Microsoft Ðû²¼ÔÚ Windows ÖÐÆúÓà 1024 λ RSA ÃÜÔ¿
Ðû²¼Ê±¼ä 2024-03-203ÔÂ18ÈÕ£¬Microsoft Ðû²¼£¬Windows ´«Êä²ãÄþ¾² (TLS) Öн«ºÜ¿ìÆúÓöÌÓÚ 2048 λµÄ RSA ÃÜÔ¿£¬ÒÔÌṩ¸ü¸ßµÄÄþ¾²ÐÔ¡£Rivest¨CShamir¨CAdleman (RSA) ÊÇÒ»ÖַǶԳƼÓÃÜϵͳ£¬ËüʹÓÃÒ»¶Ô¹«Ô¿ºÍ˽ԿÀ´¼ÓÃÜÊý¾Ý£¬ÆäÇ¿¶ÈÓëÃÜÔ¿µÄ³¤¶ÈÖ±½ÓÏà¹Ø¡£ÕâЩÃÜÔ¿Ô½³¤ £¬¾ÍÔ½ÄÑÆƽ⡣1024 λ RSA ÃÜÔ¿µÄÇ¿¶ÈԼΪ 80 룬¶ø 2048 λÃÜÔ¿µÄÇ¿¶ÈԼΪ 112 룬ÕâʹµÃºóÕßµÄÆÊÎöʱ¼ä³¤ÁË 40 ÒÚ±¶¡£¸ÃÁìÓòµÄר¼ÒÈÏΪ 2048 λÃÜÔ¿ ÖÁÉÙÔÚ 2030 Äê֮ǰ¶¼ÊÇÄþ¾²µÄ¡£RSA ÃÜÔ¿ÔÚ Windows ÖÐÓÃÓÚ¶àÖÖÓÃ;£¬°üÂÞ·þÎñÆ÷Éí·ÝÑéÖ¤¡¢Êý¾Ý¼ÓÃܺÍÈ·±£Í¨ÐŵÄÍêÕûÐÔ¡£Microsoft ¾ö¶¨½« TLS ·þÎñÆ÷Éí·ÝÑéÖ¤ÖÐʹÓõÄÖ¤ÊéµÄ RSA ÃÜÔ¿×îµÍÒªÇóÌá¸ßµ½ 2048 λ»ò¸ü³¤£¬Õâ¶ÔÓÚ±£»¤×éÖ¯ÃâÊÜÈõ¼ÓÃܵÄÓ°Ïì·Ç³£ÖØÒª¡£
https://www.bleepingcomputer.com/news/microsoft/microsoft-announces-deprecation-of-1024-bit-rsa-keys-in-windows/
2. ¶ñÒâÈí¼þ»î¶¯ÀÄÓà Google ÍøÕ¾À´ÇÔÈ¡Êý¾Ý Azorult
3ÔÂ19ÈÕ£¬Netskope ÍþвʵÑéÊÒµÄÄþ¾²Ñо¿ÈËÔ±ÆعâÁËÒ»¸öÅÓ´óµÄ¶ñÒâÈí¼þ»î¶¯£¬¸Ã»î¶¯ÀûÓà Google Ð×÷ƽ̨µÄ¿ÉÐŶÈÀ´Ìṩǿ´óµÄа汾 Azorult ÐÅÏ¢ÇÔÈ¡·¨Ê½¡£¸Ã¶ñÒâÈí¼þÓÉÓÚÆäÌӱܼì²âºÍÇÔÈ¡ÖÖÖÖÃô¸ÐÐÅÏ¢µÄÏȽøÄÜÁ¦¶ø×é³ÉÁËÖØ´óµÄÍøÂçÄþ¾²·çÏÕ¡£Azorult ÊÇÒ»¸ö¶ñÒⷨʽ£¬Ö¼ÔÚÇÔÈ¡ÄúµÄ˽ÈËÐÅÏ¢¡£ËüµÄÄ¿±êÊÇÓû§Ãû¡¢ÃÜÂë¡¢ä¯ÀÀÀúÊ·¼Ç¼£¬ÉõÖÁ¼ÓÃÜ»õ±ÒÇ®°üÊý¾Ý¡£Òź¶µÄÊÇ£¬Azorult ͵ÇÔ°¸¼þ³ÊÉÏÉýÇ÷ÊÆ£¬ÓÈÆäÊÇÔÚÒ½ÁƱ£½¡ÐÐÒµ¡£Azorult ±»ÈÏΪÊǹýÈ¥Ò»ÄêÖй¥»÷Ò½ÁƱ£½¡ÐÐÒµµÄ¶¥¼¶¶ñÒâÈí¼þ¼Ò×åÖ®Ò»¡£È»¶ø£¬Æä×î½üµÄ»î¶¯½«Æäа¶ñ»î¶¯ÍÆÏòÁËеĸ߶ȣ¬½ÓÄɶ෽ÃæµÄÒªÁìÀ´Í¨±¨ÆäÓÐЧ¸ºÔØ£¬Í¬Ê±Ìӱܼì²â¡£¹¥»÷µÄ³õʼ½×¶ÎÉæ¼°HTML ×ß˽£¬ÕâÖÖ¼¼ÊõÔÚÍøÂç¹¥»÷ÕßÖÐÔ½À´Ô½Á÷ÐС£´ËÒªÁìͨ¹ýʹÓúϷ¨µÄ HTML5 ¹¦Ð§ºÍ Javascript Ö±½ÓÔÚ¿Í»§¶Ë¹¹½¨¶ñÒ⸺ÔØ£¬ÇÉÃîµØÈƹýWeb ¿ØÖÆ¡£ÇÉÃîµÄÊÇ£¬¸Ã»î¶¯²¢Î´½«ÓÐЧ¸ºÔØǶÈëµ½ Javascript ×Ô¼ºÖУ¬¶øÊÇǶÈëµ½ÍⲿÍйܵĵ¥¶À JSON ÎļþÖУ¬´Ó¶øÔö¼ÓÁËÌرðµÄÒþÃز㡣
https://securityonline.info/sneaky-malware-campaign-abuses-google-sites-to-deliver-data-stealing-azorult/
3. Õë¶ÔÎÚ¿ËÀ¼µÄРLinux ¶ñÒâÈí¼þ±äÖÖAcidPour
3ÔÂ19ÈÕ£¬SentinelLabs µÄÑо¿ÈËÔ±·¢ÏÖÁËËáÓê¶ñÒâÈí¼þµÄÒ»ÖÖбäÖÖ£¬³ÆΪ¡°Acid Pour¡±£¬ÒÑÔÚÎÚ¿ËÀ¼·ºÆð¡£ÕâÒ»·¢ÏÖÊÇÔÚÖÜÄ©ÓÉ SentinelLabs µÄ¸±×ܲà JA Guerrero-Saade ͨ¹ý X£¨ÒÔÇ°µÄ Twitter£©·ÖÏíµÄ¼û½âµÃ³öµÄ¡£×î³õµÄ AcidRain ¶ñÒâÈí¼þÓÚ 2022 Äê 3 Ô·ºÆð£¬ÌرðÊÇÔÚ¡°Viasat ºÚ¿Í¹¥»÷¡±ÆÚ¼äʹÓ㬸úڿ͹¥»÷ÔÚ¶íÂÞ˹ÈëÇÖÎÚ¿ËÀ¼¿ªÊ¼Ê±ÖжÏÁË KA-SAT Surfbeam2 µ÷Öƽâµ÷Æ÷¡£SentinelLabs µÄÊ×ϯÍþвÑо¿Ô±TomHegel·¢ÏÖÁËרΪ Linux x86 É豸±àÒëµÄбäÌå¡£ËäÈ» AcidPour Óë AcidRain ÔÚijЩ×Ö·û´®ÖоßÓÐÏàËÆÖ®´¦£¬µ«ËüÔÚ´úÂë¿âÖдæÔÚÏÔ×ŲîÒ죬´úÂë¿âÊÇÕë¶Ô x86 ¼Ü¹¹¶ø²»ÊÇ MIPS ±àÒëµÄ¡£ÖµµÃ×¢ÒâµÄÊÇ£¬ÊÊÓÃÓÚ x86 É豸µÄÁ÷ÐÐ Linux ¿¯Ðаæ°üÂÞ Ubuntu¡¢Mint¡¢Fedora ºÍ Debian¡£ÁíÒ»·½Ã棬MIPS£¨ÎÞ»¥ËøÁ÷Ë®Ï߽׶εÄ΢´¦ÖÃÆ÷£©ÊÇÒ»ÖÖÖ¸Á¼Ü¹¹£¨ISA£©£¬Ëü±¾ÖÊÉϽç˵ÁË´¦ÖÃÆ÷Àí½â²¢ÓÃÓÚÖ´ÐÐÖ¸ÁîµÄÓïÑÔ¡£Óë x86 ÀàËÆ£¬ËüÊÇÒ»×é¹ØÓÚ´¦ÖÃÆ÷ÈçºÎÔËÐеĹæÔòºÍ¹æ·¶¡£
