Microsoft Ðû²¼ÔÚ Windows ÖÐÆúÓà 1024 λ RSA ÃÜÔ¿

Ðû²¼Ê±¼ä 2024-03-20
1. Microsoft Ðû²¼ÔÚ Windows ÖÐÆúÓà 1024 λ RSA ÃÜÔ¿


3ÔÂ18ÈÕ £¬Microsoft Ðû²¼ £¬Windows ´«Êä²ãÄþ¾² (TLS) Öн«ºÜ¿ìÆúÓöÌÓÚ 2048 λµÄ RSA ÃÜÔ¿ £¬ÒÔÌṩ¸ü¸ßµÄÄþ¾²ÐÔ¡£Rivest¨CShamir¨CAdleman (RSA) ÊÇÒ»ÖַǶԳƼÓÃÜϵͳ £¬ËüʹÓÃÒ»¶Ô¹«Ô¿ºÍ˽ԿÀ´¼ÓÃÜÊý¾Ý £¬ÆäÇ¿¶ÈÓëÃÜÔ¿µÄ³¤¶ÈÖ±½ÓÏà¹Ø¡£ÕâЩÃÜÔ¿Ô½³¤ £¬¾ÍÔ½ÄÑÆƽâ¡£1024 λ RSA ÃÜÔ¿µÄÇ¿¶ÈԼΪ 80 λ £¬¶ø 2048 λÃÜÔ¿µÄÇ¿¶ÈԼΪ 112 λ £¬ÕâʹµÃºóÕßµÄÆÊÎöʱ¼ä³¤ÁË 40 ÒÚ±¶¡£¸ÃÁìÓòµÄר¼ÒÈÏΪ 2048 λÃÜÔ¿ ÖÁÉÙÔÚ 2030 Äê֮ǰ¶¼ÊÇÄþ¾²µÄ¡£RSA ÃÜÔ¿ÔÚ Windows ÖÐÓÃÓÚ¶àÖÖÓÃ; £¬°üÂÞ·þÎñÆ÷Éí·ÝÑéÖ¤¡¢Êý¾Ý¼ÓÃܺÍÈ·±£Í¨ÐŵÄÍêÕûÐÔ¡£Microsoft ¾ö¶¨½« TLS ·þÎñÆ÷Éí·ÝÑéÖ¤ÖÐʹÓõÄÖ¤ÊéµÄ RSA ÃÜÔ¿×îµÍÒªÇóÌá¸ßµ½ 2048 λ»ò¸ü³¤ £¬Õâ¶ÔÓÚ±£»¤×éÖ¯ÃâÊÜÈõ¼ÓÃܵÄÓ°Ïì·Ç³£ÖØÒª¡£


https://www.bleepingcomputer.com/news/microsoft/microsoft-announces-deprecation-of-1024-bit-rsa-keys-in-windows/


