
https://www.bleepingcomputer.com/news/legal/interpol-operation-synergia-takes-down-1-300-servers-used-for-cybercrime/
5.FritzFrog ½©Ê¬ÍøÂç¹¥»÷ Linux ·þÎñÆ÷ÇÔÈ¡ SSH ƾ֤
2ÔÂ2ÈÕ£¬FritzFrog ½©Ê¬ÍøÂç×î³õÓÚ 2020 Äê±»·¢ÏÖ£¬ÊÇÒ»ÖÖÓà Golang ¹¹½¨µÄ¸ß¼¶µã¶Ôµã½©Ê¬ÍøÂ磬¿ÉÒÔÔÚ»ùÓÚ AMD ºÍ ARM µÄÉ豸ÉÏÔËÐС£Ëæ×Ų»Í£µÄ¸üУ¬¶ñÒâÈí¼þËæ×Åʱ¼äµÄÍÆÒƲ»Í£Éú³¤£¬Ìí¼ÓºÍÔöÇ¿Á˹¦Ð§¡£ÈËÃÇ·¢ÏÖÁË FritzFrog ½©Ê¬ÍøÂçµÄбäÖÖ£¬ËüÀûÓÃLog4Shell ©¶´À´Õë¶ÔÄÚ²¿ÍøÂçÖеÄËùÓÐÖ÷»ú¡£´ËÍ⣬ͨ¹ýʹÓÃÈõ SSH ƾ¾Ý£¬¶ñÒâÈí¼þ»á¹¥»÷¿Éͨ¹ý»¥ÁªÍø·ÃÎʵķþÎñÆ÷¡£Akamai Ó롶ÍøÂçÄþ¾²ÐÂÎÅ¡··ÖÏíµÀ£º¡°½ÏеıäÌåÏÖÔÚ»á¶ÁÈ¡ÊÜѬȾÖ÷»úÉϵĶà¸öϵͳÎļþ£¬ÒÔ¼ì²âºÜ¿ÉÄÜÈÝÒ×Êܵ½¹¥»÷µÄDZÔÚÄ¿±ê¡£¡±FritzFrog ʹÓõÄΨһѬȾý½éÊÇ SSH±©Á¦Æƽ⣻Ȼ¶ø£¬¸Ã¶ñÒâÈí¼þµÄ×îа汾Ìí¼ÓÁËÃûΪ¡°Frog4Shell¡±µÄ Log4Shell ©¶´ÀûÓá£
https://gbhackers.com/fritzfrog-botnet-linux-servers/
6. PurpleFox ¶ñÒâÈí¼þѬȾÎÚ¿ËÀ¼Êýǧ̨¼ÆËã»ú
2ÔÂ1ÈÕ£¬ÎÚ¿ËÀ¼¼ÆËã»ú½ô¼±ÏìӦС×é (CERT-UA) ¾¯¸æ³Æ£¬PurpleFox ¶ñÒâÈí¼þ»î¶¯ÒÑѬȾ¸Ã¹úÖÁÉÙ 2,000 ̨¼ÆËã»ú¡£ÕâÖֹ㷺ѬȾ¼òÖ±ÇÐÓ°ÏìÒÔ¼°ËüÊÇ·ñÓ°ÏìÁ˹ú¼Ò×éÖ¯»òÆÕͨÈ˵ļÆËã»úÉÐδȷ¶¨£¬µ«¸Ã»ú¹¹ÒѾ·ÖÏíÁËÓйØÈçºÎ¶¨Î»Ñ¬È¾ºÍɾ³ý¶ñÒâÈí¼þµÄÏêϸÐÅÏ¢¡£PurpleFox£¨»ò¡°DirtyMoe¡±£©ÊÇÒ»ÖÖ Ä£¿é»¯ Windows ½©Ê¬ÍøÂç¶ñÒâÈí¼þ £¬ÓÚ 2018 ÄêÊ״η¢ÏÖ£¬´øÓÐ rootkit Ä£¿é£¬ÔÊÐíÆäÔÚÉ豸ÖØÐÂÆô¶¯ÆÚ¼äÒþ²Ø²¢Á¬Ðø´æÔÚ¡£Ëü¿ÉÒÔÓÃ×÷ÏÂÔØ·¨Ê½£¬ÔÚÊÜѬȾµÄϵͳÉÏÒýÈë¸üÇ¿´óµÄµÚ¶þ½×¶ÎÓÐЧ¸ºÔØ£¬ÎªÆäÔËÓªÉÌÌṩºóÃŹ¦Ð§£¬»¹¿ÉÒԳ䵱ÂþÑÜʽ¾Ü¾ø·þÎñ£¨DDoS£©»úÆ÷ÈË¡£
https://www.bleepingcomputer.com/news/security/purplefox-malware-infects-thousands-of-computers-in-ukraine/?&web_view=true