https://www.hackread.com/acidrain-linux-malware-variant-acidpour-ukraine/#google_vignette
4. Ð嵀 DEEP#GOSU ¶ñÒâÈí¼þ»î¶¯ÀûÓø߼¶¼ÆıÃé×¼ Windows Óû§
3ÔÂ18ÈÕ£¬¸Ã¹¥»÷»î¶¯ÀûÓà PowerShell ºÍ VBScript ¶ñÒâÈí¼þÀ´Ñ¬È¾ Windows ϵͳ²¢»ñÈ¡Ãô¸ÐÐÅÏ¢¡£ÍøÂçÄþ¾²¹«Ë¾ Securonix ½«¸Ã»î¶¯³ÆΪ¡°DEEP#GOSU¡±£¬ÌåÏָû¿ÉÄÜÓ볯Ïʹú¼ÒÖ§³ÖµÄÃûΪKimsukyµÄ×éÖ¯Óйء£DEEP#GOSUÖÐʹÓõĶñÒâÈí¼þÓÐЧ¸ºÔØ´ú±íÁËÒ»ÖÖÅÓ´óµÄ¶à½×¶ÎÍþв£¬Ö¼ÔÚÔÚ Windows ϵͳÉÏÃØÃÜÔËÐУ¬ÓÈÆäÊÇ´ÓÍøÂç¼à¿ØµÄ½Ç¶ÈÀ´¿´¡£ËüµÄ¹¦Ð§°üÂÞ¼üÅ̼Ǽ¡¢¼ôÌù°å¼à¿Ø¡¢¶¯Ì¬ÓÐЧ¸ºÔØÖ´ÐкÍÊý¾Ýй¶£¬ÒÔ¼°Ê¹Óà RAT Èí¼þ½øÐÐÍêÈ«Ô¶³Ì·ÃÎÊ¡¢¼Æ»®ÈÎÎñÒÔ¼°Ê¹ÓÃ×÷Òµ×Ô¶¯Ö´ÐÐ PowerShell ½Å±¾µÄ³Ö¾ÃÐÔ¡£Ñ¬È¾¹ý³ÌµÄÒ»¸öÖµµÃ×¢ÒâµÄ·½ÃæÊÇ£¬ËüÀûÓà Dropbox »ò Google Docs µÈºÏ·¨·þÎñ½øÐÐÃüÁîºÍ¿ØÖÆ (C2)£¬´Ó¶øÔÊÐíÍþвÐÐΪÕßÔÚδ¼ì²âµ½µÄÇé¿öÏÂÈÚÈëͨÀýÍøÂçÁ÷Á¿¡£
https://thehackernews.com/2024/03/new-deepgosu-malware-campaign-targets.html
5. ºÚ¿ÍÔÚÍøÂç¹¥»÷ÖÐʹÓÃÎäÆ÷»¯ SVG Îļþ
3ÔÂ18ÈÕ£¬ÍøÂç·¸×ï·Ö×ÓÖØÐÂÀûÓÿÉÀ©Õ¹Ê¸Á¿Í¼ÐÎ (SVG) ÎļþÀ´Á÷´«¶ñÒâÈí¼þ£¬ÕâÖÖ¼¼ÊõËæ×Å AutoSmuggle ¹¤¾ßµÄ·ºÆð¶øµÃµ½ÁËÏÔ×ÅÉú³¤¡£AutoSmuggle ÓÚ 2022 Äê 5 ÔÂÍƳö£¬ÓÐÖúÓÚÔÚ HTML »ò SVG ÄÚÈÝÖÐǶÈë¶ñÒâÎļþ£¬Ê¹¹¥»÷Õ߸üÈÝÒ×ÈƹýÄþ¾²´ëÊ©¡£ÀÄÓà