2. ¶ñÒâÈí¼þ»î¶¯ÀÄÓà Google ÍøÕ¾À´ÇÔÈ¡Êý¾Ý Azorult


3ÔÂ19ÈÕ £¬Netskope ÍþвʵÑéÊÒµÄÄþ¾²Ñо¿ÈËÔ±ÆعâÁËÒ»¸öÅÓ´óµÄ¶ñÒâÈí¼þ»î¶¯ £¬¸Ã»î¶¯ÀûÓà Google Э×÷ƽ̨µÄ¿ÉÐŶÈÀ´Ìṩǿ´óµÄа汾 Azorult ÐÅÏ¢ÇÔÈ¡·¨Ê½¡£¸Ã¶ñÒâÈí¼þÓÉÓÚÆäÌӱܼì²âºÍÇÔÈ¡ÖÖÖÖÃô¸ÐÐÅÏ¢µÄÏȽøÄÜÁ¦¶ø×é³ÉÁËÖØ´óµÄÍøÂçÄþ¾²·çÏÕ¡£Azorult ÊÇÒ»¸ö¶ñÒⷨʽ £¬Ö¼ÔÚÇÔÈ¡ÄúµÄ˽ÈËÐÅÏ¢¡£ËüµÄÄ¿±êÊÇÓû§Ãû¡¢ÃÜÂë¡¢ä¯ÀÀÀúÊ·¼Ç¼ £¬ÉõÖÁ¼ÓÃÜ»õ±ÒÇ®°üÊý¾Ý¡£Òź¶µÄÊÇ £¬Azorult ͵ÇÔ°¸¼þ³ÊÉÏÉýÇ÷ÊÆ £¬ÓÈÆäÊÇÔÚÒ½ÁƱ£½¡ÐÐÒµ¡£Azorult ±»ÈÏΪÊǹýÈ¥Ò»ÄêÖй¥»÷Ò½ÁƱ£½¡ÐÐÒµµÄ¶¥¼¶¶ñÒâÈí¼þ¼Ò×åÖ®Ò»¡£È»¶ø £¬Æä×î½üµÄ»î¶¯½«Æäа¶ñ»î¶¯ÍÆÏòÁËÐÂµÄ¸ß¶È £¬½ÓÄɶ෽ÃæµÄÒªÁìÀ´Í¨±¨ÆäÓÐЧ¸ºÔØ £¬Í¬Ê±Ìӱܼì²â¡£¹¥»÷µÄ³õʼ½×¶ÎÉæ¼°HTML ×ß˽ £¬ÕâÖÖ¼¼ÊõÔÚÍøÂç¹¥»÷ÕßÖÐÔ½À´Ô½Á÷ÐС£´ËÒªÁìͨ¹ýʹÓúϷ¨µÄ HTML5 ¹¦Ð§ºÍ Javascript Ö±½ÓÔÚ¿Í»§¶Ë¹¹½¨¶ñÒ⸺ÔØ £¬ÇÉÃîµØÈƹýWeb ¿ØÖÆ¡£ÇÉÃîµÄÊÇ £¬¸Ã»î¶¯²¢Î´½«ÓÐЧ¸ºÔØǶÈëµ½ Javascript ×Ô¼ºÖÐ £¬¶øÊÇǶÈëµ½ÍⲿÍйܵĵ¥¶À JSON ÎļþÖÐ £¬´Ó¶øÔö¼ÓÁËÌرðµÄÒþÃزã¡£


https://securityonline.info/sneaky-malware-campaign-abuses-google-sites-to-deliver-data-stealing-azorult/


3. Õë¶ÔÎÚ¿ËÀ¼µÄРLinux ¶ñÒâÈí¼þ±äÖÖAcidPour


3ÔÂ19ÈÕ £¬SentinelLabs µÄÑо¿ÈËÔ±·¢ÏÖÁËËáÓê¶ñÒâÈí¼þµÄÒ»ÖÖбäÖÖ £¬³ÆΪ¡°Acid Pour¡± £¬ÒÑÔÚÎÚ¿ËÀ¼·ºÆð¡£ÕâÒ»·¢ÏÖÊÇÔÚÖÜÄ©ÓÉ SentinelLabs µÄ¸±×ܲà JA Guerrero-Saade ͨ¹ý X£¨ÒÔÇ°µÄ Twitter£©·ÖÏíµÄ¼û½âµÃ³öµÄ¡£×î³õµÄ AcidRain ¶ñÒâÈí¼þÓÚ 2022 Äê 3 Ô·ºÆ𠣬ÌرðÊÇÔÚ¡°Viasat ºÚ¿Í¹¥»÷¡±ÆÚ¼äʹÓà £¬¸ÃºÚ¿Í¹¥»÷ÔÚ¶íÂÞ˹ÈëÇÖÎÚ¿ËÀ¼¿ªÊ¼Ê±ÖжÏÁË KA-SAT Surfbeam2 µ÷Öƽâµ÷Æ÷¡£SentinelLabs µÄÊ×ϯÍþвÑо¿Ô±TomHegel·¢ÏÖÁËרΪ Linux x86 É豸±àÒëµÄбäÌå¡£ËäÈ» AcidPour Óë AcidRain ÔÚijЩ×Ö·û´®ÖоßÓÐÏàËÆÖ®´¦ £¬µ«ËüÔÚ´úÂë¿âÖдæÔÚÏÔ×ŲîÒì £¬´úÂë¿âÊÇÕë¶Ô x86 ¼Ü¹¹¶ø²»ÊÇ MIPS ±àÒëµÄ¡£ÖµµÃ×¢ÒâµÄÊÇ £¬ÊÊÓÃÓÚ x86 É豸µÄÁ÷ÐÐ Linux ¿¯Ðаæ°üÂÞ Ubuntu¡¢Mint¡¢Fedora ºÍ Debian¡£ÁíÒ»·½Ãæ £¬MIPS£¨ÎÞ»¥ËøÁ÷Ë®Ï߽׶εÄ΢´¦ÖÃÆ÷£©ÊÇÒ»ÖÖÖ¸Á¼Ü¹¹£¨ISA£© £¬Ëü±¾ÖÊÉϽç˵ÁË´¦ÖÃÆ÷Àí½â²¢ÓÃÓÚÖ´ÐÐÖ¸ÁîµÄÓïÑÔ¡£Óë x86 ÀàËÆ £¬ËüÊÇÒ»×é¹ØÓÚ´¦ÖÃÆ÷ÈçºÎÔËÐеĹæÔòºÍ¹æ·¶¡£