SVG ÎļþÁ÷´«¶ñÒâÈí¼þµÄÇé¿ö¿ÉÒÔ×·Ëݵ½ 2015 Ä꣬ÀÕË÷Èí¼þÊÇ×îÏÈͨ¹ý´Ëý½éÁ÷´«µÄÀÕË÷Èí¼þÖ®Ò»¡£2017 Äê 1 Ô£¬SVG Îļþ±»ÓÃÀ´Í¨¹ý URL ÏÂÔØ Ursnif ¶ñÒâÈí¼þ¡£2022 Äê·¢ÉúÁËÖØ´ó·ÉÔ¾£¬Æäʱ SVG ͨ¹ýǶÈëʽ .zip ´æµµÁ÷´«QakBotµÈ¶ñÒâÈí¼þ£¬Õ¹Ê¾ÁË´ÓÍⲿÏÂÔص½ HTML ×ß˽¼¼ÊõµÄת±ä¡£2022 Äê AutoSmuggle ÔÚ GitHub ÉϵÄÐû²¼±êÖ¾×ÅÒ»¸öתÕ۵㡣¸Ã¹¤¾ß½«¿ÉÖ´ÐÐÎļþ»ò´æµµÇ¶Èëµ½ SVG/HTML ÎļþÖУ¬È»ºóÔÚÊܺ¦Õß´ò¿ªÊ±½âÃܲ¢Ö´ÐС£´ËÒªÁìÇÉÃîµØ±Ü¿ªÁËͨ³£»á¼ì²âºÍ¸ôÀëÖ±½Óµç×ÓÓʼþ¸½¼þµÄÄþ¾²µç×ÓÓʼþÍø¹Ø(SEG)¡£
https://gbhackers.com/hackers-using-weaponized-svg-files-in-cyber-attacks/
6. Nissan Oceania ÒÑÈ·ÈÏÈ¥ÄêÔâÊܵÄÊý¾Ýй¶ӰÏìÔ¼ 10 ÍòÈË
3ÔÂ18ÈÕ£¬Nissan Oceania ÒÑÈ·ÈÏ 2023 Äê 12 ÔÂÔâÊܵÄÊý¾Ýй¶ӰÏìÁËÔ¼ 10 ÍòÈË£¬²¢ÒÑ¿ªÊ¼ÏòËûÃÇ·¢³ö֪ͨ¡££¬¸Ã¹«Ë¾£¨°üÂÞÈÕ²úÆû³µ¹«Ë¾ÒÔ¼°°Ä´óÀûÑǺÍÐÂÎ÷À¼µÄÈÕ²ú½ðÈÚ·þÎñ¹«Ë¾£©Í¸Â¶£¬Î´¾ÊÚȨµÄµÚÈý·½·ÃÎÊÁËÆäµ±µØ IT ·þÎñÆ÷²¢µ¼ÖÂÍ£»ú¡£¸Ã¹«Ë¾Ö¸³ö£º¡°ÎÒÃÇÁ¢¼´½ÓÄÉÐж¯Í£Ö¹Î¥¹æÐÐΪ£¬²¢¼°Ê±ÏòÏà¹ØÕþ¸®»ú¹¹·¢³ö¾¯±¨£¬°üÂÞ°Ä´óÀûÑǺÍÐÂÎ÷À¼¹ú¼ÒÍøÂçÄþ¾²ÖÐÐĺÍÒþ˽¼à¹Ü»ú¹¹¡£¡±Æäʱ£¬ËûÃÇÎÞ·¨È·ÈÏʼþµÄÑÏÖØˮƽºÍÀàÐÍ£¬µ«¼¸Öܺó£¬Akira ÀÕË÷Èí¼þ×éÖ¯Éù³Æ¶Ô´Ë´Î¹¥»÷ÂôÁ¦£¬²¢Ð¹Â¶Á˾ݳƴӸù«Ë¾ÇÔÈ¡µÄÊý¾Ý¡£¸Ã¹«Ë¾Ëæºó¶Ø´Ù¿Í»§ÁôÒâÒì³£»î¶¯ºÍ¿ÉÄܵÄÕ©Æ£¬Í¬Ê±ÓëÕþ¸®Õþ¸®ºÍÍⲿÍøÂçȡ֤ר¼ÒºÏ×÷¼ÌÐøÊӲ졣
https://www.helpnetsecurity.com/2024/03/18/nissan-data-breach/