https://www.hackread.com/acidrain-linux-malware-variant-acidpour-ukraine/#google_vignette


4. Ð嵀 DEEP#GOSU ¶ñÒâÈí¼þ»î¶¯ÀûÓø߼¶¼ÆıÃé×¼ Windows Óû§


3ÔÂ18ÈÕ £¬¸Ã¹¥»÷»î¶¯ÀûÓà PowerShell ºÍ VBScript ¶ñÒâÈí¼þÀ´Ñ¬È¾ Windows ϵͳ²¢»ñÈ¡Ãô¸ÐÐÅÏ¢¡£ÍøÂçÄþ¾²¹«Ë¾ Securonix ½«¸Ã»î¶¯³ÆΪ¡°DEEP#GOSU¡± £¬ÌåÏָû¿ÉÄÜÓ볯Ïʹú¼ÒÖ§³ÖµÄÃûΪKimsukyµÄ×éÖ¯ÓйØ¡£DEEP#GOSUÖÐʹÓõĶñÒâÈí¼þÓÐЧ¸ºÔØ´ú±íÁËÒ»ÖÖÅÓ´óµÄ¶à½×¶ÎÍþв £¬Ö¼ÔÚÔÚ Windows ϵͳÉÏÃØÃÜÔËÐÐ £¬ÓÈÆäÊÇ´ÓÍøÂç¼à¿ØµÄ½Ç¶ÈÀ´¿´¡£ËüµÄ¹¦Ð§°üÂÞ¼üÅ̼Ǽ¡¢¼ôÌù°å¼à¿Ø¡¢¶¯Ì¬ÓÐЧ¸ºÔØÖ´ÐкÍÊý¾Ýй¶ £¬ÒÔ¼°Ê¹Óà RAT Èí¼þ½øÐÐÍêÈ«Ô¶³Ì·ÃÎÊ¡¢¼Æ»®ÈÎÎñÒÔ¼°Ê¹ÓÃ×÷Òµ×Ô¶¯Ö´ÐÐ PowerShell ½Å±¾µÄ³Ö¾ÃÐÔ¡£Ñ¬È¾¹ý³ÌµÄÒ»¸öÖµµÃ×¢ÒâµÄ·½ÃæÊÇ £¬ËüÀûÓà Dropbox »ò Google Docs µÈºÏ·¨·þÎñ½øÐÐÃüÁîºÍ¿ØÖÆ (C2) £¬´Ó¶øÔÊÐíÍþвÐÐΪÕßÔÚδ¼ì²âµ½µÄÇé¿öÏÂÈÚÈëͨÀýÍøÂçÁ÷Á¿¡£


https://thehackernews.com/2024/03/new-deepgosu-malware-campaign-targets.html


5. ºÚ¿ÍÔÚÍøÂç¹¥»÷ÖÐʹÓÃÎäÆ÷»¯ SVG Îļþ


3ÔÂ18ÈÕ £¬ÍøÂç·¸×ï·Ö×ÓÖØÐÂÀûÓÿÉÀ©Õ¹Ê¸Á¿Í¼ÐÎ (SVG) ÎļþÀ´Á÷´«¶ñÒâÈí¼þ £¬ÕâÖÖ¼¼ÊõËæ×Å AutoSmuggle ¹¤¾ßµÄ·ºÆð¶øµÃµ½ÁËÏÔ×ÅÉú³¤¡£AutoSmuggle ÓÚ 2022 Äê 5 ÔÂÍƳö £¬ÓÐÖúÓÚÔÚ HTML »ò SVG ÄÚÈÝÖÐǶÈë¶ñÒâÎļþ £¬Ê¹¹¥»÷Õ߸üÈÝÒ×ÈƹýÄþ¾²´ëÊ©¡£ÀÄÓà SVG ÎļþÁ÷´«¶ñÒâÈí¼þµÄÇé¿ö¿ÉÒÔ×·Ëݵ½ 2015 Äê £¬ÀÕË÷Èí¼þÊÇ×îÏÈͨ¹ý´Ëý½éÁ÷´«µÄÀÕË÷Èí¼þÖ®Ò»¡£2017 Äê 1 Ô £¬SVG Îļþ±»ÓÃÀ´Í¨¹ý URL ÏÂÔØ Ursnif ¶ñÒâÈí¼þ¡£2022 Äê·¢ÉúÁËÖØ´ó·ÉÔ¾ £¬Æäʱ SVG ͨ¹ýǶÈëʽ .zip ´æµµÁ÷´«QakBotµÈ¶ñÒâÈí¼þ £¬Õ¹Ê¾ÁË´ÓÍⲿÏÂÔص½ HTML ×ß˽¼¼ÊõµÄת±ä¡£2022 Äê AutoSmuggle ÔÚ GitHub ÉϵÄÐû²¼±êÖ¾×ÅÒ»¸öתÕ۵㡣¸Ã¹¤¾ß½«¿ÉÖ´ÐÐÎļþ»ò´æµµÇ¶Èëµ½ SVG/HTML ÎļþÖÐ £¬È»ºóÔÚÊܺ¦Õß´ò¿ªÊ±½âÃܲ¢Ö´ÐС£´ËÒªÁìÇÉÃîµØ±Ü¿ªÁËͨ³£»á¼ì²âºÍ¸ôÀëÖ±½Óµç×ÓÓʼþ¸½¼þµÄÄþ¾²µç×ÓÓʼþÍø¹Ø(SEG)¡£


https://gbhackers.com/hackers-using-weaponized-svg-files-in-cyber-attacks/


6. Nissan Oceania ÒÑÈ·ÈÏÈ¥ÄêÔâÊܵÄÊý¾Ýй¶ӰÏìÔ¼ 10 ÍòÈË


3ÔÂ18ÈÕ £¬Nissan Oceania ÒÑÈ·ÈÏ 2023 Äê 12 ÔÂÔâÊܵÄÊý¾Ýй¶ӰÏìÁËÔ¼ 10 ÍòÈË £¬²¢ÒÑ¿ªÊ¼ÏòËûÃÇ·¢³ö֪ͨ¡£ £¬¸Ã¹«Ë¾£¨°üÂÞÈÕ²úÆû³µ¹«Ë¾ÒÔ¼°°Ä´óÀûÑǺÍÐÂÎ÷À¼µÄÈÕ²ú½ðÈÚ·þÎñ¹«Ë¾£©Í¸Â¶ £¬Î´¾­ÊÚȨµÄµÚÈý·½·ÃÎÊÁËÆäµ±µØ IT ·þÎñÆ÷²¢µ¼ÖÂÍ£»ú¡£¸Ã¹«Ë¾Ö¸³ö£º¡°ÎÒÃÇÁ¢¼´½ÓÄÉÐж¯Í£Ö¹Î¥¹æÐÐΪ £¬²¢¼°Ê±ÏòÏà¹ØÕþ¸®»ú¹¹·¢³ö¾¯±¨ £¬°üÂÞ°Ä´óÀûÑǺÍÐÂÎ÷À¼¹ú¼ÒÍøÂçÄþ¾²ÖÐÐĺÍÒþ˽¼à¹Ü»ú¹¹¡£¡±Æäʱ £¬ËûÃÇÎÞ·¨È·ÈÏʼþµÄÑÏÖØˮƽºÍÀàÐÍ £¬µ«¼¸ÖÜºó £¬Akira ÀÕË÷Èí¼þ×éÖ¯Éù³Æ¶Ô´Ë´Î¹¥»÷ÂôÁ¦ £¬²¢Ð¹Â¶Á˾ݳƴӸù«Ë¾ÇÔÈ¡µÄÊý¾Ý¡£¸Ã¹«Ë¾Ëæºó¶Ø´Ù¿Í»§ÁôÒâÒì³£»î¶¯ºÍ¿ÉÄܵÄÕ©Æ­ £¬Í¬Ê±ÓëÕþ¸®Õþ¸®ºÍÍⲿÍøÂçȡ֤ר¼ÒºÏ×÷¼ÌÐøÊӲ졣


https://www.helpnetsecurity.com/2024/03/18/nissan-data-breach/